Zola ʕ•ᴥ•ʔ Bear Blog

Two-step authentication: better security with Google and Facebook (not with iCloud)

A few days ago Matt Honan, tech writer for Wired Magazine, was hacked.

His Google, Apple and Twitter accounts, among other stuff, were hacked, deleted and probably ransacked before that. So, how was this done? In Honan's own words:

I know how it was done now. Confirmed with both the hacker and Apple. It wasn't password related. They got in via Apple tech support and some clever social engineering that let them bypass security questions.

All of his iCloud stuff is gone. Photos, documents, et.c. He's since received help from both Google and Twitter, but Apple can do little about it; they don't even offer two-step authentication through iCloud. Hey, what is that two-step thing? From Gizmodo:

Facebook and Google both offer the option of 2-Step authentication when you login, meaning you have to enter a secondary pin number which is generated and/or texted to your phone. It's a complete and utter pain in the ass whenever you're logged out, but it's also a pretty safe guarantee that no one will be getting into your account without a heavy-duty targeted attack.

Still need info on how Amazon's saving your entire credit card number could financially ruin you, why you should always use HTTPS or why linking accounts all over the Internet is like copying your house keys over and over, read these two very interesting posts:

Gizmodo - 9 things you absolutely must do to keep your online identity secure

Android Central - No excuses: It's time to turn on two-step authentication

Enabling two-step authentication on Google: