Live data from Hacker News

I got hacked, lost crypto and what it says about Apple’s security. Part 1

ksaitor.medium.com

1–10 of 60 posts

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#2
So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in the few places they had it; no separate password for Chrome browser sync's DB; no secure password management app; and kept the keys to their crypto accounts in the cloud. The list of compounded failures is long. There's no reason to think this has anything to do with Apple at all.

They haven't learned any lesson, either. Their advice after this? Turn your laptop off when you're not using it (useless) and use Google Voice for 2FA. This is worse than useless; this is actively bad advice and you should not follow it.

The average user should install 1Password and use a TOTP application. Anyone can learn to do that, and it's really all you need. More advanced users, those with particularly extreme security needs, and pedantic nerds can use YubiKeys, hardware wallets, self-hosted password vaults, PGP-encrypted backup codes, and other measures that are worth considering, but aren't as approachable for everyone.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#3

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

For any significant bitcoin amounts I would buy some cheap laptop and use it as offline storage without ever connecting it to anything. I don't trust hardware wallets because they are an obvious target for attacks, but one can't attack offline computer.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#4

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Why are 3rd party password stores like 1Password better than Apple’s Keychain or Google’s password store?

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#5
> Do not save passwords in your Chrome. Or, if you do, make sure your Google account has multiple levels of 2FA. SMS is not one of them.

I stopped using Chrome but now realize I never thought to check into what it has saved for me. I’ll have to check into that and erase it all if I can.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#8
post #4

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Why are 3rd party password stores like 1Password better than Apple’s Keychain or Google’s password store?

The attack vector in this case appears to have been read access to the user's SMS messages. (Via some kind of a tee rather than a traditional SIM swap, since the user was also getting copies on their phone. My best guess would be that their mobile operator runs one of those crappy services for reading your SMS via a web browser.)

There is no sign that the attacker had a keylogger on the user's laptops, for extracting passwords. If they did, they wouldn't have needed to do account recovery on all these accounts. So the master password of a traditional password manager would not have been compromised.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#9

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#10

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

For any significant bitcoin amounts I would buy some cheap laptop and use it as offline storage without ever connecting it to anything. I don't trust hardware wallets because they are an obvious target for attacks, but one can't attack offline computer.

> buy some cheap laptop and use it as offline storage

Cheap laptop might not have redundancy, so if your SSD dies, you might be in for a rough ride. Best case, you can recover your wallet, worst case you're SOL.

Post reply on HN