"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
Wow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.
Recent 'MFA Bombing' Attacks Targeting Apple Users
121–130 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#122Earlier quoted context omitted.
>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
> On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target Funny thing is you cannot set a passphrase or equivalent recovery code unless you have an apple device. So users who have an apple account for development purposes (I hate apple device UX and wont ever use anything apple again other than to approve releases and manage certificates) and have no ap…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#123Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#124Earlier quoted context omitted.
> Particularly 1Password which I think is a pattern if I remember correctly. What does that mean?
Probably that the key has features that allows 1Password (and potentially anyone) to recognize that its a 1Password key. E.g. Fixed size, patterns of spaces or dashes, specific digits, embedded error correction, etc.
Similar to how a lot of package companies have a certain pattern, length, whatever for their tracking numbers. If there was a somewhat reliable way to say "This is a 1Password key" or "This is an iCloud key" it makes it means even without context it could be an issue.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#125Earlier quoted context omitted.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.
E.g. you could make it costly to attempt, require a notarized proof of identity -and- showing up at the Apple store, and enforce a n-day waiting period. A different employee does the unlock (from a customer service queue) than accepts the paperwork.
We don't lock people out of financial accounts forever when they forget a credential. It could definitely be solved for other types of accounts.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#126Earlier quoted context omitted.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#127Earlier quoted context omitted.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
Have you seen how easy it is to get fake government ID? It’s damn near a rite of passage for teenagers so they can buy alcohol. $20-$50 if you know the right person or can wander the dark web right. I’m not sure you want that to be the absolute best digital security you can get.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#128Earlier quoted context omitted.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
Because they aren’t required to by law. I have filed comments with the FTC that this recovery path should be legally mandated for digital accounts, I encourage others to do the same. It doesn’t have to be an Apple Store (insider risk, see SIM swapping analogy); could be USPS or another government identity proofer they partner with. Login.gov uses USPS for in person identity proofing, for example. Your data and accoun…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#129Earlier quoted context omitted.
Because they aren’t required to by law. I have filed comments with the FTC that this recovery path should be legally mandated for digital accounts, I encourage others to do the same. It doesn’t have to be an Apple Store (insider risk, see SIM swapping analogy); could be USPS or another government identity proofer they partner with. Login.gov uses USPS for in person identity proofing, for example. Your data and accoun…
Well previously when stock trades involved exchanging physical certificates, I could imagine that ownership could evaporate if you lost that piece of paper. Or just think about cash: you do lose that ownership when you lose that magical piece of paper. It's a simpler world when what you have physically determines what you own.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#130Earlier quoted context omitted.
But you shouldn't ONLY store it in a box or in your house. That means you're one natural disaster away from losing everything. As much as it can "weaken" security, an electronic backup is still recommended for most
Why can't you bury a 2nd box in your friends yard who lives across the country?