Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

11–20 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#11
post #9

Earlier quoted context omitted.

This has nothing to do with SIM swapping or phone numbers.

>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.

Yes, like password :)

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#12
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

It's not a recent approach, but this is a recent campaign using it against many people. Someone likely got a list of hacked passwords from some recent dump and is going through the apple accounts from it.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#13
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

It's not a recent approach, but this is a recent campaign using it against many people. Someone likely got a list of hacked passwords from some recent dump and is going through the apple accounts from it.

I ventured as much. Given the amount of messages and the personal details gathered, I also guess attacker tools have significantly been improved or streamlined.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#14
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

I think we should start doing product liability lawsuits to any organization capable of having user financial data affected from their account, that is using SMS one time codes as either default, enabled by default, and the heaviest legal remedies to financial organizations where that's the only option

we should also update PCI DSS compliance or whatever relevant security standard to call SMS one time codes totally insecure

we can also reach insurers these companies use and tell them to force removal of SMS one time codes

do a multi pronged assault on SMS one time passcodes

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#16

I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.

Interesting. I was contemplating moving to security keys (which according to the setup flow "replaces verification codes" but IIUC you're saying one can still fall back to verification codes in some flows?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#17
post #9

Earlier quoted context omitted.

This has nothing to do with SIM swapping or phone numbers.

>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.

> On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target

Funny thing is you cannot set a passphrase or equivalent recovery code unless you have an apple device. So users who have an apple account for development purposes (I hate apple device UX and wont ever use anything apple again other than to approve releases and manage certificates) and have no apple products are cursed to use ones phone number.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#19
post #3

Same problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.

The problem with adding rate limits, at least a global per user rate limit, is that you then create a new denial of service issue, preventing people from being able to recover their account.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#20
post #15

I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.

Exactly this.

Another reason to not to use phone (or the numbers) calls to verify users even with so called 'voice identification or voice ID' which can easily be broken with advanced voice cloning.

Post reply on HN