ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    With iOS 9 Apple Gets Serious On Security

    News
    ios 9 inforworld apple security
    5
    7
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • mlnewsM
      mlnews
      last edited by

      Security is a major focus in Apple's recent release of iOS 9.

      1 Reply Last reply Reply Quote 2
      • DashrenderD
        Dashrender
        last edited by

        Despite Apple touting the system as two-factor authentication for iCloud, this is really a two-step verification method for Apple ID. There is no second factor -- such as a physical token or biometric identifier -- to authenticate users.

        Is that right? I thought something you know (password) and something you have, and another preconfigured device or phone number (phone most likely device) would qualify as two factor.

        scottalanmillerS 1 Reply Last reply Reply Quote 1
        • DustinB3403D
          DustinB3403
          last edited by

          If I were going to steal an apple device, I would happily enter 10 incorrect passwords just to wipe the device.

          Shrink wrap it, and sell it on craigslist for a few hundred bucks. The best security addition that Apple added was the functionality to not wipe the iCloud account at a system reset, requiring the correct username / password to continue with the setup.

          This combined with Find My iPhone and tools like Meraki make it very difficult for a device to actually walk away.

          6 Digit pass-codes are only a minimalist approach to attempt securing their devices.

          JaredBuschJ 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            Exactly - if you really want to cut down on theft, you need to remove the thief's ability to get any value from the device after they steal it, both in the form of data on the device and reselling the device.

            I didn't know they added that piece about locking the phone to a specific iCloud account regardless of data wipe - that's pretty cool, sounds basically like a type of lojack.

            1 Reply Last reply Reply Quote 1
            • scottalanmillerS
              scottalanmiller @Dashrender
              last edited by

              @Dashrender said:

              Despite Apple touting the system as two-factor authentication for iCloud, this is really a two-step verification method for Apple ID. There is no second factor -- such as a physical token or biometric identifier -- to authenticate users.

              Is that right? I thought something you know (password) and something you have, and another preconfigured device or phone number (phone most likely device) would qualify as two factor.

              Seems as much or more two factor as most of the two factor systems out there.

              1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch @DustinB3403
                last edited by

                @DustinB3403 said:

                6 Digit pass-codes are only a minimalist approach to attempt securing their devices.

                It is better than 4 by a long shot and the cries if they forced users to switch from the simple code to alphanumeric would be immense

                scottalanmillerS 1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller @JaredBusch
                  last edited by

                  @JaredBusch said:

                  @DustinB3403 said:

                  6 Digit pass-codes are only a minimalist approach to attempt securing their devices.

                  It is better than 4 by a long shot and the cries if they forced users to switch from the simple code to alphanumeric would be immense

                  And there isn't any RDP type access to these devices where that access can be attempted remotely. That's a physical input device with a ten attempt limit. It's far more secure than the same thing on an SSH password, for example. I think that people are thinking of it in terms of different types of security.

                  1 Reply Last reply Reply Quote 0
                  • 1 / 1
                  • First post
                    Last post