Earlier quoted context omitted.
You know, as much as I laughed at your comment I think you have a point here. The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.
True, however it also means if your account does get hacked, you will have to wait weeks until they respond to your plea for help (if they respond at all). I think neither of these is the solution. If you can't talk to a human you'll never get help if you're locked out. If human support is available, there is always a chance they'll hand over your account to some scammer. Two-factor authentication means you'll be scr…
Apple Support Allowed Hacker Access to Reporter's iCloud Account
161–170 of 181 posts
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#162Earlier quoted context omitted.
Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…
I can barely answer half of those for myself and out of those that I can answer I'm either not sure I'd answer the same thing a few years later or it will probably be something a lot of people know. Those questions are terrible . Answering with a random string is the only sensible solution. But it is just as mindbogglingly bad. Because then you could just as well write down the password - and bam, you'd never lose it…
What was your first car? "spaceship" is perfectly acceptable response, and its not discoverable by public means.
it does however mean you need to know what you would have typed in for each of the questions.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#163Earlier quoted context omitted.
Phone is not the only way to access customer support. And for the look of this, BTW, Mat's gmail account got hacked first and then the social engineering on Apple side took part (the password reset was sent to his gmail account). Im not suggesting that doing nothing is the same of doing something. Im just saying that not matter how secure and prepared Apple had been, this could have happened anyway. Zero incident rec…
Security is a two way street: both the user, as well as the company have a responsibility. When i claimed certain high target technological companies have a zero incident grade, im talking about the fact the companies were never themselves the weak link. If this guys account was hacked because he tattoos his password on his forehead, Apple too would be in the clear. But here, not the user, but the company screwed up.…
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#164It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…
Makes you wonder if offering accessible customer service, at scale, eventually it's not even the guy on the phone that's the problem. The policy person cries uncle.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#165Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#166Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.
One problem is I have no idea what physical address Apple has for me, but I'm sure I have moved at least three times (as many as five) since I gave them that address. A better solution is require a notarized physical mail in the event of password changes for high-security accounts. Everything else just goes to your email account.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#167Earlier quoted context omitted.
> Security at the bank seems discretionary at best No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address. The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the l…
I totally agree with you but on two points: 1) Cost benefit analysis and discretionary security is not mutually exclusive. It's cost benefit analysis ergo discretionary security. 2) Crime pays. You just have to be sophisticated and powerful enough to not be indicted. (TARP?) The interesting thing about your comment is when you apply your logic towards combating terrorism. The cumulative harm of prevention of terroris…
For 2) white collar crime certainly has shorter prison sentences in the US. It is a little harder to apportion blame as directly as with a bank robber. The general cause of problems has been the US government bailing out creditors. Because of that creditors have been laxer in their standards, had lower oversight and a greater tolerance for risk. This is virtually US government policy and has been going on since the 1984 rescue of the creditors of Continental Illinois. Ultimately fixing this involves fixing the US government and the corruption of Congress - see Lawrence Lessig's talk about they operate around money - and smaller things like regulatory capture.
The response to 9/11 has been to massively amplify the original effects, giving a huge return on investment to Al-Qaeda. In the positive column has been some of the security theatre - the appearance of improved security will be reassuring to some people. But everything else has been negative - the government expenditures, making new enemies in Iraq and Afghanistan, the loss of freedom for Americans, the massive invasive spying on Americans, the use of "terrorism" as an excuse for inexcusable things, the loss of American prestige (Guantanamo Bay isn't good PR), the additional friction on American life in both time and money (try taking a flight) and the list goes on.
I don't want to belittle 9/11, but the same number of people die each and every single month on American roads. It happened that same month, and every month since.
IMHO it would be a far better remembrance to the victims if we said "fuck you" to the perpetrators and lived free and open lives despite them, rather than the crippling effects that did happen.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#168Earlier quoted context omitted.
not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.
"Unusable while you travel" or in other countries is simply false: one of the two-factor authentication options is the google authenticator app on your smartphone, which requires no internet/phone connectivity at all. It's time-based. The imap/pop thing is still a legitimate concern. App-specific passwords let those continue working, but they have security issues of their own.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#169Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.
One problem is I have no idea what physical address Apple has for me, but I'm sure I have moved at least three times (as many as five) since I gave them that address. A better solution is require a notarized physical mail in the event of password changes for high-security accounts. Everything else just goes to your email account.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#170Earlier quoted context omitted.
I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…
My father-in-law told me yesterday about a novel he's reading. The thief wanted to test the target's security system, so he threw clods of dirt over the fence until security came out and investigated. For a week. Then he threw cats over (good luck finding a pissed off cat in the middle of the night). Then they declared the alarm dysfunctional and posted a sign in the security shack: until further notice, disregard al…