Good point. But even two-factor auth wouldn't have saved him because the hacker got the customer support people to issue a temporary password. Apple (and others) need to implement better controls on how you reestablish identity once you've lost access.
Wouldn't the hacker still need the temporary password AND the Google Authenticator code? Or are you assuming that the customer support people could and would turn off two-factor auth while resetting the password?
Yes I'm assuming I call a company having lost all access. Would a company have a different way of establishing identity for someone who lost all access if they've implemented TFA?
Comments
Good point. But even two-factor auth wouldn't have saved him because the hacker got the customer support people to issue a temporary password. Apple (and others) need to implement better controls on how you reestablish identity once you've lost access.
Wouldn't the hacker still need the temporary password AND the Google Authenticator code? Or are you assuming that the customer support people could and would turn off two-factor auth while resetting the password?
Yes I'm assuming I call a company having lost all access. Would a company have a different way of establishing identity for someone who lost all access if they've implemented TFA?
Que the "Apple locked me out of my OWN DATA!" screed in 3, 2, ...