Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

61–70 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#63
post #35

Earlier quoted context omitted.

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

Microsoft and Google have zero incidents only for very large values of zero. Google "gmail account hacked" or "Xbox live account hacked" or "hotmail account hacked". In the last case, the top links are to Microsoft's FAQ pages.

Irrelevant because those accounts are hacked by someone who acquired the password of the actual user by a keylogger etc. They were not exploiting flaws related to server side. In iCloud's case, there is nothing the user could have done to prevent this attack.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#64
post #20

Are they saying Apple sent the password reset request to a different backup email entirely? Or that they reset the password to a requested password while one the phone? Even if someone had properly identified themselves as Mat Honan, neither of these should be permitted.

Mat posted a screenshot of his Gmail inbox which showed an email about Apple's password reset. So I'm guessing the hackers had compromised Gmail account BEFORE they called up Apple tech support. Or maybe that email was just an attempt and didn't help anyway with the actual password retrieval. I'm confused about this...

The original blog post makes it quite clear that the .mac account was used to compromise the Gmail account.

I think the screenshot is from after he regained control of the Gmail account.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#65
post #35

Earlier quoted context omitted.

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

Microsoft and Google have zero incidents only for very large values of zero. Google "gmail account hacked" or "Xbox live account hacked" or "hotmail account hacked". In the last case, the top links are to Microsoft's FAQ pages.

Just because a company can have their FAQ pages SEO'd to the top of the SERPS doesn't mean their services haven't been hacked.

Most people who get hacked hardly ever report it, they just want their account(s) back.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#66

Everybody should read the account of an opposite situation with Apple tech support and password retrieval: http://www.pcworld.com/businesscenter/article/260414/how_did...

Its a good interesting piece but in this case could easily be that the employee in Mat's case didn't follow correct procedure or was not familiar with it (new employee?). Even if he knew the procedure for this cases there are all kinds of possible explanations: maybe the hacker pay him, maybe himself is the attacker, etc...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#67
post #58
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

Physical IDs can be faked.

Isn't that an area that cannot be controlled at all? There are government issued IDs and if a normal company cannot trust them, then there's no way out. Biometric identification can be the last unbreakable protection, but that's also only valid until you find someone who, for example, lost/damaged his eyes in an accident and is up for scamming the company you're targeting.

I mean, there's a reasonable limit of what companies may want to check, but once those proofs can be faked, it's not their responsibility to fix the issue anymore.

(PS. some countries have more restrictions than others too - for example in Poland you need two IDs with a photo to get any kind of mobile plan on a contract - that leaves plenty of ways to verify your identity)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#68
post #58
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

Physical IDs can be faked.

However, showing up in person is a huge inconvenience for a hacker in another country. Another technique banks use is to send a physical piece of snail mail to a physical postal address containing a verification code or card.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#69
post #18

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I once had to reset the password of my stock trading account. All they needed for verification was my home address. I am also pretty leery of putting anything online.

Didn't they call you back to your phone number prior to resetting your password?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#70
post #46

Earlier quoted context omitted.

From the article: The backup email address on my Gmail account is that same .mac email address. At 4:52 PM, they sent a Gmail password recovery email to the .mac account. Here Gmail was only as strong as the weakest password recovery email service it was linked to. I consider this a failure on Google's part.

With two factor authentication enabled this shouldn't be an issue.

Why not require it then?
Post reply on HN