Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

111–120 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#111

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

"I'm not sure how to solve this problem"

Easy. CSR has exactly the same screen as you do. With the same security questions as you have. In this case it seems, those questions were never asked. You design CSR frontend where they must themselves answer those questions before proceed. You may pay off that CSR, but she/he does not know answers to those questions so she/he can not do a thing.

If you forgot answer to those questions, alert is escalated, which needs two together CSR's + their supervisor to unlock your account + you must make Facetime call + whole process gets documented carefully.

What did I miss?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#112
post #51
post #42

Earlier quoted context omitted.

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex. This reminds me of facebook and how all its employees were stalking people using the god password. They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

> This reminds me of facebook and how all its employees were stalking people using the god password. Wait what? Sorry to get off topic but when did this happen?

Facebook employees were able to login to any acount using the password "chucknorris".

Including being able to read private messages of their friends, families, ex-girlfriends, etc

This wasnt just true when facebook was a university startup, but even when they were already the largest social network in the US.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#113
post #50
post #39

Earlier quoted context omitted.

No. They just need to implement one of the common protocols. For example, they could just require ID.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.

The security of an ID is protected by the state. Screwing around with that is a federal, put your ass in prison, kind of breach, irregardless of your intention or the context.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#114

Earlier quoted context omitted.

You know, as much as I laughed at your comment I think you have a point here. The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.

Security through support obscurity?

Not really. More having a smaller attack vector. There are less people that could authorize a reset, they are better paid, and centralized. (rather than being an underpaid store clerk)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#115
post #111

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

"I'm not sure how to solve this problem" Easy. CSR has exactly the same screen as you do. With the same security questions as you have. In this case it seems, those questions were never asked. You design CSR frontend where they must themselves answer those questions before proceed. You may pay off that CSR, but she/he does not know answers to those questions so she/he can not do a thing. If you forgot answer to those…

That is an interesting approach. Given the retail presence Apple has the opportunity to ask you to go to an Apple store in person and talk with service personnel there. One could easily put a picture on file (every Apple device has a camera now) of the owner, and the two bits of information:

1) You have the device with you

2) You are the same person as the picture of the owner

Would set a reasonably high bar to cross.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#116
post #42

Earlier quoted context omitted.

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex. This reminds me of facebook and how all its employees were stalking people using the god password. They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

Honestly, the bank protocol is overkill for 90% of users. Most people using iCloud are using it to sync photos of their cat. The number who are keeping "their life" in the cloud is basically confined to techno-geeks. Your average iCloud user is not necessarily going to want to a) prove their identity initially or b) do so again to get support. I think you are better off taking the approach of "don't put something in…

If you dont put anything of value in iCloud, you dont care enough about a reset: you could just setup a new account.

Having every underpaid store clerk being able to reset the account of every customer, is just dangerously stupid.

Just not having a reset feature is even better.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#117
post #74
post #50

Earlier quoted context omitted.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.

They still require additional effort. Right now, in my pajamas, without leaving my house or spending money, I can do exactly what that hacker did. I probably wouldn't even try it if I knew I would have to get a fake ID just to punish some Gizmodo employee for shits.

Besides: banks videotape their customers. We would have the culprit on video.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#118
post #97

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

Indeed, but even companies who don't offer a phone-based customer support service can be susceptible to basic social engineering.

When Facebook was still granting new users access by checking that their email matched a school's domain, I was able to make accounts at multiple schools by sending a forged email (claiming to originate from the school domain) to Facebook support saying something like: "I never received the confirmation email. Will you please activate my account at fakename@targetschool.edu?"

And it worked 90% of the time.

I wonder how many websites nowadays would be susceptible to a targeted and personalized forged email to customer service (especially since emails are frequently used to prove account ownership).

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#119
post #58

Earlier quoted context omitted.

Physical IDs can be faked.

Isn't that an area that cannot be controlled at all? There are government issued IDs and if a normal company cannot trust them, then there's no way out. Biometric identification can be the last unbreakable protection, but that's also only valid until you find someone who, for example, lost/damaged his eyes in an accident and is up for scamming the company you're targeting. I mean, there's a reasonable limit of what c…

Biometrics aren't unbreakable and can be spoofed quite trivially in many cases.

Here's a professor spoofing high-end fingerprint scanners with gelatin and a printer: http://vast.uccs.edu/~tboult/tmp/fingerprint-boult-koaa-medi... (sorry for the sensationalism at the beginning)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#120

The thought hadn't cross my mind, but after reading this post it got me thinking: Sensa So, let's get this straight...a hacker "decides" to hack the account of a semi-high profile tech guy and then after committing several serious crimes like fraud that could land him in jail for an extended period of time repeatedly contacts the person he hacked when he must know that Apple will surely pursue this matter? I smell a…

What are you even alleging? What is the rat?
Post reply on HN