I got hacked, lost crypto and what it says about Apple’s security. Part 1
11–20 of 60 posts
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#12Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#13Why would you store cryto wallets in iCloud unencrypted? OS X makes it easy to create AES-256 encrypted sparsebundle disk images.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#14Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#15So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#16So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#17That article doesn’t say anything at all about Apple’s security.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#18Earlier quoted context omitted.
Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?
Save the security codes. I keep a small file encrypted with Veracrypt with the "top level passwords", things like email, password managers and one time recovery codes. And since this is the last recourse, the password for this file is only stored physically.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#19Earlier quoted context omitted.
Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?
Save the qrcode in 1password. Makes seeing up a new phone trivial. Also, 1password can generate the top.
Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1
#20So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…
Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?
The keys are generated by the service and you must make a note of them ahead of time. And keep them secure obviously. You get about 10 possible keys from GitHub iirc.
Also, some services (Google, apple) allow you to perform 2FA over multiple options like one of TOTP, phone call, SMS or other device interaction (in apple's case).
So if the device gets bricked, find a cheap replacement and Bob's your auntie.