Apple makes 2FA mandatory for boss developers

By

Better late than never, and you’ve got a week to make this happen.

Apple has announced that from February 27, 2019, two-factor authentication (2FA) will be compulsory for boss developers.

Apple makes 2FA mandatory for boss developers

“In an effort to keep accounts more secure, developers with the Account Holder role in a developer program will need to enable two-factor authentication to sign in to their Apple Developer account and Certificates, Identifiers & Profiles,” the company announced today.

Apple’s announcement was typically brief, so offers no information about why it’s added the requirement. But it is not hard to surmise the reasons: as explained here, the Account Holder role has powers that even Admins don’t possess, including the ability to create and revoke distribution certificates with which apps are signed.

Gaining access to an Account Holder’s account is therefore a ticket to potential App Store mass-scale mischief and mayhem for miscreants. 2FA will reduce the likelihood of that happening.

The indecent haste of the new policy’s introduction is a case of better late than never: Account Holder creds are surely a known target for attackers and the lack of 2FA makes them vulnerable.

You’d hope that folks with Account Holder status would understand the need for strong passwords, but a myriad incidents show it’s seldom hard to find someone who thinks an attack would never happen them …

Account Holders will need a device running iOS, or a Mac running OS X El Capitan or later, as their second source of authentication.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Victoria's Secret pulls down website amid security incident

Victoria's Secret pulls down website amid security incident

Log In

  |  Forgot your password?