I got hacked, lost crypto and what it says about Apple’s security. Part 1
1–10 of 60 posts
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#2They haven't learned any lesson, either. Their advice after this? Turn your laptop off when you're not using it (useless) and use Google Voice for 2FA. This is worse than useless; this is actively bad advice and you should not follow it.
The average user should install 1Password and use a TOTP application. Anyone can learn to do that, and it's really all you need. More advanced users, those with particularly extreme security needs, and pedantic nerds can use YubiKeys, hardware wallets, self-hosted password vaults, PGP-encrypted backup codes, and other measures that are worth considering, but aren't as approachable for everyone.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#3So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#4So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#5I stopped using Chrome but now realize I never thought to check into what it has saved for me. I’ll have to check into that and erase it all if I can.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#6Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#7Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#8So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Why are 3rd party password stores like 1Password better than Apple’s Keychain or Google’s password store?
There is no sign that the attacker had a keylogger on the user's laptops, for extracting passwords. If they did, they wouldn't have needed to do account recovery on all these accounts. So the master password of a traditional password manager would not have been compromised.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#9So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#10So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
For any significant bitcoin amounts I would buy some cheap laptop and use it as offline storage without ever connecting it to anything. I don't trust hardware wallets because they are an obvious target for attacks, but one can't attack offline computer.
Cheap laptop might not have redundancy, so if your SSD dies, you might be in for a rough ride. Best case, you can recover your wallet, worst case you're SOL.