Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

151–160 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#151

Earlier quoted context omitted.

But is it the case that the Yubikey is essentially treated the same as a trusted device? What if I want to untrust my devices and only trust ubikeys (without removing the device from my icloud account?)

I don’t seem to have the push option now

Yes but my understanding is that you can remove the Yubikey without possessing it, just with a “trusted device”. I want to mark all of my devices untrusted (wrt icloud account changes) and rely only on Yubikeys

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#152
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

[deleted]

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#153
post #92

Earlier quoted context omitted.

You can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose. https://support.apple.com/en-gb/HT213154

They mention "FIDO® Certified* security keys", this presumably means physical keys only, and not soft keys like the ones that keepassxc/bitwarden provides? If so that might be too much of a hassle for me. I care about my security, but I don't care enough to drop $100 on 3 separate security keys, and finding 3 separate places to keep them secure.

You need two keys, not three.

But yes I wish you could use one hardware key as backup and one software key for day-to-day usage, or at least the security key in a trusted device (up to you to have a circular dependency to your main device or not).

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#154
post #132

Earlier quoted context omitted.

Engraved onto something like titanium would be better than a fireproof safe - they're only safe for X amount of time (I want to take a stab in the dark and say about 90 minutes?). This is how I have backed up some (since retired) crypto seed phrases in the past.

Where do you keep the titanium plate? I'd be more worried about losing it due to a natural disaster than merely having it destroyed beyond readability in a natural disaster.

What happens if there's a typo in the engraving? Who's doing the engraving? How much do you trust the people you are providing the key to do it? When does the paranoia kick in vs being diligent?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#155

I have hated Push MFA since it was introduced. How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.

You can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose. https://support.apple.com/en-gb/HT213154

It does not help you when a trusted device is stolen, the yubikeys can be disabled if they unlock your phone or device

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#156

he received a call on his iPhone that said it was from Apple support. "I said I would call them back and hung up," Chris said, demonstrating the proper response to such unbidden solicitations ." We're long-conditioned to assume that calling a large company and reaching a human will be difficult to impossible - and if we succeed, it will be an unpleasant experience. Much more so for a major tech company. As far as thi…

This is true, and it is because the public is mostly too inept to be responsible for themselves

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#157

Quite shocking how oblivious a lot of ostensibly tech savvy people are to the existence of hardware security tokens. Yubikeys have been around for over 15 years now, although Apple only added support for hardware tokens recently. https://support.apple.com/en-us/HT213154

They don’t help in the case that your unlocked phone is stolen

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#158
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

You can regenerate a new key from any logged in device, so you have to lose the key AND every device.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#159
post #15

I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.

There is already a variant where they try to get someone to say „yes“ and just use a recording of it to use as „proof“ that you agreed to some contract.

OMG that explains so much. I kept getting these calls where they would ask "Am I speaking with the head of the household?"...crap

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#160
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

Wow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.

Krebs notes that the recovery form does have some form of CAPTCHA on them, which mostly just goes to show that CAPTCHA systems are a poor and increasingly deficient rate limiter.

ETA: Also from a user experience even once a week between attempts is still enough to deeply annoy a user getting popups on their devices. This is one of those cases where rate limits probably still can't solve the user irritation.

Post reply on HN