Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

91–100 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#91

Earlier quoted context omitted.

Is there any way to remove the wiping bit without removing the whole finding functionality? That bit is extremely useful, and if a hacker managed to get into my iCloud I wouldn't be that worried about them being able to locate it. But being able to wipe everything as well is a different matter.

IIRC it does the wipe via the recovery boot, so wiping that partition would kill it. BUT: you'd be hosed if you ever needed recovery, you wouldn't be able to use full-disk encryption, and there's likely other bits of the OS that would break in subtle and interesting ways without it there. Tread _very_ carefully.

>IIRC it does the wipe via the recovery boot, so wiping that partition would kill it.

Isn't this not an option in relatively recent Macs, which have the recovery functionality baked into the EFI firmware and not as a partition on the disk?

Newer Macs have that functionality out of the box, and a bunch from 2010 and early 2011 that did not originally ship with the recovery firmware ended up getting it later via update: http://support.apple.com/kb/HT4904

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#92
post #34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

When I opened my Ing account I didn't need any of this. They verify your identity through a series of questions about your past, as well as your SSN. In fact, all US banks allow accounts to be opened over the 'net now. I've personally done it with several of them.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#93
post #77

Earlier quoted context omitted.

Why not require it then?

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

"Unusable while you travel" or in other countries is simply false: one of the two-factor authentication options is the google authenticator app on your smartphone, which requires no internet/phone connectivity at all. It's time-based.

The imap/pop thing is still a legitimate concern. App-specific passwords let those continue working, but they have security issues of their own.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#94
post #34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

That's a great idea, and I think they already have a platform to do that with, the Apple Store and their Genius Bar. Most major cities have two Apple stores these days, and for people that aren't near one, an option to fax or mail could exist. In addition, a callback or text just plan seems necessary, even if the number is inactive.

The less information the other person (hacker/user) has to offer, the more time it should take to reset. In the meantime Apple should be notifying all the contact information on file about what's going on and offer a way to stop it.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#95
post #22

I hope he sues Apple for this and wins, behavior like this shouldn't be allowed without consequences.

I hope he sues Apple too. Not because I want any harm to come to Apple, but because I want Apple to have a significant financial incentive to push authorities to track down the villain.

And more important, a significant financial incentive to correct their own obviously inadequate procedures.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#96
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

If I got veeti's joke then I think what he was trying to say was that it's nearly impossible to get Google on the phone unless you're a corporate customer. If I didn't get his joke then I'm making it now. joke

It was the first thing I thought. "Hah! Good luck getting Google to answer a phone.." Then I thought, "wait, was that a joke?"

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#97

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#98
post #92
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

When I opened my Ing account I didn't need any of this. They verify your identity through a series of questions about your past, as well as your SSN. In fact, all US banks allow accounts to be opened over the 'net now. I've personally done it with several of them.

That does require a credit pull to accomplish. Not insurmountable (and can be done without damaging the consumers credit score via a so-called "soft pull") but the company doing the pulling has to pay for access to that data.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#99

Earlier quoted context omitted.

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

Have they? (Honest question.)

I would argue that yes, they have.

They removed the copy on their website that claimed that "Macs don't get PC Viruses"[1]. They disabled automatic execution of Java Applets in response to Flashback[2]. The introduction of Gatekeeper and the App Store model shows their intention for reducing the vectors average users can install random software (which reduces rogue installations like Flashback). ASLR is fully implemented in Lion now, and the inclusion of FileVault 2 suggests they are aware of and trying to mitigate offline attacks[3]

Regardless if you think this is enough, it does show that they are doing something. For every couple steps forward in closing a security issue, issues such as this article show that more could be done. Security is hard, no OS or company will ever be Perfectly Secure(tm). Apple is not "doing nothing". Claiming that they aren't is an uneducated answer, claiming that they could do more and be more transparent about it is a more valid argument.

[1] http://www.wired.com/wiredenterprise/2012/06/mac_viruses/ [2] http://support.apple.com/kb/HT5242 [3] http://www.securitynewsdaily.com/960-apple-mac-osx-lion-secu...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#100
post #94
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

That's a great idea, and I think they already have a platform to do that with, the Apple Store and their Genius Bar. Most major cities have two Apple stores these days, and for people that aren't near one, an option to fax or mail could exist. In addition, a callback or text just plan seems necessary, even if the number is inactive. The less information the other person (hacker/user) has to offer, the more time it sh…

>>for people that aren't near [an Apple Store], an option to fax or mail could exist.

Almost ten years ago, I asked an old friend (that got rich doing security for online gambling companies) about verifying identity with VISA cards.

He told me that the Russian mob would open a new account in e.g. the English countryside. When the security people called the (non-mobile) phone number, then someone answered and verified that it was their VISA card and yes, they wanted to open an account.

Edit: If my point isn't clear -- it is that the present capabilities of the criminal networks are probably much superior these days. (Addition: I assume he knew where the criminals came from because of police reports.)

Post reply on HN