Live data from Hacker News

I got hacked, lost crypto and what it says about Apple’s security. Part 1

ksaitor.medium.com

21–30 of 60 posts

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#21

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

Buy a physical U2F key and add it also on accounts where you enable 2FA. Now you're only locked out if you lose both it and your phone.

I use one of these https://www.yubico.com/product/security-key-by-yubico/

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#22

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

Not GP, but I use Authy, which allows multiple devices, approving each new one with one of the others.

I don't recommend using its browser add-on though, so this only fixes your case if you have two (or more) devices to use that will be active at the same time, so that any one (all but one) can die.

Also, have multiple forms of 2FA (as in any one may be used) such as a FIDO key or printed codes.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#23

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

For any significant bitcoin amounts I would buy some cheap laptop and use it as offline storage without ever connecting it to anything. I don't trust hardware wallets because they are an obvious target for attacks, but one can't attack offline computer.

Don't forget about the bitcoins when you do your spring cleaning, and throw it away. That's how I lost bitcoins :P

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#25

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

[deleted]

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#26

Earlier quoted context omitted.

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

Buy a physical U2F key and add it also on accounts where you enable 2FA. Now you're only locked out if you lose both it and your phone. I use one of these https://www.yubico.com/product/security-key-by-yubico/

At least 2 keys for redundancy in case of loss or theft. I have 4 Yubikeys (2 of them freebies with an Ars Technica and Wired subscription).

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#27
I've noticed that he has an app called "Whoscall" installed providing Caller ID in the Phone app. I wonder if this has access to Messages on the phone and is able to read/upload SMS?

A quick search online suggests that this is a Chinese app.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#28
post #4

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Why are 3rd party password stores like 1Password better than Apple’s Keychain or Google’s password store?

Email services (e.g. Gmail) are often used as a unique identifier for logins. Want to reset your password? It's often by email.

Storing passwords in the same account creates a single point of failure. If I get into your Gmail account I have total control of everything.

Third party stores separate passwords from logins, including for the email account itself.

Now I cannot get complete control of all your accounts just via your gmail/logins account. At best I can control them for a short period of time. Which means I maybe get your Skype account for a day or so.

It's all about making it harder for an attacker to get something valuable. The harder you make it the less likely they are to succeed.

Because the login accounts and passwords are separated an attacker has to do more work basically.

Addendum: the single point of failure actually becomes the third party password store. Which is good in some respects and bad in others.

Addendum 2: also, iirc, Google stuff doesn't ask if you want to create a password for the account, only if you want to store it. Which encourages password reuse.

Password managers often have the ability to generate a random password up to the maximum allowed length, meaning no account passwords are ever the the same and are harder to crack.

Furthermore some of them can automatically update your passwords for you if they've become stale.

So all I have to do is remember (and regularly change) my one super strong pass phrase for the password manager.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#29
post #16

Earlier quoted context omitted.

Save the qrcode in 1password. Makes seeing up a new phone trivial. Also, 1password can generate the top.

I see 1password on HN frequently. I opted for bitwarden after leaving lasspass. Any comments on BW vs 1pass?

I switched from 1Password to LastPass because (at the time) 1Password’s support on Windows was rudimentary, and on Linux was basically non-existant. And then I switched from LastPass to BitWarden, because I became uncomfortable with LastPass (for reasons which I don’t recall).

And then when 1Password released their 1Password X system which works via a browser extension that works really nicely across Windows/Mac/Linux/iOS/etc, I switched from BitWarden back to 1Password again. (caveat: I haven’t actually tested the chrome extension myself; only the firefox and safari ones)

RE: BitWarden vs 1Password, they’re pretty similar in most respects. 1Password is arguably more polished (especially in the native OS X app), and has support for storing multiple separate vaults of data (a feature which I don’t actually use). BitWarden has the ability to self-host the server (which I’ve never done, but I very much appreciated that it was an option), and 1Password historically let you just sync your vault file however you wanted to; I had mine in a Dropbox folder to share between computers, for a while, and it worked great. But now with 1Password X, they want you to use their servers. Which obvs is less great, but.. I’m willing to put up with it, personally. (I mean, I was doing the same with LastPass and BitWarden already, anyway).

For me, the big killer feature for 1Password is that it can handle “Authenticator” features; scan the QR code into 1Password and it’ll handle the TOTP code for 2FA in addition to your username/password, etc. It’s so much nicer to have it all integrated together in a single flow than to need to find my phone and launch Authy separately every time I want to log into a web site.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#30
post #26

Earlier quoted context omitted.

Buy a physical U2F key and add it also on accounts where you enable 2FA. Now you're only locked out if you lose both it and your phone. I use one of these https://www.yubico.com/product/security-key-by-yubico/

At least 2 keys for redundancy in case of loss or theft. I have 4 Yubikeys (2 of them freebies with an Ars Technica and Wired subscription).

Redundancy is taken care of by the TOTP app on your phone.
Post reply on HN