Earlier quoted context omitted.
On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.
I don't know, I have mixed feelings about this. It's akin to building even more inscrutable captchas or tightening up airport security measures every time a new breach happens. At best it might close one particular loop hole but at what cost and incovenience to millions of people and billions of transactions? I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was…
Apple Support Allowed Hacker Access to Reporter's iCloud Account
171–180 of 181 posts
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#172It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…
I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…
"Sir, we are just going to need to send an SMS to your phone number"
"Ok which number is that.. "
"it is the 065 488 48.."
"..that is my old work phone, which I no longer have access to"
Works all the time. The tip with social engineering is to ask for a little at a time. You don't call up and say "I don't have my phone, email, password, and nor do I know my mothers maiden name.. please let me into my account"
You take it all a step at a time and give it a narrative, just like a real user in the predicament would (and I have been in the predicament and called Apple). Works almost every time.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#173Earlier quoted context omitted.
HR can screen for people that have been bankrupt, and (probably a lot trickier) personalities that might be susceptible to taking bribes.
Take two people, one went bankrupt 10 times, one never, both make minimum wage. Offer them a $10 million dollar bribe. Is one really less likely to be bribed than the other?
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#174One of the main issues with the Apple ID is the ease of use vs security. Tying the remote wipe functionality with the ability to purchase low cost content (the primary use case for the Apple ID) is always going to have one group of users unhappy. I frequently want to quickly purchase a song on my iPhone. I also, frequently tell my friends my password so they can do the same. How many of you have typed your Apple ID p…
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#175Earlier quoted context omitted.
HR can screen for people that have been bankrupt, and (probably a lot trickier) personalities that might be susceptible to taking bribes.
Take two people, one went bankrupt 10 times, one never, both make minimum wage. Offer them a $10 million dollar bribe. Is one really less likely to be bribed than the other?
What about people protecting $500?
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#176In the middle of a 'major crisis' this guy finds time to type up a story, on a computer? He can still access work machines to submit? And then the hacker is kind enough to tell him what happened? And oddly, there is no mention of involving the police or the FBI?
This episode is either an inside job or a complete fabrication. My prediction is it will fall apart within the week, rather like Gizmodo's exclusive story based on the purchase of stolen prototype equipment.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#177Earlier quoted context omitted.
I totally agree with you but on two points: 1) Cost benefit analysis and discretionary security is not mutually exclusive. It's cost benefit analysis ergo discretionary security. 2) Crime pays. You just have to be sophisticated and powerful enough to not be indicted. (TARP?) The interesting thing about your comment is when you apply your logic towards combating terrorism. The cumulative harm of prevention of terroris…
On 1) that is what I meant. The level of security measures is proportional to the risks, and a realisation that every measure costs time and money. For 2) white collar crime certainly has shorter prison sentences in the US. It is a little harder to apportion blame as directly as with a bank robber. The general cause of problems has been the US government bailing out creditors. Because of that creditors have been laxe…
Very few are murders. Murders and accidents are not the same thing and not equally bad.
One difference: if you don't do anything about accidents, the rate stays the same. If you don't do anything about murder and just let it happen, the rate goes up as more people realize they can get away with it and serial killers or terrorists get more bold.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#178Earlier quoted context omitted.
Microsoft and Google have zero incidents only for very large values of zero. Google "gmail account hacked" or "Xbox live account hacked" or "hotmail account hacked". In the last case, the top links are to Microsoft's FAQ pages.
Just because a company can have their FAQ pages SEO'd to the top of the SERPS doesn't mean their services haven't been hacked. Most people who get hacked hardly ever report it, they just want their account(s) back.
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#179Earlier quoted context omitted.
Microsoft and Google have zero incidents only for very large values of zero. Google "gmail account hacked" or "Xbox live account hacked" or "hotmail account hacked". In the last case, the top links are to Microsoft's FAQ pages.
Irrelevant because those accounts are hacked by someone who acquired the password of the actual user by a keylogger etc. They were not exploiting flaws related to server side. In iCloud's case, there is nothing the user could have done to prevent this attack.
Not having any customer support worth a damn is a different kind of policy failure. (For example.)
Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account
#180Earlier quoted context omitted.
Again there is no Google mail support to speak of (even with Google Apps for Business in my experience).
Sure there is. if you pay for your Google Apps account: http://support.google.com/a/bin/request.py
(I am a Google Apps for Business user and have had to contact Google Apps support a few times … the process has never been really pleasant.)