Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

71–80 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#71
I wonder if attacker will be caught and would end up in jail. All password change requests like that must be carefully recorded and are probably very traceable. Considering public nature of this exploit, Apple might put quite some effort to carefully investigate the incident.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#72
post #54
post #36

Earlier quoted context omitted.

joke's on me then :) But back to my point social engineering doesn't require voice. you can do it via email just as easily.

Again there is no Google mail support to speak of (even with Google Apps for Business in my experience).

Sure there is. if you pay for your Google Apps account: http://support.google.com/a/bin/request.py

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#73
post #34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

You're right. When I forgot my battle.net secret question answer and wanted to change my password I had to send Blizzard two forms of ID. For some games.

The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#74
post #50
post #39

Earlier quoted context omitted.

No. They just need to implement one of the common protocols. For example, they could just require ID.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.

They still require additional effort. Right now, in my pajamas, without leaving my house or spending money, I can do exactly what that hacker did. I probably wouldn't even try it if I knew I would have to get a fake ID just to punish some Gizmodo employee for shits.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#75
Social Engineering will usually win out as long as a person is in the loop. It's just not feasible to expect a poorly paid CSR to be able to cope with this type of threat.

In the end, a company has to constantly weigh the cost of strong protections versus the risk, and what this exposure will cost them in terms of customer goodwill as well as any civil penalties that may arise.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#76
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

You're right. When I forgot my battle.net secret question answer and wanted to change my password I had to send Blizzard two forms of ID. For some games. The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.

No, you had to send copies/images of your ID. ID that is trivial for a hacker to duplicate.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#77
post #46

Earlier quoted context omitted.

With two factor authentication enabled this shouldn't be an issue.

Why not require it then?

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#79
post #76

Earlier quoted context omitted.

You're right. When I forgot my battle.net secret question answer and wanted to change my password I had to send Blizzard two forms of ID. For some games. The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.

No, you had to send copies/images of your ID. ID that is trivial for a hacker to duplicate.

This is true.

There are lots of ways to mitigate this, but would drive up costs considerably.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#80
post #58

Earlier quoted context omitted.

Physical IDs can be faked.

Isn't that an area that cannot be controlled at all? There are government issued IDs and if a normal company cannot trust them, then there's no way out. Biometric identification can be the last unbreakable protection, but that's also only valid until you find someone who, for example, lost/damaged his eyes in an accident and is up for scamming the company you're targeting. I mean, there's a reasonable limit of what c…

It's a question of how closely the ID can be inspected for accuracy.

When I go to the store and buy beer, they want to see my license. They always make me take it out, which means the clerk can feel it, and the "feel" will often give away a fake to someone who has handled thousands of legit IDs. Next, they look at the pic on the ID and then look at me to make sure they at least kinda match. Nobody is really holding them up for a side-by-side, but you at least kind of have to look like the guy on the ID, which immediately limits the pool of people who could be faking my identity. Then, assuming it feels right and looks like me, they scan the ID and verify a record of that ID card with the state, which simply confirms that the state issued such an ID.

Between those three things, the system is actually pretty secure. But when you ask someone to scan in and email a copy of the front of their license as proof of ID, all three of those "checks" are eliminated.

Post reply on HN