Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

41–50 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#41
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

I agree. If it's a random attack, then the probability is relatively low to get attacked. But if you're targeted, quite frankly it's probably very easy to attack you, either virtually or physically. One thing I do know, though, is that like you said, security is likely going to get tightened across the board, and that means that it's going to get a lot more inconvenient for all of us. I guess that's a good thing, but…

I think the services can be improved without becoming too annoying. Someone in this thread suggested a 24 hour delay, which seems reasonable. You could also send a "last call" email and text message to make sure the right user is the one that has requested the password change. Apple could easily separate Find my Mac from "wiping", or add a second password for that.

None of these will be 100% effective, but it will make things more difficult for attackers and not too uncomfortable for users.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#42
post #8

I hope he sues Apple for this and wins, behavior like this shouldn't be allowed without consequences.

I don't think I would label this horrible behavior on the part of Apple. When you provide customer service for something like iCloud things like these are bound to happen. This is a case of social engineering not some tech rep downloading plaintext passwords to a laptop and losing it. With a really targeted attack they are bound to be successful with some rep. Its a matter of when not if. Having said that they will i…

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex.

This reminds me of facebook and how all its employees were stalking people using the god password.

They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#43
post #27

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure. Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE. This is almost as silly as credit card…

The thing to remember here is that where the liability lies matters. The banks effectively take on all the liability for financial losses due to credit card fraud & they're free to setup their systems to constrain losses to a level that they're happy with. Yes, arguably not all the losses fall on the banks, particularly the hassle and time of recovering from a particular instance of fraud but the majority of them probably do and that's what matters because the interests of those who bear the losses and those who run the system are aligned.

The trouble with cloud systems is that all the losses fall on the end user who has no influence over the security systems put in place to protect their data. (Except with Google where you can at least choose to use 2-factor authentication.)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#44
post #19

Earlier quoted context omitted.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

That's why I always give a ten character random string as answers to those questions.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#45
post #35
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

From the article:

The backup email address on my Gmail account is that same .mac email address. At 4:52 PM, they sent a Gmail password recovery email to the .mac account.

Here Gmail was only as strong as the weakest password recovery email service it was linked to. I consider this a failure on Google's part.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#46
post #35

Earlier quoted context omitted.

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

From the article: The backup email address on my Gmail account is that same .mac email address. At 4:52 PM, they sent a Gmail password recovery email to the .mac account. Here Gmail was only as strong as the weakest password recovery email service it was linked to. I consider this a failure on Google's part.

With two factor authentication enabled this shouldn't be an issue.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#47
post #35
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

Phone is not the only way to access customer support. And for the look of this, BTW, Mat's gmail account got hacked first and then the social engineering on Apple side took part (the password reset was sent to his gmail account).

Im not suggesting that doing nothing is the same of doing something. Im just saying that not matter how secure and prepared Apple had been, this could have happened anyway.

Zero incident record, in any case, seems very unrealistic. I don't know any particular case first hand but then again i'm sure this is not the first time this happens with an iCloud account either. Mat is a public person and has commented his case publicly and thats why we are openly talking about it here.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#48
post #19

Earlier quoted context omitted.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

I use the 1password pronounceable strings. Still plenty random, but you can say it over the phone to a customer service person if you ever do need.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#49

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#50
post #39
post #24

Earlier quoted context omitted.

Perhaps what they need here is an optional 24-hour password reset delay. A user could only adjust this setting when properly logged in. Even if Apple gets social engineered, the user has 24 hours to notice the difference. Although it's extremely inconvenient to wait 1 full day to get back in, forgetting a password should be a rare circumstance .

No. They just need to implement one of the common protocols. For example, they could just require ID.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.
Post reply on HN