The hour a hacker deleted a man's life

In August 2012, the technology writer Mat Honan watched his digital life end in the time it takes to eat lunch. First his iPhone went blank and asked to be set up like new. Then his iPad. Then his MacBook, mid-sentence, wiped clean — and with it the only copies of the first year of his daughter's photographs.
He hadn't been "hacked" the way movies show it. Nobody cracked his password. Instead, an attacker called Amazon and talked his way into the last four digits of Honan's credit card, then called Apple support and used those same four digits to prove he was Honan. One conversation unlocked the next. Within minutes he owned Honan's email — and email is the master key: reset one account, and it hands you the rest.
The whole collapse turned on a single missing thing. Honan had no second step — no code from an app, no physical key — standing between his password and his life. A password is a secret, and secrets leak, get guessed, get talked out of a call-center employee. A second factor is different: it's a thing you physically hold, and a stranger three time zones away simply cannot hold it.
Microsoft's engineers later studied billions of break-in attempts and found that turning on that second step blocks more than 99.9% of automated account takeovers. Few numbers in security are that lopsided.
The setup takes an afternoon. An authenticator app or a small hardware key on your email and money accounts, once, and the daisy chain that ended Honan's day can't even start. The wall you already have finally gets the second wall it was always missing.
Honan got some of his data back, eventually, after pleading with Apple and hiring a recovery firm. Most people don't get the second chance. The lock on your front door is fine. It's just that, right now, it's the only one.
