Security experts applaud Apple's new two-factor authentication
Option locks Apple IDs, stymies account hijacking
Computerworld - Apple this week followed the lead of rivals like Facebook, Google and Microsoft, offering two-step authentication to help customers secure their Apple IDs against hacking.
The new feature is designed to block unauthorized changes to iCloud or iTunes accounts, and keep hackers who steal Apple IDs from purchasing digital content or hardware using the credit cards stored in customers' iTunes and Apple Store accounts.
iTunes users in particular have complained for years about security so lax that hackers have easily hijacked their accounts to run up big bills.
Security experts commended Apple, even though the company was slow pulling the trigger.
"Always exciting to see a major consumer-oriented service roll out some sort of two-factor authentication," said Jon Oberheide, co-founder and CTO of Duo Security, a developer of authentication software, in an email. "Rolling your own two-factor definitely isn't a trivial task, both from an upfront engineering cost and continued support and maintenance, despite the perceived ease from an external view."
Two-factor authentication -- sometimes called two-step verification -- is a more demanding method of locking an account than a password-only process. In enterprises, for instance, two-factor relies on hardware tokens that generate passcodes, which are valid for just moments and must be entered along with the usual password.
But Web services don't distribute tokens. Instead, they send a passcode to a mobile phone number the account owner has set earlier. The passcode is typically sent as an SMS (short message service) text.
Apple's optional two-factor authentication uses that same approach, but also will send the passcode to an iOS device -- iPhone or iPad -- via the Find My iPhone app's notification feature. Find My iPhone is normally used to, not surprisingly, help users locate lost, stolen or misplaced devices.
That drew accolades from the experts.
"I'd say [Apple's] is above-average for a consumer-oriented two-factor solution, particularly with respect to leveraging the Find My iPhone mobile application," said Oberheide in an email Friday. "Using a native app for two-factor authentication, like Find My iPhone, is a much better approach than simply relying on SMS, which has a number of security and reliability concerns."
SMS messages, for instance, can be faked, and receiving them requires that the user be in range of their carrier's signal. Find My iPhone, on the other hand, operates independently of the wireless carrier, letting iOS owners get passcodes when all that's available is Wi-Fi, or on tablets like the iPad and iPad Mini that lack cellular connectivity.
Andrew Storms, director of security operations at nCircle Security, had a different thought on Find My iPhone's advantage.
"It has some potential for good contextual awareness authentication," said Storms in an interview via instant messaging. "GPS could be used as the second factor of authentication. Are you really at the home address you already have on file with your iTunes account? If so, Apple could check your iPhone's GPS location to verify."
- Apple updates OS X Yosemite public beta
- Even rivals are waiting for Apple to get into wearables
- Apple preps final non-security Mavericks update
- New Yosemite dev preview may herald public beta update later this week
- iPhone 5C's China bust raises questions about Apple's pricing for '14 models
- Mac sales so far in '14 may signal share push
- China scrubs Apple's iPad and MacBooks from government buying list
- Circle the date: Apple's iPhone 6 event slated for Sept. 9
- Stable Mac prices fuel reliable profit engine
- Apple unveils minor bumps to MacBook Pro laptops
- Deep Security +VMware vSphere with Operations Management Most midsize organizations are highly virtualized on VMware, and while this has produced significant savings, it also has created new challenges when it...
- 3 Questions to Ask Your DNS Host about Lowering DDoS Risks Neustar has had wide-ranging conversations with clients wanting to know how they can optimize protection as DDoS attacks increase in frequency and size.
- The Danger Deepens: 2014 Neustar Annual DDoS Attacks and Impact Report This report compares DDoS findings from 2013 to 2012, based on a survey of 440 North American companies, including 139 businesses delivering technology...
- DDoS Infographic: How Are Attacks Evolving? For the third consecutive year, Neustar surveyed businesses across major industries to track the evolution of DDoS attacks. Are they more frequent? Larger?...
- How to Use Crowd-Sourced Threat Intelligence to Stop Malware in its Tracks Threat sharing networks have been around for a long time, however they have typically been "invitation-only", available to only large companies, or those...
- An Incident Response Playbook: From Monitoring to Operations As cyber-attacks grow more sophisticated, many organizations are investing more into incident detection and response capabilities. In this webcast, learn how to develop... All Malware and Vulnerabilities White Papers | Webcasts