Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

21–30 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#21

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

This _could_ be a lesson in not trusting cloud services where issues can be resolved by human intermediaries. Sounds a bit counter-intuitive but to me a bit more reassuring. But I could be wrong.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#22

I hope he sues Apple for this and wins, behavior like this shouldn't be allowed without consequences.

I hope he sues Apple too. Not because I want any harm to come to Apple, but because I want Apple to have a significant financial incentive to push authorities to track down the villain.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#23
post #20

Are they saying Apple sent the password reset request to a different backup email entirely? Or that they reset the password to a requested password while one the phone? Even if someone had properly identified themselves as Mat Honan, neither of these should be permitted.

Mat posted a screenshot of his Gmail inbox which showed an email about Apple's password reset. So I'm guessing the hackers had compromised Gmail account BEFORE they called up Apple tech support. Or maybe that email was just an attempt and didn't help anyway with the actual password retrieval. I'm confused about this...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#24

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Perhaps what they need here is an optional 24-hour password reset delay. A user could only adjust this setting when properly logged in. Even if Apple gets social engineered, the user has 24 hours to notice the difference.

Although it's extremely inconvenient to wait 1 full day to get back in, forgetting a password should be a rare circumstance .

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#25
post #17

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Maybe this is a great reason to stick with Google's cloud services.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain.

Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for Microsoft, Sony and, yes, Google.

There's no magic solution other than being careful. And even with that security is always an illusion. Your door lock is easily opened, no matter how much money you put in it, the only thing preventing you from being robbed is that are more houses in your neighbourhood and that some of those could seem like an easier target.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#26
post #25
post #17

Earlier quoted context omitted.

Maybe this is a great reason to stick with Google's cloud services.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

If I got veeti's joke then I think what he was trying to say was that it's nearly impossible to get Google on the phone unless you're a corporate customer. If I didn't get his joke then I'm making it now. joke

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#27

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure.

Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE.

This is almost as silly as credit cards, where you are supposed to give the card number, card holder's name (not required most of the time), expire date, and the 3-digit PIN. Anyone who touches your card will have that information, once and forever. Yes, ANYONE, that includes your grocery store cashiers, your favorite bar tenders, your mobile phone billing representatives, etc. The list could go on very, very long.

And I'm totally amazed that both systems persist as a fallback plan in this digital world with countless attacking vectors.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#28

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Whoa, wait, what? What occured was a simple confidence hack, not some industrial spy escapade.

Anyway, to answer your initial point, two factor authentication helps with this problem, as you have to still have the security token to authenticate. And if the "Something you have" gets stolen, then you need a manager to work through it to get you set up again, and all resets are heavily monitored and audited.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#30
post #25
post #17

Earlier quoted context omitted.

Maybe this is a great reason to stick with Google's cloud services.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

I agree. If it's a random attack, then the probability is relatively low to get attacked. But if you're targeted, quite frankly it's probably very easy to attack you, either virtually or physically.

One thing I do know, though, is that like you said, security is likely going to get tightened across the board, and that means that it's going to get a lot more inconvenient for all of us. I guess that's a good thing, but it will definitely impact the usability of these services.

If it means that all vendors will tie their services to a two-factor authentication scheme linked to our phone, well that might just stop me from using the services altogether.

Post reply on HN