Hacker News new | ask | show | jobs
by nwh 4301 days ago
2FA does not protect iCloud data at all, it would have done nothing here.
1 comments

My understanding is it just doesn't protect iCloud backups, which is what were compromised here - also why things deleted from the phone were still in the cloud.
That's mine too, an iCloud backup is pretty much keys to the kingdom. Could also just have been that they had access for a very long time and downloaded data multiple times in that period without being detected.