Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

11–20 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#11
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

Not a solution, but I have a feeling Apple is going to be tightening their policy very soon. This story has gotten a lot of attention.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#12
post #7

We need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem. One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protes…

If you're trying to remote-wipe your computer so that a thief doesn't access your sensitive data, wouldn't you want the data to be lost permanently?

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#13
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

run your own server.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#14
post #7

We need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem. One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protes…

I assume the remote wipe zeros out the data a few times, otherwise the feature is somewhat useless.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#15
post #7

We need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem. One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protes…

If you ever reach the point that your account is so hard to recover that it requires human customer service intervention, the recovery process needs to be tedious and thorough.

"Okay, I'll need a notarized copy of a photo ID and once we have that, we'll give you a call to the number we have on file to confirm the change."

It's not perfect, but it would require an extremely dedicated and targeted attack to bypass, as opposed to "Hi, I'm your pizza delivery guy. I took a look at the receipt before I delivered your pie, and now I know the last 4 on your CC, your billing address, and your name. Let's go iCloud fishing!"

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#16
post #3

Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…

the weakness with 2-factor auth is that almost all of us with a smartphone use that phone for email. And that phone is the same one google sends the sms to...

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#17
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

Honestly, the credit cards are the easiest part. I'd much rather someone get my credit card number than my email account.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#18
post #2

It turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

Give your parent's email as your recovery email address. If you need to reset, you can call them and talk them through clicking the link and resetting the password.

The bad guys then have to crack your parents email account too, and being older they will be less likely to have daisy-chained Google, Apple and Amazon accounts.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#19
post #3

Given how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but…

I've been using google two-factor auth for the better part of a year now, and the annoyance comes down to, once every 30 days or so, having to take 5 extra seconds during login to enter a code sent to my cell phone.

I can't _think_ of anything less of a hassle.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#20

Can we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!

How is that going to help? Are people going to be expected to use a unique username per site? And password recovery is still going to let someone take over.
Post reply on HN