
Security is at constant war with convenience. The stronger the passwords we use to keep our data safe, the more steps we take to lock down what we own, the less accessible our data and our devices become -- even to us. Balancing it all can be tough, and a lot depends on what the platforms and services we use do to help us. And nowhere is this more evident than mobile.
Multitouch keyboards, in large part, rely on things like like character pair prediction and auto-correct to make entry acceptable. Neither of those things are possible with passwords, and strong passwords require far higher than normal frequencies of shifting between upper and lower case, and between letters and numbers and symbols. It's the worst possible experience.
A 4-digit passcode lock, or weak password, gets around that by reducing the complexity at the expense of security. Intervals can also be set, so that your passcode is only required minutes after you last used your device instead of seconds. A short interval offers better protection should you lose your device or should a friend try to prank you during an unguarded moment, but it can be maddening if you need to complete a long series of intermittent tasks.
On iOS, ironically, Apple's security policies prevent password managers from working through Safari browser extensions the way they do on OS X, thus requiring more cumbersome copy-paste procedures, or the use of an in-app browser instead of Safari. Some websites, flabbergastingly, use JavaScript to block copy-paste, increasing the difficulty of using strong passwords.
2-step verification requires the use of an authenticator app, or the transmission of a token. Sometimes tokens don't work for no apparent reason, or network connectivity is spotty, complicating transmission. Sometimes it ends up being so secure, even you can't get in.
It's not an iOS-only problem either by any means. BlackBerry Z10 passcode entry is such that Adam Zeis of CrackBerry has stopped using a password to secure his phone.
It's possible future technologies like biometrics might make security more convenient, for example letting a thumbprint automagically allow access to a device. But what happens if your thumbprint is hacked or phished or otherwise compromised? You can't change your body as easily as you can a password.
Where do you stand between convenience and security? Do you use a passcode? A strong one? A password manager? 2-step verification? And what could be done to make being secure even more convenient for you?

Rene Ritchie
Editor-in-Chief of iMore, co-host of Iterate, Debug, ZEN and TECH, MacBreak Weekly. Cook, grappler, photon wrangler. Follow him on Twitter, App.net, Google+.
More Posts
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\twitter.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\facebook.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\google.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\ajax-loader.gif)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\ajax-loader.gif)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\ajax-loader.gif)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\ajax-loader.gif)
More of: Security, Passwords, Passcode ? PreviouslyDebug 12: iCloud and Core Data sync Next up ?iMore Editors' Choice: Badland, Soundcloud, Veronica Mars, and more There are 21 comments. Add yours.
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_93045.jpg)
That's why we need to see the biometric scanner in the new iPhone 5S
http://www.youtube.com/watch?v=LM-0EbS2O38
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4764302.jpg)
Well when i'm at home my 4S is open but i do have a App thats Called Big brother Security and i love it if some steals my phone it takes pics of the person and sends it to my Email. But when i'm out and about i do Lock my Phone
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4955788.jpg)
A nice feature in iOS is that if you turn Simple Passcode off, but then only enter numbers for your passcode, when you unlock your device it will still give you the number pad, rather than the full-blown keyboard. The biggest deterrent for me on using a complicated passcode is I fat finger iOS' keyboard far too much to make its use every time I need to unlock my phone impractical. However, using a longer, numeric passcode adds a little more complexity while still keeping it fairly easy to enter.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_5463993.jpg)
Did this myself, but it keeps people from being able to guess as most think its 4 digits.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_214.jpg)
Didn't know that, nice!
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4660659.jpg)
I bought 1password but never got around to finding the time to set it up. It'd be nice if Apple worked with them to integrate it into safari.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_avatar-generic.jpg)
Really it depends what you use your phone for and security features for the individual apps. I have a pass code for the phone to protect others from getting my contacts but I only have their publicly available info on the phone. Otherwise content I access is in the cloud or on work servers (with 2step authorization). Each app with their own password. I have memorized four 8-digit alphanumeric passwords and cycle them between all my apps and memorize a new set every 6 months. Tedious but I don't trust password managers.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_avatar-generic.jpg)
Well it is not even just the passcode. Have you tried setting up a Apple ID recently? Telling others using an Apple devices is simple is no longer true. Since you cant do anything without an Apple ID.
Apple ID force you to have alphabetic and numbers and Capital letters for password. Great that is good for security. But 99% of people i set up for them simply forgotten their password and write it down somewhere. ( Now that is not secure )
Then you have to setup three security questions! And 90% of times i see people just stop and find someone to help or totally give up.
Security vs. convenience, Apple was used to be good at the later, ( and pretty crap on the other ), now it is just not good at both.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4669381.jpg)
1Password for iPhone and Mac. Plus two step verification when applicable.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_31210.jpg)
Agreed. For now, at least, it's the best compromise between security and convenience.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_582402.jpg)
Well, I hope it let me vote for all the choices. I have apps that I lock down with a 4 digit passcode as I should do my phone itself. Most sites I use 1Password for and some I still need to make a password for with 1Password and for WoW it was a self created password but I also have 2 step verification and have their authentication app. I literally use all the options and it's only inconvenient when logging in to things ok my laptop and not on my phone, but completely worth it.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4693488.jpg)
Just set up 2-step verification for my iCloud account. Took a few days because I needed to improve the strength of my password before even starting the process. I highly recommend doing it, even if you don't have a credit card associated with your account.
re: "2-step verification requires the use of an authenticator app, or the transmission of a token. Sometimes tokens don't work for no apparent reason, or network connectivity is spotty, complicating transmission."
Fortunately, you rarely ever need to go through that 2-step process (typing your password into Apple's login page, waiting for Apple to display a 4-digit code on a "trusted device," then typing that code into Apple's login page). You only need to do it when you want to view or change your actual Apple ID account info. My guess is that most people won't need to do it until they change their credit card expiration date every few years.
Re: "But what happens if your thumbprint is hacked or phished or otherwise compromised?"
I've read that some fingerprint scanners can detect temperature and density of the finger. So a severed finger won't work. Of course, all that does is prevent unauthorized access with the severed finger. It won't stop the bad guys from severing your finger(s) in the first place. :-(
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_5721157.jpg)
I read somewhere that they didn't detect temperature. Did this change recently?
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_avatar-generic.jpg)
Hey Rene, update your stock photos! using the same for your black wallpaper article, i see. Dec 6 :o
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4771678.jpg)
Another good thing to consider adding to passwords: à,á,â,ä,æ,ã,å,a and so on and so forth.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_avatar-generic.jpg)
"none" should be an answer as well. well at least considering the lock screen.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_avatar-generic.jpg)
I used 1password for all my passwords. I allow it to create the password. I would rather have complicated password than, what used to do prior. Before I would use the same password to almost everything. Thanks to 1password, my life has changed!
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_5721157.jpg)
I didn't know it had this ability. I've downloaded it illegally, and I'm already loving it. I'll probably purchase it legally by day's end. Up until now, I didn't like using security codes because I hate having to unlock it each time I turn on my phone.
Reply\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_5866081.jpg)
I Use LastPass it is cross platform and integrates into almost anything that connects to the internet
Source: http://bit.ly/XwpqXP
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_2738937.jpg)
I use msecure to track passwords. I am not trustworthy enough to allow browsers to link to these password managing apps tho. So I still memorize. The apps mainly keep track of the passwords for me.
Four digit numeric passwords for the iPhone and iPad.
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\100x100_4770976.jpg)
Passwords are pointless. They are easy to get by.
Reply Contact iMoreSEND US NEWS | SUBMIT AN APP Shop iMoreTHE #1 ACCESSORY STORE | 2 MILLION+ ORDERS SHIPPED

\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1444_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1456_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1513_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1379_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1385_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\1253_98x169.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\cb_header_phones_shadow.png)
THE #1 ACCESSORY STORE | 2 MILLION+ ORDERS SHIPPED





Follow @iMore!function(d,s,id){var js,fjs=d.getElementsByTagName(s)[0];if(!d.getElementById(id)){js=d.createElement(s);js.id=id;js.src="//platform.twitter.com/widgets.js";fjs.parentNode.insertBefore(js,fjs);}}(document,"script","twitter-wjs");



Google+

RSS

YouTube

iTunes Download iMore


Rene

Georgia

Leanna

Chris

Ally

Simon

Chris

Michelle
ABOUT iMORE Wear iMore

CrackBerry, iMore, webOS Nation, and WPCentral
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\rss_teaser_2f3e8bb228.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\rss_teaser_96b0220296.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\tipb_182x101.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\mbn2-android.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\rss_teaser_4ad19cf01a.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\mbn2-crackberry.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\rss_teaser_559daa0302.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\mbn2-wpcentral.png)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\rss_teaser_6c95473579.jpg)
\ABS\Auto Blog Samurai\data\ALL IN ONE SERVICE PROVIDERS\iph\mbn2-precentral.png)