Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

31–40 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#32
post #19

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Here is the list; You tell me.

Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did.

---------------------------------

What was the first car you owned?

Who was your first teacher?

What was the first album you owned?

Where was your first job?

In which city were you first kissed?

---

Which of the cars you’ve owned has been your favorite?

Who was your favourite teacher?

What was the first concert you attended?

Where was your favourite job?

Who was your best childhood friend?

---

Which of the cars you’ve owned has been your least favorite?

Who was your least favourite teacher?

Where was your least favourite job?

In which city did your mother and father meet?

Where were you on January 1, 2000?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#33

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? Apple didn't send a text message to his number-on-file? They didn't try a callback? Were there any challenge-response questions at all?

That's absurd.

This should make every iCloud user reeeeeaally nervous.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem

It's easily solved, banks and other institutions have been doing it for years.

The solution is trivial, too: Require physical ID.

In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent).

Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#35
post #25
post #17

Earlier quoted context omitted.

Maybe this is a great reason to stick with Google's cloud services.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

Google isnt susceptible to this kind of social engineering attack.

It requires the existence of a customer service in the first place. Good luck trying to call Google.

There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy.

Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother anything to secure it.

Microsoft and Google still have a zero incident record. After all this time. They even went beyond their own responsibility many times, getting police involved because they suspected targetted (political) malware.

And no, in the world of formal discrete systems (computers) there are provable correct, and provably incorrect solutions. For example: DRM can always be hacked, but we can secure ourselves from the middlemen.

Any analog with a "door" deserves only ridicule.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#36
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

If I got veeti's joke then I think what he was trying to say was that it's nearly impossible to get Google on the phone unless you're a corporate customer. If I didn't get his joke then I'm making it now. joke

joke's on me then :)

But back to my point social engineering doesn't require voice. you can do it via email just as easily.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#37
post #27

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure. Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE. This is almost as silly as credit card…

As I've said elsewhere: "Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did."

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#38

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Whoa, wait, what? What occured was a simple confidence hack, not some industrial spy escapade. Anyway, to answer your initial point, two factor authentication helps with this problem, as you have to still have the security token to authenticate. And if the "Something you have" gets stolen, then you need a manager to work through it to get you set up again, and all resets are heavily monitored and audited.

My point wasn't that this particular incident was some great case of industrial espionage. But it's a rather easy slippery slope to that outcome.

But what if your website is secured behind an Amazon EC2 or Linode CSR? Isn't Instagram and Netflix run at least in part on EC2? I have no clue what the security schemes are for either of those service providers, but if they allow CSRs to change passwords, then it's the same thing. If the CSRs can be paid off, or fooled over a phone call, then it might be cheaper to just do that if they want to inflict potentially millions of dollars worth of damage to a rival.

Having the security of your entire business behind a single CSR or a cell phone is the equivalent of millions of dollars worth of Cisco firewalls being outdone by a $20 wifi-router plugged into the internal network.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#39
post #24

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Perhaps what they need here is an optional 24-hour password reset delay. A user could only adjust this setting when properly logged in. Even if Apple gets social engineered, the user has 24 hours to notice the difference. Although it's extremely inconvenient to wait 1 full day to get back in, forgetting a password should be a rare circumstance .

No. They just need to implement one of the common protocols. For example, they could just require ID.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#40
post #27

Earlier quoted context omitted.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure. Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE. This is almost as silly as credit card…

As I've said elsewhere: "Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did."

Based on my experience, that's not how it works at all in practice. They will ask these info about your real identity as recorded in their CRM systems. I doubt you can list your name as BLAH BLAH BLAH there and still receive your package delivered correctly.
Post reply on HN