Security experts applaud Apple's new two-factor authentication
Option locks Apple IDs, stymies account hijacking
Computerworld - Apple this week followed the lead of rivals like Facebook, Google and Microsoft, offering two-step authentication to help customers secure their Apple IDs against hacking.
The new feature is designed to block unauthorized changes to iCloud or iTunes accounts, and keep hackers who steal Apple IDs from purchasing digital content or hardware using the credit cards stored in customers' iTunes and Apple Store accounts.
iTunes users in particular have complained for years about security so lax that hackers have easily hijacked their accounts to run up big bills.
Security experts commended Apple, even though the company was slow pulling the trigger.
"Always exciting to see a major consumer-oriented service roll out some sort of two-factor authentication," said Jon Oberheide, co-founder and CTO of Duo Security, a developer of authentication software, in an email. "Rolling your own two-factor definitely isn't a trivial task, both from an upfront engineering cost and continued support and maintenance, despite the perceived ease from an external view."
Two-factor authentication -- sometimes called two-step verification -- is a more demanding method of locking an account than a password-only process. In enterprises, for instance, two-factor relies on hardware tokens that generate passcodes, which are valid for just moments and must be entered along with the usual password.
But Web services don't distribute tokens. Instead, they send a passcode to a mobile phone number the account owner has set earlier. The passcode is typically sent as an SMS (short message service) text.
Apple's optional two-factor authentication uses that same approach, but also will send the passcode to an iOS device -- iPhone or iPad -- via the Find My iPhone app's notification feature. Find My iPhone is normally used to, not surprisingly, help users locate lost, stolen or misplaced devices.
That drew accolades from the experts.
"I'd say [Apple's] is above-average for a consumer-oriented two-factor solution, particularly with respect to leveraging the Find My iPhone mobile application," said Oberheide in an email Friday. "Using a native app for two-factor authentication, like Find My iPhone, is a much better approach than simply relying on SMS, which has a number of security and reliability concerns."
SMS messages, for instance, can be faked, and receiving them requires that the user be in range of their carrier's signal. Find My iPhone, on the other hand, operates independently of the wireless carrier, letting iOS owners get passcodes when all that's available is Wi-Fi, or on tablets like the iPad and iPad Mini that lack cellular connectivity.
Andrew Storms, director of security operations at nCircle Security, had a different thought on Find My iPhone's advantage.
"It has some potential for good contextual awareness authentication," said Storms in an interview via instant messaging. "GPS could be used as the second factor of authentication. Are you really at the home address you already have on file with your iTunes account? If so, Apple could check your iPhone's GPS location to verify."
- Apple unwraps OS X Yosemite public beta Thursday
- Apple grows Mac sales by 18% on the back of the MacBook Air
- Want an Apple watch? Just 3D print one
- What to listen for during Apple's earnings call today
- Mac sales will again outstrip industry average
- Apple, IBM spell out enterprise support for iPhone, iPad
- Timeline: How Apple's iOS gained enterprise cred
- Apple and IBM: A winning combo for IT
- Why Microsoft isn't spooked by the Apple-IBM alliance
- Apple-IBM deal threatens Android's enterprise push
- Comprehensive Advanced Threat Defense The hot topic in the information security industry these days is "Advanced Threat Defense" (ATD). This paper describes a comprehensive, network-based approach to...
- Advanced Threat Defense: A Comprehensive Approach In this interview, Peter George, president, General Dynamics Fidelis Cybersecurity Solutions, explains why we need more than anti-malware, and what constitutes a comprehensive...
- Who's Spying on You? You're aware of the threats of malware to your business but what about the ever-changing ground rules? Cybercriminals today are launching attacks against...
- Market Overview: Digital Customer Experience Delivery Platforms Forrester states that businesses today struggle to understand and use the tools necessary to create and manage unified, multichannel digital customer experiences across...
- On-demand webinar - 7 Keys to Service Catalog Implementation Success Watch this webinar to learn 7 crucial keys to make your service catalog a success!
- Transform Your IT Service Management Watch this webinar, to learn how EasyVista can increase IT productivity & efficiency and deliver streamlined & integrated IT Service & Asset Mgmt. All Malware and Vulnerabilities White Papers | Webcasts