Even if Apple fix the account recovery process, the fact that any flaw in iCloud security could easily lead to all attached devices getting remotely wiped is extremely scary. All of your work gone in moments!
Don't get me wrong, remote wipes are useful. But they should be protected by some kind of a "Remote Wipe Authorization Passphrase" that the user must set up. Otherwise we are all simply at the mercy of the next access control vulnerability in iCloud.
I disagree. The onus is entirely on the user to backup his/her data.
Don't use remote wipe unless you have a backup solution. I mean seriously, the very concept of remote wiping, whether intended or not, should make you buy an external hard drive and activate Time Machine. Because a remote wipe could happen in a database-server glitch on Apple's part, which would presumably bypass a passphrase mechanism. So why leave your data to chance?
But the other reason to not have a passphrase...what is the purpose of having a remote wipe? Because you are paranoid that ot only someone will steal your laptop, but that they'll steal the data. Depending on your work situation, time could be the main factor here. What happens if you forget your passphrase...because really, how often are you going to be using that passphrase? Then you've given your robber minutes/hours to access your data.
Just to be clear, the verification process is still incredibly flawed on Apple's part, and the remote-wipe problem should not have happened in the first place. But enabling any kind of remote-wipe-power without thinking through the backup process is Honan's fault, as he admits in his article.
As long as you keep your data on your own machine, it is your responsibility to back it up. In the cloud, it's different though. The average user now expects the service provider to be responsible for keeping their cat pictures secure, warm and cozy.
And in the same way that users don't accept that hitting a delete button deletes their content - there are tons of complaints on such issues - they won't accept that remote wipe effectively rids them of all their cat pictures.
I see where you're going and every tech person should definitely keep a backup. Then again every tech person should be aware of how the cloud can fail and how putting your life into the cloud can fail you. However, the above is sadly true for Mr. John User, who has no idea what the cloud actually is, he justs wants his things synchronized between his devices. The act of paying for a services raises expectations, and data integrity as well as permanency is probably part of those expectations.
I don't agree. You should have backups regardless and the odds of your laptop drive just gives up or it falls to the floor or gets stolen should, in any universe, be way more probable (regardless of usage) than a "database-server glitch" on Apple's part.
Yes, you should backup but for way more important reasons than enabling remote wiping.
No argument there...but I'm just saying, remote wipe does what it does. Is there any consumer out there who enables it without realizing that it indeed allows the destruction of your device's data from "the cloud"? I assume that the average consumer is sufficiently paranoid about these kinds of technologies going awry...a database-server glitch is improbable, but don't you think the average consumer assumes otherwise?
Apparently remote wipe is enabled by a little innocent-sounding checkbox labelled "Enable Find My Mac", so consumers have almost certainly enabled it without realising that it allows their data to be wiped by a poorly-secured cloud system.
Don't get me wrong, remote wipes are useful. But they should be protected by some kind of a "Remote Wipe Authorization Passphrase" that the user must set up. Otherwise we are all simply at the mercy of the next access control vulnerability in iCloud.