Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

1–10 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#3
Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance.

About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but had to settle on the next best thing - spamming my email address with hundreds of emails per minute in an attempt to cover up the emails sent by my CC company.

Fortunately, the spamming wasn't very sophisticated and it only took me 30 seconds to filter it all to trash. I was on the phone with my credit card company within 10 minutes of the attack, which mitigated some of the damage.

I'm sure at some point weaknesses will be found in the 2-factor auth solution, but for now, it feels almost mandatory for important email accounts.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#4
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

Especially given that that information is available to anyone you've ever used that credit card with.

"Pay with your iCloud password" just doesn't have the same fuzzy feel, does it?

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#5
post #3

Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…

2-factor auth has been cracked before [1] and will be again until there is a standard on how to implement it. With implementations differing between companies, a cracker can play one org's weakness off another org. Like in this case, using the freely-available trailing 4 digit CC code from Amazon to get into Apple.

If both companies agreed to a standard that made it obvious such practices were non-compliant, this wouldn't have happened.

1: http://blog.cloudflare.com/post-mortem-todays-attack-apparen...

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#6
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN:

What should one try to do to protect against this?

Hypothetical actions to take:

Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail.

Take particular care to have a "recovery" email address that is used for nothing else. Don't forward it to your regular mail, naturally.

Enable two-factor auth for email if you possibly can.

Have a credit card that is only used for online stuff.

Can one get a second address that is used only as a billing address? How would one do that? (A P.O. box? Expensive! A friend's house? I fear that credit card companies will leak this address like a sieve no matter what I do.)

EDIT: Startup wizards, here's a Minimum Viable Product: a credit card that can only be used for online accounts - which you must whitelist as you add them, via two-factor auth with your phone - and that features two billing addresses: The real one where the bills go and a dummy one that still validates. (Is that even legal under the CC rules? Sigh.)

The other suggestions in the article: Disable Find my Mac, reduce coupling between your accounts… was there something else?

Alas, nobody who isn't crazy paranoid is going to bother jumping through all these hoops. (I have tried to fight that paranoia but I think I'm losing that battle.)

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#7
We need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem.

One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protest.

I don't understand how the MacBook data was permanently lost. Even if the files were deleted in the OS, they are recoverable by disk utilities. Unless they were encrypted. Which just goes to say that when you think the solution to your problem is encryption, you don't understand your problem.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#8
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

A lot of receipts contain the last 4 of the card used, it looks like most iCloud users are one garbage bag away from being compromised.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#9
post #3

Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…

    "...but had to settle on the next best thing - spamming my email address with
     hundreds of emails per minute in an attempt to cover up the emails sent by
     my CC company."
Here's an article from just last month about this very technique: https://krebsonsecurity.com/2012/07/cyberheist-smokescreen-e...

Flooding someone's inbox (or telephone) is now available as a very affordable a la carte service.

Post reply on HN