Contact
QR code for the current URL

Story Box-ID: 600122

ElcomSoft Co. Ltd. Vřesovická 429/1 15521 Praha http://www.elcomsoft.com
Contact Ms Olga Koksharova +7 495 974-11-62
Company logo of ElcomSoft Co. Ltd.
ElcomSoft Co. Ltd.

ElcomSoft news: Apple Two-Factor Authentication and the iCloud

(PresseBox) (Moskau, )
I'd like to suggest you yet another interesting topic on which we've made a research and found some really notable things we'd like to share. Everything is described in detail in our blog post (link below).

According to the opinion of an established independent security advisor (and friend of ElcomSoft) Per Thorsheim (CISA, CISM, CISSP-ISSAP, founder and organizer of annual Passwords conference) "this 2-factor authentication will only make it harder for an attacker go purchase the full collection of Justin Bieber through your account. *It will not add any additional protection to your files, documents, sounds, pictures, videos and backups made to Apple iCloud. What is the worst thing that could happen - somebody purchasing Justin Bieber on your behalf & credit card, OR somebody accessing all your files etc stored with Apple iCloud? To me it's a simple question, even when I do not like Justin Biebers music at all."

"Apple's 2fa isn't nearly as broad as I believe MOST people expect it to be. To me the story here is all about Apple offering a 2fa solution that doesn't really add much extra security for you (files, documents etc), but it protects them (and you) from unauthorized money transactions and changes to your account. People are not made aware of this at all, and it will be a false layer of security when people enable 2fa and put sensitive & secret documents into iCloud."

"People EXPECT a 2FA solution to add additional security in order to protect their data, but contrary to Dropbox & Google, Apple doesn't really do that. It's the "weakest" 2fa solution launched so far by the big & well-known services, it will only add an additional layer of false security to people's minds, which may have dangerous results."

"Besides, the verification code sent from Apple shows up as a message on the lockscreen (verification_code.png). Somehow I don't like messages that appear on lock screens - at least not messages containing information that are supposed to be "secret"."

Our blog post: Apple Two-Factor Authentication and the iCloud:

http://blog.crackpassword.com/... by Vladimir Katalov, CEO.
The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.
Important note:

Systematic data storage as well as the use of even parts of this database are only permitted with the written consent of unn | UNITED NEWS NETWORK GmbH.

unn | UNITED NEWS NETWORK GmbH 2002–2024, All rights reserved

The publisher indicated in each case (see company info by clicking on image/title or company info in the right-hand column) is solely responsible for the stories above, the event or job offer shown and for the image and audio material displayed. As a rule, the publisher is also the author of the texts and the attached image, audio and information material. The use of information published here is generally free of charge for personal information and editorial processing. Please clarify any copyright issues with the stated publisher before further use. In case of publication, please send a specimen copy to service@pressebox.de.