Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

221–230 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#221
post #72

Earlier quoted context omitted.

Myth: Right, but what happens in the very common scenario of my Android phone-- logged into Google with the Authenticator installed-- getting lost / stolen? Surely then 2-factor auth is basically useless? (insert your answer below)

You should be using POP or IMAP only on your phone so that you can revoke permission after it is stolen (when you log in to your account from a desktop and use a backup key from the printout). If you are logged in to your main Google account on your phone you are asking for trouble. While I will be sympathetic after it gets stolen and someone ruins your life, I won't be surprised.

If you're logged into your Google account from your Android, it's roughly the same amount of control as an IMAP account would give.

They can wreck havoc, but they cannot change your password and steal your account.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#222
post #217

Useful advice via http://notes.kateva.org/2012/08/net-security-is-completely-b... : 'We need to give Schneier a few drinks and get him to talk about this again. Failing that: Backup for Darwin's sake. Don't enable remote wipe of Mac OS X hardware. Just encrypt it. Use Google two-factor (two-step verification) if you are a geek and can stomach it. Fear the Cloud. Keep the data you value most close to you. Don't use iC…

Some regions have data protection laws. This means in some places the standard security questions (like "What's your mother's maiden name?") are not enough to protect people's personal data. (Which is good).

However such laws also include access. You cannot use disproportionate means to require access. Biometrics would probably not be legal to protect things like photos etc.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#223

I think a lot of people are missing the forest from the trees in this discussion. The real interesting question is not how he got hacked, it's why it doesn't happen more often? None of the tricks listed in the article are particularly time sensitive, the fundamental patterns behind this hack go back at least several years and they relate to fundamental design interactions between complex systems that are difficult to…

Most people are nice?

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#224
post #206

Earlier quoted context omitted.

That's exactly why I don't use 2-factor. It's only as secure as a single complex token. I use a password manager with complex passwords. I fail to see the added security of enabling 2-factor in this case.

2FA is equivalent to changing your password every 30 seconds. Yes, it's "only" as secure as that single token, but the entire point of doing 2FA on a separate hardware device is that even if you have every piece of malware installed on the machine you're logging in to, there is still an analog transfer of information from your phone(/keyfob/whatever) to your computer via your brain. It keeps your "password" in two pa…

The two big players here (Vasco and RSA) both do this in hardware and software. So there are soft devices that run on desktops, mobile, etc.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#225

Earlier quoted context omitted.

There seems to be something funky with "application-specific passwords" (ASP) on Chrome. Let me explain the problem (that I documented to a friend ~1 month ago): I just revoked all Google Chrome keys, cleared out all of my history / cookies / passwords / forms, etc. I went to a different computer that had previously had Chrome synced using ASP, switched to my account, and went to settings. At the top, I get this erro…

Did you also file it with Google? Definitely a nasty bug in implementation.

The friend was a GOOG employee, but not a member of the Chrome team. Indeed, I should file an official bug report... but the Matt Cutts bug reporting system is usually so much more responsive. ;-)

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#226
post #57

Last time HN discussed this story, I said "turn on 2-factor authentication for your Google account". Unsurprisingly, I got the exact reaction I'm seeing here when it has been suggested: lots of questions about how it works, people who think their situation is unique so it won't work for them, and people complaining than SMS is insecure. 1) Don't ask anymore questions. Try it out, if you hate it turn it off. 2) Your s…

This seems like poor advice. If people have questions, they should be addressed, not "oh don't worry your pretty little head, smart people came up with this." Like the discussion about app-specific passwords above was very informative to me... all it takes is one of those getting sniffed or read off disk and someone can suck down all your email. Not exactly "fire and forget" security.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#227

I think a lot of people are missing the forest from the trees in this discussion. The real interesting question is not how he got hacked, it's why it doesn't happen more often? None of the tricks listed in the article are particularly time sensitive, the fundamental patterns behind this hack go back at least several years and they relate to fundamental design interactions between complex systems that are difficult to…

A smart hacker just steals the info, doesn't wipe out the data and reveal themselves.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#228

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

There's no Google Authenticator for Windows Phone, but there's an equivalent: http://www.windowsphone.com/en-US/apps/021dd79f-0598-e011-98...
Post reply on HN