How Apple and Amazon Security Flaws Led to My Epic Hacking
1–10 of 264 posts
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#2This is scary.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#3About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but had to settle on the next best thing - spamming my email address with hundreds of emails per minute in an attempt to cover up the emails sent by my CC company.
Fortunately, the spamming wasn't very sophisticated and it only took me 30 seconds to filter it all to trash. I was on the phone with my credit card company within 10 minutes of the attack, which mitigated some of the damage.
I'm sure at some point weaknesses will be found in the 2-factor auth solution, but for now, it feels almost mandatory for important email accounts.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#4It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.
"Pay with your iCloud password" just doesn't have the same fuzzy feel, does it?
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#5Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…
If both companies agreed to a standard that made it obvious such practices were non-compliant, this wouldn't have happened.
1: http://blog.cloudflare.com/post-mortem-todays-attack-apparen...
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#6It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.
What should one try to do to protect against this?
Hypothetical actions to take:
Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail.
Take particular care to have a "recovery" email address that is used for nothing else. Don't forward it to your regular mail, naturally.
Enable two-factor auth for email if you possibly can.
Have a credit card that is only used for online stuff.
Can one get a second address that is used only as a billing address? How would one do that? (A P.O. box? Expensive! A friend's house? I fear that credit card companies will leak this address like a sieve no matter what I do.)
EDIT: Startup wizards, here's a Minimum Viable Product: a credit card that can only be used for online accounts - which you must whitelist as you add them, via two-factor auth with your phone - and that features two billing addresses: The real one where the bills go and a dummy one that still validates. (Is that even legal under the CC rules? Sigh.)
The other suggestions in the article: Disable Find my Mac, reduce coupling between your accounts… was there something else?
Alas, nobody who isn't crazy paranoid is going to bother jumping through all these hoops. (I have tried to fight that paranoia but I think I'm losing that battle.)
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#7One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protest.
I don't understand how the MacBook data was permanently lost. Even if the files were deleted in the OS, they are recoverable by disk utilities. Unless they were encrypted. Which just goes to say that when you think the solution to your problem is encryption, you don't understand your problem.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#8It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#9Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…
"...but had to settle on the next best thing - spamming my email address with
hundreds of emails per minute in an attempt to cover up the emails sent by
my CC company."
Here's an article from just last month about this very technique: https://krebsonsecurity.com/2012/07/cyberheist-smokescreen-e...Flooding someone's inbox (or telephone) is now available as a very affordable a la carte service.