Live data from Hacker News

Recent 'MFA Bombing' Attacks Targeting Apple Users

krebsonsecurity.com

41–50 of 233 posts

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#41
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.

> A recovery key is an randomly generated 28-character code

That's easy to backup. You can even print it and bury it in a sealed box in the garden or put it in a book or whatever. It depends who you are protecting against.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#42
post #27

Earlier quoted context omitted.

I think the more urgent thing is to not use the social security number both as the ultimate secret, and also as a number you must give to hundreds of people.

non sequitur, make a different thread for that cause

Not sure what sms one time codes has to do with this story either

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#43

I have hated Push MFA since it was introduced. How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.

You can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose.

https://support.apple.com/en-gb/HT213154

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#44

I’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.

Just change over to using HSMs instead of push.

https://support.apple.com/en-gb/HT213154

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#45
post #6
post #4

Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…

What's the recommended alternative for mere mortal hackers?

Use HSMs for your Apple ID MFA.

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#46
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

Also, buy some (at least three) YubiKeys and use them for your Apple ID verification instead of the dumb push MFA.

https://support.apple.com/en-gb/HT213154

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#48
post #8

"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…

It's not a recent approach, but this is a recent campaign using it against many people. Someone likely got a list of hacked passwords from some recent dump and is going through the apple accounts from it.

How would that explain Chris’ experience at the Genius Bar?

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#49

I've been getting these on my LinkedIn account since a couple of days. Every few hours I get an email with a magic login link. They seem legitimate, originating from various locations around the globe.

Happened to me yesterday, I was baffled but then I found that you can request the one time password just using the email associated with the LinkedIn account, so the password wasn't compromised

I have changed the password, main mail and in the privacy settings of LinkedIn removed the visibility of the email

Re: Recent 'MFA Bombing' Attacks Targeting Apple Users

#50

I've been getting these on my LinkedIn account since a couple of days. Every few hours I get an email with a magic login link. They seem legitimate, originating from various locations around the globe.

I get these too, I wish I could turn the feature off in my account, especially since I already have multiple forms of 2FA (TOTP, Passkeys).
Post reply on HN