Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

141–150 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#141

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

> lose the key and no one can get you back in to your account sounds like a feature "want to totally restart your entire digital life? just rip up your key :) never worry about something from your past coming back to you ever again!

Only if you do everything at Apple.

You make posts on twitter, it's not protected the same way.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#142

Earlier quoted context omitted.

Wow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.

That would allow me to log you out of your accounts

No, it would affect login status. Just a delay between reset attempts.

No reset actually occurs until one prompt is accepted.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#143
post #132

Earlier quoted context omitted.

As much as it can "weaken" security, an electronic backup is still recommended for most Maybe I'm being dense (probably), but where would you save it? iCloud? No, that doesn't work - you need the key to access iCloud. Some other cloud storage service? No, that doesn't work - you need your phone to generate a token for access and your phone was destroyed in the same fire as the paper backup. Seems like the safe choice…

Engraved onto something like titanium would be better than a fireproof safe - they're only safe for X amount of time (I want to take a stab in the dark and say about 90 minutes?). This is how I have backed up some (since retired) crypto seed phrases in the past.

Where do you keep the titanium plate? I'd be more worried about losing it due to a natural disaster than merely having it destroyed beyond readability in a natural disaster.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#144

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

> lose the key and no one can get you back in to your account sounds like a feature "want to totally restart your entire digital life? just rip up your key :) never worry about something from your past coming back to you ever again!

That seems like the worst option. Everything up to the free tier would stay there forever with no way for you to ever request it to be deleted.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#145

Earlier quoted context omitted.

Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them

What happens if you suffer a TBI and can't remember the password? I guess you'd have bigger problems at that point.

Perhaps an estate lawyer could be trusted with the information in case you become incapacitated or dead.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#146
post #73

Earlier quoted context omitted.

I think it is a good idea in theory also, there I just that voice that says "well now that key is out of my possession" and it scares me a bit. I think I might need to look up to see if there is a known pattern to these keys that it could be easily figured out what it is even if it is just on a sheet with no context. Particularly 1Password which I think is a pattern if I remember correctly.

You could split the key a few ways if you don't want to trust that one of your stores won't be compromised https://en.m.wikipedia.org/wiki/Shamir%27s_secret_sharing

Or, just apply some simple, easy to remember permutation to the key that no one would be likely to guess - eg rot13 the key, or add 1 to every character, move the first 14 characters of the key to the end of the key, etc.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#147
post #89
post #88

At some point the ability to trigger these prompts (or ones like them, like the Bluetooth-based setup new device prompts that were in the news last year) on Apple devices is itself the problem right? Obviously it must be possible to reset ones password, but from the article it's apparently possible to make 30 requests to reset ones password in a short amount of time. What possible non-malicious reason could there be…

None, it's just that they haven't bothered adding a check for them. This isn't necessarily an indictment of them. It make sense in hindsight, but between sprints, OKRs/KPIs, and promotion packets, it's easy to let non-sexy functionality like these slip through the cracks.

It's distressing and sad that we've come to expect so little from the trillion-dollar market cap companies to which we are beholden to participate in modernity.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#148
post #69

Earlier quoted context omitted.

Linkedin will silently change your visibility settings without your consent.

Do you have a source for that? Or any more info? It’s not that I doubt it, I ask because some details like my work email, job title and place of employment has been leaking into the hands of marketing companies and I an trying to figure out how.

Your own company could've sold it to data brokers. Look into Equifax's Work Number score, it includes fun things like where you worked and how much you made. But no, let's not unionize or anything.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#149
post #3

Same problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.

The problem with adding rate limits, at least a global per user rate limit, is that you then create a new denial of service issue, preventing people from being able to recover their account.

You're telling me Facebook, with its billions of dollars and leetcode interviews, can't figure this out? That is outside the realm of computable functions?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#150

Earlier quoted context omitted.

> lose the key and no one can get you back in to your account sounds like a feature "want to totally restart your entire digital life? just rip up your key :) never worry about something from your past coming back to you ever again!

Only if you do everything at Apple. You make posts on twitter, it's not protected the same way.

I want to be upset that you've made a comment so obvious, yet sadly, there will be people in the wild that don't understand the silos platforms build. However, I doubt any of them are here reading this, but you never know.
Post reply on HN