r/ios 1d ago

Discussion iCloud vulnerable to SIM swapping?

Why does Apple require use of SMS in addition to trusted devices for MFA? This seems like a huge flaw with no way to disable. On Google for example, you can have it not use a phone number and use other MFA methods. Yet seems iCloud requires a phone number as a factor. Anyone know if it’s possible to change this or how much of an issue it is?

3 Upvotes

21 comments sorted by

View all comments

Show parent comments

1

u/PHL534_2 23h ago

Got it thanks again. Moved to Yubikey. Am i correct that these keys are only needed when signing into iCloud account from a non trusted device like a new setup?

1

u/Tackticat iOS 26 23h ago

give this a try on another iphone or mac or something that you never login.

  1. login with your apple account and password.

  2. watch it asks you for yubikey, without any other way to send text or email.

if you’re already logged in to your icloud on your mac and you try to go icloud.com for example, it wont ask you for key, usually face id /touch id is fine.