Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

141–150 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#141
post #50

Earlier quoted context omitted.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.

Spending a few minutes tricking a CSR on the phone isn't even close to the difficulty of obtaining a workable fake ID. Barriers are useful even if they can be crossed with sufficient effort.

While it's hard to make a fake ID, it's trivial to make a fake image of ID.

Checking a physical ID would be a somewhat effective barrier. Checking an emailed or faxed image of an ID? Useless.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#142
post #97

Earlier quoted context omitted.

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

Indeed, but even companies who don't offer a phone-based customer support service can be susceptible to basic social engineering. When Facebook was still granting new users access by checking that their email matched a school's domain, I was able to make accounts at multiple schools by sending a forged email (claiming to originate from the school domain) to Facebook support saying something like: "I never received th…

Journalist blames Apple tech for allowing iCloud hack and for more details you can go here: http://goo.gl/Gi4B1

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#143
post #19

Earlier quoted context omitted.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

For every single of these questions, my wife, mother and sister would know the answer as well. Ergo, they are not acceptable as a "secret" that can be used to grant access to my account; Apple should provide reasonable privacy also from my in-laws. The whole concept of "security questions" is stupid and useless, and shouldn't be used ever and anywhere.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#144
post #111

Earlier quoted context omitted.

"I'm not sure how to solve this problem" Easy. CSR has exactly the same screen as you do. With the same security questions as you have. In this case it seems, those questions were never asked. You design CSR frontend where they must themselves answer those questions before proceed. You may pay off that CSR, but she/he does not know answers to those questions so she/he can not do a thing. If you forgot answer to those…

That is an interesting approach. Given the retail presence Apple has the opportunity to ask you to go to an Apple store in person and talk with service personnel there. One could easily put a picture on file (every Apple device has a camera now) of the owner, and the two bits of information: 1) You have the device with you 2) You are the same person as the picture of the owner Would set a reasonably high bar to cross…

I suspect there are a LOT of places in the United States that are a few hours' drive from the closest Apple store.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#145

Earlier quoted context omitted.

What are you even alleging? What is the rat?

I'm not alleging, I'm quoting a comment from MacRumors that got my attention. The fact that a hacker would repeatedly contact its victim and that Gizmodo has reasons for not being particularly found of Apple (after the lost iPhone incident) was not something I had though of at first, but did strike me as odd.

Honan no longer works at Gizmodo. It says so right in the OP, along with the name of his new employer. So... ??

You say that post "got you thinking." Got you thinking what?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#146
post #47
post #35

Earlier quoted context omitted.

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

Phone is not the only way to access customer support. And for the look of this, BTW, Mat's gmail account got hacked first and then the social engineering on Apple side took part (the password reset was sent to his gmail account). Im not suggesting that doing nothing is the same of doing something. Im just saying that not matter how secure and prepared Apple had been, this could have happened anyway. Zero incident rec…

Security is a two way street: both the user, as well as the company have a responsibility.

When i claimed certain high target technological companies have a zero incident grade, im talking about the fact the companies were never themselves the weak link.

If this guys account was hacked because he tattoos his password on his forehead, Apple too would be in the clear. But here, not the user, but the company screwed up.

There are many, many companies which do not have incidents, or take full responsibility when they do. The type of incidents we complain about, often indicate just gross negliance. (and this is gross negliance by Apple)

You are repeating the claim that there is no watertight security. This claim is wrong. Software can be provably secure. Authentification can be provably secure, just like any type of Content protection is provably unsecure.

Now, you are also making the claim, that we are talking about this, because of the affected users popularity.

Maybe thats why you are talking about it. But most of us are actually surprised because of the gross negliance. ICloud has no authentification, one can just call up, and take over the account. As we now know.

And if this was any other company, i doubt anyone would argue against this obvious and pretty much indisputable fact. But this isnt Sony, this is Apple, and they can never do anything wrong right? Eventhough, statistically, just like any other company, they might could not excel in every way. Maybe this is just one area, where they just screwed up?

Theyll learn from it, hopefully. But lets not pretend it didnt happen, or that it isnt as big as a fuckup as it actually is, back here in reality.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#147

Earlier quoted context omitted.

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions? I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was…

>Is this an improvement?

Yes. Without the strict checks by your bank, none of their customers would be secure. With their checks in place, some, including you, are now secure.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#148

Earlier quoted context omitted.

I was out of town and went to make a large cash purchase. (The retailer added a very hefty 10% for using debit or credit cards.) So I ran into the problem of a daily cash withdrawal at the ATM. I also did not have anything with me other than an ATM card and a Credit card with me (No ID). Turned out the bank didn't even ask for my ID when I went in. I just explained my situation and they just handed over a couple thou…

> Security at the bank seems discretionary at best No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address. The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the l…

I totally agree with you but on two points:

1) Cost benefit analysis and discretionary security is not mutually exclusive. It's cost benefit analysis ergo discretionary security.

2) Crime pays. You just have to be sophisticated and powerful enough to not be indicted. (TARP?)

The interesting thing about your comment is when you apply your logic towards combating terrorism. The cumulative harm of prevention of terrorism outweighs the damage and death caused by the terrorism itself. The 'cost-benefit analysis' must take into account the 'positive' externalities for those who advocate those policies.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#149

Earlier quoted context omitted.

Spending a few minutes tricking a CSR on the phone isn't even close to the difficulty of obtaining a workable fake ID. Barriers are useful even if they can be crossed with sufficient effort.

While it's hard to make a fake ID, it's trivial to make a fake image of ID. Checking a physical ID would be a somewhat effective barrier. Checking an emailed or faxed image of an ID? Useless.

That depends greatly on what kind of checking is done on the other side. For example, if they can cross-check your driver's license number with the rest of your info, then making a fake image of an ID that will pass muster will be tough.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#150

Earlier quoted context omitted.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

I use the 1password pronounceable strings. Still plenty random, but you can say it over the phone to a customer service person if you ever do need.

Great idea: Updating my questions now...
Post reply on HN