Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

11–20 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#11

Earlier quoted context omitted.

System Preferences - iCloud - Find My Mac (remove the checkmark)

Is there any way to remove the wiping bit without removing the whole finding functionality? That bit is extremely useful, and if a hacker managed to get into my iCloud I wouldn't be that worried about them being able to locate it. But being able to wipe everything as well is a different matter.

IIRC it does the wipe via the recovery boot, so wiping that partition would kill it.

BUT: you'd be hosed if you ever needed recovery, you wouldn't be able to use full-disk encryption, and there's likely other bits of the OS that would break in subtle and interesting ways without it there. Tread _very_ carefully.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#12
To connect or not to connect? I have been debating the advantages and disadvantages of coupling both personal and work IT systems for some time now. If you tie your IT systems together, you can manage them more easily and efficiently. On the other hand, as in Mat's case, a single node failure can cause an entire system to collapse. For another example, consider fully automatic self-updating servers. Without safe-guards, a configuration bug can bring them all down within minutes. At this point, I think some coupling, but not total coupling, is best. Too little coupling won't allow enough productivity; too much increases your risk of system-wide failure.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#14

Earlier quoted context omitted.

From iCloud's ToS, it looks like it'd depend on whether a court finds this to be either "failure to use reasonable skill and due care" or "gross negligence": APPLE SHALL USE REASONABLE SKILL AND DUE CARE IN PROVIDING THE SERVICE. THE FOLLOWING LIMITATIONS DO NOT APPLY IN RESPECT OF LOSS RESULTING FROM (A) APPLE'S FAILURE TO USE REASONABLE SKILL AND DUE CARE; (B) APPLE'S GROSS NEGLIGENCE, WILFUL MISCONDUCT OR FRAUD; O…

Just because a clause is in a contract, doesn't mean it has any effect. A lot of terms are flat out bluffing to scare off folk like you. This is why it is always a good investment to ask your lawyer.

This is really, really important advice, and if more people understood it, corporations would have a lot less power over people than they currently do. You can open up just about any ToS and find a handful of unenforceable clauses they're hoping you won't realize are unenforceable.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#15
It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that.

Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and then fake a phone call where you pretend to convince that CSR that you are that person. The person will get fired, but probably won't go to jail unless they can prove collusion. And then they can either find a new job, or depending on which country the person is living in, they can live nicely off of the money for a while.

I'm not sure how to solve this problem, except by having highly paid and specially trained CSRs that do the account resetting, or by never allowing resetting ever, and if you forget your password and your security questions, you're SOL.

I have to admit this only makes me more leery of putting anything on cloud storage, although my own personal data is pretty useless to anyone, which is my only saving grace. Others who are more important might need to think twice about relying on these types of services.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#16

Earlier quoted context omitted.

Is there any way to remove the wiping bit without removing the whole finding functionality? That bit is extremely useful, and if a hacker managed to get into my iCloud I wouldn't be that worried about them being able to locate it. But being able to wipe everything as well is a different matter.

IIRC it does the wipe via the recovery boot, so wiping that partition would kill it. BUT: you'd be hosed if you ever needed recovery, you wouldn't be able to use full-disk encryption, and there's likely other bits of the OS that would break in subtle and interesting ways without it there. Tread _very_ carefully.

As long as you have a recovery USB, you'll be fine.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#17

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Maybe this is a great reason to stick with Google's cloud services.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#18

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I once had to reset the password of my stock trading account.

All they needed for verification was my home address.

I am also pretty leery of putting anything online.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#19

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#20
Are they saying Apple sent the password reset request to a different backup email entirely? Or that they reset the password to a requested password while one the phone?

Even if someone had properly identified themselves as Mat Honan, neither of these should be permitted.

Post reply on HN