This is scary.
This is scary.
What should one try to do to protect against this?
Hypothetical actions to take:
Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail.
Take particular care to have a "recovery" email address that is used for nothing else. Don't forward it to your regular mail, naturally.
Enable two-factor auth for email if you possibly can.
Have a credit card that is only used for online stuff.
Can one get a second address that is used only as a billing address? How would one do that? (A P.O. box? Expensive! A friend's house? I fear that credit card companies will leak this address like a sieve no matter what I do.)
EDIT: Startup wizards, here's a Minimum Viable Product: a credit card that can only be used for online accounts - which you must whitelist as you add them, via two-factor auth with your phone - and that features two billing addresses: The real one where the bills go and a dummy one that still validates. (Is that even legal under the CC rules? Sigh.)
The other suggestions in the article: Disable Find my Mac, reduce coupling between your accounts… was there something else?
Alas, nobody who isn't crazy paranoid is going to bother jumping through all these hoops. (I have tried to fight that paranoia but I think I'm losing that battle.)
Website: "Hey Bill, glad to see you today, what do you want to do"
Bill: "Delete _everything_ I've ever done on every system I have"
Website: "Of course! Let's get this started... beep boop bip and done!"
What about this:
1 - Kill request sent
2 - 48 hours is set on the clock so you can choose to cancel
3 - You can choose to pay $50 via credit card to have it happen immediately
4 - You are reimbursed $45 after a couple weeks
That might make it a little harder to have such hacks like this happen in the future.
I was thinking about remote storage and devices. For example, a backpack is stolen with your phone/tablet/laptop and you need to issue a wipe to it NOW before they are compromised.
Requiring a credit card at least leaves a paper trail of some sort.
I was relieved it was so easy, but unnerved at how easy it was.
Maybe they had the cell associated with my land line, but I doubt it, since I got the line before I ever had a cell.
Apple is really bad at running online services. It's a shame that they short-sightedly decided to go to war with Facebook and Google (who are good at services and bad at hardware) rather than playing more nicely together.
For every person who loses "irreplaceable" data to malice, many more lose it out of simple incompetence.
But yes, backups -- and not just online backups, but also offline backups.
This massively raises the bar for social engineering.
It's actually a good idea. I'll think about doing that…
The bad guys then have to crack your parents email account too, and being older they will be less likely to have daisy-chained Google, Apple and Amazon accounts.
"Pay with your iCloud password" just doesn't have the same fuzzy feel, does it?