Live data from Hacker News

How Apple and Amazon Security Flaws Led to My Epic Hacking

wired.com

261–264 of 264 posts

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#261
post #216
post #166

Earlier quoted context omitted.

Any user can take over my Amazon account in five minutes. That's a security flaw, period. Yes this is 80% Apple's fault, but Amazon doesn't have the right to give up my credit card digits. They are not public information as suggested earlier; they are only public if I choose to make it so (e.g. by my usage patterns).

They aren't giving up enough information for anyone to use the credit card (which is your card provider's and Amazon's concern). They are only giving up information which Apple foolishly accepts as top-secret. The final four digits are printed on pretty much every receipt I get, and even using a shredder won't often separate them. TBH, Apple's reliance on the credit card number at all (let alone the last four digits)…

the fact that anybody can steal somebody's Amazon account and publish their private purchases is reason enough.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#263
post #261
post #216

Earlier quoted context omitted.

They aren't giving up enough information for anyone to use the credit card (which is your card provider's and Amazon's concern). They are only giving up information which Apple foolishly accepts as top-secret. The final four digits are printed on pretty much every receipt I get, and even using a shredder won't often separate them. TBH, Apple's reliance on the credit card number at all (let alone the last four digits)…

the fact that anybody can steal somebody's Amazon account and publish their private purchases is reason enough.

Yes, it's a flaw that you can get into someone's account. I was just saying that the credit card information being that available is not a big problem in my mind. Amazon clearly think the credit card should be kept more secure than the account, otherwise the whole number could be shown rather than just the last four digits, and I agree.

Re: How Apple and Amazon Security Flaws Led to My Epic Hacking

#264

For the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but…

Although enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?

If my Twitter account was hacked, the hacker could write tweets which could get a person jailed in the UK. Hence IMO Twitter really does need two-factor authentication!

Anyone else agree?

Post reply on HN