Apple Support Allowed Hacker Access to Reporter's iCloud Account
71–80 of 181 posts
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#72Earlier quoted context omitted.
joke's on me then :) But back to my point social engineering doesn't require voice. you can do it via email just as easily.
Again there is no Google mail support to speak of (even with Google Apps for Business in my experience).
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#73It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?
The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#74Earlier quoted context omitted.
No. They just need to implement one of the common protocols. For example, they could just require ID.
If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#75In the end, a company has to constantly weigh the cost of strong protections versus the risk, and what this exposure will cost them in terms of customer goodwill as well as any civil penalties that may arise.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#76Earlier quoted context omitted.
I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?
You're right. When I forgot my battle.net secret question answer and wanted to change my password I had to send Blizzard two forms of ID. For some games. The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#77Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#78Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#79Earlier quoted context omitted.
You're right. When I forgot my battle.net secret question answer and wanted to change my password I had to send Blizzard two forms of ID. For some games. The solution exists, its in use now and it is mind boggling that for hundreds of dollars in apps, my file vault password, my payment details and of course a remote wipe facility for my hardware it isn't even an option.
No, you had to send copies/images of your ID. ID that is trivial for a hacker to duplicate.
There are lots of ways to mitigate this, but would drive up costs considerably.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#80Earlier quoted context omitted.
Physical IDs can be faked.
Isn't that an area that cannot be controlled at all? There are government issued IDs and if a normal company cannot trust them, then there's no way out. Biometric identification can be the last unbreakable protection, but that's also only valid until you find someone who, for example, lost/damaged his eyes in an accident and is up for scamming the company you're targeting. I mean, there's a reasonable limit of what c…
When I go to the store and buy beer, they want to see my license. They always make me take it out, which means the clerk can feel it, and the "feel" will often give away a fake to someone who has handled thousands of legit IDs. Next, they look at the pic on the ID and then look at me to make sure they at least kinda match. Nobody is really holding them up for a side-by-side, but you at least kind of have to look like the guy on the ID, which immediately limits the pool of people who could be faking my identity. Then, assuming it feels right and looks like me, they scan the ID and verify a record of that ID card with the state, which simply confirms that the state issued such an ID.
Between those three things, the system is actually pretty secure. But when you ask someone to scan in and email a copy of the front of their license as proof of ID, all three of those "checks" are eliminated.