Earlier quoted context omitted.
This has nothing to do with SIM swapping or phone numbers.
>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
Recent 'MFA Bombing' Attacks Targeting Apple Users
11–20 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#12"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#13"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
It's not a recent approach, but this is a recent campaign using it against many people. Someone likely got a list of hacked passwords from some recent dump and is going through the apple accounts from it.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#14Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
we should also update PCI DSS compliance or whatever relevant security standard to call SMS one time codes totally insecure
we can also reach insurers these companies use and tell them to force removal of SMS one time codes
do a multi pronged assault on SMS one time passcodes
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#15Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#16I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#17Earlier quoted context omitted.
This has nothing to do with SIM swapping or phone numbers.
>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
Funny thing is you cannot set a passphrase or equivalent recovery code unless you have an apple device. So users who have an apple account for development purposes (I hate apple device UX and wont ever use anything apple again other than to approve releases and manage certificates) and have no apple products are cursed to use ones phone number.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#18I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#19Same problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#20I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
Another reason to not to use phone (or the numbers) calls to verify users even with so called 'voice identification or voice ID' which can easily be broken with advanced voice cloning.