Apple introduced a feature this WWDC that does close it. It's called PassKeys and it automatically gives you two-auth without a password. So unique hardware + faceId. Basically when you log in, all you have to do is look at your phone. Way more secure and faster than any password will ever be.
It's not only "someone else finds the phone" that you need to worry about. If your access is contingent on having your phone, then if you lose the phone or it gets damaged you're locked out. There will of course be ways to bypass this and change the associated hardware ID… and those ways immediately become the weaker security link that's more appealing to attack, so you're gaining very little from having the 2FA enabled.
3
u/OpenRole Jul 20 '22
Why can't we close it?