Showing posts with label 2fa. Show all posts
Showing posts with label 2fa. Show all posts

Friday, March 20, 2020

Authenticating with your Apple Watch

So, Apple added new security features to try to make your actions more secure but at the same time a bit more convenient.  If you decide that you want to do something in the Finder that requires additional permissions, they now display a helpful dialog.  Like, just today when I wanted to delete this 32-bit only detritus that got left when I upgraded to Catalina.

Up pops the dialog, waiting for approval...

... and look, there it is, on my wrist.




So, I'll just double-click that side button and...


Hmmm.  Do you think that perhaps Apple didn't consider that people might actually implement "security best practices"? Authenticating the current user doesn't mean you automatically get admin privileges, because people who are being safe don't log on as admin all the time.

Now, I'm not going to argue that "a non-administrator shouldn't be deleting things like this".  That's fine, it's why the regular dialog prompts for a username as well as a password.

I'm pointing out that every time that dialog displays now, my wrist twitches because Apple decided to make the watch beep and vibrate before asking for pointless validation.

And once again, it demonstrates that Apple's QA department and developers must all be logging on as administrators all the time.  That or they don't own Apple watches.

Sunday, January 26, 2020

Apple still don't understand what the 2 in 2FA is about

I've pointed this out before, but who knows, perhaps Catalina fixed it? (Spoiler: It didn't)

If you want to log into your account from a new device, Apple ask all your devices if it's ok. If one of them says OK, that's 2FA, right?


Missed my location by 1000km but you know, it's Australia, right.  It's just one state away - call it an off-by-one error. And they prompt for a code I could only get from one of the "known safe" devices, right?



Ok, so the two factors that I need are "My laptop is logged in" and "I know how to transpose numbers from one window to another" - obviously, hackers couldn't do that, could they?  What seriously was the point of this?

Apple, there is a sensible standard out here already.  Use regular TOTP, let people use 1Password or Google Authenticator or god forbid, implement the standard yourselves.  But what you have currently is a joke - please don't leave that stuff to the interns to implement.

How about focussing the next release more on security and less on making all the screen widgets look  good in the dark?