Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked.
Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com."
I don't know for sure whether that's true or not. But assume it is true. If two-factor authentication had been enabled, then the hackers would have had a much harder time guessing Mat's email address for iCloud and whether he had a @me.com email address at all.
I have two-factor authentication turned on and I can see this much (in a different web browser) without entering anything: "Choose how to get back into your account. Get a password reset link at my recovery email: uch•••••••@c••••.com"
The problem may be that "me.com" is so short that Google might display the full domain name. If that's the case, Google should fix it.
"Hackers would have had a much harder time"? No: mhonan@gmail.com mhonan@me.com
Gmail was not really needed to guess the name at @me.com.
Moreover, in his case, it seems he would be better off not having the secondary e-mail address for recovery at Google. It turned out to be anti-security measure.
It's not the mhonan part the would've been hard to guess but the @me.com. A secondary email account could be anything. It could also very well not be enabled. Knowing that it is enabled and that is an @me was definitely something that helped the attackers.
I disagree. I think most iCloud users (%80 of iOS users by Apple's count) have @me addresses when they upgraded to iOS 5 or Lion. I can use both my @gmail.com and my @me.com in App Store to purchase, or to login to icloud.com.
Comments
Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked.
Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com."
I don't know for sure whether that's true or not. But assume it is true. If two-factor authentication had been enabled, then the hackers would have had a much harder time guessing Mat's email address for iCloud and whether he had a @me.com email address at all.
I have two-factor authentication turned on and I can see this much (in a different web browser) without entering anything: "Choose how to get back into your account. Get a password reset link at my recovery email: uch•••••••@c••••.com"
The problem may be that "me.com" is so short that Google might display the full domain name. If that's the case, Google should fix it.
"Hackers would have had a much harder time"? No: mhonan@gmail.com mhonan@me.com
Gmail was not really needed to guess the name at @me.com.
Moreover, in his case, it seems he would be better off not having the secondary e-mail address for recovery at Google. It turned out to be anti-security measure.
It's not the mhonan part the would've been hard to guess but the @me.com. A secondary email account could be anything. It could also very well not be enabled. Knowing that it is enabled and that is an @me was definitely something that helped the attackers.
> ..whether he had a @me.com email address at all
I disagree. I think most iCloud users (%80 of iOS users by Apple's count) have @me addresses when they upgraded to iOS 5 or Lion. I can use both my @gmail.com and my @me.com in App Store to purchase, or to login to icloud.com.