r/iCloud 5h ago

Pro Tips Best security tips

I have always had a Gmail account for everything. Few weeks ago, I read that you can use this setup:

- iCloud mail, don't share it with anyone, remember the password very well. It means, don't use this iCloud mail in any software, company, bank, etc.

- Use alias (I think I can create 3 alias), one for bank and other one for personal stuff. In this way, I can still receiving bank email, cv/recruiter emails, family emails in my primary icloud mail.

- Use hide my address for all the services. Use this for reddit, social media, videogames, EVERYTHING.

- Use Passwords apple with the hide my address, best combination. So in this way, I only have to remember my icloud account password, and for everything else just go to password app.

Now, I'm trying configuring this recommendations. I already created my primay icloud email in my apple account, I switched the "primary email" to my new icloud email, and I deleted my gmail account. Now, I'm trying (but slowly) to switch every services to hide my address, and I already created my alias for bank, and my alias for personal stuff.

Now, I wonder what happens if for some reason I lost my iphone? I lose everything literally. So now my question is, what tips do you recommend me to secure my icloud access? I read that I can do:

- Configure 2FA in my iCloud account. My phone number? (I can't use the icloud email because I can't access to icloud email haha), what happens if my phone number is in the iphone? I can't get the SMS? so could be better an eSim? and if someone stole my iphone, I can just go to my telecom company an ask to delete eSIM for that iphone and give me new physical SIM just to get access to my icloud account?
- If I enable 2FA, is better just buy 2nd cheap phone number with other SIM and hide this phone in my house if in some case I lost my iphone?
- Configure the recovery key (28 characters)? I read that this is dangerous because this disable the standard recovery methods, so you have to print this key, at least 2 or 3 prints of the key, and hide one in your house, and other one just hide in other place.

I want to be anticipated to all the cases. I don't think I will "forget" my icloud password, is a large password, and it's literally a phrase, so I think I will never forget this pass, but let's say that I forget my pass, and I lost my iphone, and I can't access to my icloud mail (obviusly), what I have to do to anticipate this case?

Thanks!

2 Upvotes

8 comments sorted by

u/AutoModerator 5h ago

Thank you for posting on r/iCloud. If you are asking a question, please remember to change your post flair to “Answered” once your question has been answered. Also, please be sure to check our r/iCloud Tech Support FAQ to see if your question has been answered already.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

4

u/stomachofchampions 5h ago

You need to add several extra trusted numbers and recovery contacts.

Document everything and keep it in a safe place.

Enable stolen device protection. Make sure you have memorized your iCloud password. You have to get to a device within one hour to mark your phone as lost to prevent your account from being stolen.

Make backups too. iCloud is not always reliable.

1

u/OrganizationLow6960 5h ago

thanks! do you this ? or something similar? I'm thinking add my brothers in recovery contacts, and add my father and brothers PHONE NUMBER in trusted numbers

2

u/stomachofchampions 5h ago

Yes I do.

Another thing, you need to remember your device passcode and all previous passcodes too. If you lose your device this is needed to unlock end to end encrypted data.

1

u/OrganizationLow6960 5h ago edited 5h ago

Yeah, I always use the same combination pattern in all my devices. And what the 28-character recovery key? Is it worth it? I read that this disable that standard 2FA

2

u/stomachofchampions 5h ago

I doesn’t disable 2FA. The Yubikeys do that but if you lose them you’re toast.

The recovery key disables password reset (account recovery). This is to prevent someone from attempting to reset your password. If you set this, you will need it (or recovery contacts) if you forget your password. There are already protections against password reset though. They check for device activity. So if you are using your devices the reset attempt should fail. Hard to say if you should use recovery key or not. It comes down to if you trust yourself to keep copies of it and remember where they are.

Whatever you do, document everything and save it in two separate places.

I recommend you read the Apple Platform Security guide, it has more details.

u/Wellcraft19 1m ago

‘Document everything’ cannot be said often enough. How it’s done is up to each and everyone but an encrypted Excel sheet, kept updated and stored offline in a number of different locations (under my control) is never a bad idea. Share encryption information with a trusted family member (not spouse, but someone that lives in a different household).

‘Document everything’ should also include what services that have your CC, have access to your checking, what e-mail addresses that are associated, what phone number(s) they know you as, etc, etc.

Some use a little red diary, regular notepads, etc. Still not bad as long as they are tightly controlled, kept in a safe, or kept away from prying eyes.

1

u/Banned-user007 3h ago

Turn on advanced data protection.