Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

111–120 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#111
he received a call on his iPhone that said it was from Apple support.

"I said I would call them back and hung up," Chris said, demonstrating the proper response to such unbidden solicitations."

We're long-conditioned to assume that calling a large company and reaching a human will be difficult to impossible - and if we succeed, it will be an unpleasant experience. Much more so for a major tech company.

As far as this scam succeeds, it's partially due to intentional business designs.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#112

Earlier quoted context omitted.

Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them

Doesn't that just mean that Apple's X character key is protected only by a password presumably of lesser length? I suppose a phrase works too, and easy to remember.

[deleted]

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#113

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

I think their option for last resort is the trusted contact.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#114

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#115
post #41

Earlier quoted context omitted.

> A recovery key is an randomly generated 28-character code That's easy to backup. You can even print it and bury it in a sealed box in the garden or put it in a book or whatever. It depends who you are protecting against.

But you shouldn't ONLY store it in a box or in your house. That means you're one natural disaster away from losing everything. As much as it can "weaken" security, an electronic backup is still recommended for most

Why can't you bury a 2nd box in your friends yard who lives across the country?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#116

I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.

Just change over to using HSMs instead of push. https://support.apple.com/en-gb/HT213154

If I was doing something that needed heavy security, but I'm just a boring average joe. My critical accounts are protected by TOTP on one (backed up) device only, other things are kind of "good enough" with passkeys and passwords. If I ever become a criminal mastermind or double agent I'll probably dive into such methods though.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#117

Quite shocking how oblivious a lot of ostensibly tech savvy people are to the existence of hardware security tokens. Yubikeys have been around for over 15 years now, although Apple only added support for hardware tokens recently. https://support.apple.com/en-us/HT213154

I know they exist. I just don't really know how they work or what they do.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#118

Earlier quoted context omitted.

As much as it can "weaken" security, an electronic backup is still recommended for most Maybe I'm being dense (probably), but where would you save it? iCloud? No, that doesn't work - you need the key to access iCloud. Some other cloud storage service? No, that doesn't work - you need your phone to generate a token for access and your phone was destroyed in the same fire as the paper backup. Seems like the safe choice…

Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them

What happens if you suffer a TBI and can't remember the password?

I guess you'd have bigger problems at that point.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#119
post #3

Same problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.

The problem with adding rate limits, at least a global per user rate limit, is that you then create a new denial of service issue, preventing people from being able to recover their account.

it wouldn't be hard to add to the app though. obviously if you get a flood it's bullshit and more than a couple can be ignored. It's not rocket surgery

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#120
post #59

Earlier quoted context omitted.

Fidelity are clowns. They've spent an impressive effort breaking every god damn third party integration AND using Akamai to block scraping. I can scrape Ameriprise fine, but no matter how creative I get Fidelity gives back a weird error on login. (This is on top of them not sending any actionable email when changing my contributions to 0 in between pay periods) I'm rolling my 401k out as often and fast as possible. I…

> Fidelity are clowns. They've spent an impressive effort breaking every god damn third party integration AND using Akamai to block scraping. What’s funny/sad is they probably pat themselves on their back thinking their security is so advanced and awesome. Financial services web integrations are all total clown shows.

but can't you buy API access? I would assume that's more of a business decision to promote paid for API access, rather than "security" against scraping.
Post reply on HN