Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

81–90 of 90 posts

Re: Update to Celebrity Photo Investigation

#81
post #33

Earlier quoted context omitted.

Whenever these types of questions are required for account recovery, I use a false set of answers as an additional security measure. Probably a good practice for a celebrity.

If the only way to safely use the system is to deliberately ignore its instructions ("provide answers to these questions"), then the system is broken.

I agree, however sometimes your front brakes are out and you still need to bike home. A bit of critical thinking can allow you to largely overcome a serious safety issue. Saying "the system is broken" is less helpful than saying "since it's broken, give this hack a try," IMO.

Re: Update to Celebrity Photo Investigation

#82
post #80
post #44

If I was in Hollywood right now I'd be offering high-price security consultation services to teach celeb's how to use 2FA.

How do you 2fa iCloud? You end up carrying your phone and and auth token?

http://support.apple.com/kb/ht5570

> When you set up two-step verification, you register one or more trusted devices. A trusted device is a device you control that can receive 4-digit verification codes using either SMS or Find My iPhone. You're required to provide at least one SMS capable phone number.

> Then, any time you sign in to manage your Apple ID at My Apple ID or make an iTunes, App Store, or iBooks Store purchase from a new device, you'll need to verify your identity by entering both your password and a 4-digit verification code, as shown below.

Re: Update to Celebrity Photo Investigation

#83

Earlier quoted context omitted.

Just because a lot of companies are using the system does not make it secure. Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.

You're right. I guess I have too much faith in the average user to not pick a question with a potentially obvious or easily discovered answer to it.

I forget the term for it, but it's exactly like Terms and Conditions. Always expect the user to solve any puzzle put to them using the least amount of energy/effort. It's quite honestly not worth it to anyone to go through the work of securing their information/data/whatever until it's actually genuinely at risk or they have lost something in the past. Until then it's an impedance and an annoyance that makes them very unhappy.

Once something like this happens it's impressive how much cognitive dissonance there is behind the excuses those very same people make or their claims that not enough was done to protect them. Don't get me wrong, these individuals were horribly victimized and it's not ok, but we can't allow ourselves to be satisfied by just blaming the company, especially if they otherwise provided the tools that would have kept the account secure. We can only realistically expect the companies we entrust our data to be responsible for making it possible for us to secure our data and not leaking it through other systemic failures. If we choose to shortcut it then it's our responsibility to learn from that and do better next time. We can't blame anyone involved here for doing what they should otherwise be motivated/expected to do. Apple provided the tools to protect the accounts, and as far as we know didn't allow them to be otherwise compromised. The victims set up their accounts in a way that they could easily access/recover them in the future (honestly, it's now required to remember around 20+ account passwords to manage our lives and it's only getting worse) regardless if they knew the risks or not. Security education is out there and it's as loud as we could hope to get it, people just won't internalize it until the risk is tangible. We can demand that companies like Apple, but it won't actually improve anything if people can't be bothered to use them or more importantly find it WAY more inconvenient and seek ways to bypass them in whatever way possible just to get them out of the way.

It's a shame that this is blowing up for Apple as if it's all Apple's fault, but maybe some good can come from it.

Re: Update to Celebrity Photo Investigation

#84

Earlier quoted context omitted.

Just because a lot of companies are using the system does not make it secure. Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.

You're right. I guess I have too much faith in the average user to not pick a question with a potentially obvious or easily discovered answer to it.

My favorite are banks that require you to use their security questions which are along the lines of "What city were you born in?"

The average user probably trusts their bank, and assumes that their bank is doing everything to protect them, and unknowingly compromise themselves by putting in correct answers to trivial questions.

Re: Update to Celebrity Photo Investigation

#85

So i'd wager there'd be quite a few celebrity dick picks available too if hackers wanted them. We know men like to send them unsolicited, and I'm sure those celebrities had received more than a few. But there are none. And why? Because those women were specifically targeted by people with a lot of resources and patience. (it's important that they were targeted specifically for being women). To all of you idiots blami…

Re: 1) 2FA wasn't in use by these individuals. If you read the Apple release they not only neglect to mention 2FA as a source of the breach but actively encourage users to sign up for it. If 2FA was in place I doubt that this vector would have been successful.

That being said, I think the culpability is on Apple here as much as it is on the individuals responsible for obtaining the links. Security questions were never good security and companies need to start moving away from failed models.

Re: Update to Celebrity Photo Investigation

#86
post #85

So i'd wager there'd be quite a few celebrity dick picks available too if hackers wanted them. We know men like to send them unsolicited, and I'm sure those celebrities had received more than a few. But there are none. And why? Because those women were specifically targeted by people with a lot of resources and patience. (it's important that they were targeted specifically for being women). To all of you idiots blami…

Re: 1) 2FA wasn't in use by these individuals. If you read the Apple release they not only neglect to mention 2FA as a source of the breach but actively encourage users to sign up for it. If 2FA was in place I doubt that this vector would have been successful. That being said, I think the culpability is on Apple here as much as it is on the individuals responsible for obtaining the links. Security questions were neve…

Security questions are just horrible. 2FA is good, but these celebs have people that handle their social media, so even if the technical leaks are plugged, things would just move to social eng. tactics, bribe an assistant, etc.. Probably a number of people have a celebs Twitter password.

Pretty worthless statement by APPL. "happpens all the time", "not our fault", etc.. They should be called out for security questions in the 1st place if that's what they use at all. Even after Sarah Palin which was greatly publicized. These companies learn nothing.

Re: Update to Celebrity Photo Investigation

#89
post #45
post #3

So "This is a very common attack on the Internet that we didn't do much to protect you against by default"? It's a pain setting up two step authentication across a lot of services, but I guess iCloud is probably one that's worth the effort. Still I'd rather brute force was not an option.

The recently fixed "find my phone" feature doesn't support two-factor auth because, presumably, you can't find your phone to get the second factor.

[deleted]

Re: Update to Celebrity Photo Investigation

#90
post #59

Earlier quoted context omitted.

Nitpick: Ambassadors work in an Embassy.

http://www.merriam-webster.com/dictionary/ambassador > 2 a : an authorized representative or messenger > b : an unofficial representative

Parent had ambassador spelled as embassador.
Post reply on HN