Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

131–140 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#131

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

Never considered? Try to call them someday if you forget your passwords, you'll see how easy it is.

My solution at the moment is to remove every passwords from icloud. There're some nice scripts online - just did that and blogged about it on http://en.blog.guylhem.net/post/28778777551/icloud-remove-ke...

It's obvious it can't be trusted until 2-way auth is implemented. hell - if I manage to forget my password and loose my cellphones and homephone numbers, I WANT my icloud data to be gone for good!

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#132
Hopefully the article on Honan's experience will open some eyes and make everyone take the security of their personal accounts more seriously. The money in your bank is insured, your online presence is not, and there is a huge imbalance in how consumers address security for each. Some hackers don't want money or notoriety - they just want to watch the world burn.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#133

The thought hadn't cross my mind, but after reading this post it got me thinking: Sensa So, let's get this straight...a hacker "decides" to hack the account of a semi-high profile tech guy and then after committing several serious crimes like fraud that could land him in jail for an extended period of time repeatedly contacts the person he hacked when he must know that Apple will surely pursue this matter? I smell a…

What are you even alleging? What is the rat?

I'm not alleging, I'm quoting a comment from MacRumors that got my attention.

The fact that a hacker would repeatedly contact its victim and that Gizmodo has reasons for not being particularly found of Apple (after the lost iPhone incident) was not something I had though of at first, but did strike me as odd.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#134

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

I have no idea if this is related, but just now I attempted to purchase an app on the Mac AppStore and, after authenticating, I was given a prompt to re-enter my password and:

Improve Apple ID Security

- To help ensure the security of your Apple ID, choose three security questions and answers.

Just random because I don't have challenge responses on record, or immediate low-hanging fruit in response to this breach?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#135
post #90
post #77

Earlier quoted context omitted.

not useable in all country. Not applicable on imap, pop3. Use case where an email account serve more than 1 physical person. Unusable while you travel.

It's quite possible to add two-factor logins for any protocol, that works in any country with a cell phone network. Just demand a response to a challenge via cell phone before validating the password, you could even require one of those RSA token thingies if you want. Just a matter of cost and convenience.

I used 2 step verification for my gmail. Our cell phone operator cannot receive international sms (I know, that sucks), so I used my home phone, so every time I logged in to my gmail I received a call from google voice robot to tell me the pin number. It sounded perfect at first, but when I started to actually use it, I noticed everytime I needed to login to gmail, I wasn't home. I'd call my parents so they could say me the pin or use the backup codes that google provided me with. That was so uncomfortable I had to turn it off.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#136
post #97

Earlier quoted context omitted.

This should make every user of every online service really nervous. It sort of makes the Google/Facebook model of "it's impossible to actually talk to a human" look good.

You know, as much as I laughed at your comment I think you have a point here. The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.

True, however it also means if your account does get hacked, you will have to wait weeks until they respond to your plea for help (if they respond at all).

I think neither of these is the solution. If you can't talk to a human you'll never get help if you're locked out. If human support is available, there is always a chance they'll hand over your account to some scammer. Two-factor authentication means you'll be screwed if your second medium is unavailable or highjacked.

Maybe the only way to protect yourself is having independent (offline?) backups that only can control. Sadly, that's not an option regarding a lot of walled-garden services such as Facebook or iCloud.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#137

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

"Humans are the security hole that can never be patched." Social engineering will always work.

There was an article about HFT recently [0] that mentioned a case where social influence is of small importance: the game is played beyond human capabilities even when really needed.

[0] http://news.ycombinator.com/item?id=4339531

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#138

Earlier quoted context omitted.

I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions? I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was…

I was out of town and went to make a large cash purchase. (The retailer added a very hefty 10% for using debit or credit cards.) So I ran into the problem of a daily cash withdrawal at the ATM. I also did not have anything with me other than an ATM card and a Credit card with me (No ID). Turned out the bank didn't even ask for my ID when I went in. I just explained my situation and they just handed over a couple thou…

> Security at the bank seems discretionary at best

No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address.

The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the legitimate transactions harder, and chances are it won't affect those trying to commit fraud since they have a wide variety of things to try while tellers don't (eg fake id in this case).

In this specific case, anyone coming into the branch is on security cameras inside and out. TV shows, the Internet and technology make it increasingly easier to match up the footage with real people. And the bank doesn't bear the full costs of any investigation since they are passed off to the police/FBI.

If you ran the bank would you add a dollar in expenses and one minute per transaction that has a 10% chance of catching fraud, and fraud occurs one in every 25,000 transactions? Would you have the same measures in every branch across the country or have their expense and severity proportional to the amount of fraud that does actually happen at any location?

Despite what we see in films and TV shows, bank robbery is pitiful way to not make money:

http://www.thefiscaltimes.com/Articles/2012/06/11/Why-Robbin...

http://crimeblog.dallasnews.com/2009/04/new-bank-robbery-sta...

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#139

Earlier quoted context omitted.

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

I have no idea if this is related, but just now I attempted to purchase an app on the Mac AppStore and, after authenticating, I was given a prompt to re-enter my password and: Improve Apple ID Security - To help ensure the security of your Apple ID, choose three security questions and answers. Just random because I don't have challenge responses on record, or immediate low-hanging fruit in response to this breach?

Probably just a result of having no challenge responses on record. I experienced something similar a couple of months ago.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#140
post #58
post #34

Earlier quoted context omitted.

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

Physical IDs can be faked.

Physical IDs don't get faked [in places where serious physical IDs are used, USA driverlicences in bars don't count] - it's simpler to make counterfeit dollars than counterfeit passports; from what I have seen from banking fraud statistics, if physical IDs are required, fake ID's are an extremely rare circumstance. You do get cases of (a) stolen IDs and (b) IDs bought off of homeless guys, and then used to open accounts and register companies for money laundering, etc. But not fake IDs - it's apparently too much effort and risk when compared to stealing or buying identities.
Post reply on HN