This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.
Apple Support Allowed Hacker Access to Reporter's iCloud Account
121–130 of 181 posts
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#122I helped a friend set-up a account with some provider the other day and one of the security question was the classic choice of mothers maiden name, favourite colour or favourite number. All of which are hardly secure as they can be obtained or educated-guessed a lot easier than most, but that’s another discussion. He wanted his favourite football player's name, so I told him pick mothers maiden name and use your favourite football players name. He knows this, and even if somebody who knew his mothers maiden name would still fail on that security check.
What could Apple do; And they will do something I suspect. Well they could add voice recognition to there support call system or/and add preregister calling numbers only (excluding device phone numbers already to cover losing said device) like your office phone. But they will step up-to the plate and hopefully turn this around, any good tech company will do that (even if it is going oops and we added password salts now - they evolve).
The whole aspect about all this that concerned me was how you can have what you perceive as a cloud backup that can then be taken away as well as your copy of the data. That is a lesson for the user more than Apple though. But will be reassuring to find out they have a backup system and maybe also concerning. That is a individuals perception of thought for them to ascertain for themselves, everybody is different.
I might also add that the chap who initial got hacked and subsequently also had his twitter accounts hacked said in a tweet that he is leaving the hacked tweets in the same way he does not go about removing scars on his body. Shows a insightful mindset and in many ways shows that pride was not a part of this and in that we would probably not of read about this had he been burdened by pride. Respect has to be noted there for him stepping up and going, this happened before he found out how it had been done and without knowing it was not an act of his own doing.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#123I frequently want to quickly purchase a song on my iPhone. I also, frequently tell my friends my password so they can do the same. How many of you have typed your Apple ID password on your Apple TV with others watching? I wouldn't really ask my friends to exit the room to type in a super secure and long password with many characters groups (one that should be required for remote wipe functionality).
How many users keep their password secure knowing the main place they enter it is on their iOS device? For the many every day Apple users I know, they set their passwords to something easy so they don't have to hit their keyboard too many times when entering them.
If Apple, can separate the two authentication functions as they do with OS X and FileVault it would go a long way to preventing these types of rare but high impact events. Another suggestion would be to separate the remote wipe into two phases, erasing the keys and cleaning up the data. The initialization vectors (seed) do present a bit of a problem but I think the FileVault solution is more than adequate. If the encryption keys and the key escrow system is cleared remotely, that would leave me comfortable that my data is still secure. If we really trust our crypto algorithms, then erasing data and removing the encryption keys should really be no different. Users that do not have iOS data protection and OS X FileVault turned on, cannot be considered any level of secure anyway. And even with that data protection turned on, there are still many issues due to each app needing to implement security properly. It would be really great to see Apple improve their App Store to really audit the security of each application more than they do today.
Most of the work lies with Apple but it is a hard problem that will take time. I think Apple is going in the right direction by centralizing on iCloud rather than the PC as the central hub. This will give them a lot more flexibility and agility to move quicker and deliver secure results to the masses.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#124It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…
Social engineering will always work.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#125It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#126Earlier quoted context omitted.
On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.
I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions? I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was…
Security at the bank seems discretionary at best.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#127It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
In fact that entire blog post is pretty on point.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#128Earlier quoted context omitted.
Physical IDs can be faked.
Isn't that an area that cannot be controlled at all? There are government issued IDs and if a normal company cannot trust them, then there's no way out. Biometric identification can be the last unbreakable protection, but that's also only valid until you find someone who, for example, lost/damaged his eyes in an accident and is up for scamming the company you're targeting. I mean, there's a reasonable limit of what c…
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#129Earlier quoted context omitted.
No. They just need to implement one of the common protocols. For example, they could just require ID.
If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#130Earlier quoted context omitted.
> This reminds me of facebook and how all its employees were stalking people using the god password. Wait what? Sorry to get off topic but when did this happen?
Possibly referring to this story. http://online.wsj.com/article/SB1000142405270230489870457747... If so, the quote only says they could stalk people with the master password, not that they were.