Slashdot Mirror


Apple Drops Recovery Key From Two-Factor Authentication In New OS Versions

eggboard writes: If you've ever turned on what's now called "two-step verification" for an Apple ID, you had to create a Recovery Key. Lose this 14-digit code and have your password reset (because of hacking attempts against you), and you might lose access forever to purchases and data, as Owen Williams almost did. Apple confirmed today that starting with its public betas of OS X 10.11 and iOS 9, two-factor authentication won't have a Recovery Key. Instead, if you have to reset a password or lose access to devices, you'll have to go through an account verification process with human beings.

2 of 64 comments (clear)

  1. Authentication is Not Encryption by PvtVoid · · Score: 5, Insightful

    If I encrypt something and lose my key, I should lose my data. But this policy is about authentication (i.e. proving your identity) and not encryption. They're different things, except for some reason they are almost always conflated.

  2. Wonderful... by phayes · · Score: 5, Insightful

    Some random guy in the internet has a hack attempt on his account get blocked by his use of 2 factor ID. Instead of being grateful the guy complains on twitter that he is too busy to have correctly backed the recovery key he was warned he was would have to safeguard.

    Clearly, Apple's procedures up to now avoided having the backdoor of saving the recovery key. That was OUR responsibility. Not saving it meant that Apple could NOT be social engineered or hacked into revealing it.

    Some random guy complains that "it's not his fault his account was hacked" & that he "deserved" his account back. He eventually finds a screenshot but calls for Apple to change the system to add a backdoor so that they can recover any account they want.

    The attack wasn't random guy's fault but it was his fault to not save his recovery key. More importantly, any social engineering or leakage of everybody else's accounts that occur due to Apple backdooring their 2 factor ID WILL be in part his fault. Way to go there, of course your convenience is more important than our security...

    --
    Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue