If you run a system on the scale of iCloud, and you don't crack it yourself, you can bet someone else will save you the trouble.
iCloud was NOT hacked. There was simply a mistake made by a customer service rep as acknowledged by Apple.
If I can't figure out how to turn on my shiny, new Mac, there is zero need to any verification. If I'm asking for a password reset, they should know for sure who I am by the end.
I had to remove an authentication from my Blizzard account once. They required me to do all the normal verification stuff (secret questions, password, etc), send an ID and confirm the process via a contact point I already had on the account. It took 24 hours. And they did it right.
For the record, "Munich" == "Which" in iPad-ese.
In the US, at least, regulated banks have some security requirements that might prevent this (though I'm not sure). But outside of that my guess is that it's routine for a customer service agent to be able to make any modification to an account they want, without an extra authentication factor or supervision.
So yes: blame Apple. But be wary, they can't possibly be the only ones.
Frustrating? Yes. But good security can't be transparent to the user.
Now I had completely blanked on what that was.. was it my username? Was it my full name? Was it the beginning part of my email? gah, I'm on break outside a cafe and thought I could get this settled quick..
So the person on the phone, in quite a polite and understandable way, gave me a number to call back directly when I could remember it as I had passed all other verification steps. Had a moment of clarity and called back 2 seconds later and got on with it. They overnighted me a brand new phone.
I rate that interaction a 10/10. 9/10 if we can imagine a world of omniscient amazon that knows when I've received broken items..
Nearly always security is the opposite of convenience. Once people realise that you can be "more secure" or "more convenient" we'll all be better off. This implies to be "more secure" you must be "less convenient". It's always a trade off.
This type of thing is going to happen more and more and the fact that remote wipe of all the devices happened totally negates any advantages of using cloud services. I mean, what's the point of having everything backed up remotely if
a) the backup is not current b) the same remote servers can wipe your devices at any time
In addition, it's possible the remote backups could be removed as well (although not sure about that for iCloud) and in that case, you might as well not back anything up and have a hard drive die (at least that could be recovered I suppose).
Apple needs to jump out in front of this asap and announce a policy change in regards to security in order to put people at ease. I'm glad this is making waves and I think there needs to be more noise about it in order to get them to change.
Also, don't ever expect Apple to do anything ASAP. Even if the whole world shouts at them, they won't say anything. They take their time to (hopefully) think this through.
For this specific thing, no. But this was a fairly blatant act by the hacker. What if they silently read your iCloud mail, or used the Find my iPhone functionality to stalk you.
In case of cookie sniffing, Google shines. They show you the IP addresses of people who have used your account recently. If you (or them) spot an stalker, you can reset the password. I don't know how effective that could be with 3G, but at least
---
That said, It's no secret that Apple's password system is absolute garbage. I had to reset it 5 times last month because someone was trying to get to my iCloud account (probably brute-force). Apple would de-activate my account and would require me to re-enter security questions and choose a "new" password that I haven't used in the past year. And every time I had to spend an hour typing the new password in my various devices. AND I WOULDN'T RECEIVE MAILS IN THE MEANTIME. Just ridiculous.
Many sites use things which are public information (mother's maiden name) but even question's like "Where were you on this important date?" or "what was your first car?" start to look pretty silly in the age of Facebook. Worse, a dropbox-loving facebooker who's checking his gmail account from his iPhone probably has enough information in many of those places to compromise the other accounts.
like, put the first name in "Mother's maiden name", or the middle name, or swap their position
And you are right to treat it as a passsword
Bank: I'll just need you to confirm your mother's maiden...um...um
Me: Yes, it's a long string of random characters, want me to read it?
Bank: No, that's ok, thanks.
:/The EU has data protection law, which means companies that store personal data are legally required to ensure it's safe. I wonder if Apple are in breech of the law here?
In my blinkered world, Google and Facebook seem to be the companies to beat in the area of security for consumer services. 2-factor auth, proactive account security such as geographic checks etc.
I can see how Apple's corporate mindset would find it painful to sacrifice user experience for security. Google, not so much.
As an aside, it's about time Microsoft offered 2-factor auth for their accounts.