Earlier quoted context omitted.
Two-factor Google authentication would have had two benefits. First, the Gmail and Twitter accounts wouldn't have been hacked. Secondly, the Wired article made this claim: "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many character…
"Hackers would have had a much harder time"? No: mhonan@gmail.com mhonan@me.com Gmail was not really needed to guess the name at @me.com. Moreover, in his case, it seems he would be better off not having the secondary e-mail address for recovery at Google. It turned out to be anti-security measure.
How Apple and Amazon Security Flaws Led to My Epic Hacking
241–250 of 264 posts
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#242Earlier quoted context omitted.
There are many problems with this. Among them that I have some iTunes purchases associated with an email account that hasn't existed in /years/. There's no way to rename an Apple account. This same problem exists on most sites that use email as username - if your email address of choice ever changes, you're SOL on having a single identity anymore.
Not only that, but I have my own domain name which forwards anything@mydomain.com to my primary email. And to keep spam under control, I use a unique email for each (low impact) service. Therefore, I often forget which email I used when signing up for that particular service (unless they sent me a conformation mail, then I can usually dig it up).
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#243That sounds more like remote encryption to me. And a four digit PIN is easy to brute force (assuming that it isn't asking apple for the decryption key once entered (which means you need internet access do reverse it)).
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#244Earlier quoted context omitted.
I was wary to set up 2FA until I learned that you can set it up even without a cellphone or your own computer. You can have the second factor be a voice call, so it can call a landline or dumbphone without an SMS plan. Plus, if you ever lose your phone or cancel your number, you can set up backup phone numbers. I set up my fiancee's phone number as a backup number in case I ever lose my phone.
Someone big got hacked this way recently - the attacker managed to social-engineer a call forwarding change, then used a "landline 2FA auth call" to gain the foothold then needed. (I think it was Cloudflare?) It's similar to @mat's problem - Amazon assumed the CC last 4 digits was "non identifying", Apple assumed they were. How much effort do you suppose your phone company expends securing your voicemail or call forw…
First, let me explain a little bit of background on this "hack". From the article, they had 4 problems with their process that allowed them to get hacked badly:
1. AT&T was tricked into redirecting my voicemail to a fraudulent voicemail box;
2. Google's account recovery process was tricked by the fraudulent voicemail box and left an account recovery PIN code that allowed my personal Gmail account to be reset;
3. A flaw in Google's Enterprise Apps account recovery process allowed the hacker to bypass two-factor authentication on my CloudFlare.com address; and
4. CloudFlare BCCing transactional emails to some administrative accounts allowed the hacker to reset the password of a customer once the hacker had gained access to the administrative email account.
I'm not really sure what #3 is and #4 is irrelevant to our discussion, so I'll concentrate on points #1 and #2.
From #1, it follows that the attackers were able to obtain the phone number associated with the two factor auth. How did this work? My assumption is that it was a very targeted attack.
The article starts the attack at June 1st, 2012, but I believe (read: assume) that the attackers probably met the target of the attack beforehand and obtained his/her business card (with a cellphone number), which allowed them to perform #1 above.
So, given that this attack required a physical piece of paper (i.e. a business card) to be acquired from the target, it is not a stretch of imagination to say that if another attacker wanted to obtain the last 4 digits of someone's credit card, all they need to do is follow the person to a restaurant or gas station and get a payment receipt -- every receipt has the last 4 digits written on it. Some have the first four.
Therefore, I don't believe it was Amazon's fault for assuming the last 4 digits are non-identifying, but rather Apple's fault for assuming they are. To be clear, hindsight is 20/20, so I think it was relatively reasonable for Apple to assume that. However, I do expect Apple to change this policy in the future.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#245Earlier quoted context omitted.
I have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" ema…
Give your parent's email as your recovery email address. If you need to reset, you can call them and talk them through clicking the link and resetting the password. The bad guys then have to crack your parents email account too, and being older they will be less likely to have daisy-chained Google, Apple and Amazon accounts.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#246Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#247My bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like "Hello Mr 67, before we start I'll need your pin" "I have a pin?" "Yes, when you set up this account you were given a pin required for phone access" "Really? I have no idea what it is..." "That's ok. If you can just answer these other fe…
My bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it. Turns out, when I can't remember it they tell me the first 2 letters!
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#248Just logged into Amazon account and removed all of the cards I have on record. Suggest everyone else does the same.
Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#249Re: How Apple and Amazon Security Flaws Led to My Epic Hacking
#250Just logged into Amazon account and removed all of the cards I have on record. Suggest everyone else does the same.