Hackers got access to Matt Honan's iCloud account by calling Apple Support
twitter.com
twitter.com
Full name? Home address? Available from the electoral roll in Australia. Phone number? Look it up. Date of birth? Check with the Registrar of Births, Deaths and Marriages. Mother's maiden name? Ditto.
Too many of these verification questions rely on shared secrets that ... aren't secrets.
- Completely non-applicable (I'm not married and don't have any kids or pets)
- Transitory and inane (I don't really have a favorite meal or movie, and if I did, who is to say it will be the same forever?)
- Rely on information that is relatively easily to figure out (birthplace, high school mascot, mother's maiden name, etc)
Security questions alone should never be sufficient to reset a password or gain access to an account, and I'm not really sure they add a whole lot in other contexts either.
On a side note, one of these days I've got really scared when a reputable credit card company asked me for one of these security questions. WTF?!
At first I thought it was completely pointless, someone gets my bank statement then I'm done, but they only ask about the purchases since my last statement. Not saying that Apple should be asking 'what app did you buy on the 1st August?', but a small confirmation outside of the data you provide would probably be useful.
Most of the ideas batted around were technical in nature and somewhat advanced.
There should be enough of a trail to track down the hacker and have him charged, right? The call to Apple would be logged by at least the telephone company, wouldn't it?
Apple's call center probably has the CLID of the caller logged, but equally probably that person called from a prepaid cell phone.
Sure, probably not from the police. But I will put down the rest of my year's salary that Apple will be investigating like all hell how this happened and taking all kinds of steps to make sure this never happens again. Whether or not it actually will is a different story.
The remote wipe would be equivalent to a format so you may be able to get some data back but most of it would be unusable. I don't think Apple can do much about not having a backup. What Apple probably needs to do is have a popup to remind people to backup when they switch on the Find My Mac feature. But I doubt they can do more than that.
I rather doubt they will add a "I see you have enabled Find My Mac--you better back up your system because we will give any random idiot who calls in access to wipe your hard drive. Thanks for choosing Apple!" popup, though.
Apple even makes it easy with Time Machine - they can't be faulted for the wipe (I don't have this on my Mac - I just use disk+memory encryption).
Apple can be faulted for allowing the security breach.
I wonder if the same thing happens on Filevault2. In that case, Apple's only choice would be to rent some serious GPU time at NSA or something...
The remote wipe isn't the root issue here.
Apple has already done everything they should.
On the other hand, if the person said "yes yes I tried iforgot.apple.com but I can't seem to remember any of my security answers/email address used", then that should naturally raise suspicion in the mind of the Apple tech support person, right??
Hackers (in the pejorative sense of the term) and software pirates really are the scum of the earth.