User security in the Apple iCloud age
By Lex Friedman, Dan Moren, Macworld.com | Aug 8, 2012
As Honan reported on his blog, he was hacked hard. And the attacker didn’t use complicated algorithms to brute force his way into Honan’s accounts. Instead, the hacker reportedly called up Apple’s technical support line, pretended to be Honan, and successfully provided answers to Honan’s self-selected security questions—the very ones Apple asks of all iCloud customers, to ensure that their accounts are secure. (We contacted Apple to confirm that account of events, but the company hasn’t responded.)
That’s a technique called “social engineering,” which takes advantage of what is often seen to be the weakest link in the security chain: other people. Even the most secure password in the world can be compromised if you can convince the person on the other end of a phone line that you’re the account holder in question.
Merely having his Twitter and Gmail accounts compromised, and the data on his iPad, iPhone, and Mac wiped out would be bad enough for Honan (who, we should note, is a former Macworld editor). What made matters worse in Honan’s case was the fact that he lacked any backups for more than a year’s worth of data.
The take-home lesson for the rest of us, then, is that our security is multi-faceted. There are many steps you can take to keep your data secure, and some important questions you might want to consider before you sign up for new services or add new devices.