{"id":48658,"date":"2014-09-17T16:30:29","date_gmt":"2014-09-17T16:30:29","guid":{"rendered":"http:\/\/4cd.e16.myftpupload.com\/?p=48658"},"modified":"2014-09-18T07:15:20","modified_gmt":"2014-09-18T07:15:20","slug":"apple-toughens-icloud-security-after-celebrity-breach","status":"publish","type":"post","link":"https:\/\/citifmonline.com\/?p=48658","title":{"rendered":"Apple toughens iCloud security after celebrity breach"},"content":{"rendered":"<p id=\"story_continues_1\">Apple has expanded its use of &#8220;two-step verification&#8221; checks to protect data stored online by its customers.<\/p>\n<p>It follows suggestions third-party software had been used to steal intimate photos of celebrities &#8211; posted online last month &#8211; from iCloud.<\/p>\n<p>The action should stop the tool from being able to infiltrate Apple&#8217;s internet storage service if the safety measure is implemented.<\/p>\n<p>However, the security facility remains an opt-in choice.<\/p>\n<p>One expert suggested that Apple should instead make it the default option.<\/p>\n<p>The process works\u00a0<a href=\"http:\/\/support.apple.com\/kb\/ht5570\">by introducing an extra step<\/a>\u00a0after an account holder has typed their username and password into a device they have not used before.<\/p>\n<p>They are also required to enter a four-digit code that is either texted to a trusted mobile phone number or sent via Apple&#8217;s Find My iPhone app.<\/p>\n<p>If the person does not enter the code, they are refused access to iCloud and are blocked from making an iTunes, iBooks, or App Store purchase.<\/p>\n<p>They can, however, use a 14-character recovery key to regain access to the account in the event their trusted device is lost or stolen. They are told to keep this in a safe place to avoid being locked out.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" alt=\"Apple graphic\" src=\"http:\/\/news.bbcimg.co.uk\/media\/images\/77638000\/jpg\/_77638019_72e06bc1-6ef8-427f-847a-253dcbc9d441.jpg\" width=\"512\" height=\"180\" \/>Apple published this graphic to explain how to use two-factor authentication<\/div>\n<p>While Apple had offered the two-step verification system in the past, until now it had not come into play when device owners used the firm&#8217;s back-up service.<\/p>\n<p>That meant that even if people had switched on the two-step feature to prevent cyber-thieves logging into their accounts with a stolen or guessed password, the attackers could still download a complete back-up of their data by using Elcomsoft&#8217;s Phone Password Breaker.<\/p>\n<p>Several hackers&#8217; forums contain discussions about using of pirated copies of Elcomsoft&#8217;s &#8220;forensic&#8221; software, which is marketed as a tool for law enforcement agencies to access iCloud content without needing to be in possession of a suspect&#8217;s iPhone or iPad.<\/p>\n<p>ElmcomSoft&#8217;s Moscow-based owner told the BBC earlier this month that he believed his software had been used in the recent hacks, as it was &#8220;the only one able to do that&#8221;.<\/p>\n<div><img loading=\"lazy\" decoding=\"async\" alt=\"Elcomsoft\" src=\"http:\/\/news.bbcimg.co.uk\/media\/images\/77638000\/jpg\/_77638022_c47ee5e7-ec6d-4823-88ac-6d77a65eecd7.jpg\" width=\"140\" height=\"250\" \/>Elcomsoft said its software could recover password-protected back-ups<\/div>\n<p>He has now acknowledged that Apple&#8217;s changes guard against the technique he had used.<\/p>\n<p>&#8220;I think that implementation is secure, and so there is no workaround,&#8221; Vladimir Katalov told the BBC, adding that his program could no longer even get a list of devices and back-ups linked to a user&#8217;s account.<\/p>\n<p>&#8220;The other security improvement, which I like, is that now the owner of the Apple account gets a notification by email immediately when a back-up starts downloading &#8211; whether or not two-factor authentication is enabled.&#8221;<\/p>\n<p>However, he added that he still had concerns about Apple&#8217;s security system.<\/p>\n<p>&#8220;The recovery key is hard to remember. And as far as you are not going to use it frequently &#8211; it is not needed at all while you have the trusted device handy &#8211; there is a good chance that you lose it,&#8221; he said.<\/p>\n<p>&#8220;And if you lose your device too, there will be no way to get your data back.<\/p>\n<p>&#8220;Secondly, the recovery key might be stolen. And someone who managed to get your Apple ID password and your security key could make a lot of trouble for you, not just downloading your selfies.&#8221;<\/p>\n<p>But another security expert downplayed the risk of lost recovery keys, and said that Apple should do more than just recommend people switch on the two-factor test.<\/p>\n<p>&#8220;We&#8217;ve seen so much in recent times that single-step verification &#8211; ie passwords &#8211; is vulnerable, we&#8217;re at the stage that two-factor authentication should be the default,&#8221; said Prof Alan Woodward, from the University of Surrey.<\/p>\n<p>&#8220;It&#8217;s a case of turn it on by default, and let people turn it off if they really don&#8217;t want it.<\/p>\n<p>&#8220;And that applies to not just Apple, but companies like Microsoft and Google too.&#8221;<\/p>\n<p>Apple\u00a0<a href=\"http:\/\/online.wsj.com\/articles\/tim-cook-says-apple-to-add-security-alerts-for-icloud-users-1409880977\">has told the Wall Street Journal that it<\/a>\u00a0&#8220;plans to more aggressively encourage people&#8221; to turn two-factor authentication on and use stronger passwords.<\/p>\n<p>&#8220;When I step back from this terrible scenario that happened and say what more could we have done, I think about the awareness piece,&#8221; chief executive Tim Cook told the newspaper.<\/p>\n<p>&#8220;I think we have a responsibility to ratchet that up. That&#8217;s not really an engineering thing.&#8221;<\/p>\n<p>&nbsp;<\/p>\n<p>Source: BBC<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Apple has expanded its use of &#8220;two-step verification&#8221; checks to protect data stored online by its customers. It follows suggestions third-party software had been used to steal intimate photos of celebrities &#8211; posted online last month &#8211; from iCloud. The action should stop the tool from being able to infiltrate Apple&#8217;s internet storage service if [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":48793,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jnews-multi-image_gallery":[],"jnews_single_post":[],"jnews_primary_category":[],"jnews_social_meta":[],"jnews_override_counter":[],"footnotes":""},"categories":[],"tags":[18],"class_list":["post-48658","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","tag-dr-akwasi-osei"],"_links":{"self":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/48658","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=48658"}],"version-history":[{"count":0,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/posts\/48658\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=\/wp\/v2\/media\/48793"}],"wp:attachment":[{"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=48658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=48658"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/citifmonline.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=48658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}