first reported by MacRumors, Apple will now send iCloud users an email whenever they (or someone purporting to be them) log into iCloud.com via a Web browser. This seems to happen even if the browser and computer in question are ones that a user has previously logged in with. Apple’s email advises users to change their Apple ID password if they believe someone else is accessing their account. (As an additional tool, iCloud’s Web interface does provide the ability to log out every currently logged in browser in its Account Settings > Advanced.)
Granted, in my brief test, the email arrived ten minutes after I logged in, which could still give an interloper plenty of time to do some damage. Currently iCloud’s Web interface does not have the option to
require two-step authentication when logging into your account.
Given the broad publicity over this security issue, it seems likely Apple will take at least some time at Tuesday’s event to respond and potentially discuss what measures are being taken to ensure the security of its users. No doubt the company hopes that this incident won’t overshadow what most assume to be the launch of the next iPhone.
Dan has been writing about all things Apple since 2006, when he first started contributing to the MacUser blog. He's a prolific podcaster and the author of the Galactic Cold War series, including his latest, The Nova Incident.