Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

121–130 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#121
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

Wow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.

That would allow me to log you out of your accounts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#122
post #17
post #9

Earlier quoted context omitted.

>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.

> On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target Funny thing is you cannot set a passphrase or equivalent recovery code unless you have an apple device. So users who have an apple account for development purposes (I hate apple device UX and wont ever use anything apple again other than to approve releases and manage certificates) and have no ap…

I used to be hardcore about stuff like this, but as I grew older I guess I gave up some of my morality and bought things like $150 iphone # and moved on with life if it was making me $$$.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#124
post #86

Earlier quoted context omitted.

> Particularly 1Password which I think is a pattern if I remember correctly. What does that mean?

Probably that the key has features that allows 1Password (and potentially anyone) to recognize that its a 1Password key. E.g. Fixed size, patterns of spaces or dashes, specific digits, embedded error correction, etc.

Yeah that is what I mean.

Similar to how a lot of package companies have a certain pattern, length, whatever for their tracking numbers. If there was a somewhat reliable way to say "This is a 1Password key" or "This is an iCloud key" it makes it means even without context it could be an issue.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#125

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.

There's a wide set of possible approaches between "let any employee validate any ID" and "never let someone into an account that they have lost the credential to."

E.g. you could make it costly to attempt, require a notarized proof of identity -and- showing up at the Apple store, and enforce a n-day waiting period. A different employee does the unlock (from a customer service queue) than accepts the paperwork.

We don't lock people out of financial accounts forever when they forget a credential. It could definitely be solved for other types of accounts.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#126

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.

Aren't SIM swapping attacks only such a problem because you can get a new SIM without showing up in person with ID?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#127
post #104

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

Have you seen how easy it is to get fake government ID? It’s damn near a rite of passage for teenagers so they can buy alcohol. $20-$50 if you know the right person or can wander the dark web right. I’m not sure you want that to be the absolute best digital security you can get.

Okay, then also require a photo when opting in to this, and make sure the person who shows up looks like said photo too.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#128

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

Because they aren’t required to by law. I have filed comments with the FTC that this recovery path should be legally mandated for digital accounts, I encourage others to do the same. It doesn’t have to be an Apple Store (insider risk, see SIM swapping analogy); could be USPS or another government identity proofer they partner with. Login.gov uses USPS for in person identity proofing, for example. Your data and accoun…

Well previously when stock trades involved exchanging physical certificates, I could imagine that ownership could evaporate if you lost that piece of paper. Or just think about cash: you do lose that ownership when you lose that magical piece of paper. It's a simpler world when what you have physically determines what you own.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#129
post #128

Earlier quoted context omitted.

Because they aren’t required to by law. I have filed comments with the FTC that this recovery path should be legally mandated for digital accounts, I encourage others to do the same. It doesn’t have to be an Apple Store (insider risk, see SIM swapping analogy); could be USPS or another government identity proofer they partner with. Login.gov uses USPS for in person identity proofing, for example. Your data and accoun…

Well previously when stock trades involved exchanging physical certificates, I could imagine that ownership could evaporate if you lost that piece of paper. Or just think about cash: you do lose that ownership when you lose that magical piece of paper. It's a simpler world when what you have physically determines what you own.

If the deed to land or the title to a car gets destroyed, what happens? It doesn't suddenly forever become unownable.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#130

Earlier quoted context omitted.

But you shouldn't ONLY store it in a box or in your house. That means you're one natural disaster away from losing everything. As much as it can "weaken" security, an electronic backup is still recommended for most

Why can't you bury a 2nd box in your friends yard who lives across the country?

[deleted]
Post reply on HN