Finally Fixing My Lazy Passcode

Finally Fixing My Lazy Passcode

Tutorials encryption iphone passwords privacy security

So the Apple/FBI thing has been eating my brain for about three weeks now. You know the story if you've read literally any tech site since Tim Cook posted that open letter back on the 16th — the FBI wants Apple to build a way into the San Bernardino shooter's iPhone, Apple says no, everyone with a Twitter account has an opinion. I'm not going to rehash the legal fight here, partly because I don't think I have anything smarter to say about it than the actual lawyers, and partly because I guarantee three other blogs did the "here's what's happening" post already this week.

What it did do, though, is make me look at my own passcode and feel kind of stupid.

My iPhone passcode was four digits. It was not a good four digits either (think "part of a birthday, slightly rearranged.") I've known this was lazy for years and just never got around to fixing it, the same way I know I should floss more and still don't. But reading about a case where the entire argument hinges on how hard it is to brute-force a passcode made me actually go do something about mine, finally, this weekend.

What I actually changed

If you're on iOS and want to do the same thing: Settings > Touch ID & Passcode > Change Passcode. There's a small "Passcode Options" link under the numeric keypad that most people never click: that's where you can switch to a Custom Alphanumeric Code instead of the default 4 or 6 digits. I went with a longer phrase-based one, something I can type from memory in about four seconds once your fingers learn it, which took maybe a day of fumbling. Touch ID means you're barely typing it anyway, so the "annoying to type" argument against a real passcode doesn't hold up the way it used to.

Then I did the boring-but-important thing and turned on FileVault on my MacBook (System Preferences > Security & Privacy > FileVault). If you're on Windows it's BitLocker, buried in the Control Panel under Device Encryption, and it's worth checking whether your machine even supports it before you assume it's on, since a lot of cheaper laptops don't ship with it enabled by default. Full-disk encryption is one of those things that does nothing for you 99.9% of the time and then matters enormously the one time your bag gets stolen off a train.

The other thing I finally set up properly was two-factor on the accounts that actually matter, email first, then anything tied to money. I've been using Authy for the codes instead of just SMS, mostly because I've heard enough stories about SIM-swapping that texted codes make me nervous, and Authy at least backs up to another device so you're not completely dead in the water if your phone falls in a lake. Which, speaking from experience with an older phone two summers ago, does happen.

None of this is complicated. That's kind of the point I keep coming back to — the stuff that actually protects you day to day isn't some elaborate setup, it's mostly just not being lazy about the defaults. A decent passcode. Encryption that's already built into your OS and just needs one checkbox. An authenticator app instead of relying on your phone company's customer service rep not getting social-engineered.

I'll admit the timing is a little embarrassing. It shouldn't take a federal court case to get me to change a four-digit code I picked in maybe 2013. But I also don't think I'm unusual here. I'd bet most people reading this have a passcode they set once, years ago, and never thought about again. If the FBI-Apple fight has done one useful thing for the average person who isn't a lawyer or a security researcher, it's probably just this: it got a lot of us to actually open the settings menu we'd been ignoring.

Also, unrelated complaint while I'm here: why does changing a Mac password sometimes forget to update your keychain and then lock you out of your own saved wifi passwords? That happened to me on Saturday and cost me twenty minutes I will never get back.