Recent 'MFA Bombing' Attacks Targeting Apple Users
221–230 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#222Earlier quoted context omitted.
I did not see this when I read the article. Upon rereading it now, I see this: > Update, March 27, 5:06 p.m. ET: Added perspective on Ken’s experience. Internet archive confirms that this was the edit: The paragraph you quoted was added to the article the next day.
Anyone who edits news articles, blog posts or such without clearly disclosing the edit immediately loses my trust. It's a huge problem these days where everything is online instead of in print, but most people do not want to take responsibility for sloppy research or misleading reporting. And that's part of the reason why there is so much misinformation, it sometimes comes from trusted sources too, not just anonymous…
However, in this case, the edit is disclosed at the bottom of the article. Do you think this isn't sufficient? Does the edit disclosure need to contain a link to a diff of the changes or does it need to be at the top?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#223Earlier quoted context omitted.
> If you need a driver's license, how do you get a driver's license? With a birth certificate? Okay, how do you get a copy of your birth certificate when you don't have a driver's license? Using vitalchek, you can order a BC with a notarized document, using two people who have valid IDs as people to vouch for your identity. I've done it for multiple clients.
Interesting to see a modern variant of compurgation still in active use. So if I'm understanding this correctly, if me and one of my friends both have a valid ID, we can get anybody's birth certificate?
Note: The notary will record the ID #s and other info of the two ID holders. So if something goes wrong, the two ID holders will be on the hook as well.
Once the notarized document is submitted to vitalchek, they'll process the request.
Of course, one would still have to know a few details from the BC (parents, location, etc) to get vitalchek to submit the request to the county/city registrar.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#224Earlier quoted context omitted.
Anyone who edits news articles, blog posts or such without clearly disclosing the edit immediately loses my trust. It's a huge problem these days where everything is online instead of in print, but most people do not want to take responsibility for sloppy research or misleading reporting. And that's part of the reason why there is so much misinformation, it sometimes comes from trusted sources too, not just anonymous…
I agree with you. However, in this case, the edit is disclosed at the bottom of the article. Do you think this isn't sufficient? Does the edit disclosure need to contain a link to a diff of the changes or does it need to be at the top?
"Unnerved by the idea that he could have rolled over on his watch while sleeping and allowed criminals to take over his Apple account, Ken said ..."
Once the article was updated, the original sentence implying that criminals could take over your account while you are sleeping was completely rewritten to say the 180 degree opposite - completely reversing what the initial sensational content said. In reality it is not possible to accidentally hand over your account to attackers by accidentally tapping Allow on your watch in your sleep.
The update disclosure only says: "Added perspective on Ken’s experience."
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#225Earlier quoted context omitted.
That seems like the worst option. Everything up to the free tier would stay there forever with no way for you to ever request it to be deleted.
Turn on Advanced Data Protection before you rip up the key. Then it's all as good as deleted.
Do Apple definitely not retain a key? If they don’t is the encryption quantum secure?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#226That message is horribly designed if it allows a password reset to happen on any other device after you click allow. It specifically says "Use this iPhone to reset". I'd have assumed it asks the person who clicked allow to set a new password, on the same device they clicked allow. Then again if it shows on the watch too (and isn't just mirroring a phone notification, since it ignores quiet mode), I can't imagine the…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#227Earlier quoted context omitted.
You probably not going to get a voice clone from someone saying "hello?" 100 times. However, you don't really need to "MFA Bomb" people to clone their voice, just call them with a plausible sounding reason that will cause them to engage in an extended conversation (eg. "hey this is your uber/doordash driver/doctor/school/daycare).
I just really want to hear you say "passport" !
I thought it was a joke at first. I have no idea what they compare it to??
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#228Earlier quoted context omitted.
Interesting to see a modern variant of compurgation still in active use. So if I'm understanding this correctly, if me and one of my friends both have a valid ID, we can get anybody's birth certificate?
There also has to be someone that needs the BC to see the notary. But, for the most part, yes, it's that easy to obtain a BC using vitalchek. Note: The notary will record the ID #s and other info of the two ID holders. So if something goes wrong, the two ID holders will be on the hook as well. Once the notarized document is submitted to vitalchek, they'll process the request. Of course, one would still have to know a…
Though of course this is a method of fraudulently obtaining an official ID, so you do need to be concerned that the people engaged in that sort of enterprise might already have a couple of them.
> Of course, one would still have to know a few details from the BC (parents, location, etc) to get vitalchek to submit the request to the county/city registrar.
Which is the sort of thing that gets collected in big databases which then get breached and published on the internet.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#229Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#230Quite shocking how oblivious a lot of ostensibly tech savvy people are to the existence of hardware security tokens. Yubikeys have been around for over 15 years now, although Apple only added support for hardware tokens recently. https://support.apple.com/en-us/HT213154
They don’t help in the case that your unlocked phone is stolen