1 Why 'It Was an Accident' Does Not Work as a Long-Term Strategy
Accidental purchases cluster into predictable patterns: a child playing a 'free' game that pops a glowing buy button exactly when excitement peaks; an adult tapping through a subscription paywall at 1 a.m.; a grandparent confused by a dialog that looks like a system message. Refunding these works sometimes — Apple's 'child made purchase without permission' path is relatively forgiving — but the approach fails in three ways. First, approval rates fall sharply with repetition: the third refund request in two months triggers scrutiny, and accounts flagged for excessive refunds can lose purchase ability entirely. Second, the process takes days, and during that time the money is gone. Third, it teaches nothing: the same glowing button appears tomorrow. Prevention is structurally better than refunds because it acts before money moves, costs five minutes once, and never needs Apple's approval. The setup below layers four defenses; the principle behind all of them is the same — make the default path for spending require a deliberate, authenticated human decision, and make everything else fail closed (blocked by default) rather than open.
为什么'不小心点的'不能作为长期策略
误触消费集中在可预测的模式:孩子在'免费'游戏里,兴奋到顶点时弹出发光的购买按钮;成年人凌晨一点划过订阅付费墙随手一点;祖父母把应用弹窗误当成系统消息。退款有时有效——Apple 的'儿童未经许可购买'通道相对宽容——但这个思路在三方面失败。第一,重复次数一多批准率骤降:两个月内第三次退款请求会触发审查,被标记为退款过多的账户可能彻底失去购买能力。第二,流程耗时数天,期间钱已不在。第三,它什么也没教会你:明天同样的发光按钮照样出现。预防在结构上优于退款,因为它在资金流动之前就起作用,一次性花五分钟,永远不需要 Apple 批准。下面的设置分层布防四道防线;它们背后的原则相同——让花钱的默认路径需要一个深思熟虑、经过验证的人工决定,让其他一切路径默认关闭而非默认打开。
Every layer of defense against accidental purchases on iPhone and iPad: purchase authentication, Screen Time restrictions, Ask to Buy, gift-card-only funding, and how each fails.
iPhone 和 iPad 上防误触消费的每一层防御:购买验证、屏幕使用时间限制、购买前询问、仅礼品卡充值,以及每层防线的失效方式。
2 Layer One: Purchase Authentication Settings
The single highest-value setting is requiring authentication for every purchase. On the device, open Settings > your name > Media & Purchases > Password Settings (on newer systems this appears as 'Require Purchase Approval' or lives under Screen Time depending on version). Set it to 'Always Require' password or passcode, not 'Require After 15 Minutes' — the 15-minute grace window is the cause of a large share of accidental purchases, because anything bought within 15 minutes of an intentional purchase goes through without any prompt. That includes a child holding the device after you just bought something, and it includes loot-box prompts that queue up multiple charges in quick succession. For Face ID / Touch ID enabled accounts, check that the biometric confirmation actually appears for each purchase — if it doesn't, an earlier setting has silently authorized a window. Note the failure mode of this layer: authentication protects against unauthorized users, but not against the device owner tapping 'Confirm' themselves, whether that owner is a child who knows the passcode or an adult acting on impulse. That is what the next layer solves.
第一层:购买验证设置
价值最高的单项设置是每笔购买都要求验证。在设备上打开设置 > 你的名字 > 媒体与购买项目 > 密码设置(新系统中显示为'要求购买批准',或视版本位于屏幕使用时间下)。设为'始终需要'密码或通行码,而不是'15 分钟后要求'——15 分钟宽限窗口是大量误触消费的元凶,因为有意购买后 15 分钟内的任何购买都不再弹出提示。这包括你刚买完东西后拿着设备的孩子,也包括短时间内连续弹出多笔扣费的抽卡提示。对启用了面容 ID / 触控 ID 的账户,确认每笔购买确实出现生物识别确认——如果没有,说明某个早期设置已悄悄授权了一个窗口。注意这层的失效方式:验证防的是未授权使用者,防不了设备主人自己点'确认',无论主人是知道密码的孩子还是冲动之下的成年人。这正是下一层要解决的。
3 Layer Two: Screen Time Purchase Restrictions
Screen Time (Settings > Screen Time > Content & Privacy Restrictions) is the enforcement layer that works even when someone knows the passcode. Enable Content & Privacy Restrictions, then under 'iTunes & App Store Purchases' set 'In-app Purchases' to 'Don't Allow' — this kills in-app purchase prompts entirely, which covers the majority of accidental spend routes in games. Set 'Installing Apps' and 'Deleting Apps' to 'Don't Allow' as well for a child's device: it prevents installing new free-to-play games (the main delivery vehicle for purchase traps) and prevents deleting apps to hide evidence of charges. Critically, set a Screen Time passcode that is different from the device passcode and known only to the parent — without this, restrictions are one settings visit away from being undone by a tech-savvy ten-year-old. The failure mode of this layer is the parent forgetting the Screen Time passcode; write it down physically, because resetting it requires erasing the device in the worst case. A useful refinement: rather than banning purchases everywhere, many families keep 'In-app Purchases: Don't Allow' on permanently and allow spending through App Store gift cards only — money in, spending capped at the balance, no bank card attached at all.
第二层:屏幕使用时间购买限制
屏幕使用时间(设置 > 屏幕使用时间 > 内容和隐私访问限制)是即使有人知道密码也生效的强制层。启用内容和隐私访问限制,然后在'iTunes Store 与 App Store 购买项目'下把'App 内购买项目'设为'不允许'——这会彻底杀掉应用内购买弹窗,覆盖游戏里大多数误触消费路径。对孩子的设备,把'安装 App'和'删除 App'也设为'不允许':既防止安装新的免费游戏(购买陷阱的主要载体),也防止删应用来掩盖扣费痕迹。关键是要设置一个与设备密码不同、只有家长知道的屏幕使用时间密码——否则限制随时可能被懂事的十岁孩子解除。这层的失效方式是家长忘记屏幕使用时间密码;务必写下来存在实体纸上,因为最坏情况下重置它需要抹掉设备。一个实用细化:许多家庭不全面禁买,而是永久保持'App 内购买:不允许',只允许通过 App Store 礼品卡消费——充多少用多少,消费封顶于余额,账户上完全不绑银行卡。
4 Layer Three: Ask to Buy for Children
Ask to Buy (part of Family Sharing) routes every installation and purchase request to a parent's device for approval. Set it up under Settings > Family, tap the child, and enable 'Ask to Buy'. From that moment, any attempt to install an app, make a purchase, or start a subscription on the child's device sends a notification to the organizer's iPhone, which shows the app name, price, and rating before approval. Three practical notes from real family usage. First, approval prompts expire — if you ignore the request, it disappears and the child will ask again; that is fine, but know that 'approve later' effectively means 'never' for an impatient child, so respond when asked. Second, the approval dialog on your own phone can be approved accidentally by a tap while your phone is unlocked in your pocket or by a child holding your phone; use Face ID-protected approval if available and keep your own device locked. Third, Ask to Buy ages out: Apple removes it automatically when the child reaches the age of majority in their region, so the year it disappears is the year to teach budgeting — better to hand over a gift-card-funded allowance before that transition than to have an unrestricted card discovered on the eighteenth birthday. Ask to Buy's failure mode: it only covers Apple-billed purchases; websites billing through Safari, and purchases inside apps that use their own payment systems (where permitted, such as some regions after regulatory changes), bypass it entirely.
第三层:儿童的购买前询问
购买前询问(家庭共享的一部分)把每次安装和购买请求都送到家长设备审批。在设置 > 家庭中点孩子名字,启用'购买前询问'。从那一刻起,孩子设备上任何安装应用、购买或开启订阅的尝试都会向组织者的 iPhone 推送通知,批准前显示应用名称、价格和分级。来自真实家庭使用的三点提示。第一,批准提示会过期——忽略请求它会消失,孩子会再问;没关系,但要知道'稍后批准'对没耐心的孩子等于'永不',被问到时及时回应。第二,你手机上的批准弹窗可能在口袋里解锁时被误触,或被拿着你手机的孩子点掉;如可用请使用面容 ID 保护的批准,并保持自己的设备上锁。第三,购买前询问有年龄上限:孩子达到所在地区成年年龄时 Apple 会自动移除它,所以它消失的那一年就是教预算管理的一年——在过渡前先给礼品卡额度的零花钱,好过十八岁生日那天发现一张不受限的卡。它的失效方式:只覆盖经 Apple 计费的购买;通过 Safari 在网站上消费,以及(在监管变化后允许的地区)使用自有支付系统的应用内消费,会完全绕过它。
"Ask to Buy (part of Family Sharing) routes every installation and purchase request to a parent's device for approval."
「购买前询问(家庭共享的一部分)把每次安装和购买请求都送到家长设备审批。」
5 Layer Four: Funding Design — Gift Cards, Not Cards
The final layer caps the maximum possible loss. Remove the payment card from the Apple Account (Settings > your name > Payment & Shipping > edit) and fund purchases exclusively with App Store & iTunes gift cards redeemed to the account balance. The properties that make this work: the balance is prepaid, so the ceiling on any disaster is the balance itself; a compromised account cannot drain a linked bank account that does not exist; and for children, a monthly gift-card allowance converts 'ask for money' into a teachable budget — when the balance is gone, it is gone until next month. Buy gift cards only from reputable retailers and never from online marketplaces at a 'discount' — counterfeit and already-redeemed codes are a documented scam category, covered in our gift card safety guide. Check the account balance together with your purchase history weekly (Settings > your name > Media & Purchases > View Account shows the balance); a dropping balance you cannot explain is the earliest possible alarm of unwanted subscriptions. The failure mode of this layer is social engineering that convinces someone to buy fresh gift cards and read the codes aloud — which is not an App Store problem but a telephone fraud problem, and the defense against it is recognizing the script, which our fake support guide covers in detail.
第四层:资金设计——用礼品卡,不用银行卡
最后一层封顶最大可能损失。从 Apple 账户移除支付卡(设置 > 你的名字 > 付款与配送 > 编辑),购买资金完全使用兑换到账户余额的 App Store 与 iTunes 礼品卡。起作用的特性:余额是预充值的,任何灾难的上限就是余额本身;被入侵的账户无法掏空一张不存在的绑定银行卡;对孩子来说,每月礼品卡额度把'要钱'变成可教育的预算——余额用完就没了,等下月。礼品卡只从正规零售商购买,绝不从线上市场的'折扣'渠道买——假卡和已被兑换的码是有据可查的诈骗类别,详见我们的礼品卡安全指南。每周把账户余额和购买记录一起检查(设置 > 你的名字 > 媒体与购买项目 > 查看账户可见余额);无法解释的余额下降是不想要的订阅最早期的警报。这层的失效方式是社会工程,诱导人购买新礼品卡并念出卡号——那不是应用商店问题而是电话诈骗问题,防御之道是识破剧本,详见我们的假客服指南。
6 Testing Your Setup: A Five-Minute Drill
Settings that are never tested are settings that silently stopped working after an OS update. Run this drill twice a year. On the child's device (or your own, if you are hardening your own habits), open any free game known for purchase prompts and attempt a purchase on the smallest available item — the expected result with Layer Two active is that the option is greyed out or blocked entirely. Next, attempt to install a new free app — with Ask to Buy active, the child's device should show 'Ask to Buy sent' and your device should receive the request within seconds. Then check Settings > your name > Payment & Shipping and confirm no card is attached if that is your design. Then check the account balance and the last two weeks of purchase history for anything unrecognized. Finally, verify the Screen Time passcode still works and is still different from the device passcode — this is the lock that holds the whole structure together. Total time: about five minutes. Families who run this drill after every major iOS update catch the two most common regressions: 'Require Purchase Approval' silently reverting to a grace window, and Content & Privacy Restrictions switching off after a restore from backup. An untested defense is indistinguishable from no defense.
测试你的设置:五分钟演练
从未测试过的设置,就是系统更新后悄悄失效的设置。每半年跑一次这个演练。在孩子设备上(或在 hardened 自己的习惯时用你自己的),打开任何以购买弹窗著称的免费游戏,尝试购买最小档位的商品——第二层生效时预期结果是选项变灰或完全被阻止。接着尝试安装一个新的免费应用——购买前询问生效时,孩子设备应显示'已发送购买前询问',你的设备应在数秒内收到请求。然后检查设置 > 你的名字 > 付款与配送,确认按你的设计没有绑定银行卡。再检查账户余额和过去两周购买记录中有无认不出的项目。最后验证屏幕使用时间密码仍然有效、且仍与设备密码不同——这是撑起整个结构的锁。总耗时约五分钟。每次 iOS 大版本更新后跑这个演练的家庭,能抓住两类最常见回退:'要求购买批准'悄悄退回宽限窗口,以及从备份恢复后内容和隐私访问限制被关闭。未经测试的防御与没有防御无法区分。