Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

211–220 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#211

There's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple p…

It's in the article:

> Ken didn’t know it when all this was happening (and it’s not at all obvious from the Apple prompts), but clicking “Allow” would not have allowed the attackers to change Ken’s password. Rather, clicking “Allow” displays a six digit PIN that must be entered on Ken’s device — allowing Ken to change his password. It appears that these rapid password reset prompts are being used to make a subsequent inbound phone call spoofing Apple more believable.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#212

Earlier quoted context omitted.

That seems to be an entirely different point. Krebs suggests repeatedly that all you need to do to get hacked is click "Allow" in the push notification. This is demonstrably false. "Assuming the user manages not to fat-finger the wrong button" means "assuming the user clicks Don't Allow". They call on the phone to try and convince the user to say Allow next time. Of course that's kinda BS too, because the only time "…

Are you reading the second half of the sentence I posted? Sorry but I'm not understanding where you are coming from - Krebbs lays out clearly in the first paragraph how the attack works and you seem to be deliberately ignoring that.

Are you reading the first half of the sentence you posted? They are clearly implying pressing the wrong button would be dangerous.

It’s a bit confused about what exactly the problem is, so is a little self-contradictory (including elsewhere in the article).

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#213
post #189
post #68

Earlier quoted context omitted.

You can setup a recovery contact incase you do loose the key. I just set that up with my partner and the chance of loosing the key and both of us losing all of our apple devices I think is fairly slim. I also stuck that key in 1Password (sure it's less safe, but if my 1Password was breached I have far bigger problems than this key being retrieved). Then keep a hard copy in a safe. Been contemplating sending my parent…

How many people own a safe? I personally don’t know anybody that does. I do know that safes sometimes get stolen.

You personally don’t know anyone who obviously discloses that they have a safe. If you have a safe you are keeping something valuable secure. The fewer people know that you have something valuable that needs to be secured the better. If people don’t even know your safe exists then that reduces the chances of it being compromised.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#214
post #204

Earlier quoted context omitted.

I argue for and advocate that this capability should exist, but not be mandatory. If you do not want to tie your personal identity to your digital identity, certainly, you should be able to not do so and rely solely on a cryptographic primitive, recovery key, or other digital mechanism to govern access of last resort. If your account access is lost forever, it's on you and that was a choice that was made. > Somehow y…

> If you need a driver's license, how do you get a driver's license? With a birth certificate? Okay, how do you get a copy of your birth certificate when you don't have a driver's license? Using vitalchek, you can order a BC with a notarized document, using two people who have valid IDs as people to vouch for your identity. I've done it for multiple clients.

Interesting to see a modern variant of compurgation still in active use.

So if I'm understanding this correctly, if me and one of my friends both have a valid ID, we can get anybody's birth certificate?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#215

There's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple p…

It's in the article: > Ken didn’t know it when all this was happening (and it’s not at all obvious from the Apple prompts), but clicking “Allow” would not have allowed the attackers to change Ken’s password. Rather, clicking “Allow” displays a six digit PIN that must be entered on Ken’s device — allowing Ken to change his password. It appears that these rapid password reset prompts are being used to make a subsequent…

I did not see this when I read the article. Upon rereading it now, I see this:

> Update, March 27, 5:06 p.m. ET: Added perspective on Ken’s experience.

Internet archive confirms that this was the edit: The paragraph you quoted was added to the article the next day.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#216
post #189

Earlier quoted context omitted.

How many people own a safe? I personally don’t know anybody that does. I do know that safes sometimes get stolen.

You personally don’t know anyone who obviously discloses that they have a safe. If you have a safe you are keeping something valuable secure. The fewer people know that you have something valuable that needs to be secured the better. If people don’t even know your safe exists then that reduces the chances of it being compromised.

I know for a fact that many of my friends don’t own a safe, and I don’t think I’m an outlier here.

I don’t doubt that many people do, but it’s still not a solution for the majority of Apple users.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#217

I've been getting these on my LinkedIn account since a couple of days. Every few hours I get an email with a magic login link. They seem legitimate, originating from various locations around the globe.

Happened to me yesterday, I was baffled but then I found that you can request the one time password just using the email associated with the LinkedIn account, so the password wasn't compromised I have changed the password, main mail and in the privacy settings of LinkedIn removed the visibility of the email

What I don’t get is what is the ploy here. I’m getting them too, but have no indication my email is hacked. Therefore what’s happening?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#218

Earlier quoted context omitted.

Are you reading the second half of the sentence I posted? Sorry but I'm not understanding where you are coming from - Krebbs lays out clearly in the first paragraph how the attack works and you seem to be deliberately ignoring that.

No? I thought I specifically addressed that. They call you on the phone and ask for a code you won't have, even if you hit Allow. What I find interesting is that Krebs didn't do any legwork to verify the claims before publishing.

Why wouldn't you have the code? I thought your device shows the code when you press 'allow'.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#219

Earlier quoted context omitted.

It's in the article: > Ken didn’t know it when all this was happening (and it’s not at all obvious from the Apple prompts), but clicking “Allow” would not have allowed the attackers to change Ken’s password. Rather, clicking “Allow” displays a six digit PIN that must be entered on Ken’s device — allowing Ken to change his password. It appears that these rapid password reset prompts are being used to make a subsequent…

I did not see this when I read the article. Upon rereading it now, I see this: > Update, March 27, 5:06 p.m. ET: Added perspective on Ken’s experience. Internet archive confirms that this was the edit: The paragraph you quoted was added to the article the next day.

Anyone who edits news articles, blog posts or such without clearly disclosing the edit immediately loses my trust. It's a huge problem these days where everything is online instead of in print, but most people do not want to take responsibility for sloppy research or misleading reporting. And that's part of the reason why there is so much misinformation, it sometimes comes from trusted sources too, not just anonymous social media users.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#220

Earlier quoted context omitted.

Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?

> Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID? This is easy to defeat and completely subverts the purpose of the system. If you are not comfortable with self-custody then don’t opt in.

Only because you don't have proper IDs over there in the US?

I'd say a lot of identity problems are there because companies have to identify people without an official ID somehow...

Post reply on HN