Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

151–160 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#151
post #113
post #50

Earlier quoted context omitted.

If you are willing to take the time to social engineer a CSR to get a password, you are likely willing to take the time to acquire a fake ID. They aren't hard to come by.

The security of an ID is protected by the state. Screwing around with that is a federal, put your ass in prison, kind of breach, irregardless of your intention or the context.

Jurisdiction is an issue - what if the attacker is from outside the USA (especially those countries w/o an extradition treaty)?

ID is not a panacea, especially in this case. Apple is probably best to roll out some form of multi-factor auth.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#152
post #27

Earlier quoted context omitted.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure. Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE. This is almost as silly as credit card…

As I've said elsewhere: "Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did."

If a human is in the loop and you need to call in to verify - this could get quite difficult unless you use the "pronounceable" option in password generation.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#153
post #144

Earlier quoted context omitted.

That is an interesting approach. Given the retail presence Apple has the opportunity to ask you to go to an Apple store in person and talk with service personnel there. One could easily put a picture on file (every Apple device has a camera now) of the owner, and the two bits of information: 1) You have the device with you 2) You are the same person as the picture of the owner Would set a reasonably high bar to cross…

I suspect there are a LOT of places in the United States that are a few hours' drive from the closest Apple store.

I agree, I bet there are a ton of Apple users for whom going to an Apple store could be a real pain. However, they could make it an optional account security feature. (Then they just have to handle "you got hacked? Well, that's your fault for turning down our free enhanced security feature!")

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#154
post #58

Earlier quoted context omitted.

Physical IDs can be faked.

Physical IDs don't get faked [in places where serious physical IDs are used, USA driverlicences in bars don't count] - it's simpler to make counterfeit dollars than counterfeit passports; from what I have seen from banking fraud statistics, if physical IDs are required, fake ID's are an extremely rare circumstance. You do get cases of (a) stolen IDs and (b) IDs bought off of homeless guys, and then used to open accou…

Exactly, but as you say the reason is that there's an easier and less risky (although it depends on the quality of the ID) way to get/steal money.

But that doesn't prove that requiring a physical ID is a safer method, just that there is a better workaround.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#155

I am confused; did the hacker guess the security questions or obviate them? If the former it's not Apple's fault. If the latter; that's inexcusable.

According to the guy's comments on Twitter, the hacker didn't have to answer the security questions.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#156

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

A good social engineering attack knows more about me than I do. They know my first pet, my mother's maiden name, and where all my banking records are. Lots of ways of getting that. Notice - the call was because the guys _phone_ was inoperable. A call back could go to a burner, and Apple would be none the wiser.

Very few, if any, defenses against social engineering, other than (A) Not allowing it, or (B) Requiring a Notarized-registered-letter of identification to start the process.

I'm a fan of using Notaries for password resets. Particularly to my email account, as it's the most valuable thing I own. Double-notarize in the event of two-factor resets. Make it a HUGE burden. Lock me out of email for a week or two if required, but don't give anyone access to my email.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#157
post #121

Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.

One problem is I have no idea what physical address Apple has for me, but I'm sure I have moved at least three times (as many as five) since I gave them that address.

A better solution is require a notarized physical mail in the event of password changes for high-security accounts. Everything else just goes to your email account.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#158

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

HR can screen for people that have been bankrupt, and (probably a lot trickier) personalities that might be susceptible to taking bribes.

Take two people, one went bankrupt 10 times, one never, both make minimum wage. Offer them a $10 million dollar bribe. Is one really less likely to be bribed than the other?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#159
post #121

Why isn't this part of every password-reset procedure? "We'll mail a reset code to the postal address you gave when you created your account" This would mean that the attacker would have to commit mail fraud, which (a) is quite difficult; and (b) carries heavy penalties in law.

Because it's very inconvenient. I'm not judging, just answering. :)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#160

Earlier quoted context omitted.

I was out of town and went to make a large cash purchase. (The retailer added a very hefty 10% for using debit or credit cards.) So I ran into the problem of a daily cash withdrawal at the ATM. I also did not have anything with me other than an ATM card and a Credit card with me (No ID). Turned out the bank didn't even ask for my ID when I went in. I just explained my situation and they just handed over a couple thou…

> Security at the bank seems discretionary at best No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address. The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the l…

Once, while getting a certified check, I was unable to sign correctly (you have to sign two or three times). After a couple of failures the teller turned her computer screen around to show me my saved signature and said "just sign it so it looks like this"
Post reply on HN