Got a tip for us?

iOS

Security has a broad meaning in everyday life, but a more specific one when it comes to data, networks, computers, and mobile devices.

As a general rule, we talk about security when we mean a means of reducing the likelihood of harm. You go through a security checkpoint at the airport. You have a home security system. A lecture is canceled due to security concerns. An ad for a bike lock claims it offers high security.

With computing and networking, however, security is more specific: it’s the measures you take to prevent harm to you by the extraction, interception, loss, or corruption of your data.

You may also see the term exfiltration, which sounds highly technical but simply means the extraction of data from a device, often over a network, to a malicious or unwanted recipient.

It’s rare that a violation of your device’s security would result in physical harm to you or anyone else—unless someone attacks you while also stealing your equipment. That’s quite rare in a home or office, but it can happen when out and about, where an assault or threat of it could lead you to reveal your iPhone passcode or other passwords.

While it’s also rare to be attacked, or even drugged, to get your passcode, it does happen often enough that Apple added a new protection. See how to turn on Stolen Device Protection.

But even without a physical assault or fear of it, you can suffer emotional harm from the sense of invasion or damage that results from an invasion, particularly if someone violates your security to steal personal information that is then disseminated or used against you.

You can also certainly incur financial damage (theft of identity or money), waste your time (canceling credit cards, changing passwords), find yourself spending hours coping with the aftermath (removing malware, restoring deleted files), and so on. If your Mac became part of a botnet, you could also harm other people’s devices. As a result, your ISP might temporarily cut off your internet service to block attacks originating from inside its network.

Apple’s security options through the mid-2010s focused mostly on resisting attacks carried out over a network and exploits that relied on software that was downloaded and installed with or without your permission. In the new era stretching back nearly a decade now, Apple shifted to giving you tools and automatically protecting your data when someone can take physical control of your device.

The company also puts a lot of attention on blocking exploits and malware in macOS, which, because it allows any software to be installed, remains more vulnerable; the network as a vector for compromising a Mac is nearly entirely ignored. It’s different with iOS and iPadOS, as the key vector for attack there seems to be phishing text messages and attachments, which has led Apple to a constant cycle of hardening Messages and related components.

Protecting against physical attacks requires your device to resist intrusion. That intrusion might be someone merely sitting down in front of a Mac for a few minutes and extracting the contents of your drive without leaving a trace, popularized by hackers in movies. But it more frequently includes deterring a thief who has purloined your iPhone, iPad, or Mac—whether for a period of time or forever—from successfully cracking it at their leisure.

As a result, you now should think both about the digital sense of security and the physical sense:

  • The digital part involves protecting your passwords and passcodes, guarding against remote attacks over the internet, and halting the delivery, installation, and deployment of malware.
  • The physical part involves configuring and understanding Apple’s features that deter hands-on attacks, such as plugging in a USB or Thunderbolt device or even an SD Card that performs an exploit, and up to and including someone removing a motherboard or an SSD or hard disk drive or disassembling an iPhone or iPad. It also includes enabling Stolen Device Protection on an iPhone, Apple’s current highest level of optional physical security enhancement.

Improving your device’s security reduces the chance of certain harms:

  • Loss of data
  • Data taken off your device and sent elsewhere
  • Degraded performance
  • Malware that locks files or sends private data elsewhere
  • Loss of control over your device, including being locked out
  • Hijacking of your Apple Account, which could lead to permanent loss of access to the account

How security, privacy and anonymity differ

Security is closely related to privacy and anonymity, but distinct. Here’s how to keep the three terms straight:

  • Security is freedom from danger or harm.
  • Privacy is freedom from observation or attention.
  • Anonymity is freedom from identification or recognition.

You can have security without privacy (imagine living in a house made of bulletproof glass). You can also have privacy without security (think of a changing room at a clothing store with just a curtain). And you can have both privacy and security without anonymity (think of a royal family ensconced in a castle).

When it comes to your digital life, these concepts—especially security and privacy—go together more often than not. Many of the harms or dangers that might befall you if your security is insufficient involve the exposure of personal data, so one of the biggest reasons to have better security is to maintain your privacy. Or, to put it the other way around, many of the things you can do to protect your privacy are, in fact, security measures.

Which of the three you most need shapes everything else, and that depends on your own risk profile.

It’s a fact of life: software has bugs. And some of those bugs result in security vulnerabilities. Fortunately, most major software vendors, including Apple, have teams of programmers working constantly to identify and fix security-related bugs.

I can’t tell you how many times I’ve read breathless news reports about some newly discovered and seemingly disastrous Apple security issue, only to see a software update from Apple fix it a few days later before any damage occurs. This is Apple’s normal pattern, and it’s why you should never lose sleep about the security crisis du jour.

However, Apple security updates don’t help unless you install them! If you have automatic software updates turned off and ignore alerts or badges, you could be needlessly putting your devices and your data at risk from problems that were solved months or years ago.

Software updates fall into several categories, all of which can fix security issues:

  • Major upgrades, such as from macOS 26 Tahoe to macOS 27 Golden Gate or iOS 26 to iOS 27
  • Minor updates, which can be small increments for big fixes (27.1.0 to 27.1.1), or larger ones when they include feature changes but not a full operating system upgrade (such as 27.0.1 to 27.1)
  • Standalone security updates that fix specific pieces of system software, usually stuff deep beneath the surface (most common with a Mac)
  • Updates to individual Apple apps (Safari, Music, Books, QuickTime Player, etc.)
  • Updates to third-party apps

Which of these should you keep up with? Ideally, all of them, but at a bare minimum, install the standalone security updates. After confirming you haven’t heard of any problems others have had, install minor updates. Major updates require more planning and involve much more than security fixes.

To learn about all Apple software updates with security implications, see the Apple security releases page. Click a specific update to read the security details.

Zero-day exploits

Apple, Google, Microsoft, security firms, anti-malware software developers, independent security consultants, and “gray-hat” hackers (not criminals, but they don’t always play by the rules—or laws) are constantly on the lookout for significant flaws to fix them and release updates before they become a zero-day exploit or zero-day attack. That’s when there’s literally zero days to patch the problem.

Malicious parties—including nation-state actors, such as the security agencies of major countries—may hold zero-days in reserve or use them in such a limited fashion that they remain available for some time. It’s the job of all software developers to patch zero-days before they’re exploited.

It’s much more often the case that ugly bugs are fixed by Apple before they’re exploited in the wild; or the exploit is so tricky, it requires physical device access or incredible sophistication, timing, and targeting. Apple will flag particularly severe exploits and recommend immediate installation when necessary. This happened on April 16, 2025, when Apple pushed out updates across their operating systems to fix zero-day exploits that the company said were already used in the wild in individually targeted attacks.

Zero-day exploits that aren’t reported to Apple and other companies responsibly—sometimes for significant “bug bounties” these firms and zero-day projects pay out—are sold on the gray market and used for pinpoint government operations. These are often ones most people would feel are illegitimate or violate human rights, such as three separate zero days used allegedly by the United Arab Emirates to hijack a single human-rights advocate in their country.

In most cases, Apple releases security updates for the current version of macOS, iOS, and iPadOS, and the previous three—or even four. If you aren’t at least on the third-most-recent version of one of these operating systems, you risk being vulnerable to known security problems that Apple won’t ever fix.

Apple also looks backward quite a ways with hardware, letting you upgrade fairly old Macs, iPhones, and iPads to at least one of the third-oldest operating systems, if not the current one. With Golden Gate, support covers all Apple silicon Macs; Tahoe included four Intel models from 2019 and 2020. iOS 26 and 27 look back to the iPhone 11 series (2019), while the cutoff points for iPadOS 26 and iPadOS 27 are very complicated.

Often the initial releases of new operating system versions (27.0.0, say) have significant bugs that Apple fixes quickly. So it’s fine to wait a few weeks on major upgrades, by which time enough others will have tried out the new release that you can judge how stable it may be for you.

Apple delivers minor and major updates and security updates through Software Update: go to System Settings (Mac) or Settings (iPhone/iPad) > General > Software Update.

Configure automatic security updates

Apple wants you to install updates as soon as possible on all its operating systems. The approach you take may be different between a Mac and an iPhone or iPad.

On a Mac

Software Update shows whether you’re up to date and notes any available updates if you are not. If you’re a major system update behind (or further), it also shows an area at the top urging you to install it. In a secondary area below, the pane may read “Another update is available” for Safari and security updates, and you have to click “More info” to discover which are and proceed to install them.

It also runs in the background and displays a red badge in System Settings indicating quantity. You can’t disable this.

You can completely automate minor macOS, security, and other updates—in fact, that’s the default. (Major macOS updates require direct action.) Go to System Settings > General > Software Update and, to the right of Automatic Updates, click the info button to see settings and make changes.

  • Download new updates when available: This includes all the updates listed below. The advantage is that they are either installed automatically or available for immediate installation if you install manually. Disable this if you’re bandwidth-limited or pay for bandwidth and want to plan downloads.
  • Install macOS updates: This includes all “dot” updates, like moving from 27.0.0 to 27.0.1 and from 27.0.1 to 27.1.0.
  • Install system data files and security updates (Golden Gate) or Security Responses and System files (Tahoe): Apple used to use the term “Rapid Security Response” for these security updates; I’m guessing they now incorporate more kinds of security fixes? Previously, the company explained those updates addressed exploits that Apple discovered were already happening in the wild, not just identified by researchers. These fixes are installed automatically when this option is turned on—no reboot required.

Apple moved automatic App Store updates from Software Update to the App Store app in macOS 26.

In most cases, you can view a list of available updates, deselect or select items in the list, select items to view their contents, and click Install Now to proceed towards installation. Updates that require restarting your Mac are marked with “Restart Required” after their title in the detail section, and you’re warned when you click Install Now that you will need to let the updater restart your Mac to complete the update.

The next major operating system update past what you’re running used to appear as a short entry with a More Info link. But in Monterey, Apple transformed the upgrade notice into a full advertisement that listed all the available features. Minor updates still use the More Info link to tell you what to expect.

When preparing to install updates that require a restart, make sure you have no unsaved files, no open Terminal windows, and nothing in progress in an app. Often, this can halt a restart—particularly an issue if you walk away hoping to return with the update done. I always wait until my Mac restarts before leaving.

In addition to the Software Update setting for system data files and security updates, make sure the setting introduced in macOS 26.1 is enabled: System Settings > Privacy & Security > Background Security Improvement. With this enabled, Apple can update certain parts of the system, such as components of Safari and system libraries used by multiple apps, without requiring a full incremental update and restart.

On an iPhone or iPad

Software Update on an iPhone or iPad, in Settings > General > Software Updates > Automatic Updates, offers options similar to those on a Mac. If you enabled Automatically Install, you’re alerted that an update will happen overnight the next time the device is plugged in and idle. This option also hides the next two: Automatically Download and System Files > Automatically Install.

Even if you don’t want updates to be installed automatically, enabling downloads for iOS/iPadOS Updates lets you avoid waiting for a download to happen when you make the decision to trigger an update manually—the file is ready to go.

Everyone should leave System Files enabled for automatic updates, for the reasons given above.

As with macOS, Background Security Improvements should also be turned on. Go to Settings > Privacy & Security > Background Security Improvements, and make sure it’s enabled.

Configure App Store updates

The App Store is where you buy apps and acquire free apps, including those with in-app purchases, that have gone through additional layers of vetting by Apple. One advantage is that you don’t need to use the app or visit a website to check whether the latest version is installed.

On a Mac, the App Store has an Updates item in its left-hand navigation bar. Click that, and you can see available updates. You can also use App Store’s Preferences to control automatic updates: select or deselect Automatic Updates.

On iPhone/iPad, the default is for updates to be quietly updated in the background. You can change this in Settings > Apps > App Store, where you can disable App Updates. You can see the queue of updates waiting to happen in the App Store app: tap the account button in the upper-right corner and then tap App Updates. Any apps with pending updates appear under an Upcoming Automatic Updates label. You can force a check for updates by swiping down and releasing, and you can tap Update All to force an immediate app update.

Update everything else on a Mac

Software that didn’t come from the Mac App Store must be updated separately. Fortunately, most apps include an automatic, configurable update check whenever you launch them, and also check for updates periodically. You can disable this in nearly all apps, though I recommend keeping the feature on, or enabling it if it’s turned off by default.

If you haven’t seen update notifications lately, or aren’t sure how your favorite apps have automatic updates configured, now is the time to check. Launch each app, select its option to check, and install updates.

Some apps use “check for updates” as a way to sell you on a paid upgrade to the next version of the product. I don’t mind seeing this once or twice, but some software I use brings up a paid update available message at every launch; not cool.

How Apple numbers its releases

Starting with fall 2025 operating system releases, Apple reset their numbering system to the last two digits of the following year, starting with 26. So 2026 releases are iOS 27, iPadOS 27, macOS 27 Golden Gate, tvOS 27, and watchOS 27; and 2025 releases were iOS 26, iPadOS 26, macOS 26 Tahoe, tvOS 26, and watchOS 26.

The reason for the above change appears to stem from some extraordinary articles in the Wall Street Journal. In February 2023, the Journal published a story with an alarming headline: “A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life” by Joanna Stern and Nicole Nguyen. The article noted that individuals were reporting and police departments confirming that an increasing number of thieves were stealing people’s iPhones and coercing or extracting the corresponding passcodes through in-person methods. With the iPhone and its passcode, the thief could unlock an Apple Account using a loophole.

If you don’t enable Stolen Device Protection, you remain susceptible to this real-world exploit, and should read on.

How physical passcode theft happens

The Journal article details multiple kinds of attacks, the most prevalent of which is shoulder-surfing criminal teams, which involve one thief interacting with you and another surreptitiously watching you or recording you.

For instance, one ne’er-do-well might offer to take a couple’s photo. They take the picture, but then sneakily press and hold the volume up/standby button on the phone and tap Cancel (see how to set a stronger iPhone passcode) This requires a passcode to unlock, which someone might naturally enter. However, Stern explained on a podcast that tests with 4K iPhone video indicate someone could easily record your passcode entry from nearly across a room. Then it’s just a snatch-and-grab operation.

Even more disturbingly, the reporters interviewed a number of people who said they were physically assaulted and coerced into revealing their passcode and giving up their phones, or waking up believing they were drugged with their phone missing and later account issues. (The prevalence of druggings at bars has become something awful.)

The reporters explained a criminal can reset an Apple Account password with nothing more than an iPhone passcode and possession of the iPhone. At that point, if someone uses iCloud email with their financial and other accounts, the thief can send password resets and receive second factor SMS and device-based tokens to validate changes and logins. One victim, an economist, lost access to her Apple Account and everything attached to it, and told the reporters that about $10,000 vanished from her bank account within a day.

While Face ID and Touch ID can’t be used to extract your passcode and then reset your Apple Account, they can be used against you if you’re drugged, threatened, or in custody of a government that compels their use. See how to set a stronger iPhone passcode for how to disable Face ID or Touch ID quickly.

We don’t know the scale of these attacks, as there’s no comprehensive accounting and Apple hasn’t made a statement. Does it happen to hundreds of people a year in the United States—the article’s geographical focus—or tens of thousands? Because of that two-thief passcode approach, I’d put my money on hundreds to thousands where the passcode is obtained when an iPhone is stolen.

The Journal raised important questions about how tightly Apple has linked a passcode to the ability to log in to an Apple Account. That led Apple to create Stolen Device Protection.

None of this is the fault of crime victims entering their passcode in public or…being drugged or mugged. Rather, the person who stole from you—I mean, it shouldn’t even have to be said that it’s that person who did wrong.

Before venturing forth into the world:

  • Set a longer or more complicated passcode. This makes it harder for a thief to see or capture what you’re entering.
  • Enable Face ID or Touch ID. This prevents unsophisticated shoulder-surfer snoops. Coupled with the Stolen Device Protection option, it dramatically reduces your exposure to Apple Account and other data hijacking.
  • If you need to enter your passcode in public, make sure there’s no direct line of sight other than your own. Holding your hand over your phone or peering through your fingers is unfortunately not a ridiculous strategy. (I never enter my ATM PIN without holding my hand over the keypad.)

ATMs are also a prime spot for “skimmers” to be attached where thieves have a camera and sensor to grab your card number and PIN. Never use an ATM if anything around the keypad looks suspect, such as a raised external surface around any part.

  • Make sure Find My is turned on. This will help you later if you need to erase your device remotely.
  • Remove from your Photos library any images that show your passport, driver’s license, or Social Security number, or any other cards or information that contain numbers useful for information theft. (“Surely the writer of this book hasn’t left his…oh, no.” Deletes many images.)

This might deter most instances. But for best results, if you consider yourself possibly at risk, read on to enable Stolen Device Protection.

What to do after a theft

Stolen Device Protection doesn’t prevent robberies. If your device is brazenly or violently stolen, here’s what else you can do:

  • Access Find My: If you have access to Find My from one of your other devices right away, use a native app. Otherwise, you can use the Find My app on someone else’s device or log in to iCloud.com and use Find My there. (You have to have your iCloud password memorized or available through some backup method or other device, of course.)

Next, consider doing one or all of the following:

— Put the device in Lost Mode: If you have Stolen Device Protection enabled, putting your iPhone in Lost Mode could make it more recoverable as the thieves won’t be able to do anything useful with it. If the thieves haven’t powered down the iPhone or put it into Airplane Mode, it might immediately enter Lost Mode, or enter it the next time it has even the briefest internet connection. Because Find My is on, and the thieves can’t disable it, your iPhone retains Activation Lock, making it difficult or impossible to resell or reuse the phone.

— Erase the device remotely if it’s online: You can opt instead to try to erase your phone. If it’s online at any point, erasure is immediate, and Activation Lock remains on. In fact, it’s still trackable even after being erased with iOS 15 or later.

— Remove the device from your account if it’s offline: I recommend that if you don’t have Stolen Device Protection enabled and your iPhone is showing as offline, consider whether to remove the iPhone from your Apple Account on another device or via iCloud.com. This prevents Find My tracking, but it also halts iCloud syncing, so there’s a tradeoff.

  • Change your Apple Account password immediately: You may, ironically, need another trusted device connected to your account to do so.
  • Change important financial and email account passwords: If you don’t have Stolen Device Protection enabled, you should change critical passwords elsewhere; with it on, you might consider doing so anyway. After erasing or disconnecting your device, you can create new passwords they won’t have access to. (If you can’t erase or disconnect your device, turn off Passwords syncing in iCloud on your remaining devices.)
  • Call your phone company: If you haven’t enabled Stolen Device Protection, you can block your device from receiving SMS messages by calling your carrier. Have them remove the phone number from the SIM and disable the line temporarily at least. (If you wisely set a PIN for your cellular account, you’ll need that PIN to get the account locked, too.)

This experience can be scary. Theft and assault always is. If you can summon the strength to act quickly, you can minimize harm.

Automatic restart after three days

In late 2024, law-enforcement departments began to exchange stories of iPhones that had been unlocked and were kept carefully in that state in locked, shielded storage areas had spontaneously rebooted. While Apple didn’t make an announcement, iOS 18.1 apparently included a “reboot after inactivity” timer, according to reporting by 404 Media.

iPhones have two general states: Before First Unlock (BFU), which happens after a restart, and After First Unlock (AFU). An iPhone is easier to rummage through for investigative or illicit purposes in the AFU state, when its internal storage has been unlocked and other kinds of access remain available, even if some data remains protected by a passcode or biometrics.

Apple now apparently starts a three-day timer (as of 2026) when an iPhone is in the AFU state. If it’s inactive for that period of time, it restarts, putting it back into the harder-to-crack BFU state. Security researcher Matthew Green told 404 Media it wasn’t about blocking police access—but criminal use. He told them, “This feature means that if your phone gets stolen, the thieves can’t nurse it along for months until they develop the tech to crack it.”

Tags: iOS, Security

Advanced Data Protection (ADP) is an option to enable end-to-end encryption (E2EE) for iCloud-stored data from your Mac, iPhone, or iPad. ADP covers nearly all the data for which Apple previously lacked an E2EE option. (See how to share files with end-to-end encryption for a full definition.)

You can see a full list of the items that are encrypted at rest (on servers using keys Apple possesses) and those with E2EE enabled in iCloud on Apple’s website, both with and without ADP enabled. Without ADP, these items remain encrypted at rest only: iCloud backups, Freeform (Apple’s collaborative drawing tool), iCloud Drive, Apple Invites, Messages in iCloud, Notes, Photos, Reminders, Safari bookmarks, Siri Shortcuts, Voice Memos, and Wallet passes. Enabling ADP adds E2EE to all of them. (Apple Invites has exceptions; see note on the page linked just above.)

Email, contacts, and calendar entries can only be encrypted at rest due to interoperability with third-party services and apps.

I recommend enabling ADP if you qualify, as it provides a strong additional layer of protection for private data that you might consider “local” if you never access it via iCloud.com.

What ADP requires

ADP requires two-factor authentication on your Apple Account, which most accounts already have enabled due to Apple’s nearly mandatory policy. You also have to have passcodes on all of your devices—also, nearly universal. One requirement not everyone will have met: iCloud Data Recovery has to be turned on with at least one active contact or an Apple Account Recovery Key.

All your devices must meet minimum system requirements, which nearly every current device exceeds: macOS 13.1 Ventura, iOS 16.2, iPadOS 16.2, tvOS 16.2, watchOS 9.2, and—yes—HomePod 16.2. If you have any associated Windows computers, they must have iCloud for Windows 14.1 or later installed.

Apple says managed Apple Accounts and accounts set up for children cannot enable ADP.

An Apple Account Recovery Key is entirely unrelated to the FileVault Recovery Key. See where to find your FileVault Recovery Key.

Siri AI, Private Cloud Compute and conversations

Apple introduced Siri AI with iOS 27, iPadOS 27 and macOS 27, a more full-featured chatbot version of Siri on devices that support Apple Intelligence. Conversations with Siri are stored in the new Siri app and synced via iCloud. However, these are end-to-end encrypted sync operations, such as what’s used with Messages and iCloud Passwords. You don’t need to enable ADP, as described next.

To provide these enhanced services, Apple may send portions of your queries to what they call Private Cloud Compute. Private Cloud Compute consists of both servers they own and operate and servers in Google Cloud that Apple controls every component of, even though it’s not Apple hardware or in an Apple data center. You can’t prevent these requests from leaving your hardware, but Apple says all queries are encrypted end to end, untraceable back to you, impenetrable to Apple and any partners (even when debugging servers or code), and so forth. This is covered further in what Apple Intelligence, Siri AI and Visual Intelligence actually are.

Turn on ADP

Start by going to the ADP setting section: System Settings (Mac)/Settings (iPhone/iPad) > Account Name > iCloud > Advanced Data Protection. Tap Turn On Advanced Data Protection or click Turn On.

Apple now lets you turn on ADP:

  1. Apple warns you that “you will be responsible for your data recovery.” You have to click or tap the Review Recovery Methods option or Set Up next to an Account Recovery button.
  2. If you have Recovery Contacts, they’re shown. Click or tap Contacts Up to Date if they are or select Update Recovery Contacts if they are not to revise. Then return to step 1.
  3. If you have a Recovery Key, you must enter it and click or tap Next.
  4. With your recovery methods approved, enter your macOS account password or device passcode when prompted.
  5. Finally, you’re told, “Advanced Data Protection is On.” Click Done.

You should also receive an email to your iCloud.com address that tells you ADP was enabled.

If your devices aren’t all running the minimum supported operating system versions, you’ll be told which ones require an update. You can choose to upgrade all devices or remove one or more outdated devices from your account. Go to Settings/System Settings > Account Name, select a device, click or tap Remove from Account, and follow the prompts.

Reach your data on iCloud.com

With ADP enabled, all your data except email, contacts, and calendar entries is encrypted by keys held on your devices. That would appear to count iCloud.com access out. But Apple has a workaround. They allow temporary access using in-browser encryption.

First, you have to let yourself view the data on iCloud.com: go to Settings/System Settings > Account Name > iCloud. On an iPhone or iPad, tap iCloud.com and then Allow Data Access; on a Mac, click Data Access on iCloud.com and enable Allow Data Access. Confirm your choice; in fact, you have to confirm twice.

You can disable non-ADP access via iCloud.com using that setting, too.

With that enabled, here’s how to unlock temporary access:

  1. Visit icloud.com in a browser and log in.
  2. Apple shows a banner that explains that ADP is on and how to proceed.
  3. Select an app, such as Photos.
  4. Apple sends an access request to trusted devices. (If you don’t see the prompt, you can click or tap Request New Access.)
  5. On a trusted device, click or tap Allow Access.
  6. On your trusted devices, a banner appears alerting you that you’ve enabled temporary access.

Data remains accessible for an hour from each request. Each additional data type you want to access may require another permission request and approval unless requested shortly after a previous request.

Data previously unavailable on iCloud, such as Passwords entries and Health data, remains locked on devices.

The Find My exceptions

Until mid-2021, Apple listed Find My (Devices and People) as protected by their keys. When the company started to break out “in transit & on server” and E2EE, it dropped Find My from the iCloud page. Apple then stopped documenting the relationship of Find My with iCloud. That leaves it to me to try to explain.

The Find My Device web app is available at iCloud.com when you log in with two-factor authentication or a passkey. Even if ADP is enabled, you’re not asked to start a secure, device-approved session. Apple uses secure transit and their own keys to pass your location from your devices and those of people in your Family Sharing group who have shared location with you to your iCloud account. There’s no other way for that information to appear.

Apple doesn’t pass information about other people’s location, nor do they provide AirTag and other Find My item positioning, and thus I assume there is device-based E2EE involved in sharing that information among your hardware that Apple doesn’t want to override.

Turn ADP off

Disabling ADP is straightforward. Go to Settings/System Settings > Account Name > iCloud > Advanced Data Protection. Tap Turn Off Advanced Data Protection or click Turn Off. Follow the prompts to confirm you understand you’re removing E2EE protection from many of your synced and stored data.

One of the most unsettling things that can happen to your device and your data is when you are locked out from your computer. It’s rare, and you can prepare against the possibility so that your recovery is quick—or at least feasible, if not fast.

An ounce of prevention saves a kiloton of cure when it comes to accounts and access. If you follow the following advice ahead of time, you can avoid serious downtime and loss of data.

Keep fresh backups

Backups are the strongest protection you can have against theft, destruction, and loss, including “loss of access.”

If you have daily backups of your Mac and attached drives onsite (via Time Machine or third-party software), copies of your startup volume and external drives offsite, active continuous or daily cloud-hosted backups, or use a sync service to ensure multiple copies and a version history of your active documents, losing access to your Mac still has a sting, but you likely will lose very little data, if any.

You could be like me and do all four. But that’s me.

In some cases, you might be locked out of your current Mac, such as with a FileVault failure or the loss of a Recovery Key. In those cases, you can erase the computer and restore from a full backup, putting you right back in business. Or you may be able to use an external drive or synced files to get back to work on another machine—perhaps a borrowed one—while you plot unlocking the Mac you can’t get to.

Macs that support Activation Lock and have it enabled by turning on Find My Mac require that you can log in to your Apple Account to erase the computer. See how to reset a forgotten Mac password.

With an iPhone or iPad, your biggest job is ensuring you have enough storage in your iCloud+ plan to allow iCloud backups. You can also use a Mac for device backups, but that dramatically increases the odds you’ll be out of date and missing data. With automatic iCloud backups enabled and using iCloud Photos, it’s unlikely you would lose any data—at worst, very little.

Where to keep your passwords

You should have a go-to, secure place for all passwords, passkeys, and other login and encryption keys you may need in the event of a disaster, including:

  • Passwords for one or more administrator accounts on your Mac
  • Passcodes for any iPhones or iPads
  • The Recovery Key for macOS’s FileVault; see where to find your FileVault Recovery Key
  • The account name and password or passkey (or hardware security keys) for your Apple Account (or Accounts)
  • The password for your password manager (which may be the sole item you memorize, and you may also provide a copy to a lawyer, sibling, or trusted party to hold securely)

This secure password repository should preferably be available from a device or location that isn’t tied to where you keep your hardware.

Check your trusted devices and numbers

With two-factor authentication (2FA) enabled on your Apple Account, you might be locked out permanently if you lose access to trusted devices, and trusted phone numbers for SMS and automated voice calls, or can’t find hardware security keys that can be used with an Apple Account.

If you’re using hardware security keys with your Apple Account, Apple already requires that you associate two of them with the account. Always keep one in a place you can get to in an emergency in case the other is lost or destroyed.

Any Apple device logged in to an iCloud account with 2FA active is a so-called trusted device. You can tell that this is working when you try to log in via a browser to the Apple Account website, as every trusted device will display a notification for the 2FA code needed to confirm the login.

If one of your trusted devices doesn’t show that message, check in System Settings/Settings > Account Name that you’re correctly logged in and that you see all the associated devices you expect. If you still can’t get your Apple Account to message trusted devices or the list of devices is missing, you may want to log out of your Apple Account on affected devices and then log back in.

This can take a while and prompt you to answer a lot of questions about synced data—the answer for most is “keep data stored on this device.” When you log back in to iCloud on the device, you agree to merge data, which should avoid duplication and deletion.

You should also check that trusted phone numbers are still properly registered:

  1. Log in at the Apple Account website. If you have Touch ID or Face ID active, click “Use a different Apple Account” and then enter your ID and password.
  2. Instead of entering a 2FA code, click or tap “Didn’t get a verification code?”
  3. Click or tap Text Me. (This will be labeled differently if you marked any or all trusted phone numbers as receiving automatic voice calls instead of text messages.)
  4. Select a trusted number if more than one is available; if only one, Apple texts that number.
  5. Enter the code that’s sent or use the AutoFill option in Safari.

If you never receive the code, log in with a trusted device, check the phone number, and remove and add it. I also recommend having multiple trusted phone numbers as backups.

Changing your phone number has a huge impact in the era of 2FA. You should instead try to transfer your old number to another phone temporarily so you can switch the number listed for various accounts’ 2FA and for iCloud trusted phone numbers.

If you have willing friends, colleagues, or families, having their number as a backup in case your phone isn’t available doesn’t really reduce security, as they would need to know your Apple Account username and password to compromise your security.

Put a PIN on your carrier account

Add a PIN (if you don’t already have one) for account access to your wireless carrier or enable the highest security available for an increasingly rare wired home phone line. Someone who could obtain codes from your phone number might be able to reset your Apple Account and then access iCloud information. (Enabling Advanced Data Protection is one way of preventing that.) Because of accessibility, codes can often be sent both by SMS and by an automated voice system that speaks the code.

Crackers often target people and combine social engineering and easily available online information to convince a customer-service representative that they are the legitimate account holder to get a phone number migrated to a new phone. (Are you likely to be targeted? See whether you need more security than Apple’s defaults. Yet someone may target your account at random to launch attacks.)

The PIN sets a higher bar, because a cracker might have your phone number, financial details, and other information, depending on data breaches floating around.

Keeping your security keys safe

You should treat hardware security keys as if they were irreplaceable keys to the castle—like a passphrase for a cryptocurrency wallet or a password for a vault that self-destructs when you’re one number off in a Dan Brown novel. They’re extremely secure, absolutely vital, and also can be used by other people!

Apple requires that you enroll at least two hardware security keys for an Apple Account. Most sites only require a single hardware key, or won’t let you enroll more than one. If you lose the key, most sites offer a workaround that requires more forms of validation to gain access. Apple does not.

If you can’t find your hardware security keys (or they’re irretrievable, stolen, or busted), but do have access to any of your Apple devices, you can go to Settings/System Settings > Account Name > Sign-In & Security > Two-Factor Authentication > Security Keys and remove all hardware security keys. This requires your device passcode or macOS account password if Stolen Device Protection is disabled, or Touch ID or Face ID if that feature is enabled. Then you can use code-based 2FA to log in to your Apple Account. You can choose to add new security keys if you want to re-enable that level of account security.

Apple has a significant flaw in hardware key management: you can remove all the keys from your Apple Account on an iPhone, iPad, or Mac using only the device passcode or the macOS account password. I feel Apple should demand additional information or another hardware key on the account, since the keys are meant to provide an extra-high level of security.

Enabling Stolen Device Protection requires Face ID or Touch ID to remove all keys. So if you’re concerned about someone gaining access to your device and its associated device or account secret, enable that feature. See how to turn on Stolen Device Protection.

Apple built in privacy protection for an issue adjacent to your IP address. Every Ethernet or Wi-Fi adapter, built in or plugged in, has a unique MAC address—that’s Media Access Control, not Macintosh. A MAC address appears in the form xx:xx:xx:xx:xx:xx, where each x is a value between 0 and 15 expressed in hexadecimal (0 to 9 then A to F). Apple perplexingly calls it a “Wi-Fi address”, which is the incorrect name.

A MAC address is how a device communicates over a local network, used to make sure every interface has a unique address to avoid data being delivered to the wrong location. However, because this MAC address is set in hardware, clever hackers and marketers started to use it to associate people with devices—your MAC address persisted indefinitely, so a Wi-Fi router in a public place could conceivably track you over time whenever you connected to any router that shared information with a central database, like a cell carrier or ad-targeting service. Bad!

Apple got around this by adding a “Private Wi-Fi address” option (still the wrong term) that generates a unique MAC address for each Wi-Fi network you join, changing it from time to time. This deters and potentially fully prevents MAC-based tracking.

Apple made significant changes to this several-year-old feature in iOS 18/iPadOS 18, macOS 15 Sequoia, and watchOS 11.

You can configure “Private Wi-Fi address” in one of three ways:

  • Off: The actual unique MAC address is sent to the router.
  • Fixed: Your device generates a MAC address that’s used consistently for the selected Wi-Fi network. This may be required in some places in which a MAC address is used as part of a hotspot portal’s permission system that grants you access or in corporate environments when you’re a guest. Your home router may even offer an option to set a fixed private IP address using a MAC address, so your MAC address needs to be fixed.
  • Rotating: The private address that’s generated is changed to a new, randomly created one every two weeks, whether you’re connecting in that period or after a gap of two weeks or longer.

Apple defaults to either Fixed or Rotating. It uses Fixed the first time you connect to a network with relatively modern Wi-Fi network security—WPA2 or later, to use the technical term. A network without such security, either using outdated standards or requiring no passwords, such as at an open Wi-Fi network at a café, is set to Rotating by default. You have to choose Off, read a warning, and confirm.

The options to change the type of Private Wi-Fi Address used with a network vary by operating system:

  • iPhone/iPad: Go to Settings > Wi-Fi: tap the info button next to the currently connected network or any other network that appears. You can also tap Edit, and then tap the info button next to any stored network.
  • Mac: Go to System Settings > Wi-Fi > Details for the active network. For other networks, click the More button; for Known Networks, then choose Network Settings.

To see the underlying Wi-Fi adapter’s hardware-set MAC address, go to Settings > General > About and look for Wi-Fi Address on an iPhone or iPad. On a Mac, follow the path of System Settings > Wi-Fi, click the Advanced button, and see Wi-Fi MAC Address near the top.

An iPhone or iPad will detect any item within Bluetooth range that is traveling with you persistently, whether the device works with Apple’s or Google’s crowdsourced ecosystem. An alert helps you take action.

An iPhone or iPad shows an alert that reads “AirTag Found Moving with You” or “Item Detected With You,” depending on which is true. iOS 17.5/iPadOS 17.5 or later can also detect Google trackers.

You might see such an alert because you borrowed something that has an AirTag attached or hidden in it without that person sharing the item with you. For instance, my wife has a Find My item in the car she drives most frequently. We solved the problem with device sharing. See how to share an AirTag with someone else.

The name of an Apple tracker will appear as Person Name’s Name They Gave Device, like “Moses Johnson’s Wallet.” I haven’t determined where Apple pulls the name from, but likely the Apple Account associated with the device—another strong clue to or the actual identity of the tracking person. If the name isn’t retrievable, the generic model type is shown instead. Google items also reveal some identifying information, like their serial number.

Apple told me that the alert appears for someone in three particular circumstances:

  • They arrive home, as defined in the Me card in Contacts.
  • They arrive at a Significant Location (see sidebar ahead).
  • It is the “end of the day” and they haven’t been alerted yet. Apple declined to explain when the end of the day is measured.

Apple once said they planned, in a future release, to provide alerts “sooner” than the scenarios described above. They didn’t define what “sooner” means, however, and never set a timeline for changes. It’s been years!

Because Find My items routinely change the encrypted Bluetooth ID they transmit, this recognition that an item is moving with someone has to happen over what we believe is 12 to 24 hours. Apple doesn’t disclose the interval at which the Bluetooth ID changes.

What you can do about it

The person who receives the alert can ignore it. They may know they have someone else’s Find My item with them, or they may not know why they’re receiving it, and it isn’t of interest to them.

However, the person who sees the alert can tap it to open a screen explaining why it appeared. The screen explains that “The owner can look up its location,” that they can mute the alert, that they can play a sound, and that they can get “visual guidance” to locate it. Tap Continue, and a map appears showing the track detected with a red dashed line.

This map can be viewed later by tapping the item in the Items/Unknown Items Detected With You list in the Items view; see below.

This track is made up of points at which a device has detected that the item is traveling with someone. The device knows only the time-bounded encrypted Bluetooth ID of the item and a location that the device determines.

They can now choose an option:

  • Find: Find My guides you to the item, either with Precision Finding with an AirTag (see how to use Precision Finding) or imprecise location via Bluetooth.
  • Play Sound: Play Sound is the rare communication that passes from a device to a Find My item. It uses Bluetooth to trigger a sound from the device to help determine its physical location. AirTags produce a mid-level volume pattern of audio; the Chipolo ONE Spot has a 120 dB emitter that is pretty impossible to not pay attention to. Other Find My items vary from loud to extremely loud.
  • Pause Tracking Notifications: Pause Safety Alerts doesn’t disable tracking, but stops the device from popping up the “Detected/Moving with You” warning. Strangers can tap to disable notifications for a day; people in your Family Sharing group see the additional option to pause indefinitely. (I recommend sharing an item in this case.)

If you don’t take an immediate action on an item that’s been identified as traveling with you, it appears in the Items list in a new category, Items Detected With You.

I’d argue your best strategy is to find the device using Find and Play Sound, then use the Find My app’s ability to learn more about the item as described in how to identify an AirTag you have found.

You can use the native Find My app on an iPhone, iPad, or Apple Watch (the Find Items app) to find nearby Find My items. See how to identify an AirTag you have found.

With Android 6 or later and a 2024 update, you should receive alerts about Apple and Google tracking devices with no additional effort on your part. The message and options are similar to those on an iPhone or iPad.

There’s also a manual scanning app called Tracker Detect that Apple released for Android. It requires Android 9 or later. See how to identify an AirTag you have found.

Why an AirTag chirps alone

The iPhone or iPad requirement for the previous notification leaves out people with older hardware or who use an Android phone that doesn’t have Apple’s Tracker Detect app installed (or no smartphone at all). For them, Apple has the device itself issue a secondary warning.

Whenever an item becomes separated from its owner, it starts an internal timer. At a random point 8 to 24 hours later, the AirTag or third-party item plays a sound—but only when it’s moved. This timer is internal to the device, so it’s not reliant on other hardware tracking Bluetooth IDs over time.

Some third-party trackers produce a sound dramatically louder than the 1st-generation AirTag. Apple increased audio volume with the 2nd-generation AirTag, which the company says is 50% louder. While the company declined to answer questions about loudness and anti-stalking measures, it’s clear that the more intense sound benefits both finding an AirTag you placed intentionally and one placed without your knowledge.

This requirement that the device be moved strikes a balance between deterring stalking and allowing the use of Find My items for items that you want to remain in place without you around. Because the owner of an AirTag or other item knows where they left it the last time their paired device was nearby, the only information they can derive if it isn’t moved, is that it has remained in place. That could reveal some “negative knowledge”: that someone’s purse or car, say, remained in place. Yet, the unwanted-tracking party would never be sure whether or not it were moved and made a great racket. That risk will help deter misuse.

A great justification for the movement requirement comes from an example a friend gave me. His son wanted to put an AirTag on his bike when he parked it at school for more than eight hours at a time. If the bike started keening while left behind, this might lead passersby or university police or security to investigate.

The same is true if you’re traveling or living with other people. If you or others leave bags or items behind while elsewhere for extended periods, you and they don’t want a sound to go off in the middle of the night, say, or from an obscure closet.

Significant Locations stay on your device

Your iPhone or iPad takes note of places you frequently visit, and some others it thinks are “significant.” I went to a sushi place once, was there for a few minutes picking up takeout, and my phone decided that was significant.

Significant Locations are stored only on your devices, and are synced using end-to-end encryption. Apple says they never have access to them, and that iPhones, iPads, and Macs use them entirely on-device.

These locations are stored in Settings/System Settings > Privacy & Security > Location Services > System Services (tap on an iPhone or iPad; click Details on a Mac). The label reads Significant Locations & Routes starting in iOS 26/iPadOS 26 and Tahoe; it’s called Significant Locations in earlier releases. Tap the item or click Details next to it on a Mac. You can view the places you consider significant, disable the feature, or clear the locations currently stored.

Where to get help

There are many organizations beyond law enforcement eager to help people trapped in situations of domestic abuse or child subject to violence and an unsafe environment. For adults in the United States, that includes the National Domestic Violence Hotline; for children or those concerned about their welfare in the United States and Canada, the Childhelp National Child Abuse Hotline.

For those being stalked, one starting point is Safehope. It’s more likely you will need the help of police or federal authorities. Local police departments have their own paths to navigate, but for online or cyber stalking, it may be better to start with the FBI.

If the person you are worried about may be watching your device, use one they cannot see. Removing a tracker or turning off sharing can be noticed, and advocates warn that it can make a situation worse rather than better, so it is worth talking to someone before you act.

Biometric protection is a terrific safeguard to layer on top of other basic protections. By letting you use a fingerprint or your face to unlock your device, it increases security for your files and data while also making it easier for you to log in.

Touch ID first appeared on iPhones with the iPhone 5s in 2013, and was added to iPads starting with the iPad Air 2 model the next year. All subsequent iPhones and iPads included Touch ID until Face ID replaced fingerprint authentication on the iPhone starting with the iPhone X in 2017. Since then, it’s been part of every iPhone except the iPhone SE series, which retains Touch ID.

The sole iPad model with Face ID is the iPad Pro, starting with the 1st-generation 11-inch and 3rd-generation 12.9-inch models in 2018. All other iPads that can run iPadOS 26 or 27 have Touch ID, which dates back to 2014 in some iPad model lines.

Touch ID was extended to Mac laptops starting with two 2016 MacBook Pro models. It was later added to all new MacBook Pro models and the MacBook Air starting in 2018, when it became standard. However, that doesn’t help those of us with desktop Macs.

In May 2021, Apple released the Magic Keyboard with Touch ID (in both standard and extended versions) along with their new M1 iMac. This brought Touch ID to a desktop Mac for the first time. Apple later began selling this version of the Magic Keyboard separately, and while the keyboard part works with any Mac, the Touch ID sensor requires an Apple silicon processor.

Apple uses a secure wireless connection between the keyboard and the Secure Enclave module in an Apple silicon Mac to manage Touch ID. That technology is the Secure Enclave.

Apple requires the use of Touch ID or Face ID with its iPhone anti-theft feature, Stolen Device Protection.

Apple lets you choose to enable Touch ID or Face ID to unlock your device, use Apple Pay, pay for items in Apple’s various stores, validate that you want to automatically fill in a password field in Safari and some other locations, and switch between user accounts when fast user switching is turned on. Some third-party apps offer Touch ID or Face ID as a verification option.

Why Apple Pay turns itself off

You may find that your Mac has disabled Apple Pay without a notification, and you notice only when you attempt to use it in Safari or open System Settings > Wallet & Apple Pay.

This can happen for several reasons:

  • Security level changes: If you lower the level of security for an Apple silicon Mac, you may see the message “Apple Pay has been disabled because the security settings of this Mac were modified.” See how macOS protects its own system files.
  • Laptop lid closed: If you have a laptop, its lid must be open. The exception? If you have an Apple silicon laptop Mac paired with a Magic Keyboard with Touch ID, you can use the keyboard’s sensor.
  • System out of date: Apple says that the “Install system data files and security updates” box should be checked for automatic installation of those files in Software Update. See how to set up automatic security updates.
  • Insecure miscellany: Apple also says ambiguously it disables Apple Pay “when it detects third-party software or malware that affects its ability to keep your payment information secure.”

Enroll in Touch ID

You can enroll your device to use Touch ID via Settings/System Settings > Touch ID & Password. Click or tap Add Fingerprint, then follow the prompts to fill in the fingerprint’s main portion, and then the edges. On a Mac, click Done to finish.

I always name the fingerprint descriptively by clicking or tapping it and then typing text.

Naming fingerprints can be a security or personal safety weakness, allowing someone who wants to coerce you to know which finger to force. However, they would also need to open the Touch ID settings to find out.

You can lock your device against Touch ID by using the wrong fingertip five times in succession; see the lockout section below. This is a good trick when you want to prevent being physically coerced into unlocking your Mac.

I like to enroll at least two of my fingers, because it’s a one-time process per fingertip and it lets me avoid remembering which finger is the right one. You can have a total of three on a Mac or five with an iPhone or iPad. Add other people in your household if you want them to be able to unlock your device or use other Touch ID-required features.

Enroll in Face ID

Face ID for the iPhone and iPad Pro (models noted above) uses an infrared laser and sensor to project and measure 30,000 separate data points on a person’s face to create a profile while also capturing other flat views. Subsequent logins repeat those tasks and introduce randomization, allowing the phone to compare the current face with the stored profile and detect face forgery.

iPhone and iPads with Face ID can recognize just one face plus an “alternate appearance,” or a common secondary appearance of yourself, like with any or different makeup, hat, or glasses. Face ID has worked in portrait orientation since its introduction on all supported devices. Landscape authentication works on all supported iPads and iPhone 13 series models and later.

Enrollment uses a similar process to Touch ID: you use Settings > Face ID & Passcode, and choose Enroll Face. The process has you move your head in a circular motion framed on screen until enough information has been gathered.

Apple says they track and retain temporary updates when they find a good match that falls outside their ideal parameters. These temporary updates are good for only a “finite” number of unlocks, which is a little vague. Maybe it’s to cope with temporary clothing choices or eyebrow plucking? A change in glasses?

You can tap Set Up an Alternative Appearance, useful if you have different ways you make yourself up or attire yourself. Apple has never made fully clear how different that can be.

Face ID relies on an “attentive” expression when you log in. This prevents unlocking the phone or tablet when you’re just glancing past the Lock screen, and it requires someone to have their eyes open. Apple says you can unlock wearing sunglasses. The emitters and sensors are designed for use in all lighting conditions, both indoors and outdoors. The alternate appearance helps here, too.

Apple offers support for facial recognition while wearing a mask with iPhone 12 models and later in portrait orientation only. Here’s how to set up the Face ID with a Mask feature:

  1. Go to Settings > Face ID & Passcode.
  2. Enter your passcode.
  3. Tap Face ID with a Mask while wearing a mask typical of the kind you normally wear.
  4. Apple now informs you of the risks and nature of Face ID with a Mask. Tap Use Face ID with a Mask to continue.
  5. While wearing a typical mask, tap Get Started and walk through the facial training system you’re already familiar with for unmasked Face ID.

Apple appears to ignore most of the mask area, so if you use patterned cloth or medical-grade masks, it shouldn’t prevent you from swapping out masks.

If you wear glasses normally with a mask, wear those while setting up Face ID with a Mask; my current enrollment shows “1 pair of glasses added.” You can have a total of four sets of glasses. Add more by tapping Add Glasses.

Face ID can be delightful as you can merely raise an iPhone or iPad to wake it and, while glancing attentively, the device unlocks.

With Apple Pay at a store payment terminal or in conjunction with Apple Pay in Safari for Mac, you have an extra step even with an unlocked iPhone or iPad. A message appears requesting payment. You double-tap the side or top button, then glance to approve the payment.

For the best results when using Apple Pay with Face ID while wearing a mask, first double-press the side button and authenticate with Face ID; then, with the screen showing “Hold Near Reader,” hold your device to the terminal. I adopted this after finding the angle of terminal, mask, and Face ID sensor were often out of alignment.

Although I recommend setting a strong passcode, you may wind up entering your passcode more frequently with Face ID than with Touch ID for a few reasons:

  • Face ID is good but not perfect; bright light can prevent a match.
  • Some models and brands of sunglasses use optical filters that apparently prevent a good or reliable match.
  • When the sensors can’t perform as exact a match as required, they defer to the passcode. This happens routinely but not constantly.
  • Face ID requires a first-use step with Ask to Buy, used for parents or guardians to approve children’s purchase requests. While Touch ID may be used without any preamble, on Face ID-equipped devices, the first time there’s an Ask to Buy request, you have to enter your Apple Account password. You can then enable Face ID for future approvals.

When biometric lockout happens

Apple disables Touch ID and Face ID in a number of cases. Technically, the operating system flushes a kind of temporary permission for accessing certain data. Entering the passcode refreshes that access. Here are several cases in which you’re required to enter the passcode again:

  • After five incorrect fingerprint or facial recognition attempts. Apple notes, in a parenthetical in their security documentation: “(though for usability, the device might offer entering a passcode or password instead of using biometrics after a smaller number of failures)”.
  • After a restart.
  • When you’ve marked the device as lost via Find My.
  • When you add or remove fingerprints or refresh Face ID.
  • When you try to visit Settings/System Settings > Touch ID/Face ID & Passcode.
  • After you try to use Emergency SOS on an iPhone to make an emergency call. This can be changed in Settings > Emergency SOS.
  • After an attempt to view your Medical ID is made on your iPhone.
  • After 48 hours of a device not being unlocked with Touch ID, Face ID, or an account password.

There’s one more case that’s hard to put into a bullet point. There’s a special countdown clock with two phases. It resets each time you enter your passcode. A 156-hour countdown begins (six and a half days). After that period, a second timer starts a four-hour countdown. If, during those last four hours, you don’t use Face ID or Touch ID to unlock your iPhone or iPad, the next time you use it, you’ll be required to enter your passcode.

You’re probably thinking: “Why?! Why, Apple?! Why!!!” Apple has never made a public statement after this biometrics lockout was added several years ago. The best I can figure, they want to ensure you have to enter your password on a regular basis so it doesn’t fall out of your brain. Now, should you be expected to keep track of the above clocks? No! Not at all! However, if you’re asked for your passcode every week or so when you wake up, and wonder why, that’s probably the reason.

You can make a variety of medical information available at Settings > Health > Medical ID. Once you create this, anyone can attempt to view it via the emergency dialer screen. Understandably, this signals your iPhone or iPad is in someone else’s hands, so locking out biometrics is a logical move.

Also, if you have Face ID with a Mask enabled, Apple reduces the interval between passcode requests on your iPhone to 6.5 hours. Every time you use Face ID (with or without a mask), enter the passcode, or use your Watch to unlock your iPhone, the 6.5-hour timer resets its countdown.

Disable Touch ID or Face ID

You may choose to stop using Touch ID or Face ID or want to use it in a more limited fashion.

If you’re in a situation in which you temporarily want to disable Touch ID or Face ID, the easiest way is to hold down either volume button and the side/top button until a screen appears a few seconds later.

iPhones show you the Emergency SOS screen, including Medical ID, if set; iPads show the Slide to Power Off button. At this point, Touch ID or Face ID is disabled, no matter what action you take. Typically, tap Cancel. (For more strategies, see how to set a stronger iPhone passcode.)

You can access your iPhone or iPad after this only by entering your passcode. However, that re-enables Touch ID or Face ID. In some countries and conditions, you can refuse to enter your passcode.

If you don’t want either biometric capability available—for instance, while crossing a national border—go to Settings > Touch ID/Face ID & Passcode and disable the four “Use Touch ID/Face ID For” switches.

In a native Find My app or the Find Items app on an Apple Watch, you can discover the location of your AirTags and other Find My items in the Items view and any someone else has shared with you. The map zooms in as with Devices; in the version 27 releases, select again to deselect the item, and the map zooms out.

If you have any 2nd-generation AirTags, they appear only on devices updated to at least version 26.2.1 of Apple’s operating systems.

Ultrawideband (UWB) can be used for short-range finding, which Apple calls Precision Finding. (See AirTag 2 vs AirTag for the explanation of UWB.) A Find button with a Nearby label beneath it appears as an option if you have an iPhone 11 or later and you are trying to find an AirTag that’s nearby. It can also be used—in a more complicated manner—with certain Apple Watch models; see below. Precision Finding works with your own Find My items and any that other people have shared with you.

Tap Find and Find My pops up a wayfinding mechanism that tries to detect, range, and point to the item. Apple doesn’t provide details about the distance over which they expect Precision Finding to function. However, in my testing and that of many others, you typically start seeing a signal connection display within about 30 feet (10 meters). As you get within about 10 to 15 feet (3 to 4.5 m), a proximity indicator shows distance and direction.

That’s the baseline capability with a 1st-generation AirTag or either generation of AirTag with an iPhone that has a 1st-generation UWB chip. Apple upgraded UWB with a 2nd-generation chip in the 2nd-generation AirTag and in the iPhone 17 series, the iPhone Air, the Apple Watch Ultra 3, and the Apple Watch Series 11. A 2nd-generation AirTag and any of these devices should see about 50% greater range, according to Apple.

If your device has haptic feedback and it’s enabled, an iPhone vibrates more or less strongly as you lock onto the correct direction and come closer. You can tap the speaker button to briefly play a sound from the AirTag to aid in finding it.

When you’re adjacent to the item, Find My replaces the distance with the label “here” (yes, in lowercase), and shows a 3D rotating image of the item at the center of the display.

Why it says More Light Required

If you use Precision Finding when it’s dark around you, Find My might show the error “More Light Required.” It’s not that UWB requires light. Rather, it appears Apple uses some camera and sensor inputs to help orient your iPhone relative to an AirTag or AirPods Pro (2nd generation) charging case. You can tap the Flashlight button to help.

UWB is not available at all in 10 countries. Indonesia and Nepal allow its use only with items and devices that have the 2nd-generation UWB chip: the 2nd-generation AirTag, the iPhone 17 series, the iPhone Air, the Apple Watch Series 11, the Apple Watch Ultra 3, and the MagSafe Charging Case for AirPods Pro 3.

Precision Finding on an Apple Watch

Apple built a 1st-generation UWB chip into the Apple Watch starting with the Apple Watch Series 9 and the Apple Watch Ultra 2. But Apple didn’t enable Precision Finding until watchOS 26.2.1, and limited it to Apple Watch models with a 2nd-generation UWB chip: the Apple Watch Ultra 3 and the Apple Watch Series 11, as noted above.

Further, you don’t use Find Items for Precision Finding. Perhaps due to its late addition, Precision Finding can be used only via the Apple Watch Control Center. Press the side button to reveal Control Center, and scroll down to Edit and tap it. Tap the plus button, and any available AirTag appears. Tap to add it. Return to the Control Center when you want to use Precision Finding with that AirTag.

As you turn towards the AirTag, the display lights up green, indicating you’re getting warmer. If the item moves while you’re trying to find it, Find My shows a diffuse display indicating it’s in motion.

What else an item’s sheet offers

Select an item in the list and view its sheet of actions. Many of the actions are the same as for devices; here are the exceptions:

  • Share AirTag: Share or manage sharing of an AirTag. See how to share an AirTag with someone else. (For AirTags shared with you, a Shared AirTag label appears.)
  • Change Name and Emoji/Rename Item: On an iPhone or iPad, this option lets you change the item’s name, required because all items lack a display or interface. You can also change the emoji.
  • Find: When using the Find My app on any iPhone 11 series phone or later with an AirTag and the item is within a short distance, Directions is replaced with Find.
  • Serial number and other details: You can obtain the serial number of a Find My item in one of two ways when viewing its sheet of actions:

— AirTag: On an iPhone or iPad, tap the name area, and the serial number (and firmware release) appear.

— Find My item: On the sheet shown on an iPhone, iPad, or Mac, scroll or swipe down to see a panel of information, including the manufacturer’s name, the item’s model, serial number, and firmware version.

— Apple Watch: Select the item, scroll down, and tap Show Details for either an AirTag or Find My item.

Tags: Find My, iOS

AirTags, third-party items, and associated accessories can be used in a lot of ways, some of them more obvious than others. Clearly, you might add them to a keychain (AirTags require a keychain holder), or zip them into the pocket of a purse, messenger bag, backpack, or luggage.

Less obvious might be placing them in an interior pocket of a jacket, sewing them into clothing, or putting one in a saddle bag on your bicycle—or on a pet’s collar.

Apple differentiates between hardware that can use both the Find My Device options and Find My network and those, like AirTags, that can only use Find My network. The former, like Macs, iPads, and audio hardware, Apple always calls devices; the latter, items.

An AirTag is a powerful piece of always-on, always-broadcasting technology that can help you in four distinct ways:

  • Track stuff you lose: If you routinely can’t find things, I would urge you to not be ashamed of it. All brains are different and, as I’ve learned from my wife—an ADHD/executive-function coach—some people are not wired to retain the location of objects. Hurray, technology can help!
  • Track stuff that gets stolen: A sad fact of existence across all societies and in nature is that organisms steal from one another. If you’re concerned about theft or have been a victim of it, a Find My item can sometimes help with recovery.
  • Tracking kids: Parents definitely overestimate the risk of a child being abducted by a stranger. But the number of children who go “missing” for an hour or a few hours is huge. They might take the wrong bus, get lost, or actually be perfectly safe with a family friend, relative, parent, or guardian other than the one who is legally responsible. Putting a tracking tag in a kid’s backpack or clothing may alleviate worries and reduce anxiety.
  • Tracking animals: Those who have pets know they roam. Sometimes, we’re just curious where they get to. Other times, we need to rescue them when they’re stuck or lost. Except in quite rural areas, a lost or wayward pet is almost always quite near an Apple device possessed by people passing nearby.

Do not track adults

Tracking a child can be fraught with issues of agency, consent, and purpose, but it’s generally legal (this is not legal advice) and may be advisable. For adults, however, it’s nearly always unwarranted and unwelcome, and may violate civil statutes and constitute a crime unless one is in a guardianship relationship with the person (again, this is not legal advice). See how to check whether someone is tracking you for more on how Find My items can be misused.

Keys, wallets and small things

For items like keychains, wallets, and even non-Apple mobile devices like gaming consoles or Kindles, adding a Find My item can mean the difference between tearing your hair out while never finding something and easily recovering it.

Apple offers AirTag cases with key rings and other attachments from third parties at their online and retail stores, but there are many more, including those with built-in carabiners (and some of those with combination locks).

You might also consider a third-party Find My item that’s designed for attachment or fitting in a wallet. Many companies now make thin, wallet-sized trackers (3.35 by 2.1 inches or 85 by 54 mm), several of which can be wirelessly recharged using a Qi charger.

You can also “roll your own” solution. For an expensive pair of headphones one of my kids purchased and used away from the house, I attached a Chipolo ONE Spot: it’s thin, circular, matte, and flat—no bulge, unlike an AirTag. It blended in nearly invisibly with the headphones. We tested its weight by first attaching it with painter’s tape to wear around the house.

We paired it with their iPhone, and I attached it with an absurdly strong but removable acrylic adhesive film (3M’s 468MP). The ONE Spot has a remarkably similar black tint to the headphones, too.

Bags and luggage

We carry our lives in our purses, fanny packs/bum bags, messenger bags, and luggage. And they’re danged easy to lose, get stolen, or have an airport fling into the outer darkness, never to be seen again.

A Find My item is a chef’s-kiss match for bags. There are many ways to insert an AirTag or other item into a bag. Many AirTag cases are designed to snap onto, wrap around, or clip onto bag straps. Some even have adhesive to glue them inside a hidden area of your bag.

Even within an airport, the density of people with Apple devices and the precision of the Find My network can help you track down your luggage among thousands mounded all around you.

I started putting AirTags and Find My items in all my checked and carry-on bags—even in my wallet—when I resumed air travel in 2022. It’s worked like a charm. My family now uses about 15 AirTags across all our luggage and carry-on bags—and three trombones.

Starting in iOS 18.2/iPadOS 18.2 and macOS 15.2 Sequoia, you can opt to share a secure link that will allow them to track your item for up to seven days or until found. Apple added this to help airlines and other people recover your lost stuff that has a tracker in it. (See how to share an AirTag with someone else.)

Using iOS 26 and iPadOS 26 or later, you can add baggage to an airline flight record, so that you can see your tracked luggage at a glance. See how to track lost luggage with an AirTag.

Cars

A Find My item in a car won’t readily deter thieves because an item that’s separated from your paired device for any period of time or that travels with someone—i.e., thieves who have stolen your car—will alert a nearby iPhone, iPad, or Android device (see what an “AirTag Found Moving With You” alert means).

However, if you frequently have to park your car in different places in your neighborhood, in garages, or around work, using Find My can be a nice adjunct to dropping a pin in Maps.

My wife, who is savvy about privacy issues, opted to put an AirTag in the car she drives most often of our two after losing track of it in a badly designed, discontinuous, multi-part garage—with multiple identical-looking entrances to different subterranean floors. (I’ve lost my car in the same facility.) She was reassured by Apple’s security and privacy protocols with Find My items.

When someone else drives the car when you’re not in it, they would normally receive alerts about an AirTag moving with them. You can avoid that alert, however, by sharing the Find My item. You can share access to a Find My item with up to five other people; see how to share an AirTag. Everyone with shared access to a Find My item is treated like the owner: they don’t receive safety alerts and can track it.

Bikes

About 100 million bikes are in people’s homes in the United States, and a few tens of millions of people ride regularly. Annual thefts range from 150,000 (reported) to 2,000,000 (estimated). If you live in a high-theft area for bikes, the odds could be 5% or more that your bike will be stolen at some point across years of public use.

You can hide an AirTag in a lot of places on a bike—though I wouldn’t recommend it inside a bike, as the metal would prevent effective radio-signal transmission. I suggest an Elevation Lab TagVault: Bike. It’s a case that screws into a standard water-bottle cage mount. You can screw a cage in or use it by itself. It’s not obtrusive, and a thief might be unaware that it’s a tracker at all.

The Knog Scout is a hybrid option. It’s a Find My device that also offers Bluetooth-based alarm arming. Attached beneath a water bottle cage, you can use Find My to track it like any other item, and you can also arm it when within Bluetooth range to trigger a loud alarm. If you’re within range when the alarm goes off, you’re notified, too.

I got a deal on an Aventon e-bike several months ago, and—besides its excellent range and price—one of its selling points is a built-in GPS and cellular tracker. Even more remarkably, the first year is free, and subsequent years cost $20.

However, the Aventon tracker pushes the bike’s most recent location to your paired e-bike app only when the bike is powered down. You can activate Lost Mode, which then triggers location pings even when the bike is “off,” disabling the electric-motor assist, locking the bike’s rear wheel, and displaying an error code.

That’s all great, and I have insured the bike. But I also installed an AirTag using the Elevation Lab case. This gives me the best of both worlds: using an AirTag that’s difficult to remove, I can actively track the bike at any given time; if it’s stolen, I can engage the Aventon system to improve my odds of finding it or getting it back if a thief pries off the AirTag case.

Things that get wet

Depending on your item, you may need to consider whether it’s water-resistant—especially if it’s likely to be exposed to rain or even dunked. For portable items, here’s an incomplete selection of ratings:

  • AirTags (2021 and 2026 models) have a rating of IP67, offering protection against water intrusion from sprays, rain, and high-pressure water jets. They can also survive immersion in water up to 3.3 feet (one meter) deep for up to 30 minutes.
  • ElevationLab offers what it calls a “waterproof” TagVault in keychain and pet-collar attachment versions of AirTags. It doesn’t disclose an IP rating, but I tested one in a glass of water for several minutes with no ill effects.
  • The Chipolo ONE Spot tracker has an IPX5 rating, or resistance from water up through low-pressure water jets or sprays. The Pebblebee Clip 5 tracker is even better at IP66, which protects against high-pressure jets. Neither protects against immersion.
Tags: Find My, iOS