Earlier quoted context omitted.
How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.
Aren't SIM swapping attacks only such a problem because you can get a new SIM without showing up in person with ID?
Recent 'MFA Bombing' Attacks Targeting Apple Users
161–170 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#162Earlier quoted context omitted.
Where do you keep the titanium plate? I'd be more worried about losing it due to a natural disaster than merely having it destroyed beyond readability in a natural disaster.
What happens if there's a typo in the engraving? Who's doing the engraving? How much do you trust the people you are providing the key to do it? When does the paranoia kick in vs being diligent?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#163Earlier quoted context omitted.
Do you have a source for that? Or any more info? It’s not that I doubt it, I ask because some details like my work email, job title and place of employment has been leaking into the hands of marketing companies and I an trying to figure out how.
Your own company could've sold it to data brokers. Look into Equifax's Work Number score, it includes fun things like where you worked and how much you made. But no, let's not unionize or anything.
Unions are on board with this, see e.g. https://unitedafa.org/news/2020/5/9/employment-verification-...
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#164It's surprising that Krebs chose to omit this little detail in the security blog and instead seemed to confirm that someone could completely give away access to their account while sleeping.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#165I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.
Just change over to using HSMs instead of push. https://support.apple.com/en-gb/HT213154
https://www.yubico.com/product/yubihsm-2-series/yubihsm-2-fi...
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#166I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
There is already a variant where they try to get someone to say „yes“ and just use a recording of it to use as „proof“ that you agreed to some contract.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#167Earlier quoted context omitted.
Only if you do everything at Apple. You make posts on twitter, it's not protected the same way.
I want to be upset that you've made a comment so obvious, yet sadly, there will be people in the wild that don't understand the silos platforms build. However, I doubt any of them are here reading this, but you never know.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#168Earlier quoted context omitted.
I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
The main problem is that walking into an apple store with a government-issued warrant works just as well as walking in with a government-issued ID.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#169Earlier quoted context omitted.
What happens if there's a typo in the engraving? Who's doing the engraving? How much do you trust the people you are providing the key to do it? When does the paranoia kick in vs being diligent?
This was at least an innovation in the bitcoin community. Several assemble at home systems where you can build a physical manifestation of a secret. Metal cards you punch with a hammer and nail. Another is essentially a tube where you string along metal letters of the password.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#170Earlier quoted context omitted.
This was at least an innovation in the bitcoin community. Several assemble at home systems where you can build a physical manifestation of a secret. Metal cards you punch with a hammer and nail. Another is essentially a tube where you string along metal letters of the password.
Sure, sounds perfect. Let me send some crypto person that has invested in a home stamping kit the secret to my crypto wallet. At least they won't know what it's for to be able to hijack my wallet. phew. had me nervous that committing the cardinal sin of sharing my secret with someone I don't know isn't going to come back to haunt me.
Also, the idea is simple enough you could DIY your own version with stuff from any hardware store.