{"id":7186,"date":"2013-03-21T18:02:32","date_gmt":"2013-03-21T22:02:32","guid":{"rendered":"http:\/\/mjtsai.com\/blog\/?p=7186"},"modified":"2021-07-03T14:18:53","modified_gmt":"2021-07-03T18:18:53","slug":"two-step-verification-for-apple-id","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2013\/03\/21\/two-step-verification-for-apple-id\/","title":{"rendered":"Two-Step Verification for Apple ID"},"content":{"rendered":"<p><a href=\"http:\/\/support.apple.com\/kb\/HT5570?viewlocale=en_US&amp;locale=en_US\">Apple HT5570<\/a>:<\/p>\n<blockquote cite=\"http:\/\/support.apple.com\/kb\/HT5570?viewlocale=en_US&amp;locale=en_US\"><p>Your Apple ID is the key to many important things you do with Apple, such as purchasing from the iTunes and App Stores, keeping personal information up-to-date across your devices with iCloud, and locating, locking, or wiping your devices. Two-step verification is a feature you can use to keep your Apple ID as secure as possible.<\/p><\/blockquote>\n<p>This is much better than <a href=\"http:\/\/mjtsai.com\/blog\/2012\/08\/07\/apple-reacts-to-honan\/\">asking for a device serial number<\/a> and should help against <a href=\"http:\/\/mjtsai.com\/blog\/2012\/08\/07\/my-apple-id-episode-from-2008\/\">Mat Honan&#8211;type social engineering<\/a>.<\/p>\n<blockquote cite=\"http:\/\/support.apple.com\/kb\/HT5570?viewlocale=en_US&amp;locale=en_US\"><p>If you no longer have access to one of your devices, go to&nbsp;<a href=\"http:\/\/appleid.apple.com\">My Apple ID<\/a> to remove that device from your list of trusted devices as soon as possible so that it can no longer be used to help verify your identity.<\/p><\/blockquote>\n<p>Of note, it does not appear that two-step verification is needed to <a href=\"http:\/\/mjtsai.com\/blog\/2012\/08\/04\/find-my-mac-and-remote-wipe\/\">remote wipe<\/a> or to <a href=\"http:\/\/mjtsai.com\/blog\/2012\/08\/07\/filevault-2s-apple-id-backdoor\/\">access FileVault-encrypted files on a locked but powered-on Mac<\/a>. It seems more likely that someone would get my Apple ID password than that I would need to remote wipe or would forget my Mac&rsquo;s password, so I don&rsquo;t have Find My iPhone or login password recovery enabled. I wish there were a way to enable Find My iPhone without enabling remote wipe.<\/p>\n<p>Update (2013-03-21): <a href=\"http:\/\/the.taoofmac.com\/space\/blog\/2013\/03\/21\/2145\">Rui Carmo<\/a>:<\/p>\n<blockquote cite=\"http:\/\/the.taoofmac.com\/space\/blog\/2013\/03\/21\/2145\"><p>I am clearly in the minority that thinks of two-factor auth in and by itself as security voodoo to appease the unwashed masses &mdash; especially if you don&rsquo;t follow it up with privilege separation &mdash; and I&rsquo;m going to stick to my guns on this one.<\/p><\/blockquote>\n<p>I&rsquo;d also like to note that if you have a non-phone, you don&rsquo;t have SMS, and so in order to use two-factor authentication you must enable Find My iPhone and its remote wipe feature.<\/p>\n<p>Update (2013-03-22): <a href=\"http:\/\/www.theverge.com\/2013\/3\/22\/4136242\/major-security-hole-allows-apple-id-passwords-reset-with-email-date-of-birth\">Chris Welch<\/a> (via <a href=\"http:\/\/www.sparsebundle.net\/posts\/major-security-hole-allows-apple-passwords-to-be-reset\/\">Jordan Merrick<\/a>):<\/p><blockquote cite=\"http:\/\/www.theverge.com\/2013\/3\/22\/4136242\/major-security-hole-allows-apple-id-passwords-reset-with-email-date-of-birth\"><p>Unfortunately, today a new exploit has been discovered that affects all customers who <em>haven&rsquo;t<\/em> yet enabled the new feature. It allows anyone with your email address and date of birth to reset your password &mdash; using Apple&rsquo;s own tools.<\/p><\/blockquote>\n<p>Update (2013-05-31): <a href=\"http:\/\/arstechnica.com\/security\/2013\/05\/icloud-users-take-note-apple-two-step-protection-wont-protect-your-data\/\">Dan Goodin quotes Vladimir Katalov<\/a>:<\/p>\n<blockquote cite=\"http:\/\/arstechnica.com\/security\/2013\/05\/icloud-users-take-note-apple-two-step-protection-wont-protect-your-data\/\"><p>&ldquo;To me the story here is all about Apple offering a 2FA [two-factor authentication] solution that doesn&rsquo;t really add much extra security for you (files, documents etc), but it protects them (and you) from unauthorized money transactions and changes to your account,&rdquo; Per Thorsheim, a security consultant in Oslo, Norway, wrote in an e-mail to Ars. &ldquo;People are not made aware of this at all, and it will be a false layer of security when people enable 2FA and put sensitive and secret documents into iCloud.&rdquo;<\/p><\/blockquote>\n<p><a href=\"http:\/\/tidbits.com\/article\/13804\">Glenn Fleishman<\/a>:<\/p>\n<blockquote cite=\"http:\/\/tidbits.com\/article\/13804\"><p>Apple has suffered enough security stumbles in the last few years that it shouldn&rsquo;t lag in this regard. It has been behind the curve many times in ways that damage customers&rsquo; identities, online integrity, and safety. Apple needs to use its engineering prowess to solve this problem and solve it quickly. Google already has for its users.<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>Apple HT5570: Your Apple ID is the key to many important things you do with Apple, such as purchasing from the iTunes and App Stores, keeping personal information up-to-date across your devices with iCloud, and locating, locking, or wiping your devices. Two-step verification is a feature you can use to keep your Apple ID as [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-07-03T18:18:56Z","apple_news_api_id":"8d0c7788-1407-42b4-8c2b-cfe13c73218d","apple_news_api_modified_at":"2021-07-03T18:18:56Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AjQx3iBQHQrSMK8_hPHMhjQ","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[38,48,2090],"class_list":["post-7186","post","type-post","status-publish","format-standard","hentry","category-technology","tag-apple","tag-security","tag-two-factor-authentication-2fa"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7186","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=7186"}],"version-history":[{"count":9,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7186\/revisions"}],"predecessor-version":[{"id":14458,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/7186\/revisions\/14458"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=7186"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=7186"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=7186"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}