Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

81–90 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#81

Earlier quoted context omitted.

Mat posted a screenshot of his Gmail inbox which showed an email about Apple's password reset. So I'm guessing the hackers had compromised Gmail account BEFORE they called up Apple tech support. Or maybe that email was just an attempt and didn't help anyway with the actual password retrieval. I'm confused about this...

The original blog post makes it quite clear that the .mac account was used to compromise the Gmail account. I think the screenshot is from after he regained control of the Gmail account.

Oh... in that case, how can a .mac account be used to compromise a Gmail account - using Forgot Password?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#82
post #66

Everybody should read the account of an opposite situation with Apple tech support and password retrieval: http://www.pcworld.com/businesscenter/article/260414/how_did...

Its a good interesting piece but in this case could easily be that the employee in Mat's case didn't follow correct procedure or was not familiar with it (new employee?). Even if he knew the procedure for this cases there are all kinds of possible explanations: maybe the hacker pay him, maybe himself is the attacker, etc...

I totally agree that customer support is a very inconsistent department. I was just hoping Apple would have stringent training for these reps to all follow the strictest possible security checks. Who knows...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#83
post #51
post #42

Earlier quoted context omitted.

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex. This reminds me of facebook and how all its employees were stalking people using the god password. They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

> This reminds me of facebook and how all its employees were stalking people using the god password. Wait what? Sorry to get off topic but when did this happen?

Possibly referring to this story. http://online.wsj.com/article/SB1000142405270230489870457747... If so, the quote only says they could stalk people with the master password, not that they were.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#84

I wonder if attacker will be caught and would end up in jail. All password change requests like that must be carefully recorded and are probably very traceable. Considering public nature of this exploit, Apple might put quite some effort to carefully investigate the incident.

The kid who hacked Sarah Palin's email got a year in jail. He was convicted of "the felony of anticipatory obstruction of justice by destruction of records and a misdemeanor of unauthorized access to a computer." [wikipedia]

The guy who hacked Honan is certainly guilty of the misdemeanor (which could wind you up in jail) and depending on what he erased and how they want to interpret his motives, he could be guilty of the same felony.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#85

Earlier quoted context omitted.

The original blog post makes it quite clear that the .mac account was used to compromise the Gmail account. I think the screenshot is from after he regained control of the Gmail account.

Oh... in that case, how can a .mac account be used to compromise a Gmail account - using Forgot Password?

Yeah, one of the Gmail account recovery mechanisms is some process involving another email address.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#86

Damn.. this is popcorn-worthy. Anti-Applites are gonna say "sue them!" and Fanboys are gonna post a rebuttal to each of those posts.

I'm sitting at home surrounded by a bunch of Apple hardware, and my first reaction is "This is why you shouldn't use iCloud!". This is also why I refused to connect my iOS device to an Exchange server at work (which grants remote-wipe capability).

I don't think this is Apple versus non-Apple. I think this is everything-in-the-cloud versus everything-local.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#87

Earlier quoted context omitted.

Just because a clause is in a contract, doesn't mean it has any effect. A lot of terms are flat out bluffing to scare off folk like you. This is why it is always a good investment to ask your lawyer.

This is really, really important advice, and if more people understood it, corporations would have a lot less power over people than they currently do. You can open up just about any ToS and find a handful of unenforceable clauses they're hoping you won't realize are unenforceable.

I suspect the vast majority of people never read the TOS and decide to sue, or not, for completely independent reasons.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#88

Earlier quoted context omitted.

The original blog post makes it quite clear that the .mac account was used to compromise the Gmail account. I think the screenshot is from after he regained control of the Gmail account.

Oh... in that case, how can a .mac account be used to compromise a Gmail account - using Forgot Password?

AIUI the .mac account was the backup email address of the Gmail account. So 1. The attacker compromised the .mac account. 2. The attacker used the I forgot my password feature of Gmail - to get an account reset email for the gmail account sent to the .mac account.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#89
Large amounts of personal data are collected by data brokers like Intelius, Spokeo and Whitepages - which makes this easier to pull off. It's fairly trivial to find answers to questions like "What's your DOB?" or "What's your billing address" by looking in one of these places. Most data brokers will have opt-out pages where you can request removal of your data - though they don't make it easy. There are also services that help with this: MyPrivacy (reputation.com/myprivacy) which I work on and Safe Shepherd (safesheperd.com).

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#90
post #77

Earlier quoted context omitted.

Why not require it then?

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

It's quite possible to add two-factor logins for any protocol, that works in any country with a cell phone network. Just demand a response to a challenge via cell phone before validating the password, you could even require one of those RSA token thingies if you want. Just a matter of cost and convenience.
Post reply on HN