Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account.
Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?
If I'm reading the blog post correctly, his Twitter account was compromised via GMail. If his GMail account had not been compromised, they wouldn't have gained access to his Twitter feed (which was the true target of the attack).
They would still have been able to compromise his iCloud account and thus destroy the data stored on his computers.
Unfortunately, I think that in this particular case, having two-factor auth on GMail wouldn't have helped. His account was compromised by having a password recovery email sent to his iCloud address. Presumably, password recovery bypasses two-factor auth.
In this attack and the earlier CloudFlare attack, the attacker took advantage of inappropriate recovery email settings. While it's reasonable for consumers to enter recovery emails, I think that professionals should avoid enabling them. When a @gmail.com sends recovery mail to @me.com (or vice-versa), the attack surface is greatly increased.
Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked.
Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com."
I don't know for sure whether that's true or not. But assume it is true. If two-factor authentication had been enabled, then the hackers would have had a much harder time guessing Mat's email address for iCloud and whether he had a @me.com email address at all.
I have two-factor authentication turned on and I can see this much (in a different web browser) without entering anything: "Choose how to get back into your account. Get a password reset link at my recovery email: uch•••••••@c••••.com"
The problem may be that "me.com" is so short that Google might display the full domain name. If that's the case, Google should fix it.
I disagree. I think most iCloud users (%80 of iOS users by Apple's count) have @me addresses when they upgraded to iOS 5 or Lion. I can use both my @gmail.com and my @me.com in App Store to purchase, or to login to icloud.com.
"Hackers would have had a much harder time"? No: mhonan@gmail.com mhonan@me.com
Gmail was not really needed to guess the name at @me.com.
Moreover, in his case, it seems he would be better off not having the secondary e-mail address for recovery at Google. It turned out to be anti-security measure.
It's not the mhonan part the would've been hard to guess but the @me.com. A secondary email account could be anything. It could also very well not be enabled. Knowing that it is enabled and that is an @me was definitely something that helped the attackers.
Good point. But even two-factor auth wouldn't have saved him because the hacker got the customer support people to issue a temporary password. Apple (and others) need to implement better controls on how you reestablish identity once you've lost access.
Wouldn't the hacker still need the temporary password AND the Google Authenticator code? Or are you assuming that the customer support people could and would turn off two-factor auth while resetting the password?
Yes I'm assuming I call a company having lost all access. Would a company have a different way of establishing identity for someone who lost all access if they've implemented TFA?