Storewise Check before you pay 付款前先核对

Security

Apple ID Security Checklist: Two-Factor, Recovery, and Trusted Devices Apple ID 安全清单:双重认证、恢复与受信设备

A practical checklist for auditing Apple ID security: two-factor authentication, recovery contacts, trusted devices, and password rotation. 审计 Apple ID 安全的实用清单:双重认证、恢复联系人、受信设备与密码轮换。

Apple ID 安全清单:双重认证、恢复与受信设备

审计 Apple ID 安全的实用清单:双重认证、恢复联系人、受信设备与密码轮换。

Reading series · 8/11

阅读系列 · 8/11

Install safety & profiles

安装安全与配置描述文件

Spot low-quality listings, profile/VPN risks, and unofficial install narratives.

识别低质上架、配置描述文件/VPN 风险与非官方安装话术。

Series hub 系列枢纽
  1. 1 How to Spot Low-Quality App Store Listings 如何识别低质量 App Store 页面
  2. 2 App Store Scam Pattern Recognition: Phishing, Clone Apps, and Fake Support App Store 诈骗模式识别:钓鱼、克隆应用与假客服
  3. 3 When You Should Not Install a Free App 什么时候不该安装免费应用
  4. 4 App Store Search Manipulation, Lookalike Apps, and Fake Popularity Signals App Store 搜索操纵、仿冒应用与虚假热度信号
  5. 5 iOS VPN, Configuration Profile, and Certificate Risks Explained iOS VPN、配置描述文件与证书风险说明
  6. 6 iOS Configuration Profiles, VPN Apps, and Certificate Danger Signs iOS 配置描述文件、VPN 应用与证书危险信号指南
  7. 7 TestFlight, Sideloading Narratives, and Unofficial Install Risks on iPhone TestFlight、侧载叙事与 iPhone 非官方安装风险
  8. 8 Apple ID Security Checklist: Two-Factor, Recovery, and Trusted Devices Apple ID 安全清单:双重认证、恢复与受信设备
  9. 9 EU DMA and Third-Party App Stores: What Changed for Purchase Safety and Refunds 欧盟 DMA 与第三方应用商店:购买安全与退款的变化
  10. 10 Buying a Used iPhone: How to Check Apple ID Purchase History and Avoid Residual Charges 购买二手 iPhone:如何检查 Apple ID 购买记录并避免残余扣费
  11. 11 Cross-Device Purchase Risks: iPad, Mac, Apple TV, and the Hidden Costs of Apple's Ecosystem 跨设备购买风险:iPad、Mac、Apple TV 与 Apple 生态系统的隐藏成本

Verifying Two-Factor Authentication Is Active and Not SMS-Based

Open Settings on your iPhone, tap your name at the top, then tap Sign-In & Security. The screen should display Two-Factor Authentication with a green indicator and your trusted phone numbers listed below. If you instead see Two-Step Verification or a note about SMS codes, your account is running an older, weaker method that Apple no longer allows new accounts to use. Two-factor authentication (2FA) generates codes on trusted devices through a secure enclave challenge, not through carrier SMS, which is vulnerable to SIM-swap attacks. If a device you no longer own still appears in the trusted phone list, remove it immediately. The verification code should arrive as a system-level prompt on your active devices, never as a text from a random short code. A common failure mode is inheriting an Apple ID set up before 2015 that never migrated to 2FA; you will need to complete the migration from the Apple ID web portal at appleid.apple.com. If you share an Apple ID with a spouse or sibling, each person should have their own account; shared IDs make 2FA prompts confusing because verification codes go to all devices simultaneously, increasing the risk that someone taps Allow on a prompt they did not initiate.

验证双重认证已启用且不依赖短信

在 iPhone 上打开“设置”,点击顶部姓名,再点击“登录与安全”。屏幕应显示“双重认证”并有绿色标识,下方列出受信电话号码。如果你看到的是“两步验证”或有关短信验证码的提示,说明账户仍在使用较旧、较弱的方式,Apple 已不再允许新账户使用。双重认证通过安全隔离区的挑战在受信设备上生成验证码,而非通过运营商短信,后者容易受到 SIM 卡劫持攻击。如果你已不再拥有的设备仍出现在受信电话列表中,请立即移除。验证码应作为系统级弹窗出现在你的活跃设备上,而非来自随机短代码的短信。常见问题之一是继承了 2015 年之前创建且从未迁移至双重认证的 Apple ID;你需要从 appleid.apple.com 网页门户完成迁移。

Auditing the Trusted Devices List for Stale or Sold Hardware

Navigate to Settings > [your name] and scroll past Payment & Shipping to the device list at the bottom. Every iPhone, iPad, Mac, Apple Watch, and Apple TV associated with your Apple ID appears here. A device listed in green means it is currently signed in and reachable; grey means it is offline but still trusted. If you sold, traded in, or gave away a device and it still appears here, tap it and select Remove from Account. A lingering trusted device can receive 2FA push prompts, which means a buyer or recycler could intercept verification codes or even approve a login on your behalf. Before selling any Apple device, always sign out of iCloud and turn off Find My; if you forgot to do so, the remote removal from this screen is your safety net. Check this list at least twice a year, especially after upgrading hardware. If a device you do not recognize appears, treat it as a possible compromise: change your password immediately and review recent login activity.

审计受信设备列表中残留或已售出的硬件

进入“设置”> [你的姓名],向下翻过“付款与配送”,查看底部的设备列表。与你 Apple ID 关联的每台 iPhone、iPad、Mac、Apple Watch 和 Apple TV 都会显示在这里。绿色表示设备已登录且可达;灰色表示离线但仍受信。如果你出售、以旧换新或赠送了某台设备而它仍出现在此,点击它并选择“从账户中移除”。残留的受信设备可以接收双重认证推送,这意味着买家或回收商可能截获验证码,甚至代表你批准登录。出售任何 Apple 设备前,务必退出 iCloud 并关闭“查找”;如果忘记操作,此界面的远程移除是你的安全兜底。至少每半年检查一次此列表,尤其在升级硬件后。如果出现你不认识的设备,视为可能的入侵:立即更改密码并查看最近的登录活动。

Adding Recovery Contacts Who Can Help Regain Access

Go to Settings > [your name] > Sign-In & Security > Account Recovery, then tap Recovery Contacts. A recovery contact is a trusted person who can verify your identity and generate a recovery code if you are locked out of your account. They cannot see your data or read your messages; they only receive a code on their own device that you enter during recovery. Choose someone reliable who uses an Apple device daily and whom you can reach by phone. Avoid using your own secondary number as a recovery contact because it defeats the purpose of having an independent verifier. You can add up to five recovery contacts. If you previously relied on a Recovery Key (a 28-character alphanumeric string), understand that enabling one disables the contact-based recovery entirely; Apple now recommends contacts over keys for most users because keys are easy to lose permanently. If you do use a Recovery Key, store it in a password manager, not in your iCloud Keychain.

添加可以帮助恢复账户访问的恢复联系人

进入“设置”> [你的姓名] >“登录与安全”>“账户恢复”,点击“恢复联系人”。恢复联系人是一位受信的人,在你被锁定账户时可以验证你的身份并生成恢复代码。他们无法查看你的数据或阅读你的信息;他们只在自己的设备上收到一个代码,供你在恢复过程中输入。选择一位可靠、每天使用 Apple 设备、且你能通过电话联系到的人。避免使用你自己的次要号码作为恢复联系人,因为那样就失去了独立验证的意义。你最多可以添加五位恢复联系人。如果你之前依赖恢复密钥(28 位字母数字字符串),请注意启用它将完全禁用基于联系人的恢复;Apple 现在对大多数用户推荐联系人而非密钥,因为密钥一旦丢失便无法找回。如果你确实使用恢复密钥,请将其存入密码管理器,而非 iCloud 钥匙串。

Rotating Your Apple ID Password Without Breaking App-Specific Access

Changing your Apple ID password every 12 to 18 months is reasonable if you have not suffered a breach. Go to appleid.apple.com, sign in, and under Sign-In & Security select Password. You will need to enter your current password and a new one that has not been used in the last year. After the change, all devices will be signed out except the one you used to make the change. Apps that use app-specific passwords (for third-party email or calendar clients) continue to work because those passwords are independent tokens. However, any app that stores your Apple ID password directly will prompt you to sign in again. If you have children in a Family Sharing group, their devices will also sign out; make sure they know their own Apple ID passwords or set up Ask to Buy so they cannot re-purchase without approval. Avoid reusing passwords from other services. Use a passphrase of four random words plus a number and symbol for strength without memorization pain. If you use a password manager like 1Password or Bitwarden, generate a 20-character random password and let the manager remember it. After changing the password, test that you can sign in on at least one other device to confirm the new password works before you need it in an emergency. Store the password hint somewhere accessible but not on the same device.

在不中断应用专用访问的情况下轮换 Apple ID 密码

如果未遭受泄露,每 12 到 18 个月更换一次 Apple ID 密码是合理的。前往 appleid.apple.com 登录,在“登录与安全”中选择“密码”。你需要输入当前密码以及一个过去一年未使用过的新密码。更改后,除你用于修改的设备外,所有设备都将退出登录。使用应用专用密码的第三方邮件或日历客户端将继续正常工作,因为这些密码是独立令牌。但任何直接存储 Apple ID 密码的应用都会提示你重新登录。如果你的家庭共享组中有儿童,他们的设备也会退出登录;确保他们知道自己的 Apple ID 密码,或设置“购买前询问”以防未经批准重新购买。不要复用其他服务的密码。使用四个随机单词加数字和符号的口令短语,既安全又免于记忆之苦。

Securing Trusted Phone Numbers Against SIM-Swap Risk

A trusted phone number is the fallback channel Apple uses when no trusted device can receive a 2FA prompt. If a carrier transfers your number to a new SIM without your consent, an attacker can intercept the fallback SMS and approve logins. To reduce this risk, call your carrier and request a port-out PIN or transfer lock. AT&T, T-Mobile, and Verizon all offer this feature, though it is often not enabled by default. On the Apple side, add a secondary trusted number (a family member or landline) so that a single number compromise does not lock you out. Navigate to Settings > [your name] > Sign-In & Security > Two-Factor Authentication and review the numbers listed. Remove any number you no longer control. If you travel internationally, a local SIM card number added as trusted can simplify login while abroad; remember to remove it when you return. Never rely on SMS as your sole verification channel; the device-based 2FA prompt is always preferable. If your carrier does not offer port-out protection, consider porting your number to a carrier that does, or use a VoIP number that is not tied to a physical SIM as your secondary trusted number. Some users keep a dedicated backup phone with a separate carrier solely for this purpose.

防范 SIM 卡劫持风险,加固受信电话号码

受信电话号码是 Apple 在没有受信设备可接收双重认证弹窗时的备用渠道。如果运营商未经你同意将号码转移到新 SIM 卡,攻击者可以截获备用短信并批准登录。为降低此风险,致电运营商申请转网 PIN 或转网锁定。AT&T、T-Mobile 和 Verizon 都提供此功能,但通常默认不启用。在 Apple 端,添加一个次要受信号码(家人或座机),这样单一号码被攻破不会锁定你。进入“设置”> [你的姓名] >“登录与安全”>“双重认证”,查看列出的号码。移除你不再控制的号码。如果你在国际旅行时添加了当地 SIM 卡号码作为受信号码,可以简化境外登录;回国后记得移除。永远不要仅依赖短信作为唯一验证渠道;基于设备的双重认证弹窗始终更优。如果你的运营商不提供转网保护,考虑将号码转到提供此功能的运营商,或使用不绑定物理 SIM 的 VoIP 号码作为次要受信号码。一些用户专门保留一台备用手机使用不同运营商仅为此目的。

Reviewing App-Specific Passwords and Revoking Unused Tokens

App-specific passwords let third-party apps like Spark Mail or Thunderbird access your iCloud data without using your main password. Each one is a 16-character token tied to a specific app. Over time you may accumulate tokens from apps you no longer use, and each is a potential access path if that app is later compromised. To audit them, go to appleid.apple.com, sign in, and under Sign-In & Security select App-Specific Passwords. You will see a list of all active tokens with the app name and creation date. Click any token to revoke it; the associated app will immediately lose access and prompt for a new password on next launch. Make it a habit to revoke tokens when you uninstall the corresponding app. If you see a token for an app you never installed, revoke it immediately and change your Apple ID password. This section is separate from the list of apps using Sign in with Apple, which is under the same menu but manages OAuth-style logins rather than data access tokens.

审查应用专用密码并撤销未使用令牌

应用专用密码让 Spark Mail 或 Thunderbird 等第三方应用在不使用主密码的情况下访问你的 iCloud 数据。每个令牌是绑定到特定应用的 16 位字符。随着时间推移,你可能积累了已卸载应用的令牌,每个令牌在该应用日后被攻破时都是一条潜在访问路径。要审查它们,前往 appleid.apple.com 登录,在“登录与安全”中选择“应用专用密码”。你会看到所有活跃令牌的列表,包含应用名称和创建日期。点击任意令牌即可撤销;关联的应用将立即失去访问权限并在下次启动时提示输入新密码。卸载应用时养成撤销令牌的习惯。如果看到从未安装过的应用令牌,立即撤销并更改 Apple ID 密码。此部分与使用 Sign in with Apple 的应用列表不同,后者在同一菜单下但管理的是 OAuth 式登录而非数据访问令牌。

Detecting and Removing Unauthorized Sign-Ins Across Devices

Apple sends an email and push notification whenever your Apple ID is used to sign in on a new device or browser. Do not ignore these messages. If you did not initiate the sign-in, tap the email link or go to appleid.apple.com > Devices to review and remove the unauthorized device immediately. Also check the Sign-In History on the web portal for any logins from unfamiliar IP addresses or locations. A subtle indicator of compromise is receiving 2FA prompts you did not request; tapping Deny blocks the attempt, but it means someone has your password. If this happens, change your password right away and review your trusted devices list for intruders. Enable notification alerts for Apple ID activity by keeping push notifications on for the Apple ID system service in Settings > Notifications > Apple ID. If you manage a Family Sharing group, encourage each member to check their own device list; a child compromised Apple ID can expose shared payment methods.

检测并移除跨设备的未授权登录

每当你的 Apple ID 在新设备或浏览器上登录时,Apple 会发送电子邮件和推送通知。不要忽视这些消息。如果你未发起登录,点击邮件中的链接或前往 appleid.apple.com > 设备,立即审查并移除未授权设备。同时查看网页门户上的登录历史,留意来自陌生 IP 地址或地点的登录。一个微妙的入侵迹象是收到你未请求的双重认证弹窗;点击“拒绝”可阻止尝试,但这意味着有人掌握了你的密码。如果发生这种情况,立即更改密码并审查受信设备列表中是否有入侵者。在“设置”>“通知”>“Apple ID”中保持 Apple ID 系统服务的推送通知开启,以启用 Apple ID 活动提醒。如果你管理家庭共享组,鼓励每位成员检查自己的设备列表;儿童的 Apple ID 被攻破可能暴露共享支付方式。

Enabling Stolen Device Protection for Your iPhone and Mac

Stolen Device Protection is a security feature introduced in iOS 17.3 that adds an extra layer when your iPhone is away from familiar locations like home or work. With it enabled, certain sensitive actions require Face ID or Touch ID with no passcode fallback, including viewing saved passwords, applying for a new Apple Card, and turning off Lost Mode. Additionally, actions like changing your Apple ID password or removing trusted devices trigger a one-hour security delay when you are away from familiar locations. To enable it, go to Settings > Face ID & Passcode > Stolen Device Protection and toggle it on. This means if a thief watches you enter your passcode and then steals your phone, they cannot immediately change your Apple ID password because the Face ID requirement blocks the passcode fallback. On Mac, ensure FileVault is enabled (System Settings > Privacy & Security > FileVault) so your data is encrypted at rest. If your Mac is stolen, use Find My to mark it as lost, which locks it with your Apple ID password. FileVault ensures the thief cannot extract your data by removing the drive and reading it on another machine.

为 iPhone 和 Mac 启用失窃设备保护

失窃设备保护是 iOS 17.3 引入的安全功能,当 iPhone 不在家庭或工作等熟悉位置时增加额外保护层。启用后,某些敏感操作要求 Face ID 或 Touch ID 且无密码备用,包括查看已保存密码、申请新 Apple Card 和关闭丢失模式。此外,当你不在熟悉位置时,更改 Apple ID 密码或移除受信设备等操作会触发一小时安全延迟。要启用,进入"设置">"Face ID 与密码">"失窃设备保护"并打开开关。这意味着如果小偷看到你输入密码然后偷走手机,他们无法立即更改 Apple ID 密码,因为 Face ID 要求阻止了密码备用。在 Mac 上,确保已启用 FileVault("系统设置">"隐私与安全性">"FileVault")以使数据在静止时加密。如果 Mac 被盗,使用"查找"将其标记为丢失,这会用 Apple ID 密码锁定。FileVault 确保小偷无法通过拆下硬盘在另一台机器上读取来提取你的数据。

Next in this series · 9/11

本系列下一篇 · 9/11

EU DMA and Third-Party App Stores: What Changed for Purchase Safety and Refunds

欧盟 DMA 与第三方应用商店:购买安全与退款的变化

Keep the same research path so related decisions stay consistent.

沿同一研究路径继续,相关决策会更连贯。

Related guides

相关指南

Continue with a matching research note or checklist instead of opening a separate tool.

继续读匹配的研究笔记或清单,而不是开另一个工具。

Related articles

相关文章

Buying a Used iPhone: How to Check Apple ID Purchase History and Avoid Residual Charges

购买二手 iPhone:如何检查 Apple ID 购买记录并避免残余扣费

What to check before and after buying a used iPhone — activation lock, residual subscriptions, hardware-linked purchases, and the proper factory reset sequence.

购买二手 iPhone 前后要检查什么——激活锁、残余订阅、硬件关联购买和正确的出厂重置顺序。

iOS VPN, Configuration Profile, and Certificate Risks Explained

iOS VPN、配置描述文件与证书风险说明

Treat iOS VPN profiles and certificates as high-risk installs: what they can intercept, red-flag install paths, and removal steps.

把 iOS VPN 配置与证书当作高风险安装:可能拦截什么、危险安装路径,以及如何移除。

Cross-Device Purchase Risks: iPad, Mac, Apple TV, and the Hidden Costs of Apple's Ecosystem

跨设备购买风险:iPad、Mac、Apple TV 与 Apple 生态系统的隐藏成本

How subscriptions, in-app purchases, and family sharing across Apple devices create unexpected charges — and how to audit and prevent them.

Apple 设备间的订阅、应用内购买和家庭共享如何产生意外扣费——以及如何审计和预防。

iOS Configuration Profiles, VPN Apps, and Certificate Danger Signs

iOS 配置描述文件、VPN 应用与证书危险信号指南

How to evaluate VPN apps and configuration profiles on iOS, including certificate prompts, always-on claims, and safer verification steps.

如何评估 iOS 上的 VPN 应用与配置描述文件,包括证书提示、始终开启宣传,以及更安全的核验步骤。

TestFlight, Sideloading Narratives, and Unofficial Install Risks on iPhone

TestFlight、侧载叙事与 iPhone 非官方安装风险

How to evaluate TestFlight invites and unofficial install narratives without confusing legitimate beta testing with high-risk distribution channels.

如何评估 TestFlight 邀请与非官方安装叙事,避免把正当内测与高风险分发渠道混为一谈。

EU DMA and Third-Party App Stores: What Changed for Purchase Safety and Refunds

欧盟 DMA 与第三方应用商店:购买安全与退款的变化

How the Digital Markets Act affects iOS app purchases, refunds, payment safety, and scam risks for EU users.

《数字市场法案》如何影响欧盟用户的 iOS 应用购买、退款、支付安全和诈骗风险。

Explore more on Storewise

继续探索 Storewise

Jump to research hubs, practical tools, or site policies without going back to the homepage.

可直接进入研究枢纽、实用工具或站点政策页,无需回到首页。