Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

161–170 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#161

Earlier quoted context omitted.

How would this work? If this was possible, that would mean an Apple employee is verifying the ID. This has failure modes. See SIM swapping attacks.

Aren't SIM swapping attacks only such a problem because you can get a new SIM without showing up in person with ID?

No, they're also a problem because you can run into a storefront and snatch the employee's authenticated tablet, regardless of what company policy is.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#162

Earlier quoted context omitted.

Where do you keep the titanium plate? I'd be more worried about losing it due to a natural disaster than merely having it destroyed beyond readability in a natural disaster.

What happens if there's a typo in the engraving? Who's doing the engraving? How much do you trust the people you are providing the key to do it? When does the paranoia kick in vs being diligent?

This was at least an innovation in the bitcoin community. Several assemble at home systems where you can build a physical manifestation of a secret. Metal cards you punch with a hammer and nail. Another is essentially a tube where you string along metal letters of the password.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#163

Earlier quoted context omitted.

Do you have a source for that? Or any more info? It’s not that I doubt it, I ask because some details like my work email, job title and place of employment has been leaking into the hands of marketing companies and I an trying to figure out how.

Your own company could've sold it to data brokers. Look into Equifax's Work Number score, it includes fun things like where you worked and how much you made. But no, let's not unionize or anything.

Companies with union labor also sell their employees' data to Equifax.

Unions are on board with this, see e.g. https://unitedafa.org/news/2020/5/9/employment-verification-...

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#164
There's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple phone number and asks you to read out the 6-digit pin to them. If you choose to give out the 6-digit pin to the attacker over an incoming phone call, then they can use it in their browser to reset your password.

It's surprising that Krebs chose to omit this little detail in the security blog and instead seemed to confirm that someone could completely give away access to their account while sleeping.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#165

I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.

Just change over to using HSMs instead of push. https://support.apple.com/en-gb/HT213154

YubiKeys aren't HSMs, Yubico sells an HSM though.

https://www.yubico.com/product/yubihsm-2-series/yubihsm-2-fi...

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#166
post #15

I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.

There is already a variant where they try to get someone to say „yes“ and just use a recording of it to use as „proof“ that you agreed to some contract.

I actually don’t answer unknown callers with “hello” or any words actually. I simply just say “mmmhhmm” or make a dumb sound if it is automated it will trigger the automatic message. Someone asked why and I said voice cloning software they said wtf you have nothing to steal. Just feels risky idk why.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#167

Earlier quoted context omitted.

Only if you do everything at Apple. You make posts on twitter, it's not protected the same way.

I want to be upset that you've made a comment so obvious, yet sadly, there will be people in the wild that don't understand the silos platforms build. However, I doubt any of them are here reading this, but you never know.

Go read any thread about passkeys. :-)

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#168

Earlier quoted context omitted.

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

This is the default behavior if you don't turn this stuff on. They store your account recovery key in an escrow device.

The main problem is that walking into an apple store with a government-issued warrant works just as well as walking in with a government-issued ID.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#169

Earlier quoted context omitted.

What happens if there's a typo in the engraving? Who's doing the engraving? How much do you trust the people you are providing the key to do it? When does the paranoia kick in vs being diligent?

This was at least an innovation in the bitcoin community. Several assemble at home systems where you can build a physical manifestation of a secret. Metal cards you punch with a hammer and nail. Another is essentially a tube where you string along metal letters of the password.

Sure, sounds perfect. Let me send some crypto person that has invested in a home stamping kit the secret to my crypto wallet. At least they won't know what it's for to be able to hijack my wallet. phew. had me nervous that committing the cardinal sin of sharing my secret with someone I don't know isn't going to come back to haunt me.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#170

Earlier quoted context omitted.

This was at least an innovation in the bitcoin community. Several assemble at home systems where you can build a physical manifestation of a secret. Metal cards you punch with a hammer and nail. Another is essentially a tube where you string along metal letters of the password.

Sure, sounds perfect. Let me send some crypto person that has invested in a home stamping kit the secret to my crypto wallet. At least they won't know what it's for to be able to hijack my wallet. phew. had me nervous that committing the cardinal sin of sharing my secret with someone I don't know isn't going to come back to haunt me.

You assemble it at home? You do not send anyone your secrets.

Also, the idea is simple enough you could DIY your own version with stuff from any hardware store.

Post reply on HN