<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>iPadOS Archives | nerdsmodo</title>
	<atom:link href="https://nerdsmodo.com/tag/ipados/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Apple Blog: iPhone • iPad • Mac • iOS</description>
	<lastBuildDate>Wed, 23 Sep 2026 16:03:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>https://nerdsmodo.com/wp-content/uploads/2026/02/cropped-img_5063-32x32.png</url>
	<title>iPadOS Archives | nerdsmodo</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">252786843</site>	<item>
		<title>How to Share Files With End-to-End Encryption</title>
		<link>https://nerdsmodo.com/e2ee-file-sharing/</link>
					<comments>https://nerdsmodo.com/e2ee-file-sharing/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 16:03:44 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4838</guid>

					<description><![CDATA[<p>Someone who steals an encrypted vault from a sync service has stolen trash.</p>
<p>The post <a href="https://nerdsmodo.com/e2ee-file-sharing/">How to Share Files With End-to-End Encryption</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Because of the fraught nature of putting your devices or services on them directly in the path of the entire internet, it’s almost always the case that you can share files more easily, with more control, and more securely using a cloud-based sharing service, with a lot of provisos that I describe along with each service.</p>
<p>Each of these services <em>partitions</em> access, so you know precisely what you are letting someone view or download, and whether they can modify, delete, or upload files. You can set a time limit that a link will work, and usually restrict whether something can be downloaded or just viewed online. You may also be able to tell when they access or view files and see exactly what changes they make, if they have permission to modify files.</p>
<p>All the major tech companies offer them, and you may already have free access to substantial storage, or already be paying for a subscription plan or higher level of storage for other purposes.</p>
<p>All these services encrypt data at rest and use encrypted transport (HTTPS, primarily) for uploads, downloads, and link creation. However, if someone can access your account, they can view, delete, modify, download, and add files without restriction.</p>
<p>If you want to share files in a truly secure, end-to-end manner, however, the gold standard is end-to-end encryption (often abbreviated E2EE). With E2EE, the ecosystem you use generates and retains keys only at endpoints, on devices under your control. (Sometimes you’re involved in generating them, but usually the key creation and management is silently handled by the software.)</p>
<p>iCloud.com was never protected by E2EE before December 2022; after that, it became optional for some services if you enabled Advanced Data Protection (ADP). With ADP, <a href="https://nerdsmodo.com/icloud-dropbox-sharing/">iCloud Drive</a> and other items synced, shared, and available via iCloud.com are protected by E2EE for you and with people with whom you share—so long as they also have ADP enabled. See <a href="https://nerdsmodo.com/advanced-data-protection/">how to turn on Advanced Data Protection</a>.</p>
<h2>Layer your own encryption on top</h2>
<p>If you or your shared partners don’t have ADP enabled or can’t turn it on, you can layer E2EE on top of standard secure cloud services, because data that’s encrypted before transfer and stored in these locations remains encrypted, and is only decrypted by endpoints that have the keys.</p>
<p>That is, if you have an encrypted disk image and upload it, that integral encryption isn’t stripped off. If someone downloads the disk image, they still have to break the encryption applied to that data to access what’s inside.</p>
<p>But you can be more sophisticated than a disk image. Software that handles its own encryption—say, the password-management app 1Password—can safely hold and sync its separately encrypted data on a sync service. Someone stealing your 1Password vault has stolen trash.</p>
<p>As of 1Password 8, the app works only with its own syncing system. It used to work with Dropbox and iCloud.</p>
<p>Beyond software that uses E2EE for its internal format are packages that allow generic file sync by effectively tunneling the end-to-end encryption across a sync service! From your perspective, the files are readily available; to everyone in between you and your devices, including the sync services, it’s just a bunch of garbage-looking data. This is a nifty workaround.</p>
<p>I can’t recommend a service, as I don’t use any, but there are two options you can test for this purpose that are Mac compatible:</p>
<ul>
<li>Cryptomator is an open-source solution to create an encrypted package, called a vault. It’s free to use on Mac, Windows, and Linux. The Android and iPhone/iPad apps have a one-time €19.99 (about US$23) purchase price to cover development costs.</li>
<li>VeraCrypt is also free, open-source software for creating virtual encrypted disks or partitions. However, the project supports desktop operating systems only: Linux, macOS, and Windows.</li>
</ul>
<p>Cloud sync services usually reduce data transfer required by syncing only changed portions of files. (Unix folks call it the <em>diff</em> after a command-line tool; <em>delta encoding</em> is a more exact technical term.)</p>
<p>With encrypted files you upload, large portions of the file or the entire file change whenever it’s modified, resulting in a lot of data synced. However, Apple’s bundle form of disk images and some third-party software breaks large files into smaller ones to solve this problem. Only those sub-portions are changed, resulting in less syncing.</p>
<h2>Encrypted messaging with others</h2>
<p>Apple enabled E2EE with Android users for messaging over RCS, an industry standard Google championed. However, be sure to check when you start messaging with someone using RCS that their Android device has RCS encryption enabled. You can see whether it’s enabled in Messages: an Encrypted label appears at the top of the conversation, or inline if the encryption method changes. (If you had an ongoing conversation with someone over RCS, upgraded your device, and they have encryption enabled, an inline message in the conversation would appear.)</p>
<p>If you want to use E2EE to exchange data with others, you can use options like GPG Suite ($23.90 per year, 30-day trial, Mac only), which manages public-key encryption data for you, and lets you exchange encrypted files via email with anyone else who uses PGP- or GPG-compatible software. (PGP is a decades-old implementation of public-key encryption; GPG is the GNU, free-software version.)</p>
<p>If you trust other parties to manage the process, you can use iMessage or Signal. In early 2021, Apple quietly overhauled iMessage’s innards to make it more robust, but still needs to publish its spec and allow outside auditing. The company quickly had to patch major exploits found in their update in September 2021, making an even better case for allowing more eyes on the problem.</p>
<p>In May 2025, people were baffled that they couldn’t type “Dave &amp; Buster’s” and similar ampersand-containing names into Messages. Turns out, Messages transformed the ampersand into something that triggered the protection! Apple fixed it, but it showed it worked?</p>
<p>Despite Apple’s lack of full transparency, iMessage remains trustworthy. Signal is created by an organization devoted to privacy, and has proven itself a great way to avoid interception.</p>
<p>The post <a href="https://nerdsmodo.com/e2ee-file-sharing/">How to Share Files With End-to-End Encryption</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/e2ee-file-sharing/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4838</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5614-2.jpg" />	</item>
		<item>
		<title>Do You Need More Security Than Apple’s Defaults?</title>
		<link>https://nerdsmodo.com/security-risk-profile/</link>
					<comments>https://nerdsmodo.com/security-risk-profile/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:49:07 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4837</guid>

					<description><![CDATA[<p>Phishing and social engineering overtook malware as the main risk years ago.</p>
<p>The post <a href="https://nerdsmodo.com/security-risk-profile/">Do You Need More Security Than Apple’s Defaults?</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In a TidBITS article, Evaluating Wireless Security Needs: The Three L’s, Adam Engst laid out the three factors he considered relevant to determining one’s risk when it comes to Wi-Fi security. He called them the three L’s: <em>likelihood</em> (the probability that someone will violate your security), <em>liability</em> (the cost—financial or otherwise—that you’d incur if a security breach happened), and <em>lost opportunity</em> (what you lose in terms of time and convenience by implementing stronger security). That article is still well worth a read almost two decades later.</p>
<p>Times, technologies, and threats change, but some people still face greater risks than others. If you can assess your own level of risk soberly, you’ll be able to take appropriate measures—neither too weak nor too strong.</p>
<h2>The risk for most people</h2>
<p>Years ago, it made more sense for nearly all Mac owners to consider their susceptibility to outside attack: how likely were you to visit sketchy sites, download applications that might contain Trojan horses, be infected by malware by visiting a site or running software, or even configure a network sharing setting that allowed people on the internet to scan and find weaknesses they could use to potentially copy data from your Mac, or worse. iPhone and then iPad users had fewer risks because of how iOS and iPadOS were constructed and locked down, but external attacks remained the central problem for them.</p>
<p>That profile changed considerably by the late 2010s. The biggest risk that most Apple users have faced since then—no matter their specific Apple hardware—comes from phishing and <em>social engineering</em>.</p>
<p>Phishing describes when someone impersonates a person, group, or website in the hopes you will click through and be infected by malware or enter login credentials. Phishers want your personal data, preferably financial information, such as your credit card number, expiration date, and verification code. They try to offer credible-looking security warnings and fraudulent webpages where you enter payment information or credentials they can use to access your bank and other accounts.</p>
<p>Social engineering is when people attempt to convince you to do something harmful to your device—and compromise your security and privacy. A common scam is that you visit a website and are redirected to another site (via malicious advertising or injected code) that claims your computer, phone, or tablet is infected and urges you to call a number. Calling that number leads you to a boiler room in which the other parties try to get you to install remote access software and sign up for expensive, hard-to-cancel tech services—or worse.</p>
<p>There are also more general attackers, who want to fool you into installing Mac apps that appear to be legitimate, but actually encrypt your personal files and hold them for ransom (<em>ransomware</em>). iOS and iPadOS don’t allow this vector because of how apps are installed and files managed. And even after over a decade into what remains rampant use of ransomware, that scourge hasn’t found a foothold on Mac.</p>
<p>From the mid-2020s, I would also argue that governments of democracies have increasingly chosen to enact laws or stretch the limits of existing ones to intrude into our private spaces, including accessing data that they would never previously have considered due to pushback from both ends of the political spectrum and, in some countries, a strong libertarian philosophy on the primacy of privacy.</p>
<p>Even if you don’t believe you fit in a category where the government of the place you reside would target you personally, you should assume your risk is elevated in any country that is sweeping away previous protections in the vague interests of “protecting children” even when no children are involved and “national security” when no national security interests are shown.</p>
<h2>The high value of privacy violations</h2>
<p>Some unwanted software doesn’t mess up a device or steal data, but installs <em>adware</em> that can display rogue ads (overlaying ones served by webpages), hijack web searches, and redirect affiliate clicks through portals controlled by the operators to make money illegitimately off you from advertisers. Other software is more insidious, tracking your location to sell it to companies that target you with ads—it’s a kind of malware, even if it doesn’t subvert the device.</p>
<p>The most obvious vector is a Mac, where you can install third-party software that isn’t vetted by Apple. But given that you can install extensions in Safari for the iPhone, iPad, or Mac, and that Apple has routinely failed to catch App Store apps that violate user privacy or include adware components, you can be at risk on any platform. Fortunately, so far, I have heard of no iPhone or iPad examples.</p>
<p>To step up protections, you can engage any or all of the following security or software integrity steps that reduce the area of attack on you that could succeed:</p>
<ul>
<li><strong>Two-factor authentication (2FA):</strong> This extra step for logging in deters attackers who have phished or otherwise obtained your password. Apple requires 2FA for Apple Accounts (with a few legacy exceptions), limiting access to iCloud-synced information, purchases, email, and much more. Most non-Apple services offer code-based 2FA (sent via SMS) or other ways to validate a password login. To compromise your account, someone has to obtain your SMS messages, your trusted devices, or your authentication app.</li>
</ul>
<p>Some phishers perform a “two-step” attack in which they convince you not only to enter your account name and password on a site, but then also relay that information in real time to the actual site you intended to access. This causes the real site to send you a confirmation code (or the fake site requests that you generate one). The attackers capture that code when you enter it. However, that scam works only for brief periods, as short as one minute.</p>
<ul>
<li><strong>Passkey:</strong> Upgrade accounts at websites that support <em>passkeys</em>, a secure method of logging in that’s deeply embedded on iPhones, iPads, and Macs, and supported by Google and Microsoft. The secret part of a passkey is never transmitted over the internet, and a passkey is phishing-resistant. You can sync and share passkeys when using recent operating systems and password managers. I’ve shifted from tolerating passkeys to preferring them to a password-and-second-factor combo. See <a href="https://nerdsmodo.com/apple-passwords-passkeys/">where Apple stores your passwords and passkeys</a>.</li>
</ul>
<p>Sounds great, right? But passkeys are, in every case I’m aware of, a supplemented to two-factor-protected accounts, not a replacement. Until you can make a passkey replace a regular login (with some kind of recovery option), they’re only as secure as the next-weakest link in the chain.</p>
<ul>
<li>
<strong>Hardware security key:</strong> Another form of 2FA, a relative of a passkey, is a hardware security key. These small physical objects plug into a USB or Lightning port or can connect via NFC to iPhones or iPads. The hardware key has embedded encryption circuitry that generates a unique, highly secure login key for each site you use it with. These keys are built on a standard nearly identical to the technology underlying passkeys, and most websites that support passkeys can accept a hardware security key and vice versa. (These keys also rarely fully replace access to an account yet, meaning a flaw in password and two-factor authentication could compromise access.)
</li>
<li>
<strong>Apple Pay:</strong> Avoid sites that don’t let you pay by Apple Pay, which prevents your credit-card number from being transmitted directly.
</li>
<li>
<strong>Install financial apps:</strong> Financial apps and their associated notifications make it more likely you will know immediately if any part of your financial life has been manipulated without permission. I’ve noticed a trend since 2024 for financial apps that support Face ID or Touch ID to let you log in from a desktop browser using a QR code or a push notification from the app. You then verify via biometrics, so you’re never entering any credentials in a browser.
</li>
</ul>
<p>Apple already blocks the direct installation of unsigned software on a Mac—apps that were released by people without an Apple Developer account or who bypassed Apple’s minimally involved signing system. By not allowing the easy installation of unsigned software, Apple prevents most malicious software from running at all. See <a href="https://nerdsmodo.com/gatekeeper-mac/">how Gatekeeper decides which Mac apps can run</a>.</p>
<ul>
<li><strong>Continuous backups:</strong> The technology for making constant, secure online backups of documents and creating local clones and backups obviates risks more present now than in the past when those options were slow, expensive, or not feasible due to cost or bandwidth limitations. Having such backups in place gives you a point to revert to if you have data corruption or loss.</li>
<li><strong>End-to-end encryption (E2EE) for iCloud:</strong> Apple’s Advanced Data Protection lets iCloud users put media, notes, reminders, and iCloud Drive files under the gold standard of end-to-end encryption, which requires possession of a device and the means to unlock to access data. Because we may store details that can be used to exploit us in these various kinds of media, E2EE is another leg up on attackers. See <a href="https://nerdsmodo.com/advanced-data-protection/">how to turn on Advanced Data Protection</a>.</li>
</ul>
<p>By using Apple and industry technologies and safeguards and keeping backups current, you can dramatically reduce your likelihood of risks while also curtailing the liability that results. Even if you’re infected by ransomware—an unlikely event—and don’t want to pay, you might lose <em>no</em> files by reverting to a snapshot before the attack; or if someone guesses or obtains an account login, you’re alerted as they try to log in, so you can change the password, or they’re blocked entirely without a second factor or hardware element.</p>
<p>The change in our general risk profile over time, however, comes with one big flashing red light. I noted a couple of times above that most people only need to take certain default strong, reasonable measures. However, if you’re someone in particular fields of work or who engages in political advocacy, you may face <a href="https://nerdsmodo.com/elevated-security-risk/">targeted attacks</a> that evade basic measures that suffice for everyone else.</p>
<p>A human-rights reformer in an incipient dictatorship needs to take more safeguards than a suburban online shopper in Ohio. But identity theft can sometimes lift that Ohioan—or you—into a much higher category of risk, because someone decides your assets or information are valuable to them, and they’ve acquired credentials or personal information that will let them attempt to crack your security shell.</p>
<h2>What about children?</h2>
<p>If your minor child has their own iPhone, iPad, or Mac, you might assume they are at very low risk. After all, their device probably contains nothing but games, educational software, a school-provided office suite, and a browser playing videos from Disney+.</p>
<p>But no! Sad to say, children are at greater risk than adults, all else being equal, because they’re less experienced and more trusting—and because, let’s face it, there are a lot of creeps out there who stalk children online.</p>
<p>If you travel to a country with severe laws or a propensity to jail people without legitimate charges, you should raise your risk profile before you travel and while there.</p>
<p>The post <a href="https://nerdsmodo.com/security-risk-profile/">Do You Need More Security Than Apple’s Defaults?</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/security-risk-profile/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4837</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5048.jpg" />	</item>
		<item>
		<title>How to Set an iPhone Passcode Stronger Than Six Digits</title>
		<link>https://nerdsmodo.com/iphone-passcode-strength/</link>
					<comments>https://nerdsmodo.com/iphone-passcode-strength/#respond</comments>
		
		<dc:creator><![CDATA[Moses Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:37:50 +0000</pubDate>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4836</guid>

					<description><![CDATA[<p>A three-word passcode takes centuries to crack; six digits takes a minute.</p>
<p>The post <a href="https://nerdsmodo.com/iphone-passcode-strength/">How to Set an iPhone Passcode Stronger Than Six Digits</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Your single best protection against anyone unauthorized having access to data is enabling the passcode lock. This allows you to set a code required to wake and gain access to the device.</p>
<p>When Touch ID or Face ID is enabled, you must also have a passcode set, and Apple will ask you for that passcode on a regular basis.</p>
<p>A small number of people seem to avoid adding a passcode to their devices. That is extremely dangerous given how much of our lives can be affected by someone gaining access to an iPhone or other device. So the place to start is making your passcode stronger.</p>
<h2>Set up a passcode</h2>
<p>If you are setting up a new phone or helping someone else, here are the basics, just in case:</p>
<ol>
<li>Go to Settings &gt; Touch ID &amp; Passcode or Face ID &amp; Passcode.</li>
<li>Tap Turn Passcode On.</li>
<li>If you want to use the default, a six-digit passcode, tap it in and re-enter it when prompted.</li>
</ol>
<p>Passcode Options, below, lets you pick an alphanumeric password of letters, punctuation, and numbers.</p>
<p>Many mobile security gurus say that not only are four digits too few to resist cracking, but six aren’t enough, either (six being the default that Apple now suggests when you set up an iPhone or iPad). Experts recommend picking something that’s as long as you’re comfortable with while remaining memorable, with six digits being the absolute minimum.</p>
<p>Picking a three-word phrase separated by a punctuation character is often recommended and provides real security, but can be a pain to enter over and over again. (This is what I do.) For instance, <code>horse-stapler-cracker</code> is 100 million times more difficult to crack than <code>672940</code> through brute force algorithms. The former could take under a minute, depending on the hardware; the latter, a couple of centuries.</p>
<p>Apple lets you change your passcode whenever you like via Settings &gt; Touch ID/Face ID &amp; Passcode &gt; Change Password, so you can improve your password today. To choose a stronger password than one that’s six digits long, tap Passcode Options and then tap Custom Alphanumeric Code.</p>
<p>Make sure that however many words it is, it’s at least 20 characters with a special character (like a hyphen) dividing them.</p>
<p>Apple has built-in features to prevent tapping in passwords rapidly using an onscreen keyboard or through external hardware, making even weak passwords difficult to crack when they’re not <code>0000</code> or <code>4567</code>. However, from time to time, companies that provide software to law enforcement and governments have developed workarounds. These hacks typically work only for short periods.</p>
<p>There’s one big waving flag you should notice—what’s the opposite of a warning flag? Your iPhone or iPad retains the previous passcode for 72 hours. Apple lets you know you aren’t sunk if you forget your password during that grace period.</p>
<p>You can also enable the passcode lock remotely if you have an active iCloud account and Find My iPhone enabled on the device.</p>
<h2>Require passcode and lock screen access</h2>
<p>The Require Passcode option offers a few choices if you don’t enable Touch ID or Face ID, depending on your device:</p>
<ul>
<li>With Immediately, you’re asked for the passcode whenever the device wakes—this is also the only option for Touch ID and Face ID. (You can set it to sleep automatically, using Settings &gt; Display &amp; Brightness &gt; Auto-Lock.)</li>
<li>Longer intervals let the device be unlocked without a passcode for up to the time duration you’ve chosen from the list.</li>
</ul>
<p>In the Allow Access When Locked section, you can also set which services are available when your device is locked, which is a good way to prevent leakage of information, such as viewing appointments, having access to Siri, or using Messages to reply.</p>
<p>This list used to be a few items long. Now it has 11 choices!</p>
<p>As a nuclear option, you can set your device to self-destruct—destroy its data, at least—by switching on Erase Data at the bottom of the settings list. If there are more than ten failed attempts to enter the passcode, boom! What do you lose? Only items created since the last iCloud backup (or Finder sync if you back up via a Mac).</p>
<p>Apple says entering the same wrong passcode doesn’t count toward the ten failed attempts limit.</p>
<p>A passcode may be required in several cases, as described in <a href="https://nerdsmodo.com/touch-id-face-id-setup/">how to set up Touch ID and Face ID</a>.</p>
<h2>Revert to a passcode for safety</h2>
<p>There will be times when you will want to revert to a passcode instead of Touch ID or Face ID for personal safety, extra security, or in certain legal situations. In the United States, while the law isn’t yet fully established, it appears that in criminal proceedings, the government can compel the use of a fingerprint but can’t compel you to give up your password.</p>
<p>You can accidentally trigger an Emergency SOS call when using some of the below sequences. Apple’s support site explains how to avoid that.</p>
<p>If you want to force the operating system to disable Touch ID or Face ID, you can:</p>
<ul>
<li><strong>Power down:</strong> Power down your device via Settings &gt; General &gt; Shut Down or one of the methods below. On restart, it’s disabled.</li>
<li><strong>Disable biometrics:</strong> You can use a feature designed for emergencies to disable biometrics. With all new phones starting in 2017, holding down either volume button and the side/top button disables Touch ID and Face ID, while bringing up the Slide To Power Off option. You can tap Cancel, which prompts entry of the passcode, or use the slide to power down.</li>
<li><strong>Five bad logins:</strong> Make five bad login attempts with your finger or face.</li>
<li><strong>Use Medical ID on an iPhone:</strong> Tap or press the side or top button and swipe to show a passcode screen without using an enrolled fingerprint or having your face straight on. Tap the Emergency link and then Medical ID. After you exit Medical ID, a passcode must be used to unlock the phone.</li>
</ul>
<p>The post <a href="https://nerdsmodo.com/iphone-passcode-strength/">How to Set an iPhone Passcode Stronger Than Six Digits</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/iphone-passcode-strength/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4836</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5674.jpg" />	</item>
		<item>
		<title>How to Set Up Automatic Security Updates on Apple Devices</title>
		<link>https://nerdsmodo.com/apple-security-updates/</link>
					<comments>https://nerdsmodo.com/apple-security-updates/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:22:50 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4835</guid>

					<description><![CDATA[<p>Apple patches most flaws before they are exploited, if you let it.</p>
<p>The post <a href="https://nerdsmodo.com/apple-security-updates/">How to Set Up Automatic Security Updates on Apple Devices</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>It’s a fact of life: software has bugs. And some of those bugs result in security vulnerabilities. Fortunately, most major software vendors, including Apple, have teams of programmers working constantly to identify and fix security-related bugs.</p>
<p>I can’t tell you how many times I’ve read breathless news reports about some newly discovered and seemingly disastrous Apple security issue, only to see a software update from Apple fix it a few days later before any damage occurs. This is Apple’s normal pattern, and it’s why you should never lose sleep about the security crisis <em>du jour</em>.</p>
<p>However, Apple security updates don’t help unless you install them! If you have automatic software updates turned off and ignore alerts or badges, you could be needlessly putting your devices and your data at risk from problems that were solved months or years ago.</p>
<p>Software updates fall into several categories, <em>all</em> of which can fix security issues:</p>
<ul>
<li>Major upgrades, such as from <a href="https://nerdsmodo.com/how-to-install-macos/">macOS 26 Tahoe to macOS 27 Golden Gate</a> or <a href="https://nerdsmodo.com/how-to-install-ios/">iOS 26 to iOS 27</a></li>
<li>Minor updates, which can be small increments for big fixes (27.1.0 to 27.1.1), or larger ones when they include feature changes but not a full operating system upgrade (such as 27.0.1 to 27.1)</li>
<li>Standalone security updates that fix specific pieces of system software, usually stuff deep beneath the surface (most common with a Mac)</li>
<li>Updates to individual Apple apps (Safari, Music, Books, QuickTime Player, etc.)</li>
<li>Updates to third-party apps</li>
</ul>
<p>Which of these should you keep up with? Ideally, all of them, but at a bare minimum, install the standalone security updates. After confirming you haven’t heard of any problems others have had, install minor updates. Major updates require more planning and involve much more than security fixes.</p>
<p>To learn about all Apple software updates with security implications, see the Apple security releases page. Click a specific update to read the security details.</p>
<h2>Zero-day exploits</h2>
<p>Apple, Google, Microsoft, security firms, anti-malware software developers, independent security consultants, and “gray-hat” hackers (not criminals, but they don’t always play by the rules—or laws) are constantly on the lookout for significant flaws to fix them and release updates before they become a <em>zero-day exploit</em> or <em>zero-day attack</em>. That’s when there’s literally <em>zero days</em> to patch the problem.</p>
<p>Malicious parties—including nation-state actors, such as the security agencies of major countries—may hold zero-days in reserve or use them in such a limited fashion that they remain available for some time. It’s the job of all software developers to patch zero-days before they’re exploited.</p>
<p>It’s much more often the case that ugly bugs are fixed by Apple before they’re exploited in the wild; or the exploit is so tricky, it requires physical device access or incredible sophistication, timing, and targeting. Apple will flag particularly severe exploits and recommend immediate installation when necessary. This happened on April 16, 2025, when Apple pushed out updates across their operating systems to fix zero-day exploits that the company said were already used in the wild in individually targeted attacks.</p>
<p>Zero-day exploits that aren’t reported to Apple and other companies responsibly—sometimes for significant “bug bounties” these firms and zero-day projects pay out—are sold on the gray market and used for pinpoint government operations. These are often ones most people would feel are illegitimate or violate human rights, such as three separate zero days used allegedly by the United Arab Emirates to hijack a single human-rights advocate in their country.</p>
<p>In most cases, Apple releases security updates for the current version of macOS, iOS, and iPadOS, and the previous three—or even four. If you aren’t at least on the third-most-recent version of one of these operating systems, you risk being vulnerable to known security problems that Apple won’t ever fix.</p>
<p>Apple also looks backward quite a ways with hardware, letting you upgrade fairly old Macs, iPhones, and iPads to at least one of the third-oldest operating systems, if not the current one. With Golden Gate, support covers all Apple silicon Macs; Tahoe included four Intel models from 2019 and 2020. iOS 26 and 27 look back to the iPhone 11 series (2019), while the cutoff points for iPadOS 26 and iPadOS 27 are very complicated.</p>
<p>Often the initial releases of new operating system versions (27.0.0, say) have significant bugs that Apple fixes quickly. So it’s fine to wait a few weeks on major upgrades, by which time enough others will have tried out the new release that you can judge how stable it may be for you.</p>
<p>Apple delivers minor and major updates and security updates through Software Update: go to System Settings (Mac) or Settings (iPhone/iPad) &gt; General &gt; Software Update.</p>
<h2>Configure automatic security updates</h2>
<p>Apple wants you to install updates as soon as possible on all its operating systems. The approach you take may be different between a Mac and an iPhone or iPad.</p>
<h3>On a Mac</h3>
<p>Software Update shows whether you’re up to date and notes any available updates if you are not. If you’re a major system update behind (or further), it also shows an area at the top urging you to install it. In a secondary area below, the pane may read “Another update is available” for Safari and security updates, and you have to click “More info” to discover which are and proceed to install them.</p>
<p>It also runs in the background and displays a red badge in System Settings indicating quantity. You can’t disable this.</p>
<p>You can completely automate minor macOS, security, and other updates—in fact, that’s the default. (Major macOS updates require direct action.) Go to System Settings &gt; General &gt; Software Update and, to the right of Automatic Updates, click the info button to see settings and make changes.</p>
<ul>
<li><strong>Download new updates when available:</strong> This includes all the updates listed below. The advantage is that they are either installed automatically or available for immediate installation if you install manually. Disable this if you’re bandwidth-limited or pay for bandwidth and want to plan downloads.</li>
<li><strong>Install macOS updates:</strong> This includes all “dot” updates, like moving from 27.0.0 to 27.0.1 <em>and</em> from 27.0.1 to 27.1.0.</li>
<li><strong>Install system data files and security updates (Golden Gate) or Security Responses and System files (Tahoe):</strong> Apple used to use the term “Rapid Security Response” for these security updates; I’m guessing they now incorporate more kinds of security fixes? Previously, the company explained those updates addressed exploits that Apple discovered were already happening in the wild, not just identified by researchers. These fixes are installed automatically when this option is turned on—no reboot required.</li>
</ul>
<p>Apple moved automatic App Store updates from Software Update to the App Store app in macOS 26.</p>
<p>In most cases, you can view a list of available updates, deselect or select items in the list, select items to view their contents, and click Install Now to proceed towards installation. Updates that require restarting your Mac are marked with “Restart Required” after their title in the detail section, and you’re warned when you click Install Now that you will need to let the updater restart your Mac to complete the update.</p>
<p>The next major operating system update past what you’re running used to appear as a short entry with a More Info link. But in Monterey, Apple transformed the upgrade notice into a full advertisement that listed all the available features. Minor updates still use the More Info link to tell you what to expect.</p>
<p>When preparing to install updates that require a restart, make sure you have no unsaved files, no open Terminal windows, and nothing in progress in an app. Often, this can halt a restart—particularly an issue if you walk away hoping to return with the update done. I always wait until my Mac restarts before leaving.</p>
<p>In addition to the Software Update setting for system data files and security updates, make sure the setting introduced in macOS 26.1 is enabled: System Settings &gt; Privacy &amp; Security &gt; Background Security Improvement. With this enabled, Apple can update certain parts of the system, such as components of Safari and system libraries used by multiple apps, without requiring a full incremental update and restart.</p>
<h3>On an iPhone or iPad</h3>
<p>Software Update on an iPhone or iPad, in Settings &gt; General &gt; Software Updates &gt; Automatic Updates, offers options similar to those on a Mac. If you enabled Automatically Install, you’re alerted that an update will happen overnight the next time the device is plugged in and idle. This option also hides the next two: Automatically Download and System Files &gt; Automatically Install.</p>
<p>Even if you don’t want updates to be installed automatically, enabling downloads for iOS/iPadOS Updates lets you avoid waiting for a download to happen when you make the decision to trigger an update manually—the file is ready to go.</p>
<p>Everyone should leave System Files enabled for automatic updates, for the reasons given above.</p>
<p>As with macOS, Background Security Improvements should also be turned on. Go to Settings &gt; Privacy &amp; Security &gt; Background Security Improvements, and make sure it’s enabled.</p>
<h2>Configure App Store updates</h2>
<p>The App Store is where you buy apps and acquire free apps, including those with in-app purchases, that have gone through additional layers of vetting by Apple. One advantage is that you don’t need to use the app or visit a website to check whether the latest version is installed.</p>
<p>On a Mac, the App Store has an Updates item in its left-hand navigation bar. Click that, and you can see available updates. You can also use App Store’s Preferences to control automatic updates: select or deselect Automatic Updates.</p>
<p>On iPhone/iPad, the default is for updates to be quietly updated in the background. You can change this in Settings &gt; Apps &gt; App Store, where you can disable App Updates. You can see the queue of updates waiting to happen in the App Store app: tap the account button in the upper-right corner and then tap App Updates. Any apps with pending updates appear under an Upcoming Automatic Updates label. You can force a check for updates by swiping down and releasing, and you can tap Update All to force an immediate app update.</p>
<h2>Update everything else on a Mac</h2>
<p>Software that didn’t come from the Mac App Store must be updated separately. Fortunately, most apps include an automatic, configurable update check whenever you launch them, and also check for updates periodically. You can disable this in nearly all apps, though I recommend keeping the feature on, or enabling it if it’s turned off by default.</p>
<p>If you haven’t seen update notifications lately, or aren’t sure how your favorite apps have automatic updates configured, now is the time to check. Launch each app, select its option to check, and install updates.</p>
<p>Some apps use “check for updates” as a way to sell you on a paid <em>upgrade</em> to the next version of the product. I don’t mind seeing this once or twice, but some software I use brings up a paid update available message at every launch; not cool.</p>
<h2>How Apple numbers its releases</h2>
<p>Starting with fall 2025 operating system releases, Apple reset their numbering system to the last two digits of the following year, starting with 26. So 2026 releases are iOS 27, iPadOS 27, macOS 27 Golden Gate, tvOS 27, and watchOS 27; and 2025 releases were iOS 26, iPadOS 26, macOS 26 Tahoe, tvOS 26, and watchOS 26.</p>
<p>The post <a href="https://nerdsmodo.com/apple-security-updates/">How to Set Up Automatic Security Updates on Apple Devices</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/apple-security-updates/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4835</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5613.jpg" />	</item>
		<item>
		<title>What Private Wi-Fi Address Does, and When to Change It</title>
		<link>https://nerdsmodo.com/private-wifi-address/</link>
					<comments>https://nerdsmodo.com/private-wifi-address/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:12:10 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4834</guid>

					<description><![CDATA[<p>A hardware address that never changes lets a network recognise you for years.</p>
<p>The post <a href="https://nerdsmodo.com/private-wifi-address/">What Private Wi-Fi Address Does, and When to Change It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Apple built in privacy protection for an issue adjacent to <a href="https://nerdsmodo.com/mac-public-ip-address/">your IP address</a>. Every Ethernet or Wi-Fi adapter, built in or plugged in, has a unique MAC address—that’s Media Access Control, not Macintosh. A MAC address appears in the form <code>xx:xx:xx:xx:xx:xx</code>, where each <code>x</code> is a value between 0 and 15 expressed in hexadecimal (0 to 9 then A to F). Apple perplexingly calls it a “Wi-Fi address”, which is the incorrect name.</p>
<p>A MAC address is how a device communicates over a local network, used to make sure every interface has a unique address to avoid data being delivered to the wrong location. However, because this MAC address is set in hardware, clever hackers and marketers started to use it to associate people with devices—your MAC address persisted indefinitely, so a Wi-Fi router in a public place could conceivably track you over time whenever you connected to any router that shared information with a central database, like a cell carrier or ad-targeting service. Bad!</p>
<p>Apple got around this by adding a “Private Wi-Fi address” option (still the wrong term) that generates a unique MAC address for each Wi-Fi network you join, changing it from time to time. This deters and potentially fully prevents MAC-based tracking.</p>
<p>Apple made significant changes to this several-year-old feature in iOS 18/iPadOS 18, macOS 15 Sequoia, and watchOS 11.</p>
<p>You can configure “Private Wi-Fi address” in one of three ways:</p>
<ul>
<li><strong>Off:</strong> The actual unique MAC address is sent to the router.</li>
<li><strong>Fixed:</strong> Your device generates a MAC address that’s used consistently for the selected Wi-Fi network. This may be required in some places in which a MAC address is used as part of a hotspot portal’s permission system that grants you access or in corporate environments when you’re a guest. Your home router may even offer an option to set a fixed private IP address using a MAC address, so your MAC address needs to be fixed.</li>
<li><strong>Rotating:</strong> The private address that’s generated is changed to a new, randomly created one every two weeks, whether you’re connecting in that period or after a gap of two weeks or longer.</li>
</ul>
<p>Apple defaults to either Fixed or Rotating. It uses Fixed the first time you connect to a network with relatively modern Wi-Fi network security—WPA2 or later, to use the technical term. A network without such security, either using outdated standards or requiring no passwords, such as at an open Wi-Fi network at a café, is set to Rotating by default. You have to choose Off, read a warning, and confirm.</p>
<p>The options to change the type of Private Wi-Fi Address used with a network vary by operating system:</p>
<ul>
<li>
<strong>iPhone/iPad:</strong> Go to Settings &gt; Wi-Fi: tap the info button next to the currently connected network or any other network that appears. You can also tap Edit, and then tap the info button next to any stored network.
</li>
<li>
<strong>Mac:</strong> Go to System Settings &gt; Wi-Fi &gt; Details for the active network. For other networks, click the More button; for Known Networks, then choose Network Settings.
</li>
</ul>
<p>To see the underlying Wi-Fi adapter’s hardware-set MAC address, go to Settings &gt; General &gt; About and look for Wi-Fi Address on an iPhone or iPad. On a Mac, follow the path of System Settings &gt; Wi-Fi, click the Advanced button, and see Wi-Fi MAC Address near the top.</p>
<p>The post <a href="https://nerdsmodo.com/private-wifi-address/">What Private Wi-Fi Address Does, and When to Change It</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/private-wifi-address/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4834</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2023/04/img_2098.jpg" />	</item>
		<item>
		<title>Where Apple Stores Your Passwords and Passkeys</title>
		<link>https://nerdsmodo.com/apple-passwords-passkeys/</link>
					<comments>https://nerdsmodo.com/apple-passwords-passkeys/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 13:56:59 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4831</guid>

					<description><![CDATA[<p>Apple never learns your device passcode, even while syncing your passwords.</p>
<p>The post <a href="https://nerdsmodo.com/apple-passwords-passkeys/">Where Apple Stores Your Passwords and Passkeys</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The topic of passwords is huge. The key security aspect is narrower: how you <em>secure</em> them.</p>
<p>Apple devices can store and sync passwords in many ways, each with a different risk profile. What follows is how Apple and third-party apps store passwords, and the gold standard for syncing them among devices without increasing the likelihood they could be accessed—even by the company storing them for you.</p>
<p>Apple added <em>passkeys</em> in 2022, a more secure method of logging into a website without leaking secrets and while offering phishing resistance. You use them in lieu of a password plus a second factor, as they combine the same functions. Apple has integrated passkeys into their overall password-management and fill-in approach.</p>
<p>Starting in Sonoma and iOS 17/iPadOS 17, you can also create sharing groups with other people that include both passwords and passkeys. This solves an issue where you may share account access with family members or colleagues but still want the security of a passkey. (This is managed through the Passwords app.)</p>
<p>Apple lets you log in with a passkey to your account on their Apple Account website. This was added to let you log in securely when you weren’t able to use either Touch ID/Face ID or two-factor authentication. For instance, if you’re using a browser on someone else’s Mac and don’t want to enter the password, or you’re connecting via a Google browser on an Android phone.</p>
<p>Apple’s Passwords app can generate a verification code required for login with many two-factor authentication systems and store it as part of a website password entry. Not <em>Apple’s</em>, of course, just all the others.</p>
<h2>Hardware security keys</h2>
<p>In early 2023, Apple also added direct support for Apple Account logins on devices and their Apple Account website using a standard closely related to passkeys that stores unique login information on a removable hardware security key. These hardware security keys incorporate industry standards, making them compatible across mobile devices and desktop computers, as well as working with websites and native support built into operating systems.</p>
<p>Hardware security keys have to be activated, whether you’re using them with your Apple Account or on a website (Apple’s or anyone’s). On your Mac, iPhone, or iPad, you insert a key into a port (USB Type A, USB-C, or Lightning) or, with an iPhone or iPad, bring a key with NFC near your device. You then press a trigger on the key to start the interaction.</p>
<p>Hardware security keys are obviously physical items you need to exercise distinct precautions around. Their contents are one-way vaults, much like the Secure Enclave in Apple hardware, and can’t be backed up. Make sure you have safeguards in place to avoid losing or damaging them, and to ensure they’re not stolen. Treat them like a stack of $100 bills.</p>
<p>Apple requires <em>two</em> hardware security keys to enroll in that method for your Apple Account, for just that reason. If one is broken or lost, hey, you have a second. You can enroll more than two.</p>
<h2>Where your secrets reside</h2>
<p>Starting with iOS 18, iPadOS 18, and macOS 15 Sequoia, Apple made the Passwords app the primary built-in interface for accessing secrets, whether website logins or app passwords. Previously, Apple had a Settings section for Passwords in iOS and iPadOS, and a Passwords tab in Safari for macOS.</p>
<p>Even earlier, Apple steered you to Keychain Access, a utility that still exists, and which provides lower-level access to all manner of passwords, codes, secrets, and certificates managed on your Mac. See <a href="https://nerdsmodo.com/mac-keychain-security/">how the Mac keychain works</a>. There’s no iOS/iPadOS equivalent.</p>
<p>On an iPhone, iPad, or Mac, you can enable Passwords via iCloud settings, which syncs all your app-based passwords and website logins across all the devices you own that are also logged in to the same iCloud account <em>and</em> have Passwords sync enabled.</p>
<p>Go to System Settings/Settings &gt; <em>Account Name</em> &gt; iCloud and choose Passwords or Passwords and Keychain. Enable “Sync this <em>Device type</em>.”</p>
<p>iOS and iPad app passwords use a mapping that associates them with a website, which can cause problems when you signed up in an app or at a website and then try to log in at the other entry point. The website address might not match the one provided by the app, or the app might not incorporate the right website domain. For instance, the website might use <code>login.example.com</code> while the app points to <code>api.example.com</code>.</p>
<p>You have two options to work around this when it happens. First, you can tap or click Passwords, then search for the domain, app, or site, and select the password entry. You’ll be warned about filling in the password. The better path is to open Passwords, find the entry, select it, tap or click Edit, tap or click Websites, then enter variants on the domain.</p>
<p>Browsers other than Safari have their own password storage systems for local storage and syncing. For example, Google Chrome can sync across all your apps linked to the same Google account and makes passwords available through a web-based password manager, which I have more to say about below. (Apple lets you use iCloud Passwords synced items with Chrome by installing an extension, described later.)</p>
<p>Third-party password managers are a boon for people who work across ecosystems or have more nuanced needs to share passwords and other kinds of data securely. Some offer Android, Windows, and Apple apps, plus browser-based access, and let you set up multiple shared secure vaults or storage areas with different sets of people. These third-party systems also have native plugins for Safari <em>and</em> other browsers.</p>
<h2>How your secrets are secured</h2>
<p>It’s important to know how password vaults manage the encryption and security of your data, but it can also be a bottomless well of detail. In the following entries, I explain, from a top-level view, how Apple manages these aspects for the Apple Keychain and for Passwords synced via iCloud, how other well-designed password managers do the same, and Google’s shortcomings in that regard.</p>
<h3>Local passwords and passkeys</h3>
<p>On an iPhone, iPad, or Mac, passwords and passkeys are stored in a system keychain. This is invisible to iPhone and iPad users, but you can view that secure information on a Mac via the Keychain Access app. When you enter your account password or device passcode, the keychain is unlocked for use across the device, though Apple requires biometric or password/passcode authentication to apply passwords for most logins even after that.</p>
<p>When you launch Keychain Access, Apple shows a dialog that says, “Manage Your Passwords in the new Passwords App.” You can then click Open Passwords (highlighted in blue) or Open Keychain Access. If you never want to be prompted again, check “Do not show this message again.”</p>
<p>Passkeys are stored in the keychain, but you can’t view their contents—only that you created them—because they’re based on long sequences of digits that form encryption keys meant to be kept strictly private; even displaying them reduces your security. A Mac makes a passkey available when required to log in to a website. Other browsers and apps that incorporate webpage views can also tap into Apple’s system framework to securely use passkeys.</p>
<p>In the Passwords app, you can view passkeys in their own category, although the entry also includes the login information used when you enrolled, such as username and password.</p>
<p>If you have a website login with a password, initially set up with two-factor code-based verification and then transitioned to a passkey, all those elements appear in a single Passwords manager entry.</p>
<p>You’ll also notice that, if you use Google Chrome in Sonoma or later, the browser opens its own compatible passkey validation system for Google account logins.</p>
<p>Keychain data on its own never leaves your machine, and when backed up, the associated files are encrypted. Locally stored keychain entries are backed up by full-disk encryption on all Apple silicon Macs. Your device passwords and passcodes are the only real weak points.</p>
<p>Apple and the rest of the industry agreed on a standard for passkeys, and also agreed to make passkeys securely exchangeable among ecosystems. Well, the first part was true first; the second took years to emerge, finally becoming a reality in 2025 with the version 26 operating systems. With 1Password, Bitwarden, or Dashlane installed, you can move passkeys (and other passwords) between them and Passwords; with two or more installed, they can transfer between each other.</p>
<h3>iCloud Keychain for synced data</h3>
<p>iCloud relies on endpoint security with locally stored encryption keys that never leave your Mac, iPhone, or iPad. Data is encrypted in transit, and the strongly encrypted data when synced or stored in iCloud is useless without these device-based keys, which are stored in the Secure Enclave on any hardware that has one.</p>
<p>With two-factor authentication (2FA) enabled on your iCloud account—more or less mandatory these days—it’s effectively impossible for someone in most circumstances to gain access to your synced and stored Passwords entries. They would need all three of the following:</p>
<ul>
<li>Your iCloud password</li>
<li>Either, with standard code-based 2FA:</li>
</ul>
<p>— Access to one of your trusted devices that they had the passcode or password for or could otherwise unlock to receive a 2FA token, or a trusted phone number (or hijack a phone number)</p>
<p>— The device password for one of your other Apple devices that’s already synced. When you add a new device to iCloud syncing of Passwords, Apple has you prove yourself by entering the password for an existing device in your set.</p>
<ul>
<li>Or, with an Apple Account locked to hardware security keys for 2FA, access to one of the two or more hardware security keys associated with your Apple Account.</li>
</ul>
<p>However, there’s one flaw in the above, which is covered in <a href="https://nerdsmodo.com/iphone-passcode-theft/">how thieves steal iPhone passcodes</a>: if someone can obtain your iPhone and its passcode, they may be able to use the phone to trigger a reset of your Apple Account password. See <a href="https://nerdsmodo.com/stolen-device-protection/">how to turn on Stolen Device Protection</a> for advice on preventing that.</p>
<p>Don’t worry about entering your passcode for Passwords syncing: Apple doesn’t know your passcode or store it or transmit it unencrypted. Instead, when you enable Passwords syncing on any device, part of the process bootstraps distributing a set of cryptographic elements securely to other devices. It does so by encrypting that set with the password of the device you’re using—but only the one-way encrypted form of the password is used.</p>
<p>On another device, if you don’t enter exactly the same password, when it’s also transformed in the same way, it won’t match the stored version, and it won’t be able to decrypt the syncing keys to add the device you’re on—and blocks a cracker who doesn’t know your other devices’ passwords, too.</p>
<h3>A well-designed third-party manager</h3>
<p>The system I described just above for Passwords is the same one that’s been implemented by 1Password. (I don’t recommend any other third-party password manager.)</p>
<p>It’s a <em>zero-knowledge</em> security model for syncing across the cloud, in which the parties handling data can’t actually see the secrets and have no access to keys. As you add devices to cloud syncing, you have to prove you have other devices and secrets first. This is true for both companies’ access to your data stores via their websites: all encryption happens locally in the browser; none is ever sent to the companies; and each login session requires proof of certain elevated secrets that no one can intercept.</p>
<p>1Password’s system syncs files blindly, with storage vaults encrypted and stored that way on 1Password’s servers. The master password for the vault is never transmitted in any way, nor are unencrypted entries.</p>
<p>1Password’s approach is close to Apple’s. The big difference? Apple copies all passwords to local storage and doesn’t allow web-based access to entries, even though they’re all stored with device-based encryption at iCloud.com. With 1Password, there’s no permanent local storage, but you can use a secure method for browser-based access if a native app isn’t available.</p>
<h3>Google password encryption</h3>
<p>If you use Google for password management—or as part of your password-management approach—I recommend upgrading to the device-based encryption option they introduced a few years ago.</p>
<p><strong>Tip:</strong> You can check whether you already have it set up: you might have enabled it or been walked through it by Google already. Follow the same steps below.</p>
<p>Use Google Chrome (not another Chromium-based browser) for the following steps:</p>
<ol>
<li>In the top-right corner of the browser window, click the More button and choose Passwords and Autofill &gt; Google Password Manager.</li>
<li>Click the menu button and click Settings.</li>
<li>If you see Set Up next to &#8220;On-device encryption,&#8221; click the link and follow the steps. If you see an open-in-new-window button, on-device encryption is already enabled.</li>
</ol>
<p>You can avoid Google’s password system and rely on Apple’s by installing iCloud Passwords for Chrome. It’s a Chrome extension that manages the local security issues for accessing Passwords. Unlike Google’s system, it works with Chromium browsers.</p>
<p>The post <a href="https://nerdsmodo.com/apple-passwords-passkeys/">Where Apple Stores Your Passwords and Passkeys</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/apple-passwords-passkeys/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4831</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5613.jpg" />	</item>
		<item>
		<title>Who Needs Stronger Security Than Most People</title>
		<link>https://nerdsmodo.com/elevated-security-risk/</link>
					<comments>https://nerdsmodo.com/elevated-security-risk/#respond</comments>
		
		<dc:creator><![CDATA[Stacey Butler]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 13:39:09 +0000</pubDate>
				<category><![CDATA[Mac]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4829</guid>

					<description><![CDATA[<p>Sharing a Mac with a less careful family member raises your own risk.</p>
<p>The post <a href="https://nerdsmodo.com/elevated-security-risk/">Who Needs Stronger Security Than Most People</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>If you’re at higher risk, you should consider taking the most stringent measures available, starting with <a href="https://nerdsmodo.com/security-vs-privacy-vs-anonymity/">what security actually means</a>. Check the following criteria to see if they apply:</p>
<ul>
<li><strong>You work in the financial, legal, medical, or government sector:</strong> If you use Apple hardware for work, you are likely subject to regulatory requirements and have been briefed on them. (You might even have had to take a course on compliance!) You may be required to engage additional security, like using a VPN, blocking ports for USB/Thunderbolt and SD Cards (see <a href="https://nerdsmodo.com/mac-privacy-security-settings/">the Mac settings worth changing</a>), enabling <a href="https://nerdsmodo.com/filevault-mac/">FileVault on a Mac</a>, and turning on <a href="https://nerdsmodo.com/advanced-data-protection/">Advanced Data Protection in iCloud</a>. You may also need to enable <a href="https://nerdsmodo.com/apple-account-lockout-prep/">hardware security keys for your Apple Account</a>. If you don’t take these steps, and it’s discovered, your devices are lost or data intercepted, or online accounts are compromised, you could be sanctioned, fired, fined, or even charged with a crime, depending on the employer and locality.</li>
<li><strong>Your device contains unusually sensitive data:</strong> This could be old love letters you don’t want your partner to see, confidential business information from your employer (even if they’re not in the financial, legal, etc., categories above), records of a delicate medical condition, or anything else that could cause you serious problems (like loss of your job, insurance, or marriage) if it were to get out.</li>
<li><strong>You’re famous:</strong> Congratulations! You already know the price of this on social media and when dining, traveling, or walking around, depending on how well-known you are. But you’re also more of a target online, because of the obsession so many sites and people have with secrets about people who are seen to be famous.</li>
<li><strong>You’re a journalist:</strong> Sadly, reporters are frequently targeted by criminals, people they’re writing about, and governments. For instance, Ronan Farrow reported that Harvey Weinstein hired an Israel-based private-intelligence firm to dig up dirt on him while he was researching his watershed story on Weinstein’s history of alleged and proven sexual crimes.</li>
<li><strong>Wealthy in real terms or cryptocurrency:</strong> People with more than a little money are regular targets, especially if they have significant Bitcoin or other cryptocurrency holdings. Having an expensive house doesn’t mean much in the current real-estate market; it’s more likely that you have elevated risk if there’s coverage or securities filings that disclose your wealth, stock grants, or other assets.</li>
<li><strong>Rough travel:</strong> You frequent any of the internet’s seedier neighborhoods, such as sites that traffic in online gambling, porn, or pirated content (like software, television shows, or movies).</li>
<li><strong>Secret or pseudonymous identity:</strong> You have an online identity, separate from your real-life identity, that you need to keep private. A number of times in recent years, someone whose job or political position has prevented them from having a public persona have been outed for writing under another, typically fictitious name.</li>
<li><strong>Heated online interactions:</strong> You engage in controversial discussions that might result in people being exceptionally angry with you.</li>
<li><strong>Careless co-users (Mac):</strong> Specific to a Mac, you share it with less-sophisticated family members who may not be as careful as you would be about downloading files from unknown sites, clicking links in email messages, and using good passwords. While you can set them up with their own macOS accounts—you should!—some of their actions can affect the entire Mac and your online accounts.</li>
<li><strong>People in particular professions and of genders other than male:</strong> It’s a sad fact of modern life that being a responsible journalist, being an advocate for vulnerable people, believing the Earth is round and evolution legitimately established in the fossil record, or having the temerity to be a gender that someone else has chosen to be angry about online can cause reactionary individuals and groups to target you.</li>
<li><strong>You live in a country that has reduced privacy protections:</strong> Various countries have fought with Apple over allowing back-door access to iCloud data. The United States asserts the right to login to examine incoming tourists’ and students’ social media and other accounts. Many countries now think that any checkpoint, traffic stop, or other incidental encounter gives them carte blanche to demand all your data.</li>
</ul>
<p>Now for the good news! A decade ago, my advice to you would have likely been <em>far</em> more extensive and stringent than for the average user. These days, however, Apple’s and other companies’ baseline security is more accessible, easier to use, and more effective.</p>
<p>My general advice is to <em>do everything</em> suggested here as the baseline, and build a bit from there.</p>
<h2>Take a hard look at Lockdown Mode</h2>
<p>Some people are pinpoint targeted by spyware, software that can hijack their devices, often without a single click, using previously unknown exploits. These attacks are worth a lot of money and thus typically deployed in a targeted fashion by governments and criminal syndicates against journalists, members of minority groups in a given country, human-rights activists, and opposition politicians.</p>
<p>To help counter these kinds of intrusions, Apple offers a Lockdown Mode you can invoke that highly restricts many forms of inbound messages and traffic. For the full rundown, see <a href="https://nerdsmodo.com/lockdown-mode/">how to turn on Lockdown Mode and who needs it</a>.</p>
<p>If you fall into the above categories, your biggest risks will come from how your Mac is set up, rather than your iPhone or iPad. Here’s how you could improve your Mac security:</p>
<ul>
<li><strong>Upgrade your Mac to Golden Gate:</strong> Golden Gate supports all Apple silicon Macs. A few older Intel models can upgrade to the previous release, macOS 26 Tahoe, which you should do. If you can’t run Tahoe or Golden Gate, you’re not getting the latest and best security. Consider upgrading your Mac if that’s important to you. (See <a href="https://nerdsmodo.com/macos-compatibility/">which Macs can run it</a>.)</li>
<li><strong>Allow FileVault:</strong> Apple enables FileVault by default when you upgrade to macOS 26 or 27 and on new computers running it. Leave it on (see <a href="https://nerdsmodo.com/filevault-mac/">FileVault</a>). <em>Also</em>, power down your Mac whenever it’s not in use; never leave it idle and running for more than a brief period. (A FileVault-like feature is part of iOS/iPadOS and cannot be disabled or configured.)</li>
<li><strong>Block device and card insertion:</strong> Thunderbolt and USB devices and SD Cards plugged into your Mac can be blocked from interacting with the operating system without authentication. See <a href="https://nerdsmodo.com/mac-privacy-security-settings/">the Mac settings worth changing</a>.</li>
<li><strong>Never make local, unencrypted copies of your data:</strong> All local copies should be on encrypted volumes that are unmounted after backup or shutdown when you regularly shut your Mac down; all hosted backups, if any, should only be with firms that offer strong, user-owned encryption. Time Machine lets you set up backups on an encrypted drive or add an encryption key for networked backups. All online backup services worth considering put the encryption key for your archived data solely in your hands.</li>
</ul>
<p>The post <a href="https://nerdsmodo.com/elevated-security-risk/">Who Needs Stronger Security Than Most People</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/elevated-security-risk/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4829</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/02/img_5048.jpg" />	</item>
		<item>
		<title>How to Set Up and Disable Touch ID and Face ID</title>
		<link>https://nerdsmodo.com/touch-id-face-id-setup/</link>
					<comments>https://nerdsmodo.com/touch-id-face-id-setup/#respond</comments>
		
		<dc:creator><![CDATA[Dave Johnson]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 13:22:54 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4828</guid>

					<description><![CDATA[<p>Five wrong fingers locks out Touch ID, which is useful under duress.</p>
<p>The post <a href="https://nerdsmodo.com/touch-id-face-id-setup/">How to Set Up and Disable Touch ID and Face ID</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Biometric protection is a terrific safeguard to layer on top of other basic protections. By letting you use a fingerprint or your face to unlock your device, it increases security for your files and data while also making it easier for you to log in.</p>
<p>Touch ID first appeared on iPhones with the iPhone 5s in 2013, and was added to iPads starting with the iPad Air 2 model the next year. All subsequent iPhones and iPads included Touch ID until Face ID replaced fingerprint authentication on the iPhone starting with the iPhone X in 2017. Since then, it’s been part of every iPhone except the iPhone SE series, which retains Touch ID.</p>
<p>The sole iPad model with Face ID is the iPad Pro, starting with the 1st-generation 11-inch and 3rd-generation 12.9-inch models in 2018. All other iPads that can run iPadOS 26 or 27 have Touch ID, which dates back to 2014 in some iPad model lines.</p>
<p>Touch ID was extended to Mac laptops starting with two 2016 MacBook Pro models. It was later added to all new MacBook Pro models and the MacBook Air starting in 2018, when it became standard. However, that doesn’t help those of us with desktop Macs.</p>
<p>In May 2021, Apple released the Magic Keyboard with Touch ID (in both standard and extended versions) along with their new M1 iMac. This brought Touch ID to a desktop Mac for the first time. Apple later began selling this version of the Magic Keyboard separately, and while the keyboard part works with any Mac, the Touch ID sensor requires an Apple silicon processor.</p>
<p>Apple uses a secure wireless connection between the keyboard and the Secure Enclave module in an Apple silicon Mac to manage Touch ID. That technology is <a href="https://nerdsmodo.com/secure-enclave/">the Secure Enclave</a>.</p>
<p>Apple requires the use of Touch ID or Face ID with its iPhone anti-theft feature, <a href="https://nerdsmodo.com/stolen-device-protection/">Stolen Device Protection</a>.</p>
<p>Apple lets you choose to enable Touch ID or Face ID to unlock your device, use Apple Pay, pay for items in Apple’s various stores, validate that you want to automatically fill in a password field in Safari and some other locations, and switch between user accounts when fast user switching is turned on. Some third-party apps offer Touch ID or Face ID as a verification option.</p>
<h2>Why Apple Pay turns itself off</h2>
<p>You may find that your Mac has disabled Apple Pay without a notification, and you notice only when you attempt to use it in Safari or open System Settings &gt; Wallet &amp; Apple Pay.</p>
<p>This can happen for several reasons:</p>
<ul>
<li><strong>Security level changes:</strong> If you lower the level of security for an Apple silicon Mac, you may see the message “Apple Pay has been disabled because the security settings of this Mac were modified.” See <a href="https://nerdsmodo.com/mac-system-integrity/">how macOS protects its own system files</a>.</li>
<li><strong>Laptop lid closed:</strong> If you have a laptop, its lid must be open. The exception? If you have an Apple silicon laptop Mac paired with a Magic Keyboard with Touch ID, you can use the keyboard’s sensor.</li>
<li><strong>System out of date:</strong> Apple says that the “Install system data files and security updates” box should be checked for automatic installation of those files in Software Update. See <a href="https://nerdsmodo.com/apple-security-updates/">how to set up automatic security updates</a>.</li>
<li><strong>Insecure miscellany:</strong> Apple also says ambiguously it disables Apple Pay “when it detects third-party software or malware that affects its ability to keep your payment information secure.”</li>
</ul>
<h2>Enroll in Touch ID</h2>
<p>You can enroll your device to use Touch ID via Settings/System Settings &gt; Touch ID &amp; Password. Click or tap Add Fingerprint, then follow the prompts to fill in the fingerprint’s main portion, and then the edges. On a Mac, click Done to finish.</p>
<p>I always name the fingerprint descriptively by clicking or tapping it and then typing text.</p>
<p>Naming fingerprints can be a security or personal safety weakness, allowing someone who wants to coerce you to know which finger to force. However, they would also need to open the Touch ID settings to find out.</p>
<p>You can lock your device against Touch ID by using the wrong fingertip five times in succession; see the lockout section below. This is a good trick when you want to prevent being physically coerced into unlocking your Mac.</p>
<p>I like to enroll at least two of my fingers, because it’s a one-time process per fingertip and it lets me avoid remembering which finger is the right one. You can have a total of three on a Mac or five with an iPhone or iPad. Add other people in your household if you want them to be able to unlock your device or use other Touch ID-required features.</p>
<h2>Enroll in Face ID</h2>
<p>Face ID for the iPhone and iPad Pro (models noted above) uses an infrared laser and sensor to project and measure 30,000 separate data points on a person’s face to create a profile while also capturing other flat views. Subsequent logins repeat those tasks and introduce randomization, allowing the phone to compare the current face with the stored profile and detect face forgery.</p>
<p>iPhone and iPads with Face ID can recognize just one face plus an “alternate appearance,” or a common secondary appearance of yourself, like with any or different makeup, hat, or glasses. Face ID has worked in portrait orientation since its introduction on all supported devices. Landscape authentication works on all supported iPads and iPhone 13 series models and later.</p>
<p>Enrollment uses a similar process to Touch ID: you use Settings &gt; Face ID &amp; Passcode, and choose Enroll Face. The process has you move your head in a circular motion framed on screen until enough information has been gathered.</p>
<p>Apple says they track and retain temporary updates when they find a good match that falls outside their ideal parameters. These temporary updates are good for only a “finite” number of unlocks, which is a little vague. Maybe it’s to cope with temporary clothing choices or eyebrow plucking? A change in glasses?</p>
<p>You can tap Set Up an Alternative Appearance, useful if you have different ways you make yourself up or attire yourself. Apple has never made fully clear <em>how</em> different that can be.</p>
<p>Face ID relies on an “attentive” expression when you log in. This prevents unlocking the phone or tablet when you’re just glancing past the Lock screen, and it requires someone to have their eyes open. Apple says you can unlock wearing sunglasses. The emitters and sensors are designed for use in all lighting conditions, both indoors and outdoors. The alternate appearance helps here, too.</p>
<p>Apple offers support for facial recognition while wearing a mask with iPhone 12 models and later in portrait orientation only. Here’s how to set up the Face ID with a Mask feature:</p>
<ol>
<li>Go to <strong>Settings &gt; Face ID &amp; Passcode</strong>.</li>
<li>Enter your passcode.</li>
<li>Tap Face ID with a Mask while wearing a mask typical of the kind you normally wear.</li>
<li>Apple now informs you of the risks and nature of Face ID with a Mask. Tap Use Face ID with a Mask to continue.</li>
<li>While wearing a typical mask, tap Get Started and walk through the facial training system you’re already familiar with for unmasked Face ID.</li>
</ol>
<p>Apple appears to ignore most of the mask area, so if you use patterned cloth or medical-grade masks, it shouldn’t prevent you from swapping out masks.</p>
<p>If you wear glasses normally with a mask, wear those while setting up Face ID with a Mask; my current enrollment shows “1 pair of glasses added.” You can have a total of four sets of glasses. Add more by tapping Add Glasses.</p>
<p>Face ID can be delightful as you can merely raise an iPhone or iPad to wake it and, while glancing attentively, the device unlocks.</p>
<p>With Apple Pay at a store payment terminal or in conjunction with Apple Pay in Safari for Mac, you have an extra step even with an unlocked iPhone or iPad. A message appears requesting payment. You double-tap the side or top button, then glance to approve the payment.</p>
<p>For the best results when using Apple Pay with Face ID while wearing a mask, first double-press the side button and authenticate with Face ID; then, with the screen showing “Hold Near Reader,” hold your device to the terminal. I adopted this after finding the angle of terminal, mask, and Face ID sensor were often out of alignment.</p>
<p>Although I recommend setting a strong passcode, you may wind up entering your passcode more frequently with Face ID than with Touch ID for a few reasons:</p>
<ul>
<li>Face ID is good but not perfect; bright light can prevent a match.</li>
<li>Some models and brands of sunglasses use optical filters that apparently prevent a good or reliable match.</li>
<li>When the sensors can’t perform as exact a match as required, they defer to the passcode. This happens routinely but not constantly.</li>
<li>Face ID requires a first-use step with Ask to Buy, used for parents or guardians to approve children’s purchase requests. While Touch ID may be used without any preamble, on Face ID-equipped devices, the first time there’s an Ask to Buy request, you have to enter your Apple Account password. You can then enable Face ID for future approvals.</li>
</ul>
<h2>When biometric lockout happens</h2>
<p>Apple disables Touch ID and Face ID in a number of cases. Technically, the operating system flushes a kind of temporary permission for accessing certain data. Entering the passcode refreshes that access. Here are several cases in which you’re required to enter the passcode again:</p>
<ul>
<li>After five incorrect fingerprint or facial recognition attempts. Apple notes, in a parenthetical in their security documentation: “(though for usability, the device might offer entering a passcode or password instead of using biometrics after a smaller number of failures)”.</li>
<li>After a restart.</li>
<li>When you’ve marked the device as lost via Find My.</li>
<li>When you add or remove fingerprints or refresh Face ID.</li>
<li>When you try to visit Settings/System Settings &gt; Touch ID/Face ID &amp; Passcode.</li>
<li>After you try to use Emergency SOS on an iPhone to make an emergency call. This can be changed in Settings &gt; Emergency SOS.</li>
<li>After an attempt to view your Medical ID is made on your iPhone.</li>
<li>After 48 hours of a device not being unlocked with Touch ID, Face ID, or an account password.</li>
</ul>
<p>There’s one more case that’s hard to put into a bullet point. There’s a special countdown clock with two phases. It resets each time you enter your passcode. A 156-hour countdown begins (six and a half days). After that period, a <em>second</em> timer starts a four-hour countdown. If, during those last four hours, you don’t use Face ID or Touch ID to unlock your iPhone or iPad, the next time you use it, you’ll be required to enter your passcode.</p>
<p>You’re probably thinking: “Why?! Why, Apple?! Why!!!” Apple has never made a public statement after this biometrics lockout was added several years ago. The best I can figure, they want to ensure you have to enter your password on a regular basis so it doesn’t fall out of your brain. Now, should you be expected to keep track of the above clocks? No! Not at all! However, if you’re asked for your passcode every week or so when you wake up, and wonder why, that’s probably the reason.</p>
<p>You can make a variety of medical information available at Settings &gt; Health &gt; Medical ID. Once you create this, anyone can attempt to view it via the emergency dialer screen. Understandably, this signals your iPhone or iPad is in someone else’s hands, so locking out biometrics is a logical move.</p>
<p>Also, if you have Face ID with a Mask enabled, Apple reduces the interval between passcode requests on your iPhone to 6.5 hours. Every time you use Face ID (with or without a mask), enter the passcode, or use your Watch to unlock your iPhone, the 6.5-hour timer resets its countdown.</p>
<h2>Disable Touch ID or Face ID</h2>
<p>You may choose to stop using Touch ID or Face ID or want to use it in a more limited fashion.</p>
<p>If you’re in a situation in which you temporarily want to disable Touch ID or Face ID, the easiest way is to hold down either volume button and the side/top button until a screen appears a few seconds later.</p>
<p>iPhones show you the Emergency SOS screen, including Medical ID, if set; iPads show the Slide to Power Off button. At this point, Touch ID or Face ID is disabled, no matter what action you take. Typically, tap Cancel. (For more strategies, see <a href="https://nerdsmodo.com/iphone-passcode-strength/">how to set a stronger iPhone passcode</a>.)</p>
<p>You can access your iPhone or iPad after this only by entering your passcode. However, that re-enables Touch ID or Face ID. In some countries and conditions, you can refuse to enter your passcode.</p>
<p>If you don’t want either biometric capability available—for instance, while crossing a national border—go to Settings &gt; Touch ID/Face ID &amp; Passcode and disable the four “Use Touch ID/Face ID For” switches.</p>
<p>The post <a href="https://nerdsmodo.com/touch-id-face-id-setup/">How to Set Up and Disable Touch ID and Face ID</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/touch-id-face-id-setup/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4828</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5674.jpg" />	</item>
		<item>
		<title>How to Stop Leaving Your Phone and Bags Behind</title>
		<link>https://nerdsmodo.com/notify-when-left-behind/</link>
					<comments>https://nerdsmodo.com/notify-when-left-behind/#respond</comments>
		
		<dc:creator><![CDATA[Stacey Butler]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 07:51:39 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Find My]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4898</guid>

					<description><![CDATA[<p>The alert never fires at home, because Apple excludes that location.</p>
<p>The post <a href="https://nerdsmodo.com/notify-when-left-behind/">How to Stop Leaving Your Phone and Bags Behind</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Notify When Left Behind helps with absent-mindedness, exhaustion, and theft. Using <a href="https://nerdsmodo.com/how-find-my-works/">your presence</a>, whenever you move a certain distance away from a device or item—Apple doesn’t define how far—you receive a notification on that device.</p>
<p>Found on the sheet for any device or item in native Find My apps, it’s enabled by default under Notifications. You can choose to disable it on a per-item basis. Apple also excludes the place you defined as Home or Apple inferred was your Home.</p>
<p>The device on which you would be notified is listed as part of the explanation when you tap or click Notify When Left Behind.</p>
<p>Your Apple Watch doesn’t alert you when something is left behind (and the Find My app explains this); instead, the alert comes only when the item is separated from your primary presence device, typically an iPhone. (See <a href="https://nerdsmodo.com/how-find-my-works/">how Find My works</a>.)</p>
<p>Notify When Left Behind helps in a bunch of scenarios I can imagine:</p>
<ul>
<li>Forgetting you placed an iPad in the seat-back pocket on an airplane. (This is certainly a main cause of loss for iPads and Kindles.)</li>
<li>Leaving an iPhone, iPad, or Mac in a coffee shop or restaurant.</li>
<li>Forgetting your backpack that has an AirTag in its pocket at someone’s house.</li>
<li>Checking your luggage at an airport or train station for a trip.</li>
<li>Leaving items at a hotel room, hostel, Airbnb, or the like after checking in during a trip, such as in a hotel safe.</li>
<li>Not packing your laptop in a bag you’re carrying with you before leaving for school or work—or vice versa!</li>
<li>Locking up a bike that you’ve attached a Find My item to at your destination—then forgetting you biked there and taking a bus home. (Folks, if you bike regularly and you haven’t made or almost made this mistake, count yourself lucky.)</li>
</ul>
<h2>Trust a place</h2>
<p>When you’re notified, you can tap Don’t Notify Me, and the location where your Find My item or device was left will be added as a location. If you have an Apple Watch, a notification on the watch also lets you tap Trust Location or Dismiss.</p>
<p>You can also suppress this notification in a Find My app on an iPhone, iPad, or Mac by selecting the item or device, which then shows where it was last seen. You can tap or click Don’t Notify Me Here.</p>
<p>When you add a location through this method, the operating system prompts you, “Don’t notify at <em>map description of location</em>?” You can then tap or click “For all Items or Devices,” “For this Item/Device,” or Cancel.</p>
<p>You can also manually add other locations to exclude by tapping or clicking Notify When Left Behind, then New Location. The map interface for location selection is identical to <a href="https://nerdsmodo.com/find-my-location-alerts/">the one for People</a>. You have the additional option when you click Done to add the location to select “For all Items and Devices” or “For this Device.”</p>
<p>You can accumulate a list over time of places that you don’t want to be notified about items being left behind at. For me, this has become an interesting travelogue of all the hotels, homes, and workplaces I’ve been at.</p>
<p>You can clean this list up by removing locations. On an iPhone, iPad, or Mac, tap or click the remove button to a location’s right. The exception is the Home location, which can be removed only on the device that establishes presence. You can view those locations on an Apple Watch, but not remove them.</p>
<h2>It is not an anti-theft feature</h2>
<p>Because the notification occurs only when the device remains static and you’ve left it behind, it is not an <em>anti-theft</em> feature. Conceivably, we need Apple to add the opposite case, too: Notify When Moves Away. Perhaps this could cause both the device that’s taken and the hardware that notifies to both squeal uncontrollably until reunited?</p>
<h2>A bag in a hotel safe</h2>
<p>As I was revising this edition, I received a text from a friend. After a trip out of state, he’d realized he’d forgotten to retrieve a small bag in the hotel safe. He didn’t care much about the bag—except that it contained his passport! The bag also contained an AirTag, but he wasn’t alerted that it was left behind for several hours.</p>
<p>He could see the AirTag in what appeared to be the parking lot. A few slightly clueless hotel front-desk people seemed helpless, although one walked out into the parking lot and said the location appeared to be a grate. Maybe a thief had thrown the AirTag down its openings? But that would mean someone had stolen it from the room safe or lost and found after he had checked out.</p>
<p>After a day or so, a more clued-in staffer called back: it was in the lost-and-found safe, which apparently other people hadn’t checked. For $60, the hotel used a third-party service to return the bag. And then he watched as it didn’t move for days—requiring three more calls to the hotel—before it finally landed at the airport near us. And then sat there for a day before UPS put it on a truck.</p>
<h2>The related setting: Notify When Found</h2>
<p>Device notifications don’t let you see when something comes or goes, but instead provide you useful feedback related to losing something or having it stolen.</p>
<p>Find My enhances its Lost Mode/Mark as Lost option by providing a notification option after you mark a device as lost. This notification can occur when that device is “found”—that is, when it’s back online, however briefly (see <a href="https://nerdsmodo.com/lost-mode-what-finder-sees/">what someone sees when they find your lost device</a>).</p>
<p>Notify When Found is disabled by default on the sheet of actions for a device or item in a native Find My app unless it’s been marked as lost. Then you have just the option to turn it on or off. If enabled, a notification appears on your devices in one of two cases: a piece of your equipment detects the missing item; or the device or item reports its location through Find My or the Find My network.</p>
<p>The post <a href="https://nerdsmodo.com/notify-when-left-behind/">How to Stop Leaving Your Phone and Bags Behind</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/notify-when-left-behind/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4898</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5676.jpg" />	</item>
		<item>
		<title>How to Share Your Location From an iPhone</title>
		<link>https://nerdsmodo.com/share-location-iphone/</link>
					<comments>https://nerdsmodo.com/share-location-iphone/#respond</comments>
		
		<dc:creator><![CDATA[Chris Smith]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 07:38:05 +0000</pubDate>
				<category><![CDATA[How To]]></category>
		<category><![CDATA[Find My]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iPadOS]]></category>
		<category><![CDATA[macos]]></category>
		<guid isPermaLink="false">https://nerdsmodo.com/?p=4897</guid>

					<description><![CDATA[<p>Sharing through Find My and through Family Sharing are different switches.</p>
<p>The post <a href="https://nerdsmodo.com/share-location-iphone/">How to Share Your Location From an iPhone</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Disclosing your location is a two-edged sword—or maybe a multi-bladed throwing star. It can be incredibly handy to let other people know where you are for travel, safety, timing, and even accountability. However, letting others know where you are means they <em>know where you are</em>, which even for close friends, family, and partners can feel like too much knowledge and the expectation of you sharing your position can feel invasive. (You also may feel it’s excessive that, when you launch Find My, you can see the precise location of everyone who has shared with you, even though they did so willingly!)</p>
<p>Apple tries to strike a balance with location sharing just as it does with nearly all other aspects of digital privacy that they mediate and let you choose your comfort level with.</p>
<p>Find My is the interface through which the location you share from an iPhone, iPad, Mac, or Apple Watch gets viewed, but it’s only partly the way in which you choose what is shared! That split is left over from when Apple introduced the previous standalone app, Find My Friends, and relied on preferences buried in Settings to manage all the details.</p>
<p>When you share your location, the other person cannot see your devices, but only your <em>presence</em>: the device marked as showing where you are. Only people in a Family Sharing group can see each other’s devices, and only if the person is sharing their location with them. Items don’t pick up Family Sharing settings. You can <a href="https://nerdsmodo.com/share-airtag-with-others/">share them with up to five people</a>.</p>
<p>Location has two interrelated components: how you share your location and how you choose to accept seeing other people’s locations. Let’s start with you.</p>
<p>You can use the native Find My app to view and change personal settings, even if you’re part of a Family Sharing group:</p>
<ul>
<li>
<strong>On an iPhone/iPad, watchOS 27, and macOS 27:</strong> Go to the Find My app &gt; Me button.
</li>
<li>
<strong>In macOS 26 and earlier:</strong> In the Find My app’s People view, click Me and click the Info button.
</li>
<li>
<strong>In watchOS 26 and earlier:</strong> In the Find People app, tap the Me entry.
</li>
</ul>
<p>Here is what appears in the My Location section on all these devices:</p>
<ul>
<li><strong>Share My Location:</strong> A single tap, and you let yourself be seen by those you’ve shared with; another tap, and you run silent—your location isn’t sent again until it’s re-enabled.</li>
<li><strong>Sharing From:</strong> Often called <em>presence</em>, this defines which devices are shared in Find My as being your location as a human if you own multiple devices. My Location reads This <em>Device</em> if you’re on the one defining your location; otherwise, it shows the name of that device. (See <a href="https://nerdsmodo.com/how-find-my-works/">how Find My works</a>.)</li>
<li><strong>Location Label:</strong> At the top of the Me view, you see the current inferred address. However, Find My tries to offer something more descriptive. If you’ve defined your home or work location in Contacts or Phone, it should show Home or Work as the label. You can also create your own names for other addresses; see <a href="https://nerdsmodo.com/find-someone-location/">how to see someone’s location in Find My</a>.</li>
</ul>
<h2>Share with someone</h2>
<p>You can share your location in more than one way, and the interface is essentially the same with slight differences.</p>
<p>Here’s how to share in various ways across your Apple devices, from most universal to most specific; how to set the duration option is discussed after these instructions:</p>
<ul>
<li><strong>On an iPhone or iPad, or in macOS 26 or later:</strong></li>
</ul>
<p>— <em>Find My app:</em> Click or tap the add button at the upper-right corner of the list in whatever view you’re in. Enter names or select people. Click the checkmark button. Now choose a duration.</p>
<p>— <em>Messages:</em> In any conversation in Messages, tap or click the avatar or avatars. On an iPhone or iPad, tap the Plus button, choose Location, tap Share, choose the duration, and tap the Send button. On a Mac, click Share My Location, choose a duration, and press Return to send.</p>
<p><strong>Tip:</strong> If your recipient or group isn’t all Apple users, you can still send an image that embeds a link to a map; instead of Send or Share, the button reads Send Pin.</p>
<ul>
<li><strong>In macOS Sequoia or earlier:</strong></li>
</ul>
<p>— <em>Find My app:</em> In the Find My app, click the People button, then click Share My Location. Enter names or select people. Click Send, and choose a duration.</p>
<p>— <em>Messages:</em> In any conversation in Messages, click the Info button in the upper-right corner. Click Share My Location and choose a duration. Press Return to send the location message.</p>
<ul>
<li><strong>On an Apple Watch:</strong></li>
</ul>
<p>— <em>Find My app (watchOS 27) or Find People app (watchOS 26 or earlier):</em> In watchOS 27 only, first tap People. Scroll to find Share My Location. Tap it to either dictate a name, choose a contact, or enter a contact’s phone number.</p>
<p>— <em>Messages app:</em> In the Messages app in watchOS 26 or later, choose a conversation, tap the add button, choose Location, tap Share, and choose a duration.</p>
<p><strong>Note:</strong> When someone requests your location, as explained ahead in If You’re Asked to Reciprocate, you can’t use a single tap from an Apple Watch. You have to use one of the above methods.</p>
<p><strong>Note:</strong> You can’t share your location with others or see their location in the Find Devices app on iCloud.com.</p>
<h2>Choose how long it lasts</h2>
<p>No matter which path, platform, or version you’re using from the above list, you’re asked to pick or set a duration: Always (formerly Indefinitely), End of Day, One Hour, or Custom. (These options are worded slightly differently across apps.) The Custom choice is new in the version 27 releases. Selecting that option lets you set a duration from 15 minutes to 30 days.</p>
<p>If you shared via Messages, you see a note in the conversation that says “You started sharing location with <em>person name</em>.” The recipient sees “<em>Person name</em> started sharing location with you.”</p>
<p>I’m guessing Apple switched in the version 27 releases to the simpler word “always” after years of using “indefinitely” because more people can easily parse “always.” Indefinitely has the ring of “inflammable” about it: does it mean forever or for a period of time? (Inflammable items are just as easy to set on fire as flammable ones.)</p>
<p>If you choose anything but Always/Indefinitely, a countdown clock appears when you view the details for that person’s entry in Find My: it reads “Sharing for <em>X time units</em>” in the version 27 releases and “<em>X time units</em> remaining in previous operating systems. Messages displays a map tile with an inset yellow countdown clock for the remaining time. In Apple Watch’s Find People app, the contact’s avatar is overlaid with a timer; tap the entry to see the remaining time as text.</p>
<h2>Family Sharing is a separate switch</h2>
<p>For greater flexibility, Apple also lets you use Family Sharing settings to enable to disable location sharing among group members. Go to Settings/System Settings &gt; Family &gt; Location Sharing to see family settings.</p>
<p>In Location Sharing, you see all the other members of your family sharing group and your current sharing status with them and theirs with you—sort of!</p>
<p>If you used this interface to share your location, or used the Automatically Share Location option (enabled by default) for new members, you see sharing enabled next to the group member. However, if you used the Find My app to start sharing your location, it may appear that you are <em>not</em> sharing with them! You’re just not “family” sharing with them! Yes, it’s as straightforward as a bent nail.</p>
<p>Under the Share Your Location With section, you can also see which of the group members are sharing with you. Again, this is dependent on how you shared. The pane can read “<em>person name</em> is sharing your location with you,” even though four members of my family group are sharing their locations with me. Oy!</p>
<h2>See who can currently find you</h2>
<p>Once you start sharing your location with other people, you might lose track of precisely who that is. Fortunately, you can see a list in a few different places:</p>
<ul>
<li>
<strong>Native Find My app:</strong> Use the Find My app’s People view or the Find People app on an Apple Watch (watchOS 26 or earlier). Everyone in the list who reciprocally follows you appears with location information; everyone else you share with has the label “Can see your location” beneath their name.
</li>
<li>
<strong>Find My settings:</strong> On an iPhone or iPad, go to Settings &gt; <em>Your Name</em> &gt; iCloud &gt; Find My, and you can see Family (if you’re in a Family Sharing group) and Friends. This doesn’t show reciprocal sharing status, however.
</li>
<li>
<strong>Family settings:</strong> If you’re part of a Family Sharing group, Settings/System Settings &gt; Family &gt; Location Sharing reveals any group member with whom you’ve shared using Family Sharing settings. See that befuddling situation above in Share Location with Family.
</li>
</ul>
<p>The post <a href="https://nerdsmodo.com/share-location-iphone/">How to Share Your Location From an iPhone</a> appeared first on <a href="https://nerdsmodo.com">nerdsmodo</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://nerdsmodo.com/share-location-iphone/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">4897</post-id><media:thumbnail url="https://nerdsmodo.com/wp-content/uploads/2026/09/img_5676.jpg" />	</item>
	</channel>
</rss>
