Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

161–170 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#161
post #136

Earlier quoted context omitted.

You know, as much as I laughed at your comment I think you have a point here. The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.

True, however it also means if your account does get hacked, you will have to wait weeks until they respond to your plea for help (if they respond at all). I think neither of these is the solution. If you can't talk to a human you'll never get help if you're locked out. If human support is available, there is always a chance they'll hand over your account to some scammer. Two-factor authentication means you'll be scr…

Bluehost requires ID on file before granting SSH access. Seems to me having that link to a meat-space audit trail should be required. In that sense, it would seem to me Google and Facebook should not only offer but demand two-factor authentication to a node in their social graph.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#162
post #55

Earlier quoted context omitted.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

I can barely answer half of those for myself and out of those that I can answer I'm either not sure I'd answer the same thing a few years later or it will probably be something a lot of people know. Those questions are terrible . Answering with a random string is the only sensible solution. But it is just as mindbogglingly bad. Because then you could just as well write down the password - and bam, you'd never lose it…

Just keep in mind that the ACTUAL answer to the security questions doesnt matter, just whatever you type into the box the first time.

What was your first car? "spaceship" is perfectly acceptable response, and its not discoverable by public means.

it does however mean you need to know what you would have typed in for each of the questions.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#163
post #146
post #47

Earlier quoted context omitted.

Phone is not the only way to access customer support. And for the look of this, BTW, Mat's gmail account got hacked first and then the social engineering on Apple side took part (the password reset was sent to his gmail account). Im not suggesting that doing nothing is the same of doing something. Im just saying that not matter how secure and prepared Apple had been, this could have happened anyway. Zero incident rec…

Security is a two way street: both the user, as well as the company have a responsibility. When i claimed certain high target technological companies have a zero incident grade, im talking about the fact the companies were never themselves the weak link. If this guys account was hacked because he tattoos his password on his forehead, Apple too would be in the clear. But here, not the user, but the company screwed up.…

http://blog.cloudflare.com/the-four-critical-security-flaws-...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#164

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

My father-in-law told me yesterday about a novel he's reading. The thief wanted to test the target's security system, so he threw clods of dirt over the fence until security came out and investigated. For a week. Then he threw cats over (good luck finding a pissed off cat in the middle of the night). Then they declared the alarm dysfunctional and posted a sign in the security shack: until further notice, disregard alarms between 0300 and 0500.

Makes you wonder if offering accessible customer service, at scale, eventually it's not even the guy on the phone that's the problem. The policy person cries uncle.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#166
post #121

Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.

One problem is I have no idea what physical address Apple has for me, but I'm sure I have moved at least three times (as many as five) since I gave them that address. A better solution is require a notarized physical mail in the event of password changes for high-security accounts. Everything else just goes to your email account.

I had this problem with a website from the Australian Government. I was actually trying to login to update my address, but I didn't know the password. For that though, I was able to visit a store front and update it after providing ID. I guess Apple could do a similar thing.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#167

Earlier quoted context omitted.

> Security at the bank seems discretionary at best No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address. The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the l…

I totally agree with you but on two points: 1) Cost benefit analysis and discretionary security is not mutually exclusive. It's cost benefit analysis ergo discretionary security. 2) Crime pays. You just have to be sophisticated and powerful enough to not be indicted. (TARP?) The interesting thing about your comment is when you apply your logic towards combating terrorism. The cumulative harm of prevention of terroris…

On 1) that is what I meant. The level of security measures is proportional to the risks, and a realisation that every measure costs time and money.

For 2) white collar crime certainly has shorter prison sentences in the US. It is a little harder to apportion blame as directly as with a bank robber. The general cause of problems has been the US government bailing out creditors. Because of that creditors have been laxer in their standards, had lower oversight and a greater tolerance for risk. This is virtually US government policy and has been going on since the 1984 rescue of the creditors of Continental Illinois. Ultimately fixing this involves fixing the US government and the corruption of Congress - see Lawrence Lessig's talk about they operate around money - and smaller things like regulatory capture.

The response to 9/11 has been to massively amplify the original effects, giving a huge return on investment to Al-Qaeda. In the positive column has been some of the security theatre - the appearance of improved security will be reassuring to some people. But everything else has been negative - the government expenditures, making new enemies in Iraq and Afghanistan, the loss of freedom for Americans, the massive invasive spying on Americans, the use of "terrorism" as an excuse for inexcusable things, the loss of American prestige (Guantanamo Bay isn't good PR), the additional friction on American life in both time and money (try taking a flight) and the list goes on.

I don't want to belittle 9/11, but the same number of people die each and every single month on American roads. It happened that same month, and every month since.

IMHO it would be a far better remembrance to the victims if we said "fuck you" to the perpetrators and lived free and open lives despite them, rather than the crippling effects that did happen.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#168
post #93
post #77

Earlier quoted context omitted.

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

"Unusable while you travel" or in other countries is simply false: one of the two-factor authentication options is the google authenticator app on your smartphone, which requires no internet/phone connectivity at all. It's time-based. The imap/pop thing is still a legitimate concern. App-specific passwords let those continue working, but they have security issues of their own.

And yet another option is a set of emergency use codes that you write down or print on a card.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#169
post #121

Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.

One problem is I have no idea what physical address Apple has for me, but I'm sure I have moved at least three times (as many as five) since I gave them that address. A better solution is require a notarized physical mail in the event of password changes for high-security accounts. Everything else just goes to your email account.

Apple already prompts me to agree to new terms and conditions every few months. Surely it wouldn't be too difficult to add '...and is this still your address?'

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#170

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

My father-in-law told me yesterday about a novel he's reading. The thief wanted to test the target's security system, so he threw clods of dirt over the fence until security came out and investigated. For a week. Then he threw cats over (good luck finding a pissed off cat in the middle of the night). Then they declared the alarm dysfunctional and posted a sign in the security shack: until further notice, disregard al…

People have been doing this for years to steal cars. Set off its alarm every night till the owner disables it.
Post reply on HN