MoreRSS

site iconSix ColorsModify

Six Colors provides daily coverage of Apple, other technology companies, and the intersection of technology and culture.
Please copy the RSS to your reader, or quickly subscribe to:

Inoreader Feedly Follow Feedbin Local Reader

Rss preview of Blog of Six Colors

(Podcast) Upgrade 639: I Know How to Go to Sleep

2026-09-29 05:17:12

Apple’s slow move toward a fitness band makes us wonder if the company has lost its ability to execute quickly. Also, it’s time for a MacBook Neo check-in, and Myke questions Jason’s Apple Watch use.

Go to the podcast page.

Why Stolen Device Protection makes Passwords safer

2026-09-29 01:00:43

Glenn Fleishman, art by Shafer Brown

After my massive article on migrating your passwords, passkeys, and other secrets from third-party password managers to Apple’s Passwords, Wallet, Safari, and general ecosystem—potentially with help from another app—reader Scott asked whether I was directing people into weaker security. He wrote:

If someone manages to steal my device and its passcode, they have access to the contents of my phone, including all of the information stored in Apple Passwords. This is not the case if I use a third-party password manager and have set a separate password for access, as the thief will not have access to my other passwords…I’m surprised this liability is not discussed and considered more frequently.

This is a great follow-up question, and one that I didn’t address within the scope of the migration article, which was already long. Let me pick apart how to answer that by looking at risks and mitigations.

The risks of cracking our eggs at once

I understand the fear of losing everything, whether it is a set of material objects or digital secrets. One of the most heartrending stories I ever heard was from a photographer who lost all his work in an apartment fire shortly after moving to New York City to start his career. He rebuilt. That’s harder to do digitally, where if our privacy is “burned,” we might see bank accounts drained and potentially have to get our Social Security number or other identity number replaced.

Photo of eggs in a basket
Should these eggs crack, whither our password security? (Photo by Nick Fewings on Unsplash)

But we should consider alongside that how likely it is for the scenario Scott describes: “…someone manages to steal my device and its passcode, they have access to the contents of my phone…” A sequence of actions has to take place for that to be true:

  • Someone has to steal your device.
  • Someone has to have obtained your passcode or have forced you to reveal it when or after they steal the device.
  • That person has to then have the time to put the stolen booty to use, like performing money transfers or cryptocurrency actions, before you erase your device remotely.

It’s most likely an iPhone would be the thing stolen, because we have those with us all the time, and thieves have been known to shoulder surf or record video from a distance to capture you entering your passcode. iPads and Macs can, of course, be taken from us as well, but it’s just much less likely when we’re out and about. A stolen Mac has additional protections if it’s powered down, and we often set longer passwords for a Mac, where an iPhone or iPad might still have a four-digit code.

If you are a privacy advocate, protester, journalist, opposition politician, or promoter of freedom and peace, you are at greater risk, and thus using Passwords as an in-band solution—one in which compromising a device unlock pathway could compromise our secrets—already makes no sense. (I’ve seen some people recommend Bitwarden, not because of a necessarily superior security model, but because it’s open-source and has an expansive free personal tier that includes end-to-end encryption for synchronization among your devices.)

So this worry for the rest of us is a kind of prospective and speculative anxiety: that, in the wrong circumstances, all our passwords and other secrets would be exposed. While this happens regularly, the number of instances in which a passcode is obtained and malice occurs before we can stop it is fairly low. Most iPhones are stolen to wipe them for resale, which Apple has rendered difficult with the long-ago introduction of Activation Lock. Rather than knowing your passcode, criminals are more likely to try to threaten you or use phishing to obtain the passcode after they have the device.

Fortunately, Apple came up with a solution after the Wall Street Journal in 2023 exposed how a dangerous sequence of events, which could start with drugging or violence, would allow thieves to reset an Apple Account and take over someone’s digital accounts and life.

We don’t yet have face-stealing technology

Screenshot of Stolen Device Protection section of iOS Settings
Stolen Device Protection uses a combination of delays and biometrics to deter thieves from accessing your data and accounts.

Apple’s Stolen Device Protection is a feature that may be one that has irritated you enough that you haven’t cared to understand how it may also keep your secrets safe. Go to Settings: Privacy & Security: Stolen Device Protection, and it’s likely enabled. Based on reports, I believe Apple enabled this by default in iOS 26.4. It’s available only for iPhones.

When enabled, it restricts a number of activities and requires Touch ID or Face ID for many authentication steps—passwords can’t be used instead. For the purposes of protecting your secrets, Stolen Device Protection has two key attributes:

  • It locks many actions for an hour, such as changing your Apple Account password. Even then, you have to use biometrics to start the countdown and before taking the action. Knowledge of a passcode isn’t helpful. If you have Away from Familiar Locations selected, this occurs only when the device isn’t in a place you routinely spend a lot of time, typically home and work.1
  • You cannot view passwords or fill them into form fields from Apple’s Passwords system without using Touch ID or Face ID with Always enabled, so a thief having your passcode is out of luck. (If you have Away from Familiar Locations selected, a ne’er-do-well would have to be in one of those locations to use a passcode.)

This leaves one rotten scenario, in which you are kept under duress for at least an hour and are forced to use biometrics, then perform other actions. But how likely is that for most people? I don’t want to dismiss the distress of those who have been through that, but the likelihood of most people experiencing it is vanishingly small.

Leaving Stolen Device Protection enabled does mean that you may have to wait an hour in some scenarios to manage aspects of your Apple Account, make changes to Face ID or Touch ID, change your device passcode, and a few other actions. But this minor inconvenience might assuage the kinds of concerns that Scott wrote in about, and make you more comfortable that your big basket of secret eggs won’t scramble.

For further reading

I just updated my book Take Control of Securing Your Apple Devices to incorporate changes Apple has made in the last year, including in iOS 27, iPadOS 27, and macOS 27. In the book, I dig into risks and likelihoods further. The book takes the tack that Apple, having secured a lot of our data, now has implemented many protections against physical access to our hardware, including theft, and explains how to enable, configure, and manage a wide set of features.

[Got a question for the column? You can email [email protected] or use /glenn in our subscriber-only Discord community.]


  1. Apple tracks and retains places you visit if Settings: Privacy & Security: Location Services: System Services: Significant Locations & Routes is enabled, which it is by default. This information is kept securely on your device (requiring authentication to view), and synced with end-to-end encryption among your devices. Familiar locations are derived from this data, which cannot be modified, only cleared. ↩

Imagining the next MacBook Neo

2026-09-26 04:24:35

A closed Apple laptop resting on a wooden bowl with oranges and a lemon, beside a knife on a counter.

Everyone loves the MacBook Neo. Apple’s fresh-squeezed laptop was a not-too-surprising hit with computer buyers, and presumably sales have continued to be good despite a $100 mid-stream price increase elevating its original $599 price tag to a still-good-but-not-astounding $699.

The Neo proved that Apple’s iPhone-class processor, the A18 Pro, was powerful enough to drive a Mac and the Mac’s wide-open software platform. With performance roughly in between an M1 and M2 processor, the Neo is completely capable of even somewhat difficult tasks like audio and video editing. Obviously, RAM and processor limitations prevent it from tackling the toughest jobs, but that’s why Apple makes numerous other, more expensive Macs.

A friend’s kid is moving into her college dorm—the same one both of my kids lived in!—as I write this. I have no idea what computer she’s bringing to school, but it certainly could be a MacBook Neo, and I’d wager a bunch of her classmates will have them, too.

So, hooray for the Neo, but what’s next? With the arrival of the iPhone 18 Pro and the A20 processor, the question is, will Apple release a Neo based on last year’s A19 Pro processor, or jump to the A20? I fear that the answer is the less-exciting A19 Pro, but what if it’s the A20 Pro? (And if it’s not the A20 Pro in 2027, it’ll be the A20 Pro in 2028, you could almost bank on it.)

So what’s in store for the MacBook Neo in the future? Let’s go to the charts:

Imagining the next MacBook Neo

In short, the A19 Pro would be an incremental update to the Neo, keeping it roughly in the ballpark of M1 CPU performance and M2 or M3 GPU performance. The A20 Pro, on the other hand, would elevate the Neo to M2-level CPU and M4-level GPU performance.

Also, in terms of differentiating the product line, next year the MacBook Air will presumably get the M6 chip just unveiled for the Mac mini. But regardless, both the M5 and M6 chips are still well ahead of the A20 Pro in everything that really matters for Mac performance.

I’m sure Apple could get away with releasing a MacBook Neo with an A19 Pro chip, and given the pressures on its margins caused by the RAM crisis, that’s probably what it will do. (It would presumably bring the Neo up to 12GB of RAM, which would be a nice boost—while raising the price, of course.)

But now that we’ve seen it in action in an iPhone, the prospect of the A20 Pro in a MacBook Neo is even more tantalizing. The question is how long we’ll need to wait to see it.

(Sponsor) Coherence X6

2026-09-26 02:00:05

My thanks to Coherence X6 for sponsoring Six Colors this week.

Safari web apps are great when they fit the job. But sometimes you need Chromium: a Chrome extension, a separate browser profile, or simply a website that works better in Chrome. Coherence X6 turns any website into its own standalone Mac app, powered by the Chromium browser of your choice.

Instead of living in another browser tab, each site opens in its own standard Mac window, with its own Dock icon, profile, accounts, extensions, and settings. Apps stay isolated from one another, so you can keep work and personal accounts separate, create distraction-free versions of the sites you use every day, or build dedicated apps around specific workflows.

Coherence also gives those apps capabilities you don’t normally get from a website shortcut. You can control which links stay inside an app and which open elsewhere, create apps that always open in Incognito, use different Chromium browsers for different apps, and customize how each app behaves.

Six Colors readers can save 20% on Coherence X6 this week with code SIXCOLORS. Learn more, create your first app free, or purchase Coherence at bzgapps.com/coherence.

One week with Apple Watch Series 12 (and just getting started)

2026-09-25 23:00:23

Three Apple Watches: left shows sous vide chicken advice; center shows health summary with HR 73 and HRV 20; right shows Shazam for ‘Til the Morning’ by Royel Otis on THU SEP 24.

I’ve been using the Apple Watch Series 12 for a week now, but this isn’t a review. The first wave of reviews that dropped at embargo time were all from people who had used the device for about the same amount of time, and it seems a bit silly to just repeat those observations—and a week after all of those stories were published. In addition, the most tantalizing features of the new Apple Watch—Live Rewind and Siri Recap—won’t be available until “late 2026.”1

So instead of sprinting to a quick judgment, I’ve decided to take the long path and live with the Series 12. I migrated from my own Series 10 watch, transferred my cellular plan over, and have committed to wearing it most of the time, including when I sleep. (While I tried out Apple’s sleep features the last time I reviewed an Apple Watch, I decided I didn’t really get enough benefit out of it to keep it going—but since Apple really wants me to wear the watch when I sleep, I will do so, at least for now. That way I can at least try the Vitals app, which runs in daytime mode now.)

Since I’m coming from a Series 10, I’m unfortunately not able to be impressed by how thin the Series 12 is—since the Series 10 was really the watch that got noticeably thinner. (If you’re thinking of upgrading from an older watch than Series 10, though, you’ll love it.) I’m curious to see how the watch face holds up compared to the older model, since the aluminum Series 12 has picked up Ceramic Shield 2 protection.

All summer I complained about just how sluggish the new Siri AI functionality felt in watchOS 27 on my Series 10. Obviously the watch isn’t really capable of full-on Apple Intelligence, but it’s able to phone home to its paired iPhone and relay queries made from that device, and the result is that I can stand in my kitchen and ask what temperature is right for the immersion cooker to cook tonight’s chicken, and get an answer—something that would have required me to go search on my phone before. The results aren’t iPhone fast, but they’re generally fast enough, and have the improved information density that Siri AI offers.

It does feel like Apple tightened up Siri AI responsiveness right at the end of the OS beta cycle, which is especially important when it comes to basic functions that shouldn’t require a laborious trip to an iPhone or cloud servers. Now, when I start a timer, it picks the command up pretty fast. All summer I was frustrated by the seeming inability of my watch or my iPhone to add items to Reminders lists via Siri, but that problem seems to have finally abated, which is important, since that kind of quick data capture is one of my primary Apple Watch use cases. No amount of Siri AI goodness will be worth it if you can’t properly set a timer or add a reminder from your wrist.

While I can’t rewind 15 seconds of recent conversation or check the notes on a meeting that was being monitored by my watch, I was able to use another of Apple’s “Audio Intelligence” features, which is near-instant song identification via Shazam. I suspect this is all about timing. Since this Apple Watch is apparently always buffering audio, when I’m curious about the identity of a song, it’s got the ability to use its buffer and extend the window it needs for analysis. For Shazam, this can often be the difference between success and failure—often, the most recognizable part of a song is what prompts me to want to look it up, and by the time I bring up Shazam, the moment has passed and the song is ending or the conversation in the café has picked up and I end up unsatisfied.

I was watching “Ted Lasso” the other night, and as the music at the very end of the episode began to play, I realized I was curious about the artist. With a very quick flip of the Digital Crown, I exposed the Shazam widget, which had already identified the song and was displaying it for me. There’s a plus icon there that you can use to add that song to your log for later reference.

It’s not going to change my life, but it’s a great little feature. My only real complaint about it is that if Apple’s going to let you use Siri Recap to monitor your life, I’d kind of like the option of turning on a Shazam log for an extended period of time. A few months ago, my wife and I were in a café in Portland, Oregon early on a Sunday morning, and the playlist perfectly fit the mood. I would have loved to have been able to just tell my watch to log all the songs it could identify until we left the café, or for some duration of time.

It’s a start. There’s much more to be done—by me, in terms of using it, and by Apple, in terms of shipping all the features it has promised for this hardware but was unable to deliver by launch.

The history of Apple Cards ↦

2026-09-25 22:24:21

Over at LexOnTech our pal Lex Friedman1 has the skinny behind the long defunct Apple Cards, a project driven by Steve Jobs himself:

In 2011, Mike said, “Steve Jobs was on one of his famous walks after having had a dinner with someone,” and he said to his walking companions from Apple, Mike was later told: “Wouldn’t it be great if I could just right now on my iPhone send [the dinner companion] a thank you card?”

Apple decided to build an iPhone app just for creating and mailing cards. And the project moved fast, because it was a Steve-initiated one. As it turns out, the app was built and launched during the final year of Steve’s life.

Of course, no story of cards and Apple is complete without a link to the euology for Apple’s earlier card service, iCards, created in part by our own contributor, Phil Michaels, back in 2008 (starts at 2:30). (My god, they just keep trying to make cards happen, don’t they.)


  1. The good one. ↩

Go to the linked site.

Read on Six Colors.