It's not an either/or situation – it's both. And more.
The journalist was negligent in not having backups. (And he should know better.)
He was victimized by the culprit who was able to engineer through the auth protocols. (Not the victim's fault.)
Apple's authentication protocol was apparently deficient. The other auth protocols required by the other companies may not be sufficient either.
There is some good content to study in all the authentication cross-linking he had established across the various domains, which made it easy for the culprit to attack once he owned one of the accounts in one of the domains. This could have been – as in,
might have been or might not have been - solved with multi factor authentication, but may have required coordination between the commercial entities governing the domains. (And good luck with that, given how much they compete, argue, disagree with and sue
each other.) It might also have been solved by the victim if he had refused to do the cross linking and instead kept independent authenticators for each set of domain accounts.
__________________________________________________________________________
This email message is for the sole use of the intended recipient(s) and
may contain confidential information. Any unauthorized review, use,
disclosure or distribution is prohibited. If you are not the intended
recipient, please contact the sender by reply email and destroy all copies
of the original message.
|