Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

171–180 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#172
> he received a call on his iPhone that said it was from Apple Support (the number displayed was 1-800-275-2273, Apple’s real customer support line)

This happened to me exactly once, and it was two days after I ordered a new MacBook from the online Apple Store. Since I was expecting a shipment, I almost picked it up. But instead I called Apple Support myself, and asked if they had called me, and they said they had not.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#173
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

> lose the key and no one can get you back in to your account.

Incorrect: only Apple cannot.

You can voluntarily declare:

- recovery accounts: these trusted accounts can help you authenticate anytime.

https://support.apple.com/en-us/HT212513

- legacy contacts: these trusted contacts can access your account in the event of your death.

https://support.apple.com/en-us/102631

As for the "lose recovery key" situation is no different than hardware token 2FA + recovery codes. Print multiple copies and spread them to trusted third parties.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#174

There's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple p…

He describes this in the very first paragraph of the article:

>Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user’s account is under attack and that Apple support needs to “verify” a one-time code.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#175

There's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple p…

He describes this in the very first paragraph of the article: >Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user’s account is under attack and that Apple support needs to “verify” a one-time code.

That seems to be an entirely different point. Krebs suggests repeatedly that all you need to do to get hacked is click "Allow" in the push notification. This is demonstrably false.

"Assuming the user manages not to fat-finger the wrong button" means "assuming the user clicks Don't Allow". They call on the phone to try and convince the user to say Allow next time.

Of course that's kinda BS too, because the only time "Allow" gives you a six digit code is if you successfully authenticate your apple ID on a new device. If you get the reset password dialog, the result of Allow is not a six digit code, it just allows you to reset the password. Yourself. On your device.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#176
This seems like it is entirely a human problem, not any kind of technical failure. The fix is the same as it always was -- people need to be trained to say no by default, do not trust inbound calls ever, and never ever share your credentials.

If you follow that advice, this attack poses no risk other than annoyance. If you do not give your password to the creep who calls you claiming to be apple support, you will be okay.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#177
post #166

Earlier quoted context omitted.

There is already a variant where they try to get someone to say „yes“ and just use a recording of it to use as „proof“ that you agreed to some contract.

I actually don’t answer unknown callers with “hello” or any words actually. I simply just say “mmmhhmm” or make a dumb sound if it is automated it will trigger the automatic message. Someone asked why and I said voice cloning software they said wtf you have nothing to steal. Just feels risky idk why.

https://www.youtube.com/watch?v=YFWgyi-zzmE

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#178

This seems like it is entirely a human problem, not any kind of technical failure. The fix is the same as it always was -- people need to be trained to say no by default, do not trust inbound calls ever , and never ever share your credentials. If you follow that advice, this attack poses no risk other than annoyance. If you do not give your password to the creep who calls you claiming to be apple support, you will be…

> people need to be trained to say no by default, do not trust inbound calls ever

This really sucks though. It basically means that our current phone system is inherently broken and something that was potentially useful before is no longer useful due to malicious actors.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#179

Earlier quoted context omitted.

But you shouldn't ONLY store it in a box or in your house. That means you're one natural disaster away from losing everything. As much as it can "weaken" security, an electronic backup is still recommended for most

As much as it can "weaken" security, an electronic backup is still recommended for most Maybe I'm being dense (probably), but where would you save it? iCloud? No, that doesn't work - you need the key to access iCloud. Some other cloud storage service? No, that doesn't work - you need your phone to generate a token for access and your phone was destroyed in the same fire as the paper backup. Seems like the safe choice…

Keep one copy in your fire-resistant safe at home. Then encrypt a copy, give the encrypted copy to your best friend and the decryption key to a family member, or keep one of these things in your desk at work. Neither of them have access unless they both figure out what it is and collude with each other, but you have a recovery system in case you lose your own copy.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#180

Earlier quoted context omitted.

> lose the key and no one can get you back in to your account sounds like a feature "want to totally restart your entire digital life? just rip up your key :) never worry about something from your past coming back to you ever again!

That seems like the worst option. Everything up to the free tier would stay there forever with no way for you to ever request it to be deleted.

Turn on Advanced Data Protection before you rip up the key. Then it's all as good as deleted.
Post reply on HN