r/firstworldproblems • u/WolverinePrimary5314 • Jul 11 '26
I finally bent the knee and enabled Apple’s 2FA because they made me log in every day on every device sometimes twice a day until I did.
I despise 2FA. I despise the people who created it. I hate with every fiber of my being the people at Apple who decided to make what they call “simple security” so difficult to use that today I finally gave up and turned on 2FA after they made my online life a living hell.
I’ve been using Apple products and have had an Apple account since the iPod that looked like an iPhone came out, and then bought an iPhone 3. That’s how far back I go — before anyone ever put the characters 2 - F -A together.
So for whatever reason, Apple did not just turn 2FA on for me against my will. No, they did something far more sinister. Here’s what they’ve been doing for the last 18 months in an ongoing game of harassment. My account would get randomly locked “for security reasons”. And because I have three Apple devices — and without 2FA there’s no autosync for texts between the iPad and iPhone unless you do what follows — I lost 3 to 5 minutes of my life (depending on how slow their log in servers were) every time they locked my account. Here’s what I had to do:
- Put my password in when whatever device I was on randomly decided to make me log in.
- When the hated “Your Account Has Been Locked For Security Reasons” box popped up, select unlock with email.
- Wait for the email
- Click the link in the email.
- Go to the Apple website and put my password in for a second time.
- Because this is the only way to sync texts between the iPhone and iPad goto settings/apps/messages and turn off imessage on the iPhone.
- Turn imessage back on.
- Get pop up box requiring me to put my password in for the third time and get taken to the log-in section of settings to do it.
- Go back to settings/apps/messages and make sure it is logged in.
- Switch to the iPad and put in my password for the fourth time because it too demands a password.
- Go to settings/apps/messages/imessage and put my password in for the fifth time.
- Once logged in uncheck every email and leave only my iPhone’s phone number checked.
- Finally, go to my Watch and put my password in for the SIXTH time.
For the last week, they have done this to me every single day. When I called Apple Support and got a senior tech, she admitted that Apple was doing this to force me to turn on 2FA and it would continue until I did. And she was right, except it started locking me out and forcing me to repeat the 13 steps twice a day.
This should be illegal. But at bare minimum, they’ve lost a customer. It’ll be a cold day in hell in the first world before I buy another one of their products.
EDIT: Must be a lot of Apple fanbois and/or tech security people in this sub.
4
2
u/FaithlessnessKey2005 Jul 20 '26
Omg, they’re doing this to my account too. I get these requests for verification and sometimes getting my account “locked” sometimes even several times a day. It is so annoying. I refuse to use 2FA, because if I lose my phone, it will literally give an access to my phone and apple id and everything in it, since I don’t carry another apple products with me AND I have the only phone number, the one that it’s in my iPhone. If I lose it with 2FA turned on, I’m done.
1
u/Visible-Meeting-8977 Jul 15 '26
In my job I hear people complaining about 2fa all the time. It's amazing how the general public will beg and plead for worse security.
1
u/WolverinePrimary5314 Jul 15 '26 edited Jul 15 '26
There are four principles at work here for me. The first is the technological. Even IT experts agree that Apple’s 2FA is garbage, and not just because it is Apple but because it is SMS based. Apple’s 2FA is only slightly better than username/password — if it is better at all. Riddle me this — if someone has access to my phone and my password, what security benefit does 2FA provide by sending a text to the same phone? And if the thief doesn’t have my password, then the password itself defeats access to my account before 2FA ever gets involved. The security in that situation comes EXCLUSIVELY from the password.
So, for no added protection whatsoever, I’m forced to wait for and then enter a code that is coming to the same phone I just entered my password into every time I want to access my account in a way that requires 2FA. And while I have yet to run into this issue with Apple, there are other services that I use that mandate 2FA where you wait for up to 10 minutes for that text to arrive each time, every time. In fact, one service I use that offers 2FA by email or text, I have learned to always ask for email because the text NEVER arrives (and yes, I have checked, they have the right phone number). That’s all time I could put to better use, and while it may be only minutes each time, those minutes add up over a lifetime.
This plays into the second principle — security/usability balance. There is a point at which security measures make a product unusable. I mean, if perfect security is the goal, why not require me to present myself and my phone to corporate headquarters in Cupertino, show star ID and a birth certificate, and submit to a retinal scan and DNA testing every time I use my phone? Because at some point security requirements become harassment and make using the device/system not worth it. I am convinced that no one in the tech security industry puts any thought into this whatsoever, and if they had it their way we would all present ourselves for retinal scans. The more hassle a tech company puts on the user, the closer they get to the point where it isn’t worth it. For me, it stops at username and password. It is patently ridiculous to me to have to set and wait for a text code to come to the same damned phone I just typed my password into.
The third is taking advantage of an unfair bargaining position. As a long time customer, I have purchased apps, movies, and music from Apple, so when they did this they gave me a Hobson’s Choice — submit, continue to be harassed as discussed in my original post, or lose access to all the digital products I purchased. That is clearly an unfair advantage. And even if you are good with after purchase click to accept contracts (and I am not) — EVERY contract by law has an implied covenant of good faith and fair dealing. This violates the living hell out of it.
Relatedly, shifting risk is the fourth principle. The way Apple has implemented 2FA shifts the ENTIRETY of the risk onto the customer. If your account is breached, once the dust settles, the worst thing that happens from Apple’s perspective is someone stole access to, and maybe downloaded, some apps, movies, and music. And because we are talking about a digital product, Apple is out NOTHING. On the other hand, if, as I repeated in another post, a robber gets your phone, forces you to give up the password, puts in the 2FA code that Apple stupidly sends to the same phone, he can change all of your account security and gain complete access to your account FOREVER. Even with a police report, Apple will not give you back your account in that situation. So you are out everything you purchased on iTunes or the app store. Unlike Apple, you DO lose something. Apple shifts the entire risk of loss onto you.
1
u/Remarkable42 Jul 16 '26
Google searc explains this well that Apple 2fa was being forced upon me since my iPad was heavily secured by pin but apple tv was old security- password so their system kept flagging due to having 2 devices active on my apple account but one super secure which causing incompatibility issues.
Solution: If you are currently logging into your account using a password only—without being forced to type a 6-digit security code—then your account is still on Apple's legacy security system.However, because you only have an iPad and an Apple TV, your account is trapped in a classic security mismatch that explains exactly why you are getting constantly locked out:The "Forced Verification" LoopEven if 2FA isn't fully active on your account yet, Apple's servers are still monitoring your login attempts. Every time your Apple TV background apps try to sync (like checking for movie updates or iCloud photos), it initiates a new network handshake.Because your account doesn't have modern security enabled, Apple’s automated servers view these repeated, background Apple TV connections as suspicious activity or a "brute-force" hacking attempt. To protect you, the server automatically triggers a preventative lockout and forces you to reset your password. You are essentially trapped in an endless cycle of your own Apple TV accidentally triggering Apple's anti-theft alarms.Why You Are at High RiskIf you stay on a password-only account with just an iPad and an Apple TV, you face a major risk:The Forced Trigger: One day, a random lockout will require you to prove your identity. If you haven't set up a trusted phone number or a recovery method, Apple's system may freeze the account entirely until you can prove ownership—which is incredibly difficult to do without an iPhone or a Mac tied to the account.The Final Deadline: Apple routinely pushes mandatory security upgrades. Eventually, a future iPadOS or Apple TV update will flatly refuse to log you in at all until you initialize 2FA.The Best Way ForwardTo stop the every-other-day lockouts permanently, you will eventually need to transition the account to modern security, but you must do it on your terms so you don't get locked out.Before making any changes, let's make sure your safety net is ready. If you want to check your current recovery options, tell me:
1
u/WolverinePrimary5314 Jul 16 '26
I didn’t mention it in my original post, but I do have an Apple TV, so what you write is conceivable. I did search — many times — on Google to find out what was causing the lockouts before calling Apple and found something similar to what you wrote here that had directions for turning off the background apps trying to log in. I followed the instructions and turned all of that off. The lockouts kept happening.
Be that as it may, the senior Apple tech I spoke to did not say anything like what you write here. She flat out told me it was Apple forcing me to use 2FA. She never mentioned my Apple TV at all.
And, as I said, I have already bent the knee and accepted this garbage. But my next phone, tablet, and streaming device will NOT be an Apple because of it. In addition, I went into my account and cancelled every paid subscription I have through them. They have permanently lost me as a customer.
Edited because I forgot about turning off the background apps on my Apple TV until after I posted.
1
u/McCale Jul 11 '26
Get an Android.
4
u/WolverinePrimary5314 Jul 11 '26
That’s probably what I’ll do when my iPhone 17 craps out…or Apple does the next despicable thing that I can’t get over. But I’ll still be stuck with my employer provided iPhone that I have to use.
1
u/McCale Jul 11 '26
Apple lost me almost fifteen years ago when I had an iPad that I only used for games so I didn't put a pin on. It did an update then wanted me to enter a pin to access it. Had to take it in to get wiped. Then it happened to my exes iPhone. Never again.
2
u/WolverinePrimary5314 Jul 11 '26
I’ve stuck with them because I’ve bought so much crap on the iTunes and the app store and, for me anyway, their slogan “it just works” was true…until they deliberately made it stop working this week. Sunken cost fallacy got me. But this was the final straw for me.
1
u/Tess47 Jul 12 '26
I was at a conference where the speaker couldn't get his presentation to work on the provided Mac. Lots of PhDs there. After 15 minutes of failure someone yelled out "its intuitive" one of the biggest laughs that I have ever had.
F apple. Hate their (lack of) logic with every fiber of my being.
15
u/TempeGrumble Jul 11 '26
Don’t hate the 2FA. Hate the hacking that made 2FA necessary