Earlier quoted context omitted.
I think we should start doing product liability lawsuits to any organization capable of having user financial data affected from their account, that is using SMS one time codes as either default, enabled by default, and the heaviest legal remedies to financial organizations where that's the only option we should also update PCI DSS compliance or whatever relevant security standard to call SMS one time codes totally i…
I think the more urgent thing is to not use the social security number both as the ultimate secret, and also as a number you must give to hundreds of people.
Recent 'MFA Bombing' Attacks Targeting Apple Users
31–40 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#32Earlier quoted context omitted.
I think we should start doing product liability lawsuits to any organization capable of having user financial data affected from their account, that is using SMS one time codes as either default, enabled by default, and the heaviest legal remedies to financial organizations where that's the only option we should also update PCI DSS compliance or whatever relevant security standard to call SMS one time codes totally i…
I think the more urgent thing is to not use the social security number both as the ultimate secret, and also as a number you must give to hundreds of people.
Don’t forget the final nail in the coffin, which completes the trifecta: it’s entirely immutable - damage radius = infinite.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#33I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.
What flows have you found not to use security keys?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#34How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#35I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
Exactly this. Another reason to not to use phone (or the numbers) calls to verify users even with so called 'voice identification or voice ID' which can easily be broken with advanced voice cloning.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#36I have hated Push MFA since it was introduced. How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#37I wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#38"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
It is kind of scary too — lose the key and no one can get you back in to your account.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#39Earlier quoted context omitted.
This has nothing to do with SIM swapping or phone numbers.
>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
>The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
This is a non-starter for the general public. If they can barely remember their password what are the chances they'll remember a "private identification string" or whatever?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#40Earlier quoted context omitted.
I think the more urgent thing is to not use the social security number both as the ultimate secret, and also as a number you must give to hundreds of people.
non sequitur, make a different thread for that cause