Live data from Hacker News

Apple Adds Two-Step Verification to iCloud and Apple ID

appleid.apple.com

41–50 of 51 posts

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#41

Earlier quoted context omitted.

The process forced me to update my password to use their new password requirements which then forced me to wait 3 days. I'm pretty sure my old password was secure but it didn't meet all of the new standards. Kind of annoying.

I was not prompted to update my password (and had long ago set up security questions), and was able to set up 2-factor immediately.

Your password must have already met their new "security requirements", mine did not.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#42

Argh! Incredibly annoying edge case! I'm in Poland, but have all my language settings set to English, and the only country codes for receiving SMSs are those of English-speaking countries! Can't see any easy way to change my language on the page. How annoying!

Yeah, they havent done a good job of localising this. In Australia it asks for an 'area code' as well has my phone number for my mobile phone. How can a MOBILE phone have an area code (in Australia, area codes are per state).

Now, I know that technically the area code for ALL mobile phone numbers is 04, so I split that up. Nope, SMS never arrives. Next I removed the leading zero from the area code so it would be formatted as +61 4 xxxx xxxx.

Those who are familiar with Telcos and the way phone numbers work internationally would eventually stumble onto the right solution. Still pretty shocking though.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#43
post #16
post #12

Apple has done a great job walking users through this process. Setting up "trusted devices" (iPhone, iPad, etc.) works really well: Apple already knows which devices you own, so all you have to do is select the device and you get an instant push notification to unlock to see the verification code. Apple gives you a backup recovery code with very clear instructions to print/write it somewhere safe. They require you to…

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

I haven't used Apple's system, so I can't comment on it. However, Google's system has a few gaping holes that make it far from effective from a usability standpoint.

First: A large number of Google's web applications still rely on application specific passwords. This was understandable a year or so ago, but still? It's getting very tiring generating an application specific password for some Google applications.

This brings me to my next point: the use of application specific passwords has been made complicated than what's required. When confronted with a page that asks me for an application specific password, it takes too long to navigate to the correct page so that I can generate an application specific password.

Thirdly, I can't change the name that I give to an application specific password. Discovered that you have a new installation of Chrome on a VM and want to create a password for that? Too bad: you can't rename the existing password so that you can distinguish the two easily.

Lastly: Have you checked out the mess that's the management page for it? It's extremely confronting. It takes a bit of getting used to. In-fact, until very recently it was rather buggy. For instance: the page used to have a date which showed when an application specific password was last used. This date always had the year 1970. Who lets these kind of bugs through??

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#44
post #32

Earlier quoted context omitted.

Why do you find this more friendly than Google Authenticator? Just because it pushes rather than requiring the user to open an app? Can you still manually get a code, in case you lack network (& don't want to break out the backup code)? What if you're actually logging in with the iDevice, does it just automatically allow it without asking?

> Why do you find this more friendly than Google Authenticator? Just because it pushes rather than requiring the user to open an app? Exactly. I have so many things in Google Authenticator that I have to scroll. The timer is also annoying -- sometimes you have to wait for a few seconds for the codes to refresh so you have enough time to type in the code. > Can you still manually get a code, in case you lack network (…

Fair enough.

> No, but for Apple you don't need to do this because you only need the code if you're accessing their website so you have to have internet access. I don't think I ever use the Google Authenticator without internet access.

At work, I have no cell service but can still use my laptop. I don't want to use their wifi with my phone due to proxy server setup hassles. So I think it's still a valid use case.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#45
In case anyone else changed their password to something absurdly long only to run into the same trouble I did:

Apple passwords have a max length of 32 characters.

Unfortunately, the change password page doesn't enforce this limit and will blissfully let you think you've changed your password to something that has 50 characters, but actually only stores 32.

Later, when you use a Password Manager that saved the full 50 characters, suddenly your password doesn't work.

Some Apple pages' login password fields cut off automatically at 32, which lets the pasted password work (as you can't paste more than 32), but this is not the case within iTunes itself or on the iPhone.

Solution: Apple needs to limit the new password entry fields on the My Apple ID -> Password and Security page to 32 characters. Or, alternatively, accept and store longer passwords. (as 32 characters is a bit tight if you're using a passphrase)

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#46
post #24
post #16

Earlier quoted context omitted.

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

Google's approach is more unix-y - it lets you shoot yourself in the foot. Requiring you to put your recovery code back in at least forces people to memorize or write it down. Now, Google does have a good seemingly automated recovery service (you need to share a lot about your account to prove you're you but it works) - I'd rather not have reason to use it, though.

Does nobody get the benefits of TOPA?

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#47
post #16

Earlier quoted context omitted.

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

I haven't used Apple's system, so I can't comment on it. However, Google's system has a few gaping holes that make it far from effective from a usability standpoint. First: A large number of Google's web applications still rely on application specific passwords. This was understandable a year or so ago, but still? It's getting very tiring generating an application specific password for some Google applications. This…

1) Yes, Google should move more of their apps to supporting this, but looking at only Google services is missing the point. Google Authenticator's TOPA is based on an open standard, so any third party can work with it too (and many do,Dropbox, Lastpass, Drupal, App.net, Dreamhost..."

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#48
post #16

Earlier quoted context omitted.

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

I haven't used Apple's system, so I can't comment on it. However, Google's system has a few gaping holes that make it far from effective from a usability standpoint. First: A large number of Google's web applications still rely on application specific passwords. This was understandable a year or so ago, but still? It's getting very tiring generating an application specific password for some Google applications. This…

2) I agree the UI could be much better. On the plus side, you only have to navigate it once per application.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#49
post #16

Earlier quoted context omitted.

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

I haven't used Apple's system, so I can't comment on it. However, Google's system has a few gaping holes that make it far from effective from a usability standpoint. First: A large number of Google's web applications still rely on application specific passwords. This was understandable a year or so ago, but still? It's getting very tiring generating an application specific password for some Google applications. This…

3) I haven't run in to this problem, but as you can imagine, NOT being able to change it provides a number of benefits from a security standpoint, and if you do want to change it, it is just a matter of creating a new one and deleting the old one. I should think that'd be good enough for anyone.

Re: Apple Adds Two-Step Verification to iCloud and Apple ID

#50
post #16

Earlier quoted context omitted.

I actually found Google Authenticator just as good on the user experience side, with the added benefit of being far more effective.

I haven't used Apple's system, so I can't comment on it. However, Google's system has a few gaping holes that make it far from effective from a usability standpoint. First: A large number of Google's web applications still rely on application specific passwords. This was understandable a year or so ago, but still? It's getting very tiring generating an application specific password for some Google applications. This…

4) I've never seen the 1970 bug. How odd.
Post reply on HN