6 ms·
The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile ce
by nokiaman 12y ago
The damage has been done, surely?
Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc.
Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons).
Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days.
Question is, would Apple have responded so quickly if celebrities weren't involved?
- chez17 12y agoI'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire, system. Those "security questions" are very easy to find out, therefor the system is insecure.
- Zikes 12y ago2FA needs more traction. Also, email/text alerts about new logins, login attempts, and changes to account settings.
- jfaat 12y agoWhenever these types of questions are required for account recovery, I use a false set of answers as an additional security measure. Probably a good practice for a celebrity.
- bashinator 12y agoIf the only way to safely use the system is to deliberately ignore its instructions ("provide answers to these questions"), then the system is broken.
- jfaat 12y agoI agree, however sometimes your front brakes are out and you still need to bike home. A bit of critical thinking can allow you to largely overcome a serious safety issue. Saying "the system is broken" is less helpful than saying "since it's broken, give this hack a try," IMO.
- TheHypnotist 12y agoDon't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.
- bsilvereagle 12y agoJust because a lot of companies are using the system does not make it secure. Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.
- TheHypnotist 12y agoYou're right. I guess I have too much faith in the average user to not pick a question with a potentially obvious or easily discovered answer to it.
- yojimbo311 12y agoI forget the term for it, but it's exactly like Terms and Conditions. Always expect the user to solve any puzzle put to them using the least amount of energy/effort. It's quite honestly not worth it to anyone to go through the work of securing their information/data/whatever until it's actually genuinely at risk or they have lost something in the past. Until then it's an impedance and an annoyance that makes them very unhappy. Once something like this happens it's impressive how much cognitive dissonance there is behind the excuses those very same people make or their claims that not enough was done to protect them. Don't get me wrong, these individuals were horribly victimized and it's not ok, but we can't allow ourselves to be satisfied by just blaming the company, especially if they otherwise provided the tools that would have kept the account secure. We can only realistically expect the companies we entrust our data to be responsible for making it possible for us to secure our data and not leaking it through other systemic failures. If we choose to shortcut it then it's our responsibility to learn from that and do better next time. We can't blame anyone involved here for doing what they should otherwise be motivated/expected to do. Apple provided the tools to protect the accounts, and as far as we know didn't allow them to be otherwise compromised. The victims set up their accounts in a way that they could easily access/recover them in the future (honestly, it's now required to remember around 20+ account passwords to manage our lives and it's only getting worse) regardless if they knew the risks or not. Security education is out there and it's as loud as we could hope to get it, people just won't internalize it until the risk is tangible. We can demand that companies like Apple, but it won't actually improve anything if people can't be bothered to use them or more importantly find it WAY more inconvenient and seek ways to bypass them in whatever way possible just to get them out of the way. It's a shame that this is blowing up for Apple as if it's all Apple's fault, but maybe some good can come from it.
- IBM 12y agoApple wasn't hacked in any sense by the definition of what non-pedants go by.
- pseudonym 12y agoWhile I wouldn't disagree with the stupidity of "security questions" answered straight, I don't know if this is something to lay on Apple's doorstep, because anyone with a modicum of knowledge either lies or supplies "custom" security questions-- it's basically a "if you forget password A, remember password B" system. But explaining that to users who have issues with a password is a lot more far-reaching and widespread than any one company. Additionally, making "security questions" passwords in and of themselves is going to tremendously increase the volume of your support tickets. At some point, you need to make a cost/benefit analysis and make a decision including that, not just looking at "what's more secure if we assume our users are stupid". If you really want a niche market, though, "social media security consultant" for celebrities would probably make you a pretty penny nowadays...
- x1798DE 12y ago>Additionally, making "security questions" passwords in and of themselves is going to tremendously increase the volume of your support tickets. At some point, you need to make a cost/benefit analysis and make a decision including that, not just looking at "what's more secure if we assume our users are stupid". I think as long as you can choose your own level of security, this is actually the best solution, even though some people will not have a firm grasp on how much security they are choosing to have. Right now the default is a fairly low level of security (answer the security questions correct, plus possibly an e-mail loop), but you can just answer the security questions with another password if you want to, assuming that they don't have any kind of thing that detects weird answers. Unfortunately, almost no one lets you selectively disable things like security questions or password resets.
- sixothree 12y agoPersonally I don't believe using preset security questions should ever be allowed. People should be allowed to type their own security question and answer.
- kennywinker 12y agoAAPL stock is up today, despite iCloud being implicated. I'm not sure what exactly that means, but my personal guess would be that cognitive dissonance and a general "slut shame"-y attitude means people blame these celebrities for taking the photos / getting "hacked" and not Apple. Not saying that's right, I definitely think that's the wrong take-away from all this, but I suspect that's what's happening, at least in these early days...