Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

241–250 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#241
post #169

Earlier quoted context omitted.

Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked. Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many character…

"Hackers would have had a much harder time"? No: mhonan@gmail.com mhonan@me.com Gmail was not really needed to guess the name at @me.com. Moreover, in his case, it seems he would be better off not having the secondary e-mail address for recovery at Google. It turned out to be anti-security measure.

It's not the mhonan part the would've been hard to guess but the @me.com. A secondary email account could be anything. It could also very well not be enabled. Knowing that it is enabled and that is an @me was definitely something that helped the attackers.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#242
post #38

Earlier quoted context omitted.

There are many problems with this. Among them that I have some iTunes purchases associated with an email account that hasn't existed in /years/. There's no way to rename an Apple account. This same problem exists on most sites that use email as username - if your email address of choice ever changes, you're SOL on having a single identity anymore.

Not only that, but I have my own domain name which forwards anything@mydomain.com to my primary email. And to keep spam under control, I use a unique email for each (low impact) service. Therefore, I often forget which email I used when signing up for that particular service (unless they sent me a conformation mail, then I can usually dig it up).

If you use example.com@mydomain.com as the email address for your login to example.com, then they're easy to remember.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#243
When you perform a remote hard drive wipe on Find my Mac, the system asks you to create a four-digit PIN so that the process can be reversed. But here’s the thing: If someone else performs that wipe — someone who gained access to your iCloud account through malicious means — there’s no way for you to enter that PIN.

That sounds more like remote encryption to me. And a four digit PIN is easy to brute force (assuming that it isn't asking apple for the decryption key once entered (which means you need internet access do reverse it)).

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#244

Earlier quoted context omitted.

I was wary to set up 2FA until I learned that you can set it up even without a cellphone or your own computer. You can have the second factor be a voice call, so it can call a landline or dumbphone without an SMS plan. Plus, if you ever lose your phone or cancel your number, you can set up backup phone numbers. I set up my fiancee's phone number as a backup number in case I ever lose my phone.

Someone big got hacked this way recently - the attacker managed to social-engineer a call forwarding change, then used a "landline 2FA auth call" to gain the foothold then needed. (I think it was Cloudflare?) It's similar to @mat's problem - Amazon assumed the CC last 4 digits was "non identifying", Apple assumed they were. How much effort do you suppose your phone company expends securing your voicemail or call forw…

I heard about this hack too (http://blog.cloudflare.com/the-four-critical-security-flaws-...), but I disagree with you - the last 4 CC digits should be considered non-identifying.

First, let me explain a little bit of background on this "hack". From the article, they had 4 problems with their process that allowed them to get hacked badly:

1. AT&T was tricked into redirecting my voicemail to a fraudulent voicemail box;

2. Google's account recovery process was tricked by the fraudulent voicemail box and left an account recovery PIN code that allowed my personal Gmail account to be reset;

3. A flaw in Google's Enterprise Apps account recovery process allowed the hacker to bypass two-factor authentication on my CloudFlare.com address; and

4. CloudFlare BCCing transactional emails to some administrative accounts allowed the hacker to reset the password of a customer once the hacker had gained access to the administrative email account.

I'm not really sure what #3 is and #4 is irrelevant to our discussion, so I'll concentrate on points #1 and #2.

From #1, it follows that the attackers were able to obtain the phone number associated with the two factor auth. How did this work? My assumption is that it was a very targeted attack.

The article starts the attack at June 1st, 2012, but I believe (read: assume) that the attackers probably met the target of the attack beforehand and obtained his/her business card (with a cellphone number), which allowed them to perform #1 above.

So, given that this attack required a physical piece of paper (i.e. a business card) to be acquired from the target, it is not a stretch of imagination to say that if another attacker wanted to obtain the last 4 digits of someone's credit card, all they need to do is follow the person to a restaurant or gas station and get a payment receipt -- every receipt has the last 4 digits written on it. Some have the first four.

Therefore, I don't believe it was Amazon's fault for assuming the last 4 digits are non-identifying, but rather Apple's fault for assuming they are. To be clear, hindsight is 20/20, so I think it was relatively reasonable for Apple to assume that. However, I do expect Apple to change this policy in the future.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#245
post #18

Earlier quoted context omitted.

I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…

Give your parent's email as your recovery email address. If you need to reset, you can call them and talk them through clicking the link and resetting the password. The bad guys then have to crack your parents email account too, and being older they will be less likely to have daisy-chained Google, Apple and Amazon accounts.

They will also more likely have picked a password that's easy to brute force.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#247

My bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like "Hello Mr 67, before we start I'll need your pin" "I have a pin?" "Yes, when you set up this account you were given a pin required for phone access" "Really? I have no idea what it is..." "That's ok. If you can just answer these other fe…

My bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it. Turns out, when I can't remember it they tell me the first 2 letters!

They must have some advanced crypto where the customer support person can only see the first 2 letters but the rest of password remains securely hashed...

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#248

Just logged into Amazon account and removed all of the cards I have on record. Suggest everyone else does the same.

That doesn't matter for the purposes of the crack. With your name, billing address and email the cracker was able to add a new credit card number

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#249
Most of the "security questions" can be answered by looking at the Facebook profile (of the person or his/her friends -- at least some have the info public). A motivated hacker can possibly crack even bank accounts using the facebook profile. The account/security is indeed in a big mess.
Post reply on HN