Earlier quoted context omitted.
I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…
I wouldn't do anything too crazy. If you're the 1 in a billion (7 billion, actually) who gets targeted like this, they'll probably still get in so you're just wasting oodles of time and adding a good dose of constant aggravation for essentially nothing.
How Apple and Amazon Security Flaws Led to My Epic Hacking
91–100 of 264 posts
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#92For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…
Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?
Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com."
I don't know for sure whether that's true or not. But assume it is true. If two-factor authentication had been enabled, then the hackers would have had a much harder time guessing Mat's email address for iCloud and whether he had a @me.com email address at all.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#93Earlier quoted context omitted.
The most surprising thing I see out of this isn't the need for more robust authentication but for services that aren't so damn quick to do whatever you want. Website: "Hey Bill, glad to see you today, what do you want to do" Bill: "Delete _everything_ I've ever done on every system I have" Website: "Of course! Let's get this started... beep boop bip and done!" What about this: 1 - Kill request sent 2 - 48 hours is se…
I can just imagine the HN article when someone tries to delete his Facebook account because he disagrees with some new feature, and they won't do it for 48 hours. I've been on the receiving end of "DELETE MY ACCOUNT!!!1!!1" requests, and I know those people wouldn't respond well to "wait two days or pay up."
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#94For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#95Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#96Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!
With every platform, there is compromise between convenience and security; when your platform has to reach many, many non-tech-y people, convenience is preferred.
But then there are policies and technology that increase BOTH convenience and security. Say the difference between using SSH these days versus using, say, paper and an Enigma machine.
The inconvenience of Google Authenticator is minimal and the security provided is huge.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#97For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…
Myth: Right, but what happens in the very common scenario of my Android phone-- logged into Google with the Authenticator installed-- getting lost / stolen? Surely then 2-factor auth is basically useless? (insert your answer below)
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#98My bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like "Hello Mr 67, before we start I'll need your pin" "I have a pin?" "Yes, when you set up this account you were given a pin required for phone access" "Really? I have no idea what it is..." "That's ok. If you can just answer these other fe…
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#99Earlier quoted context omitted.
On Google's "Enter your code" screen, if you click the "Don't have your phone?" link, you get a pop-up that gives you the following options: * Use a backup code. Learn more * Send to your backup phone number ending in ## * I cannot access any of my phones Learn more I presume option #2 is the one cubicle67 is referring to. So yes, if someone gets my phone, they can then gain access to my Google account. Grrrrr...
> So yes, if someone gets my phone, they can then gain access to my Google account. Grrrrr... Only if they also know your password. That's why it's called "two factor authentication". Simply compromising your password is not enough. They also have to capture your phone. Now, if you're stupid enough to write your password on the back of your phone.... you deserve everything that's coming to you.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#100For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…
I currently have two-factor setup on two accounts. I won't say there's no hassle involved--authorizing a machine via SMS so that I can login and generate an app-specific password is a chore--but the peace of mind is well worth the hassle.
Did you also know that you can re-assign your Apple ID to an existing e-mail address? Like, say, one you have two-factor enabled for? Now people can socially engineer Apple's flawed policy all day but they'll need to steal my phone, too.
EDIT: Also, if you don't have backups, you might as well just delete everything yourself right now and use that as motivation to prevent the same thing from happening again. Hackers, tornadoes, spontaneous combustion and ghosts are all conspiring to destroy your data sooner or later.