HomeSecurity2FA Apple: Blocking autofill of verification codes

Apple 2FA: Blocking autofill of verification codes

Apple's two-factor authentication (2FA) autofill feature makes it painless to enter verification codes sent via SMS, but the problem is that hackers are exploiting this feature and carrying out attacks.

See also: Apple has higher profits than ever despite the supply chain crisis

2FA Apple
Apple's 2FA check blocks SMS autofill

For starters, they trick people into clicking on a fake link to a website that asks for an SMS code, and they do exactly what Apple does, they enable autofill of the verification code, and of course no one suspects that it's a scam.

See also: Apple and Tesla supplier hit by ransomware

But Apple seems to want to guard against this and is asking companies to send SMS codes in a new, more secure format.

Your devices will only be offered verification code autofill in this format if the domains match. For example, if the website claims to be apple.com but the phishing link is apple.securelogin.com, then you won't be offered the autofill option.

The new format, which you may have started seeing since late last year, looks like this: Your Apple ID Code is: 123456. Don't share it with anyone. @apple.com #123456 %apple.com

Macworld explains the change.

The format generally looks like this:

  • A standard human-readable message, including the code, followed by a newline.
  • The scoped domain as @domain.tld.
  • The code was repeated again as #123456.
  • If the domain uses an embedded HTML element, called an iframe, the iframe source is listed after the %, such as %ecommerce.example.
Apple 2FA: Blocking autofill of verification codes

The improvement is certainly not a perfect solution, as it relies on the user noticing that their device doesn't offer autofill. It also relies on companies that use SMS 2FA to adopt the new format. Finally, as we've noted in the past, SMS is not a secure form of two-factor authentication. Code generators are a better option, and one is built into iOS 15.

See also: Apple adds 37 new emoji to iOS 15.4 beta

But of course any change for a little more security is welcome, so if you're sent an SMS verification code and you're not offered autofill, take a very close look at the domain name. Better yet, always use your own bookmarks or type in URLs instead of clicking on links.

Information source: 9to5mac.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS