So this week has been a mess of iCloud headlines, and I'm not going to rehash the whole thing because if you have a pulse and an internet connection you already know what happened to a bunch of celebrities' photos. What I want to talk about instead is what I actually did about it, because "this is scary, everyone should use better security" is a sentence I've typed on this blog probably four times since 2011 and never once acted on myself. Saturday I finally sat down and fixed that, and it took way longer than it should have.
First stop was my Apple ID. Apple put out a statement on Tuesday saying the leaked photos weren't from some giant breach of iCloud itself, it was targeted attacks on individual accounts, guessed passwords and security questions and that kind of thing, and they pointed everyone toward two-step verification. Fine, good, I turned it on. Except here's the thing nobody's saying loudly enough: Apple's two-step verification, as it exists right now, does not cover iCloud backups or Photo Stream. It protects your Apple ID sign-in, account changes, and purchases. It does not put a second lock on the thing everyone's actually worried about. I had to read that three times before I believed it. So if you're doing this thinking you've closed the loophole that was in the news, you haven't, not entirely. Turn it on anyway, it's still better than nothing, just don't feel done.
Google was a much better experience and honestly kind of satisfying. I've had 2-step verification available on my account for ages and never bothered. This time I actually installed the Authenticator app instead of relying on SMS, because my carrier has this habit of delivering text codes about ninety seconds after I need them, which defeats the entire point. Scanned a QR code, done in about two minutes. I also grabbed Authy instead, mostly because it backs up your codes so you're not completely hosed if your phone dies, which is a real thing that happens to real people and not just a hypothetical some blog told you to worry about.
Dropbox took five minutes. Twitter took two. The one that actually annoyed me was my bank, which as far as I can tell still thinks "security question about your childhood pet" is cutting-edge technology in the year 2014. I called them. The person on the phone had clearly fielded this exact complaint all week and just sort of sighed at me.
A few things I'd tell past-me before starting this:
- Do it on a weekend, not a Tuesday night when you have somewhere to be. You will get locked out of something at least once and need your backup codes, and you will not remember where you saved them.
- Print the backup codes. Actually print them. Don't screenshot them into the same cloud photo library you're trying to protect, which I almost did before catching myself, which is embarrassing to admit but here we are.
- If a service offers an authenticator app option instead of SMS, take it. SMS-based codes are better than nothing but they're the weakest version of this and everyone in the security world has been saying so for a while now.
- LastPass Premium is twelve bucks a year and lets you use a YubiKey or the Google Authenticator app as your second factor for the vault itself, not just the individual sites. If you're not using a password manager at all yet, this whole week is as good a reason as any to start, and I say that as someone who resisted for two years because typing my own passwords felt faster. It's not, not once you've got dozens of accounts, and I do not have dozens of accounts on unique passwords, not yet anyway. That's this weekend's other project.
My friend Dev thinks I'm being paranoid about all this, he said something like "nobody's coming for your Steam account," and sure, probably not, but the annoying truth about security stuff is it's boring right up until the one day it isn't, and by then it's too late to be smug about it. Also apparently there's an Apple event invite going around for next Tuesday, so we'll see if any of this becomes more relevant than usual by the end of the week.
Anyway. Go turn on two-step verification on something today. Doesn't have to be everything. Start with email, since that's the account that can reset every other account if someone gets into it.