Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

101–110 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#101

Earlier quoted context omitted.

As much as it can "weaken" security, an electronic backup is still recommended for most Maybe I'm being dense (probably), but where would you save it? iCloud? No, that doesn't work - you need the key to access iCloud. Some other cloud storage service? No, that doesn't work - you need your phone to generate a token for access and your phone was destroyed in the same fire as the paper backup. Seems like the safe choice…

Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them

Doesn't that just mean that Apple's X character key is protected only by a password presumably of lesser length?

I suppose a phrase works too, and easy to remember.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#102

B-but iPhones are secure and are the best and Apple spends so much money on security to keep us safe and don't need any government/EU oversight at all. Proof that Apple's "it's for your own good" has always just been marketing. (Don't get me wrong, let's go after Google, MS, Sony, et al too!!!)

I don't see where EU regulations would have helped in this case.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#103
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

> lose the key and no one can get you back in to your account

sounds like a feature

"want to totally restart your entire digital life? just rip up your key :) never worry about something from your past coming back to you ever again!

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#104

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

Have you seen how easy it is to get fake government ID? It’s damn near a rite of passage for teenagers so they can buy alcohol. $20-$50 if you know the right person or can wander the dark web right.

I’m not sure you want that to be the absolute best digital security you can get.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#105

Earlier quoted context omitted.

Also, buy some (at least three) YubiKeys and use them for your Apple ID verification instead of the dumb push MFA. https://support.apple.com/en-gb/HT213154

But is it the case that the Yubikey is essentially treated the same as a trusted device? What if I want to untrust my devices and only trust ubikeys (without removing the device from my icloud account?)

I don’t seem to have the push option now

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#106
post #67

Earlier quoted context omitted.

The security researcher in the article was concerned about accidently confirming the prompt on his watch. I don't think its a matter of being "smart enough". Human error can easily creep in when dismissing 10's or 100's of prompts.

The prompt UX should step into a special "bombed" mode when a frequency threshold is crossed, at which point accepting a prompt has fat-finger protection such as double confirmation steps, and declining all (or perhaps all that share a commonality, like same initiating IP address) becomes possible.

Or you know, not allow this kind of brute forcing at all?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#107
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

“ If you use Advanced Data Protection and set up both a recovery key and a recovery contact, you can use either your recovery key or recovery contact to regain access to your account.”

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#108
post #104

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

Have you seen how easy it is to get fake government ID? It’s damn near a rite of passage for teenagers so they can buy alcohol. $20-$50 if you know the right person or can wander the dark web right. I’m not sure you want that to be the absolute best digital security you can get.

Yes it is vulnerable to an attacker who is willing to present himself in person with a fake ID to target a specific account. However it's not scalable or remotely exploitable.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#109
post #104

Earlier quoted context omitted.

Have you seen how easy it is to get fake government ID? It’s damn near a rite of passage for teenagers so they can buy alcohol. $20-$50 if you know the right person or can wander the dark web right. I’m not sure you want that to be the absolute best digital security you can get.

Yes it is vulnerable to an attacker who is willing to present himself in person with a fake ID to target a specific account. However it's not scalable or remotely exploitable.

Since it requires a human looking at an ID and then pressing a button, the system triggered by the button press is likely quite exploitable no? Or even worse, scanning and storing an ID, which allows spoofing if those get compromised.

Recovery key isn’t susceptible to that - and isn’t susceptible to fake-id-spotting-ability or bribeability of staff either.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#110

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

  > Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
This is easy to defeat and completely subverts the purpose of the system. If you are not comfortable with self-custody then don’t opt in.
Post reply on HN