Latest news
The option is currently available only to users based in the US, UK, Australia, Ireland, and New Zealand, and is definitely an improvement over the previous additional protection mechanism that included security questions.

Users can set up the feature in the "Password and Security" settings in their Apple accounts, and will be required to add (if they haven't already) the number of the phone(s) to which Apple will be sending the verification code.
They will also be given a recovery key to use in case they lose the device or forget their password, and are advised not to store it on the device or computer in case they are compromised.
Apple has also decided to prevent their support personnel falling for social engineering attacks such as those that led to the unfortunate compromise and trashing of Mat Honan's Twitter, Google and iCloud accounts by making it impossible for anyone but the account owner to reset their password, manage their trusted devices, or create a new recovery key once 2-step verification is turned on.
"You must be responsible for remembering your password, keeping your trusted devices physically secure, and keeping your Recovery Key in a safe place," the Apple FAQ page additionally warns. "If you lose access to two of these three items at the same time, you could be locked out of your Apple ID account permanently."

Follow @zeljkazorz


Spotlight

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






