{"id":21229,"date":"2023-02-14T10:30:05","date_gmt":"2023-02-14T18:30:05","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2023\/02\/14\/news-14961\/"},"modified":"2023-02-14T10:30:05","modified_gmt":"2023-02-14T18:30:05","slug":"news-14961","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2023\/02\/14\/news-14961\/","title":{"rendered":"How to use Apple\u2019s advanced iCloud security tools"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2021\/06\/17\/10\/icloud-wwdc-100892657-small.jpg\"\/><\/p>\n<p>Apple <a href=\"https:\/\/www.computerworld.com\/article\/3682889\/apple-sets-a-security-challenge-for-2023.html\">recently rolled out new iCloud security features<\/a> that could help protect mobile professionals when they&#8217;re on the road. The features include better iCloud data security, improved iMessage security, and more.<\/p>\n<p>Here is how to use these new iCloud protections.<\/p>\n<p>No one should doubt that protecting personal or enterprise data has become more important than ever. Apple introduced <a href=\"https:\/\/www.applemust.com\/how-to-use-lockdown-mode-on-your-iphone-ipad-and-mac\/\" rel=\"nofollow noopener\" target=\"_blank\">Lockdown Mode<\/a> for iCloud in 2022, following this up with <a href=\"https:\/\/www.applemust.com\/apple-adds-trio-of-powerful-personal-security-tools-to-protect-your-cloud\/\" rel=\"nofollow noopener\" target=\"_blank\">even more protections<\/a> in December and, most recently, introducing <a href=\"https:\/\/www.computerworld.com\/article\/3686269\/apple-marks-data-privacy-week-with-in-store-privacy-training-more.html\">free privacy and security sessions<\/a> in Apple retail stores in 2023.<\/p>\n<p>The December collection of iCloud privacy protection tools include:<\/p>\n<p>What do they do, and how do you use them?<\/p>\n<p>Apple has always encrypted <em>some<\/em> of the information you store in iCloud to protect it from prying eyes. With the introduction of iOS 16.3 and macOS 13.2, it locked things down even further, protecting more categories of information and making it possible to decrypt that data only on trusted devices. The caveat emptor is that once you put <a href=\"https:\/\/support.apple.com\/en-gb\/HT202303\" rel=\"noopener nofollow\" target=\"_blank\">Advanced Data Protection for iCloud<\/a> in place, you must also set up an alternate recovery method (device passcode, recovery contact or recovery key) in case you lose access to your account, as Apple cannot help you when you enable protection at this level.<\/p>\n<p>Advanced Data Protection for iCloud encrypts the following additional sets of data that are not otherwise protected: Device backups, Messages backups, iCloud Drive, Photos, Notes, Siri Shortcuts, Safari Bookmarks, Reminders, Voice Memos, and Wallet Passes. These join the 14 categories of data iCloud has always encrypted, including Keychain and Health data.<\/p>\n<p>Mail, Contact, and Calendar remain unprotected, as they need to interoperate with other systems<\/p>\n<p>iMessages between Apple users have always been end-to-end encrypted, making it very difficult for man-in-the-middle attacks of message surveillance, as without the decryption cipher messages are gibberish until decoded. It isn\u2019t impossible to decode these messages, of course, but it is very complex, expensive, and most people don\u2019t need to worry about being targeted in such a way.<\/p>\n<p>But some do. Think about journalists, human rights activists, high-value business users, ministers, and others whose communications may have significant importance.<\/p>\n<p>iMessage Contact Key Verification is for just these users. It will alert them if it suspects a messaging session is being spied on. The feature also offers users the chance to compare a Contact Verification Code in person, on FaceTime, or through another secure call.<\/p>\n<p>Deyails on this feature are not yet available. It\u2019s possible it will be enabled in System Settings&gt;Password &amp; Security, where a setting will be added.<\/p>\n<p>Some of the most secure entities in business or government use hardware-based security keys to protect critical services, data, or access to information. As <em>Computerworld <\/em>readers likely know, these consist of actual hardware, a dongle, that acts as the key. It basically has a unique identifier and contains a digital cryptographic key required to open the account. When this kind of protection is in place, a user must be in possession of the key, physically connected to the system they wish to use, and must enter a passcode.<\/p>\n<p>That level of protection is now available to iCloud and means users must have both a hardware key and passcode to access data protected by their Apple ID. <a href=\"https:\/\/support.apple.com\/en-gb\/HT213154\" rel=\"nofollow noopener\" target=\"_blank\">Apple explains it as an optional feature<\/a> designed particularly for high-value targets who need additional protection against phishing or social engineering attacks.<\/p>\n<p>If you enable this feature, two things happen: The first is that each time you access your account, you will need your security key to complete the process; the second is that as you try to set up a new device, you\u2019ll no longer receive a 2FA code to authorize access; instead you\u2019ll need to use your key. This makes you more secure, as it means others cannot try to phish you or use stolen devices to access your account, and it means you won\u2019t have to use sometimes insecure SMS messages.<\/p>\n<p>The bad thing?<\/p>\n<p>If you lose your key, things will get weird. (Apple will require you to set up two FIDO Certified keys to use this service, the idea being that you keep one as a spare. You may link up to six keys to your account). You also need to enable 2FA on your account, and to sign into devices like Apple Watch or HomePod you also need an iPhone or iPad that supports the key.<\/p>\n<p>In other words, while the protection is robust, you must really want to use it.<\/p>\n<p>There are other limitations, too \u2014 you won\u2019t be able to use <a href=\"https:\/\/www.computerworld.com\/article\/3402080\/icloud-for-windows-what-is-it-and-how-do-you-use-it.html\">iCloud for Windows<\/a>, won\u2019t be able to sign into older devices and the protection doesn\u2019t work with Managed Apple IDs. That last limitation may be a deal breaker for any company that relies on managed environments.<\/p>\n<p>Apple has a tech note explaining more information about how to use these keys; it&#8217;s\u00a0<a href=\"https:\/\/support.apple.com\/en-gb\/guide\/mac-help\/mchld6920426\/mac\" rel=\"nofollow noopener\" target=\"_blank\">available here<\/a>.<\/p>\n<p><em>Please follow me on\u00a0<a href=\"https:\/\/social.vivaldi.net\/@jonnyevans\" rel=\"nofollow noopener\" target=\"_blank\">Mastodon<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<\/em><a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\"><em>Apple<\/em>\u00a0<em>Discussions<\/em><\/a><em>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3687636\/how-to-use-apples-advanced-icloud-security-tools.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/idge\/imported\/imageapi\/2021\/06\/17\/10\/icloud-wwdc-100892657-small.jpg\"\/><\/p>\n<article>\n<section class=\"page\">\n<p>Apple <a href=\"https:\/\/www.computerworld.com\/article\/3682889\/apple-sets-a-security-challenge-for-2023.html\">recently rolled out new iCloud security features<\/a> that could help protect mobile professionals when they&#8217;re on the road. The features include better iCloud data security, improved iMessage security, and more.<\/p>\n<p>Here is how to use these new iCloud protections.<\/p>\n<h2><strong>Secure your digital assets<\/strong><\/h2>\n<p>No one should doubt that protecting personal or enterprise data has become more important than ever. Apple introduced <a href=\"https:\/\/www.applemust.com\/how-to-use-lockdown-mode-on-your-iphone-ipad-and-mac\/\" rel=\"nofollow noopener\" target=\"_blank\">Lockdown Mode<\/a> for iCloud in 2022, following this up with <a href=\"https:\/\/www.applemust.com\/apple-adds-trio-of-powerful-personal-security-tools-to-protect-your-cloud\/\" rel=\"nofollow noopener\" target=\"_blank\">even more protections<\/a> in December and, most recently, introducing <a href=\"https:\/\/www.computerworld.com\/article\/3686269\/apple-marks-data-privacy-week-with-in-store-privacy-training-more.html\">free privacy and security sessions<\/a> in Apple retail stores in 2023.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3687636\/how-to-use-apples-advanced-icloud-security-tools.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,11064,10480,10403,10554,714,24580],"class_list":["post-21229","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-cloud-computing","tag-ios","tag-macos","tag-mobile","tag-security","tag-small-and-medium-business"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21229","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21229"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21229\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}