I'm a little disappointed how this article and many of the comments here ignore the specifics of what actually happened.
Yes "use different passwords" and "use a password manager" are good general advice. But this blog post expressly uses a specific case - the Honan hack - as a case study, without highlighting the one major lesson from that case.
The actual problem most strongly highlighted by the Honan case is that your Gmail account is only as strong as the "backup email address" it is tied to. Honan's problem has nothing to do with using the same password -- he /had/ different passwords which you know if you read his post carefully. Problem is, his iCloud email was his Gmail backup email, and Gmail apparently allows arbitrary persons to instantly take over an account as long as they control the backup email. No waiting period, no warning email to the Gmail account, no SMS notification. Yes this can be fixed with two-factor auth (apparently) but by default that is off and by default Google badgers you about setting up a backup email address until you do so. By default Google does not badger you about two-factor auth.
The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number.
If you think about it, it's a little insane that you can protect your Gmail with two-factor auth but you can't protect your laptop the same way.
Maybe a password manager would have encouraged Honan to use a stronger iCloud password, and maybe a stronger iCloud password would have prevented this attack, but that's not established because we don't know how the attack was pulled off. It was a seven char alphanumeric password and the attacker specifically told Honan it was not a brute force attack.
"The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number."
That depends a lot on what kind of threats you're trying to protect yourself against. I suspect there's a lot of people for whom the correct response to a misplaced phone/laptop is "remote wipe immediately - if it turns up in the back seat of my car I'll just restore from backup - if was left in a plane/taxi/competitors-office/deacon I want everything o. It wiped _right now_!"
I bet if pg lost a laptop with emails/documents about current and prospective YC deals or exits, he'd rather not have to wait till a office hours robo-call gave him a remote-wipe-PIN.
It didn't work out for @mat, but I think "good backups and easy remote wipe" is a better default than "making remote wipe harder just in case your backups don't exist."
Comments
I'm a little disappointed how this article and many of the comments here ignore the specifics of what actually happened.
Yes "use different passwords" and "use a password manager" are good general advice. But this blog post expressly uses a specific case - the Honan hack - as a case study, without highlighting the one major lesson from that case.
The actual problem most strongly highlighted by the Honan case is that your Gmail account is only as strong as the "backup email address" it is tied to. Honan's problem has nothing to do with using the same password -- he /had/ different passwords which you know if you read his post carefully. Problem is, his iCloud email was his Gmail backup email, and Gmail apparently allows arbitrary persons to instantly take over an account as long as they control the backup email. No waiting period, no warning email to the Gmail account, no SMS notification. Yes this can be fixed with two-factor auth (apparently) but by default that is off and by default Google badgers you about setting up a backup email address until you do so. By default Google does not badger you about two-factor auth.
The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number.
If you think about it, it's a little insane that you can protect your Gmail with two-factor auth but you can't protect your laptop the same way.
Maybe a password manager would have encouraged Honan to use a stronger iCloud password, and maybe a stronger iCloud password would have prevented this attack, but that's not established because we don't know how the attack was pulled off. It was a seven char alphanumeric password and the attacker specifically told Honan it was not a brute force attack.
"The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number."
That depends a lot on what kind of threats you're trying to protect yourself against. I suspect there's a lot of people for whom the correct response to a misplaced phone/laptop is "remote wipe immediately - if it turns up in the back seat of my car I'll just restore from backup - if was left in a plane/taxi/competitors-office/deacon I want everything o. It wiped _right now_!"
I bet if pg lost a laptop with emails/documents about current and prospective YC deals or exits, he'd rather not have to wait till a office hours robo-call gave him a remote-wipe-PIN.
It didn't work out for @mat, but I think "good backups and easy remote wipe" is a better default than "making remote wipe harder just in case your backups don't exist."