Live data from Hacker News

Apple Support Allowed Hacker Access to Reporter's iCloud Account

macrumors.com

51–60 of 181 posts

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#51
post #42
post #8

Earlier quoted context omitted.

I don't think I would label this horrible behavior on the part of Apple. When you provide customer service for something like iCloud things like these are bound to happen. This is a case of social engineering not some tech rep downloading plaintext passwords to a laptop and losing it. With a really targeted attack they are bound to be successful with some rep. Its a matter of when not if. Having said that they will i…

The techrep shouldnt be allowed to reset your password. For all you know, that guy is your wife's ex. This reminds me of facebook and how all its employees were stalking people using the god password. They can and should follow bank protocol. Require an ID, make every action reversable ( like being able to undo a wipe ) and have both employee and requester on tape, with id's.

> This reminds me of facebook and how all its employees were stalking people using the god password.

Wait what? Sorry to get off topic but when did this happen?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#52
post #43
post #27

Earlier quoted context omitted.

Actually, it appears to me that almost 100% of “security questions” used during support phone calls are completely insecure. Usually they'll ask a few (2~3 is normal) questions like your full name, date of birth, address with zipcode, email address, etc. Notice the problem of these? All of them, I mean, ALL, are PUBLIC INFORMATION THAT ANYONE KNOWS SOMETHING ABOUT YOU WILL HAVE. This is almost as silly as credit card…

The thing to remember here is that where the liability lies matters. The banks effectively take on all the liability for financial losses due to credit card fraud & they're free to setup their systems to constrain losses to a level that they're happy with. Yes, arguably not all the losses fall on the banks, particularly the hassle and time of recovering from a particular instance of fraud but the majority of them pro…

Banks are experts at pushing financial liability onto others. Much of the time, credit card companies inform the merchant that they aren't going to pay for a transaction that they have deemed fraudulent. The merchant can chase the fraud themselves or eat the loss.

The fact that 'identity theft' is a commonly used name for bank fraud is another example. When some bank opens an account for person Y, there should be zero consequences for person X (regardless of any fraud committed by Y), but the banking system isn't quite set up that way.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#53
post #35
post #25

Earlier quoted context omitted.

The fact that this happens doesn't have to do with any particular brand. Every company, Google included, is susceptible to this kind of social engineering attacks. Nothing is 100% safe. You can take every precaution possible and there will always be a weak link in the chain. Apple will double down in security now, especially regarding iCloud, but even doing so there is a chance that this will happen again. Same for M…

Google isnt susceptible to this kind of social engineering attack. It requires the existence of a customer service in the first place. Good luck trying to call Google. There is no "magic" solution, there are just solutions. But to suggests its all the same... Thats just lazy. Apple is more vulnerable, because they do do customer support. Sony was more vulnerable, because they just dint give a shit, and didnt bother a…

Microsoft and Google have zero incidents only for very large values of zero. Google "gmail account hacked" or "Xbox live account hacked" or "hotmail account hacked".

In the last case, the top links are to Microsoft's FAQ pages.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#54
post #36

Earlier quoted context omitted.

If I got veeti's joke then I think what he was trying to say was that it's nearly impossible to get Google on the phone unless you're a corporate customer. If I didn't get his joke then I'm making it now. joke

joke's on me then :) But back to my point social engineering doesn't require voice. you can do it via email just as easily.

Again there is no Google mail support to speak of (even with Google Apps for Business in my experience).

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#55
post #19

Earlier quoted context omitted.

If the Apple-chosen security questions are reasonably guessable, that's still Apple's fault.

Here is the list; You tell me. Keep in mind though; you can answer anything you want. Use a 1password generated string for each and store the answers redundantly. That's what I did. --------------------------------- What was the first car you owned? Who was your first teacher? What was the first album you owned? Where was your first job? In which city were you first kissed? --- Which of the cars you’ve owned has been…

I can barely answer half of those for myself and out of those that I can answer I'm either not sure I'd answer the same thing a few years later or it will probably be something a lot of people know.

Those questions are terrible.

Answering with a random string is the only sensible solution. But it is just as mindbogglingly bad. Because then you could just as well write down the password - and bam, you'd never lose it (well, if you did lose it you would have lost the answers to these questions as well so either way you are screwed).

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#56

Earlier quoted context omitted.

I'll confess, I honestly didn't even consider the possibility that the hacker just social-engineered Apple support. I mean, Mitnick wrote an entire book about that kind of stuff, and the whole HBGary thing went down in sort of the same way, but ... still, to be able to call up the support department of a major technology (!) company, in 2012, pretending to be someone else and get access to their account that way? App…

On the positive side, perhaps the publicity will cause Apple to tighten up. They have demonstrated that they are serious about security.

Have they? (Honest question.)

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#57

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

Didn't everyone learn this lesson from Hackers?

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#58
post #34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

Physical IDs can be faked.

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#59
post #34

It seems logical that the easiest attack vector for any type of cloud storage is through social engineering. You're essentially protecting potentially valuable or incriminating data behind millions of dollars worth of firewalls, encryption and other technology... or a customer service representative paid $10-15/hr, if that. Depending on how valuable the data is to you, it might be easier to just pay off a CSR, and th…

I'm not sure how to solve this problem It's easily solved, banks and other institutions have been doing it for years. The solution is trivial, too: Require physical ID. In order to open a bank account you have to either show up in person, or provide equivalent proof (e.g. PostIdent). Why should it be different with cloud-services whose stated goal is to silo all your life's data? Why are they excused on lax security?

[deleted]

Re: Apple Support Allowed Hacker Access to Reporter's iCloud Account

#60
The thought hadn't cross my mind, but after reading this post it got me thinking:

Sensa

So, let's get this straight...a hacker "decides" to hack the account of a semi-high profile tech guy and then after committing several serious crimes like fraud that could land him in jail for an extended period of time repeatedly contacts the person he hacked when he must know that Apple will surely pursue this matter?

I smell a rat...

http://forums.macrumors.com/showthread.php?p=15405091#post15...

Post reply on HN