Earlier quoted context omitted.
> 2-factor auth has been cracked before I wish people would stop bandying this about as if there was an actual flaw in the 2-factor app or the protocol or crypto algorithms used. The linked breach was likely due to a social engineering attack on phone company support staff. Yes, it's concerning, and something Google and the phone companies should be investigating, but no, 2-factor auth wasn't "cracked." Someone who's…
Given your iCloud account and/or root on the PC paired to your iPhone, I think it would be possible to compromise your Google Authenticator app. At the limit, jailbreak the connected phone, but I think it could be done more simply (all you need to do is run the Authenticator app and see the screen within 60 seconds, which should be possible from a connected, paired Mac). On Android, way way easier, due to lack of sec…
How Apple and Amazon Security Flaws Led to My Epic Hacking
251–260 of 264 posts
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#252Earlier quoted context omitted.
I can just imagine the HN article when someone tries to delete his Facebook account because he disagrees with some new feature, and they won't do it for 48 hours. I've been on the receiving end of "DELETE MY ACCOUNT!!!1!!1" requests, and I know those people wouldn't respond well to "wait two days or pay up."
Facebook doesn't even allow you to delete your account. If a site were to remove the account from the public view, but delay the actual deleting by a few days (I'd prefer a week or more actually), you wouldn't notice the difference unless you were malicious. But I don't understand what the money is for actually.
I was thinking about remote storage and devices. For example, a backpack is stolen with your phone/tablet/laptop and you need to issue a wipe to it NOW before they are compromised.
Requiring a credit card at least leaves a paper trail of some sort.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#253Earlier quoted context omitted.
Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?
Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked. Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many character…
The problem may be that "me.com" is so short that Google might display the full domain name. If that's the case, Google should fix it.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#254Earlier quoted context omitted.
Not quite the same as two factor auth (almost the opposite in fact), but I was extremely annoyed when gmail started relentlessly asking me to add a backup email address for password resets. Had the author not had an insecure backup email address, this wouldn't have happened either. Of all the passwords I'm likely to forget, gmail ranks near the bottom. The password to login to who knows where to get the gmail recover…
That's absolutely true. I was horrified last week when I discovered my Gmail account ( with a unique 30-character long password, 2-factor enabled, NEVER used unless on my MacBook at my house ) had a "backup" email address to my Yahoo account from 8 years ago, with the nice password '1123581321'. I could've killed myself.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#255Last time HN discussed this story, I said "turn on 2-factor authentication for your Google account". Unsurprisingly, I got the exact reaction I'm seeing here when it has been suggested: lots of questions about how it works, people who think their situation is unique so it won't work for them, and people complaining than SMS is insecure. 1) Don't ask anymore questions. Try it out, if you hate it turn it off. 2) Your s…
This seems like poor advice. If people have questions, they should be addressed, not "oh don't worry your pretty little head, smart people came up with this." Like the discussion about app-specific passwords above was very informative to me... all it takes is one of those getting sniffed or read off disk and someone can suck down all your email. Not exactly "fire and forget" security.
I'm saying that people should turn it on, and try it. Most of the questions are the kind of things that would be solved by just trying it!
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#256Last time HN discussed this story, I said "turn on 2-factor authentication for your Google account". Unsurprisingly, I got the exact reaction I'm seeing here when it has been suggested: lots of questions about how it works, people who think their situation is unique so it won't work for them, and people complaining than SMS is insecure. 1) Don't ask anymore questions. Try it out, if you hate it turn it off. 2) Your s…
>Don't ask any more questions - just try it out! Not even these question: Aren't we as tech people completely and utterly failing the world at large when the best possible response to this story is to turn on 2 factor auth on one of the many accounts a person has? Is a very slight reduction to the attack surface really the best we can do? Seriously?
At the moment, yes, I think it is.
At some point in the future perhaps this may improve (although I wouldn't count on it).
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#257Earlier quoted context omitted.
My bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it. Turns out, when I can't remember it they tell me the first 2 letters!
They must have some advanced crypto where the customer support person can only see the first 2 letters but the rest of password remains securely hashed...
I don't believe there is any hashing going on, after all, the bank in question is ANZ, they don't even use TANs for online-banking.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#258Earlier quoted context omitted.
Then why are you not using POP or IMAP with a separate password? What are they going to do with the auth code when they don't have your original password? I'm not trying to defend their stupid choice of offering option #2, but rather trying to offer a solution to your current problem.
I find option #2 to be very useful, not stupid. If my phone becomes unavailable (eg lost/ stolen/ dropped in a toilet) then I need a backup option to login. The backup options Google provides are: * Use a backup code * Use a backup phone number * None of the above, I still need help! 1. The backup codes are suggested to be printed and stored in a wallet; however you can put them anywhere you like. 2. The backup phone…
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#259Earlier quoted context omitted.
Someone big got hacked this way recently - the attacker managed to social-engineer a call forwarding change, then used a "landline 2FA auth call" to gain the foothold then needed. (I think it was Cloudflare?) It's similar to @mat's problem - Amazon assumed the CC last 4 digits was "non identifying", Apple assumed they were. How much effort do you suppose your phone company expends securing your voicemail or call forw…
I heard about this hack too ( http://blog.cloudflare.com/the-four-critical-security-flaws-... ), but I disagree with you - the last 4 CC digits should be considered non-identifying. First, let me explain a little bit of background on this "hack". From the article, they had 4 problems with their process that allowed them to get hacked badly: 1. AT&T was tricked into redirecting my voicemail to a fraudulent voicemail b…
(And, there are many alternative and easier ways to acquire most people's cellphone number - no need to meet someone or get them to give you a business card… But your point still stands…)
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#260Earlier quoted context omitted.
I heard about this hack too ( http://blog.cloudflare.com/the-four-critical-security-flaws-... ), but I disagree with you - the last 4 CC digits should be considered non-identifying. First, let me explain a little bit of background on this "hack". From the article, they had 4 problems with their process that allowed them to get hacked badly: 1. AT&T was tricked into redirecting my voicemail to a fraudulent voicemail b…
I think we're vigorously in agreement here - the last 4 CC digits are certainly not identifying, and I'm perhaps a little less forgiving that you in letting Apple off for thinking so. I'm also not happy with Amazon's assumption that they should be displaying them quite so easily (although at least they don't display them until you're far enough "in" to an account - and it's not easy to work out an alternative way to…
It's true about a cellphone number -- from what I heard about his attack outside of this article, this a very targeted attack, and the attacker knew exactly what kind of data to expect in the GMail account, which is what led me to conclude that the attacker probably knew or met the victim, but likewise, good point about obtaining the cell in other ways.