Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

101–110 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#101

Earlier quoted context omitted.

All the major registrars I know of offer free whois privacy services.

What does such a privacy service entail?

As far as setting it up, usually just a checkbox somewhere on the registrar's admin panel.

As far as the results, all of the contact information in the public whois record is replaced with the registrar's contact information. They will forward information on to you if absolutely necessary.

I keep whois privacy turned on for all my clients just to protect them from that damned Domain Registry of America scam.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#102

I don't have a blog and I don't know the proper convention for those "Show/Ask HN" posts so I suppose a comment here is the next best thing because my question is related. After reading the "Yes, I was Hacked. Hard." post I updated several of my passwords and found that Netflix enforces a 10 character limit on their passwords. Does anyone have an idea why or how this could be the case? I would find it very ironic if…

Very likely its just some sort of limit imposed by a security API or library call. Definitely not a way to save space. Its really idiotic - they should be extending it out to longer than that, but there are still some banks around that impose shorter limits than this (8 chars) so they are in good company.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#103
>"the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification"

I don't see how this is an Amazon security flaw. The last four digits of my credit card is printed on receipts from just about every merchant I transact credit card purchases with. Treating such public information as if it is a PIN places the flaw clearly in Apple's court.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#104

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

"Myth: I've heard two factor authentication doesn't work in IMAP and POP"

I've found this to be true - to a certain extent. I had two factor authentication turned on and found it to be a nightmare in OSX Mail. Failures to retrieve mail, asking for my password constantly, etc. I was resetting the application passwords every two days. I tried to research a fix, but in the end it became less of a hassle just to turn it off and have my email work 100% of the time.

It's probably a bug in Mail.app in Lion, but I can't say my experiences with two factor auth have been positive.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#105
post #38
post #35

Earlier quoted context omitted.

On the contrary, for a great many sites (low impact) I'm happy that they finally figured out to use my email address as a username. As a usability feature, it's much nicer than having to guess at whether my standard usernames are taken.

There are many problems with this. Among them that I have some iTunes purchases associated with an email account that hasn't existed in /years/. There's no way to rename an Apple account. This same problem exists on most sites that use email as username - if your email address of choice ever changes, you're SOL on having a single identity anymore.

Not only that, but I have my own domain name which forwards anything@mydomain.com to my primary email. And to keep spam under control, I use a unique email for each (low impact) service. Therefore, I often forget which email I used when signing up for that particular service (unless they sent me a conformation mail, then I can usually dig it up).

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#106

Earlier quoted context omitted.

Have you encountered any other sites that allow you to use Google Authenticator to generate OTPs? Part of the reason I think two-factor authentication is a usability burden is because each "identity provider" wants to use its own protocol. Google uses an Android app. PayPal sent me a card. My brokerage has a keychain token available. Other companies use a "soft" RSA token that runs on Windows. But if everyone agreed…

Good question. I have seen http://drupal.org/project/ga_login for Drupal, for example. Likewise, here's a write-up about using a YubiKey with Gmail's two-factor authentication: http://static.yubico.com/var/uploads/pdfs/Howto_GmailYubiKey... I believe Google Authenticator is based on open standards and open source, so people could standardize on it if they wanted too.

> I believe Google Authenticator is based on open standards

The standards implemented are bonafide RFCs - HOTP (counter-based) was published in 2005, no less. I'm not sure how much lower the barriers for integration could be.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#107

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

http://code.google.com/p/google-authenticator/issues/detail?...

The inflexible account ordering in Authenticator is bugging me, since I recently added a 5th account (not 5 google accounts) and my phone only shows 4 at a time. I don't know if you have any influence over the people maintaining the app, but it looks trivial to fix, given the comments.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#108

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Have you encountered any other sites that allow you to use Google Authenticator to generate OTPs? Part of the reason I think two-factor authentication is a usability burden is because each "identity provider" wants to use its own protocol. Google uses an Android app. PayPal sent me a card. My brokerage has a keychain token available. Other companies use a "soft" RSA token that runs on Windows. But if everyone agreed…

Meraki (full disclosure: my employer) has two-factor authentication for their network config/admin web interface; whatever the tool used (I haven't worked on that part of our codebase), it is compatible with Google Authenticator.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#109

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?

If I'm reading the blog post correctly, his Twitter account was compromised via GMail. If his GMail account had not been compromised, they wouldn't have gained access to his Twitter feed (which was the true target of the attack).

They would still have been able to compromise his iCloud account and thus destroy the data stored on his computers.

Unfortunately, I think that in this particular case, having two-factor auth on GMail wouldn't have helped. His account was compromised by having a password recovery email sent to his iCloud address. Presumably, password recovery bypasses two-factor auth.

In this attack and the earlier CloudFlare attack, the attacker took advantage of inappropriate recovery email settings. While it's reasonable for consumers to enter recovery emails, I think that professionals should avoid enabling them. When a @gmail.com sends recovery mail to @me.com (or vice-versa), the attack surface is greatly increased.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#110

Earlier quoted context omitted.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

Honestly, the credit cards are the easiest part. I'd much rather someone get my credit card number than my email account.

I agree with you but I think the idea of having a credit card just for online stuff is to limit the ways in which someone can get access to any information about your credit card, like the last 4 digits. For example, someone who finds your credit card receipt at a restaurant would get the digits of a different card and couldn't get access to your AppleID.

It's actually a good idea. I'll think about doing that…

Post reply on HN