Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

171–180 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#171

Some banks provide a service which allows you to create unique credit card numbers without actually having to get separate physical credit cards. Kind of like application-specific passwords, but for credit cards. See here: https://www.citibank.com/us/cards/gen-content/messages/van/i... Separate credit card numbers for Amazon and Apple would have prevented this hack.

This

This would be much more effective than the "Verified by Visa" theatre. "Virtual credit cards" with a limit and maybe even vendor limited (for example, create a virtual card and add some sort of vendor id for Amazon)

Too bad it can't be used for anything, for example, some airlines require you present your CC when traveling (if it's your cc and you're traveling)

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#172

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

There seems to be something funky with "application-specific passwords" (ASP) on Chrome. Let me explain the problem (that I documented to a friend ~1 month ago): I just revoked all Google Chrome keys, cleared out all of my history / cookies / passwords / forms, etc. I went to a different computer that had previously had Chrome synced using ASP, switched to my account, and went to settings. At the top, I get this erro…

Did you also file it with Google? Definitely a nasty bug in implementation.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#173

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?

I discussed the answer to your first question here: http://news.ycombinator.com/item?id=4348537

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#174

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Not quite the same as two factor auth (almost the opposite in fact), but I was extremely annoyed when gmail started relentlessly asking me to add a backup email address for password resets. Had the author not had an insecure backup email address, this wouldn't have happened either. Of all the passwords I'm likely to forget, gmail ranks near the bottom. The password to login to who knows where to get the gmail recover…

That's absolutely true. I was horrified last week when I discovered my Gmail account (with a unique 30-character long password, 2-factor enabled, NEVER used unless on my MacBook at my house) had a "backup" email address to my Yahoo account from 8 years ago, with the nice password '1123581321'. I could've killed myself.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#175
post #100

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

I was reluctant to setup two-factor for a long time, perceiving it to be an unnecessary hassle. Then somebody tried to gain access to some of my accounts through my Apple ID. They were unsuccessful (I don't have any common passwords these days so managing to send a password reset to my GMail wasn't terribly helpful) but it certainly made me paranoid enough to switch. I currently have two-factor setup on two accounts.…

One great Pic which I like from this article: http://goo.gl/fWpqd

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#176

Earlier quoted context omitted.

That's exactly why I don't use 2-factor. It's only as secure as a single complex token. I use a password manager with complex passwords. I fail to see the added security of enabling 2-factor in this case.

Since I've been downvoted without a response, let me elaborate on my concerns. I haven't seen the threat of application specific passwords (ASP) addressed properly. If an ASP is sniffed or somehow extracted from a device it seems like it's practically equivalent to a single-factor authentication password. I couldn't determine from Google's docs if an ASP will allow you to change a master password or not. Or if it cou…

When you need to make any changes to the 2-factor settings, you must enter your account password and the 2-factor password. The ASP cannot be used for this purpose.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#177

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

"Myth: I've heard two factor authentication doesn't work in IMAP and POP" I've found this to be true - to a certain extent. I had two factor authentication turned on and found it to be a nightmare in OSX Mail. Failures to retrieve mail, asking for my password constantly, etc. I was resetting the application passwords every two days. I tried to research a fix, but in the end it became less of a hassle just to turn it…

Definitely a bug in Mail.app, not 2FA. I had no problem with 2-way on IMAP on Lion, Mountain Lion, iOS 5 or iOS 6. But as I use Mail.app constantly I can assure you that it's desperately buggy. At times I had it laying around downloading gigabytes and gigabytes of Gmail mail again and again and again until I took pity and kill it.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#178

Earlier quoted context omitted.

Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?

Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked. Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many character…

> ..whether he had a @me.com email address at all

I disagree. I think most iCloud users (%80 of iOS users by Apple's count) have @me addresses when they upgraded to iOS 5 or Lion. I can use both my @gmail.com and my @me.com in App Store to purchase, or to login to icloud.com.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#179
post #85

Earlier quoted context omitted.

There's something that bugged me about two-factor the moment I activated it. The application specific passwords are stored in plain-text. How does Google know that it's actually e.g. Chrome accessing my mail with a given application-specific password? If a hacker gets a hold of an old backup of mine, which includes a Pidgin configuration file I forgot to delete, which holds a plaintext password, can he get into my ac…

That's exactly why I don't use 2-factor. It's only as secure as a single complex token. I use a password manager with complex passwords. I fail to see the added security of enabling 2-factor in this case.

Two factor limits the time window within which a password is useful. If one of your complex password's hashes gets exposed, someone would need to also know your ssl-only two factor auth cookie, and then reverse/bruteforce your password within the 30 day window the cookie makes it valid for - that makes the "current model" of releasing the hashes on pastebin and crowdsourcing the hash-cracking much more time critical.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#180
post #57

Last time HN discussed this story, I said "turn on 2-factor authentication for your Google account". Unsurprisingly, I got the exact reaction I'm seeing here when it has been suggested: lots of questions about how it works, people who think their situation is unique so it won't work for them, and people complaining than SMS is insecure. 1) Don't ask anymore questions. Try it out, if you hate it turn it off. 2) Your s…

Print 2 copies of the the codes and take a screenshot of that page.

Then type "gpg -c sensitive.png" and use the same password as your gmail account to secure it. Then put "sensitive.png.gpg" in "~/.ssh" or another place out of the way and forget about it, until the day comes that you'll need it.

Post reply on HN