Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

101–110 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#101
post #92
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

When I opened my Ing account I didn't need any of this. They verify your identity through a series of questions about your past, as well as your SSN. In fact, all US banks allow accounts to be opened over the 'net now. I've personally done it with several of them.

Yeah, they pull a credit report in real-time and then will do something like show you three cities and ask you to pick one you lived at in the past (with a "none of these" choice also). It's a good idea but I'd think often hackable for targets who are heavy social media users and basically have their life story online and public.

Still pretty good for now, though.

Edit: anyone know what the cost is per query for these services? I assume it's not free, thus likely not feasible for services that don't stand a good chance of providing enough revenue to offset the cost.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#102
post #90
post #77

Earlier quoted context omitted.

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

It's quite possible to add two-factor logins for any protocol, that works in any country with a cell phone network. Just demand a response to a challenge via cell phone before validating the password, you could even require one of those RSA token thingies if you want. Just a matter of cost and convenience.

Not everyone has a cell phone.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#103
post #97

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

You know, as much as I laughed at your comment I think you have a point here.

The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#104
post #87

Earlier quoted context omitted.

This is really, really important advice, and if more people understood it, corporations would have a lot less power over people than they currently do. You can open up just about any ToS and find a handful of unenforceable clauses they're hoping you won't realize are unenforceable.

I suspect the vast majority of people never read the TOS and decide to sue, or not, for completely independent reasons.

In general, I'd say that if you are getting a lawyer involved, you need to have fairly solid evidence of real loss of a value more than about $20,000, otherwise the fees are going to eat up any award you might eventually get (don't forget even if you get a favorable judgement the other side can appeal, and will if they have staff lawyers who are getting a salary either way).

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#105
post #99

Earlier quoted context omitted.

Have they? (Honest question.)

I would argue that yes, they have. They removed the copy on their website that claimed that "Macs don't get PC Viruses"[1]. They disabled automatic execution of Java Applets in response to Flashback[2]. The introduction of Gatekeeper and the App Store model shows their intention for reducing the vectors average users can install random software (which reduces rogue installations like Flashback). ASLR is fully impleme…

I would also argue that with iOS, they have the safest (big) mobile OS available as well. ASLR and DEP have long been implemented and with iOS 6 they are also implementing Kernel ASLR.

Almost everything is sandboxed and there are no known viruses out there (for devices that haven't been jailbroken).

Jailbreaks are still possible (like you said nothing is perfectly secure), but have been slowed down to a point where hackers wait for a big OS release, before they decide to burn the exploits.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#106
post #42
post #8

Earlier quoted context omitted.

I don't think I would label this horrible behavior on the part of Apple. When you provide customer service for something like iCloud things like these are bound to happen. This is a case of social engineering not some tech rep downloading plaintext passwords to a laptop and losing it. With a really targeted attack they are bound to be successful with some rep. Its a matter of when not if. Having said that they will i…

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex. This reminds me of facebook and how all its employees were stalking people using the god password. They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

Honestly, the bank protocol is overkill for 90% of users. Most people using iCloud are using it to sync photos of their cat. The number who are keeping "their life" in the cloud is basically confined to techno-geeks.

Your average iCloud user is not necessarily going to want to a) prove their identity initially or b) do so again to get support.

I think you are better off taking the approach of "don't put something in the cloud if you can't afford to lose/expose it." Yeah, that pretty much limits its usefulness, at least or now. So it is.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#107

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions?

I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was so dreadful (a 30 minutes interrogation with questions like "when and where did I make my last ATM transaction") that since then I keep the required sensitive info in a GPG encrypted file so that I never have to call them again. Other equally frustrated but less tech savvy customers are probably doing the same with post-it notes. Is this an improvement?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#108
post #91

Earlier quoted context omitted.

IIRC it does the wipe via the recovery boot, so wiping that partition would kill it. BUT: you'd be hosed if you ever needed recovery, you wouldn't be able to use full-disk encryption, and there's likely other bits of the OS that would break in subtle and interesting ways without it there. Tread _very_ carefully.

>IIRC it does the wipe via the recovery boot, so wiping that partition would kill it. Isn't this not an option in relatively recent Macs, which have the recovery functionality baked into the EFI firmware and not as a partition on the disk? Newer Macs have that functionality out of the box, and a bunch from 2010 and early 2011 that did not originally ship with the recovery firmware ended up getting it later via update…

That's 'Internet Recovery', which is just enough to fire up WLAN and grab a recovery image to netboot from in the event your disk is totally unreadable. Unlikely it'd still be able to trigger a wipe this way. Recovery itself is still it's own partition (from my mid-2011 Air):

    apaulin:~/ $ diskutil list                                                                                                                                                                       [13:38:41]

    /dev/disk0
   #:                       TYPE NAME                    SIZE       IDENTIFIER
   0:      GUID_partition_scheme                        *121.3 GB   disk0
   1:                        EFI                         209.7 MB   disk0s1
   2:                  Apple_HFS Macintosh HD            120.5 GB   disk0s2
   3:                 Apple_Boot Recovery HD             650.0 MB   disk0s3

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#109
post #97

Earlier quoted context omitted.

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

You know, as much as I laughed at your comment I think you have a point here. The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.

Security through support obscurity?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#110

Earlier quoted context omitted.

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions? I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was…

Sure - you need physical access to get to someone's post-its. Might as well install a keylogger then.
Post reply on HN