Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

91–100 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#91
post #23

Earlier quoted context omitted.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

I wouldn't do anything too crazy. If you're the 1 in a billion (7 billion, actually) who gets targeted like this, they'll probably still get in so you're just wasting oodles of time and adding a good dose of constant aggravation for essentially nothing.

There's many good reasons to make backups however, not just the chance that an advanced hack like this can occur. Definitely not wasted time.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#92

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?

Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked.

Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com."

I don't know for sure whether that's true or not. But assume it is true. If two-factor authentication had been enabled, then the hackers would have had a much harder time guessing Mat's email address for iCloud and whether he had a @me.com email address at all.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#93
post #29

Earlier quoted context omitted.

The most surprising thing I see out of this isn't the need for more robust authentication but for services that aren't so damn quick to do whatever you want. Website: "Hey Bill, glad to see you today, what do you want to do" Bill: "Delete _everything_ I've ever done on every system I have" Website: "Of course! Let's get this started... beep boop bip and done!" What about this: 1 - Kill request sent 2 - 48 hours is se…

I can just imagine the HN article when someone tries to delete his Facebook account because he disagrees with some new feature, and they won't do it for 48 hours. I've been on the receiving end of "DELETE MY ACCOUNT!!!1!!1" requests, and I know those people wouldn't respond well to "wait two days or pay up."

Facebook doesn't even allow you to delete your account. If a site were to remove the account from the public view, but delay the actual deleting by a few days (I'd prefer a week or more actually), you wouldn't notice the difference unless you were malicious. But I don't understand what the money is for actually.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#94

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

What if i lost my phone and didn't print backup codes? Will i lose my google account forever?

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#96
post #34

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

With every platform, there is compromise between convenience and security; when your platform has to reach many, many non-tech-y people, convenience is preferred.

There are easy trade-offs one can make between convenience and security. For example, identity verification on the phone with the last four digits of a credit card (Apple).

But then there are policies and technology that increase BOTH convenience and security. Say the difference between using SSH these days versus using, say, paper and an Enigma machine.

The inconvenience of Google Authenticator is minimal and the security provided is huge.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#97
post #72

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Myth: Right, but what happens in the very common scenario of my Android phone-- logged into Google with the Authenticator installed-- getting lost / stolen? Surely then 2-factor auth is basically useless? (insert your answer below)

Reality: You go into Google account security and choose 'Clear the phone info and printable codes' and 'Forget all other trusted computers. Require a verification code the next time I log in from any other computer'.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#98

My bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like "Hello Mr 67, before we start I'll need your pin" "I have a pin?" "Yes, when you set up this account you were given a pin required for phone access" "Really? I have no idea what it is..." "That's ok. If you can just answer these other fe…

These "security" questions are usually, IMHO, the weakest link.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#99
post #86
post #75

Earlier quoted context omitted.

On Google's "Enter your code" screen, if you click the "Don't have your phone?" link, you get a pop-up that gives you the following options: * Use a backup code. Learn more * Send to your backup phone number ending in ## * I cannot access any of my phones Learn more I presume option #2 is the one cubicle67 is referring to. So yes, if someone gets my phone, they can then gain access to my Google account. Grrrrr...

> So yes, if someone gets my phone, they can then gain access to my Google account. Grrrrr... Only if they also know your password. That's why it's called "two factor authentication". Simply compromising your password is not enough. They also have to capture your phone. Now, if you're stupid enough to write your password on the back of your phone.... you deserve everything that's coming to you.

There are plenty valid theoretical cases being made in this thread that the phone is not a fully-independent second factor from the password. Syncing phones to laptops is a big one. If your phone is compromised and you're concerned at all, you really should just reset your password.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#100

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

I was reluctant to setup two-factor for a long time, perceiving it to be an unnecessary hassle. Then somebody tried to gain access to some of my accounts through my Apple ID. They were unsuccessful (I don't have any common passwords these days so managing to send a password reset to my GMail wasn't terribly helpful) but it certainly made me paranoid enough to switch.

I currently have two-factor setup on two accounts. I won't say there's no hassle involved--authorizing a machine via SMS so that I can login and generate an app-specific password is a chore--but the peace of mind is well worth the hassle.

Did you also know that you can re-assign your Apple ID to an existing e-mail address? Like, say, one you have two-factor enabled for? Now people can socially engineer Apple's flawed policy all day but they'll need to steal my phone, too.

EDIT: Also, if you don't have backups, you might as well just delete everything yourself right now and use that as motivation to prevent the same thing from happening again. Hackers, tornadoes, spontaneous combustion and ghosts are all conspiring to destroy your data sooner or later.

Post reply on HN