Live data from Hacker News

I got hacked, lost crypto and what it says about Apple’s security. Part 1

ksaitor.medium.com

41–50 of 60 posts

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#41
post #35

Earlier quoted context omitted.

I'm not sure if I missed something crucial (or several things?) but this seems to be entirely an essay on how SMS is an antifactor in authentication. That they're using Apple devices and services doesn't seem to factor in to it.

what is wrong with SMS? I don't see how it is easily compromised.

TFA is a good starter as to what is wrong with SMS. It's an authentication antifactor.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#44
post #29

Earlier quoted context omitted.

I see 1password on HN frequently. I opted for bitwarden after leaving lasspass. Any comments on BW vs 1pass?

I switched from 1Password to LastPass because (at the time) 1Password’s support on Windows was rudimentary, and on Linux was basically non-existant. And then I switched from LastPass to BitWarden, because I became uncomfortable with LastPass (for reasons which I don’t recall). And then when 1Password released their 1Password X system which works via a browser extension that works really nicely across Windows/Mac/Linu…

Bitwarden can also handle TOTP codes, but you need premium ($10 / year).

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#45

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

Sometime back, I had 2fa set up on a phone, which eventually gave up the ghost. What this did was to lock me out of google and many other services I depended on. Most painful was being locked out of email. Any suggestion on how to mitigate device/ hardware failure?

Google auth works if you scan the QR code with multiple devices at setup.

So I keep a spare phone at home i my safe with google auth setup. Just in case my primary is lost or stolen.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#46

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

I don't think there is anything wrong in particular with using Chrone's browser sync or password management system at all. That is so long as the linked account is secure.

The problem here is the weakest link which I imagine is the recovery email assigned to his google account (ie probably the Yahoo account). That was likely compromised because of the phone/SMS-based 2fa.

That is nothing to do with Google as users should be aware of the security of their recovery emails.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#47

Earlier quoted context omitted.

For any significant bitcoin amounts I would buy some cheap laptop and use it as offline storage without ever connecting it to anything. I don't trust hardware wallets because they are an obvious target for attacks, but one can't attack offline computer.

> buy some cheap laptop and use it as offline storage Cheap laptop might not have redundancy, so if your SSD dies, you might be in for a rough ride. Best case, you can recover your wallet, worst case you're SOL.

Sure, backups are essential.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#48
post #33

How was 2FA bypassed here?

> How was 2FA bypassed here? very likely a sim swap attack: "A SIM swap scam is a type of account takeover fraud that generally targets a weakness in two-factor authentication and two-step verification in which the second factor or step is a text message or call placed to a mobile telephone." [1] [1] https://en.m.wikipedia.org/wiki/SIM_swap_scam

This wasn't a SIM swap. When SIM swap happens, you wont be able to receive calls and SMS. I was getting both SMS and calls during the attack.

If someone has a better explanation, that would be great.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#49
post #46

So, what does this say about Apple security? There's a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there's zero evidence other than some coincidental timing. The author clearly wasn't using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone/SMS-based 2FA in…

I don't think there is anything wrong in particular with using Chrone's browser sync or password management system at all. That is so long as the linked account is secure. The problem here is the weakest link which I imagine is the recovery email assigned to his google account (ie probably the Yahoo account). That was likely compromised because of the phone/SMS-based 2fa. That is nothing to do with Google as users sh…

Yahoo account wasn't a recovery account for Gmail.

Re: I got hacked, lost crypto and what it says about Apple’s security. Part 1

#50
Hi HN, the author of the article here.

Can someone explain how Telegram 2FA, Yahoo 2FA and Apple 2FA were bypassed?

Especially Apple 2FA - I received a 2FA call from Apple, picked it up, and the attacker logged in right after.

Please note, this was not a (typical) SIM swap. I was still receiving SMS and calls during the attack.

p.s. thanks for all the comments!

Post reply on HN