Apple Introduces Revamped Two-Factor Authentication for iOS 9 and OS X El Capitan

With the third betas of iOS 9 and OS X 10.11 El Capitan, Apple is introducing a revamped two-factor authentication system, according to both the beta release notes and a detailed support FAQ that outlines the changes.

The new two-factor authentication system is different from Apple's existing two-step verification system, using "different methods" to trust devices and deliver verification codes. Apple also says it includes a "more streamlined user experience."

Based on the support document, the new two-factor authentication system works similarly to the existing two-step verification system. Any device that you sign into using two-factor authentication in iOS 9 or El Capitan becomes a trusted device that can be used to verify identify when signing into other devices or services linked to an Apple ID.

appletwostepauth
Apple recommends that iOS 9 and OS X El Capitan beta testers using the new two-factor authentication system update all of their devices to iOS 9 or El Capitan for "the best experience." As outlined in the release notes, customers who use two-factor authentication with older devices may be required to put a six-digit verification code at the end of a password instead of using a dedicated verification field.

If you enable two-factor authentication, iTunes purchases on Mac and Windows will require you to append a 6-digit code to the end of your password on every purchase. The 6-digit code will automatically be sent to your iOS 9 or OS X El Capitan devices.

Older devices are also not able to receive two-factor authentication codes when used with devices running iOS 9 and El Capitan, but customers who stick with the older two-step verification system should not run into any issues as Apple tests the newer two-factor authentication system. Apple does not recommend that customers using two-step verification swap over to two-factor authentication until the feature is available to all.

First introduced in March of 2013, two-factor verification is an opt-in system that increases the security of Apple ID accounts. Since its debut, Apple has been working to expand two-factor authentication to cover several different services like iCloud, iMessage, and FaceTime.

It is not entirely clear what other changes the new two-factor authentication system brings to iOS and Mac devices, but the switch to a new system may allow Apple to further extend the functionality of two-factor authentication in the future.

Update: An Apple spokesperson told Macworld that the troublesome recovery key feature that has caused people to lose their Apple ID accounts in the past has been removed in the new two-factor authentication system.

With the existing two-step verification system, either a recovery key or a trusted device/trusted phone number is required to access an Apple ID account. If both should be lost, such as when a trusted device is stolen, an Apple ID is irretrievable.

With the new authentication system, Apple's customer support team will help users recover their Apple IDs through a recovery process should both trusted devices and phone numbers become inaccessible.

If you can't sign in, reset your password, or receive verification codes, you can regain access to your account by requesting account recovery. Simply provide a verified phone number where you can receive a text message or phone call regarding your account. Apple will review your case and contact you at the number provided when your Apple ID is ready for recovery. The automated message will direct you to iforgot.apple.com to complete the required steps and regain access to your account.

Account recovery will take a few days—or longer—depending on how much information you can provide to verify that you are the account owner. The process is designed to get you back into your account as quickly as possible while denying access to anyone who might be pretending to be you.

As noted by Apple, not all beta testers and developers will have access to the new two-factor authentication system right away, but Apple plans to add additional testers gradually as we get closer to the release of iOS 9 and OS X El Capitan.

Related Forums: iOS 9, OS X El Capitan

Popular Stories

iPhone SE 4 Thumb 1

iPhone SE 4 With Apple's Own 5G Modem 'Confirmed' to Launch in March

Tuesday November 19, 2024 12:12 pm PST by
Barclays analyst Tom O'Malley and his colleagues recently traveled to Asia to meet with various electronics manufacturers and suppliers. In a research note this week, outlining key takeaways from the trip, the analysts said they have "confirmed" that a fourth-generation iPhone SE with an Apple-designed 5G modem is slated to launch towards the end of the first quarter next year. In line with previo...
airtag purple

AirTag 2 Rumored to Launch Next Year With These New Features

Sunday November 17, 2024 5:18 am PST by
Apple released the AirTag in April 2021, so it is now three over and a half years old. While the AirTag has not received any hardware updates since then, a new version of the item tracking accessory is rumored to be in development. Below, we recap rumors about a second-generation AirTag. Timing Apple is aiming to release a new AirTag in mid-2025, according to Bloomberg's Mark Gurman....
Magic Mouse Next to Keyboard

No, Apple CEO Tim Cook Didn't Say He Prefers Logitech's MX Master 3 Over the Magic Mouse

Sunday November 17, 2024 3:03 pm PST by
While the Logitech MX Master 3 is a terrific mouse for the Mac, reports claiming that Apple CEO Tim Cook prefers that mouse over the Magic Mouse are false. The Wall Street Journal last month published an interview with Cook, in which he said he uses every Apple product every day. Soon after, The Verge's Wes Davis attempted to replicate using every Apple product in a single day. During that...
Generic iOS 18 Feature Real Mock

Apple Releases iOS 18.1.1 and iPadOS 18.1.1 With Security Fixes

Tuesday November 19, 2024 10:10 am PST by
Apple today released iOS 18.1.1 and iPadOS 18.1.1, minor updates to the iOS 18 and iPadOS 18 operating systems that debuted earlier in September. iOS 18.1.1 and iPadOS 18.1.1 come three weeks after the launch of iOS 18.1. The new software can be downloaded on eligible iPhones and iPads over-the-air by going to Settings > General > Software Update. Apple has also released iOS 17.7.2 for...
at t turbo indicator iphone 16 pro max v0 8hrh7w5f3w1e1

AT&T Turbo Indicator Showing Up in iPhone Status Bar for Subscribers

Wednesday November 20, 2024 3:42 am PST by
AT&T has begun displaying "Turbo" in the iPhone carrier label for customers subscribed to its premium network prioritization service, according to reports on Reddit. The new indicator seems to have started appearing after users updated to iOS 18.1.1, but that could be just coincidence. Image credit: Reddit user No_Highlight7476 The Turbo feature provides enhanced network performance through ...
iPhone 17 Slim Feature Single Camera 1 Redux

'iPhone 17 Air' Rumored to Surpass iPhone 6 as Thinnest iPhone Ever

Monday November 18, 2024 1:07 pm PST by
In a research note with Hong Kong-based investment bank Haitong today, obtained by MacRumors, Apple analyst Jeff Pu said he agrees with a recent rumor claiming that the so-called "iPhone 17 Air" will be around 6mm thick. "We agreed with the recent chatter of an 6mm thickness ultra-slim design of the iPhone 17 Slim model," he wrote. If that measurement proves to be accurate, there would be ...
bug security vulnerability issue fix larry

Make Sure to Update: iOS 18.1.1 and macOS Sequoia 15.1.1 Fix Actively Exploited Vulnerabilities

Tuesday November 19, 2024 10:52 am PST by
The iOS 18.1.1, iPadOS 18.1.1, and macOS Sequoia 15.1.1 updates that Apple released today address JavaScriptCore and WebKit vulnerabilities that Apple says have been actively exploited on some devices. With the JavaScriptCore vulnerability, processing maliciously crafted web content could lead to arbitrary code execution. The WebKit vulnerability had the same issue with maliciously crafted...

Top Rated Comments

christarp Avatar
122 months ago
Good, app specific passwords, two factor authentication, etc as it is right now is just confusing as all hell. It took me like 30 minutes to sign into imessage on my mac because of the app specific password crap. It was a PITA to set up.
Score: 8 Votes (Like | Disagree)
Erukian Avatar
122 months ago
The fact that people are involved isn't what concerns me. What concerns me is that for this to work Aplle must retain the ability to access your account, meaning they can be obliged to access your account by the American government, and people hacking Apple can access your account too. This I bad news. Remember when Apple were promoting the fact that if the NSA asked for access to your account Apple were unable to comply even if they wanted to? Clearly this is no longer the case.
This, a thousand time this. Apple being able to provide access to your account means apple holds the master key to unlock your account. This is a blow to us who rely on Apple for privacy as it's allows open season access for the US Govt or clever social engineers.
Score: 8 Votes (Like | Disagree)
mazz0 Avatar
122 months ago
Idiots!

Why are they involving humans in recovery process yet again???

Did they not learn from the infamous 2012 case???

Leave it 100% to machines!!

Humans can be easily manipulated.
The fact that people are involved isn't what concerns me. What concerns me is that for this to work Aplle must retain the ability to access your account, meaning they can be obliged to access your account by the American government, and people hacking Apple can access your account too. This I bad news. Remember when Apple were promoting the fact that if the NSA asked for access to your account Apple were unable to comply even if they wanted to? Clearly this is no longer the case.
Score: 7 Votes (Like | Disagree)
jkbuster Avatar
122 months ago
Apple still refuses to use my Google Voice # for authentication purposes. Not real enough for Apple, but I use it daily. Ah well.
I'm guessing they take advantage of email -> text addresses provided by phone carriers. Unfortunately, Google has not made this available for Voice. I'd use it in a ton of places as well.

As for having the ability to have them to let you back into your account in case you're locked out, I hope that isn't a requirement for everyone. As someone who operates rather securely, if I screw something up and lock myself out, I want that data to be completely inaccessible. I do not want Apple retaining a secondary backup key to access my information; only I should have the key. Though, not everyone is comfortable with the potential loss of data, which is why it should be an opt-in feature.
Score: 3 Votes (Like | Disagree)
jclo Avatar
122 months ago
Hey Juli Clover,

Did you just post two different articles on macrumors.com that started with the same introduction?!

Recycling at its heights, journalism at its lows.
Those two posts were written simultaneously because they were interrelated and it was at a time when we were doing a million things at once. I didn't mean to word them exactly the same way though, so I apologize for that, and I've changed the beta post.

Sometimes when you write, you skip over whole words and phrases when you read it back to yourself and repetitive bits like that can go entirely under the radar. Sorry for the brain fart there.

By the way, if you see a typo or a title/phrase/word in a post that you have an issue with, you can email us and it'll get our attention faster. It sometimes it takes me awhile to get back to the comments on a post when it's busy. tips at macrumors.com or juli at macrumors.com.
Score: 3 Votes (Like | Disagree)
farewelwilliams Avatar
122 months ago
they need to relax on the rate limiting of attempted verification codes.

i called in on Apple Support, they told me to turn off icloud and turn it on. when turning back on, I needed to send a verification code. verification code never got send to my SMS or my Google Voice, never got pushed to my iPad, and then i tried my iPod touch but the verification process said I was attempting too many codes.
Score: 3 Votes (Like | Disagree)