3 ms·
Yes, definitely blame Apple, no doubt about it. I'm still a little shocked that the last 4 cc digits constitutes 'security'. An easy alternative - which I think
by equalarrow 14y ago
Yes, definitely blame Apple, no doubt about it. I'm still a little shocked that the last 4 cc digits constitutes 'security'. An easy alternative - which I think they already have - is the whole two security questions thing. I would feel much better - as a customer - if they used those.
This type of thing is going to happen more and more and the fact that remote wipe of all the devices happened totally negates any advantages of using cloud services. I mean, what's the point of having everything backed up remotely if
a) the backup is not current
b) the same remote servers can wipe your devices at any time
In addition, it's possible the remote backups could be removed as well (although not sure about that for iCloud) and in that case, you might as well not back anything up and have a hard drive die (at least that could be recovered I suppose).
Apple needs to jump out in front of this asap and announce a policy change in regards to security in order to put people at ease. I'm glad this is making waves and I think there needs to be more noise about it in order to get them to change.
- pooriaazimi 14y agoWell, If he had a backup (either remote or local) it wouldn't have mattered. It would mean a few hours spent with Time Machine, but he wouldn't lose his data. And a remote backup should not be "removable". Also, don't ever expect Apple to do anything ASAP. Even if the whole world shouts at them, they won't say anything. They take their time to (hopefully) think this through.
- bruceboughton 14y ago>> Well, If he had a backup (either remote or local) it wouldn't have mattered. For this specific thing, no. But this was a fairly blatant act by the hacker. What if they silently read your iCloud mail, or used the Find my iPhone functionality to stalk you.
- pooriaazimi 14y agoThey couldn't silently do anything. They won't give you passwords, they give you the ability to reset it. If the hacker were to reset it, the reporter would notice (as he wouldn't be able to use his account anymore). And I think Find my iPhone would cease working if the password saved by the app does not match what's stored in the cloud (i.e. hacker's bogus password). In case of cookie sniffing, Google shines. They show you the IP addresses of people who have used your account recently. If you (or them) spot an stalker, you can reset the password. I don't know how effective that could be with 3G, but at least --- That said, It's no secret that Apple's password system is absolute garbage. I had to reset it 5 times last month because someone was trying to get to my iCloud account (probably brute-force). Apple would de-activate my account and would require me to re-enter security questions and choose a "new" password that I haven't used in the past year. And every time I had to spend an hour typing the new password in my various devices. AND I WOULDN'T RECEIVE MAILS IN THE MEANTIME. Just ridiculous.
- furyg3 14y agoThe security questions business is hard, too. Many sites use things which are public information (mother's maiden name) but even question's like "Where were you on this important date?" or "what was your first car?" start to look pretty silly in the age of Facebook. Worse, a dropbox-loving facebooker who's checking his gmail account from his iPhone probably has enough information in many of those places to compromise the other accounts.
- jwbaker 14y agoYou should never give legit answers to these security questions. I just paste in the output of pwgen -s 32 1. This may make your account harder to "recover" but it also makes it harder to steal.
- raverbashing 14y agoFor a compromise, you can add the correct answer but with a quirk. (that is easier, unless you forget the quirk) like, put the first name in "Mother's maiden name", or the middle name, or swap their position And you are right to treat it as a passsword
- furyg3 14y agoYes, this is exactly what I do. I have interesting results sometimes; Bank: I'll just need you to confirm your mother's maiden...um...um Me: Yes, it's a long string of random characters, want me to read it? Bank: No, that's ok, thanks. :/