Earlier quoted context omitted.
Rate limiting per user is mostly a thing of the past. You set other rate limits and various rules and then get the rate limit per user for free.
> Rate limiting per user is mostly a thing of the past Someone please tell this to fidelity. After 3 wrong password attempts they lock your account.
Recent 'MFA Bombing' Attacks Targeting Apple Users
81–90 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#82Earlier quoted context omitted.
I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.
> A recovery key is an randomly generated 28-character code That's easy to backup. You can even print it and bury it in a sealed box in the garden or put it in a book or whatever. It depends who you are protecting against.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#83That message is horribly designed if it allows a password reset to happen on any other device after you click allow. It specifically says "Use this iPhone to reset". I'd have assumed it asks the person who clicked allow to set a new password, on the same device they clicked allow. Then again if it shows on the watch too (and isn't just mirroring a phone notification, since it ignores quiet mode), I can't imagine the…
This was a lifesaver when my 90 year old mother forget her iMac password (and I forgot that I had created a second admin account on her machine.) After getting locked out of the iMac, we were able to reset it because we were able to get into her iPad (which she forgot the pin to, but fortunately we found it written down.)
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#84Earlier quoted context omitted.
As much as it can "weaken" security, an electronic backup is still recommended for most Maybe I'm being dense (probably), but where would you save it? iCloud? No, that doesn't work - you need the key to access iCloud. Some other cloud storage service? No, that doesn't work - you need your phone to generate a token for access and your phone was destroyed in the same fire as the paper backup. Seems like the safe choice…
Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#85I am confused. What does happen after clicking allow? Does Apple just provide a password reset form to the person on the iForgot website or does it show up only on the device?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#86Earlier quoted context omitted.
>Then keep a hard copy in a safe. Been contemplating sending my parents a safe (who live several states away) with keys on a sheet of paper without context that only I have the combination too. But not sure yet. A friend of mine who was (maybe is? he knows I'm not a fan so we don't talk about it much) big into crypto stores his secrets in similar safes with trusted friends and family around the country. I think it's…
I think it is a good idea in theory also, there I just that voice that says "well now that key is out of my possession" and it scares me a bit. I think I might need to look up to see if there is a known pattern to these keys that it could be easily figured out what it is even if it is just on a sheet with no context. Particularly 1Password which I think is a pattern if I remember correctly.
What does that mean?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#87Earlier quoted context omitted.
I think it is a good idea in theory also, there I just that voice that says "well now that key is out of my possession" and it scares me a bit. I think I might need to look up to see if there is a known pattern to these keys that it could be easily figured out what it is even if it is just on a sheet with no context. Particularly 1Password which I think is a pattern if I remember correctly.
> Particularly 1Password which I think is a pattern if I remember correctly. What does that mean?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#88Obviously it must be possible to reset ones password, but from the article it's apparently possible to make 30 requests to reset ones password in a short amount of time.
What possible non-malicious reason could there be for that to happen?
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#89At some point the ability to trigger these prompts (or ones like them, like the Bluetooth-based setup new device prompts that were in the news last year) on Apple devices is itself the problem right? Obviously it must be possible to reset ones password, but from the article it's apparently possible to make 30 requests to reset ones password in a short amount of time. What possible non-malicious reason could there be…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#90Earlier quoted context omitted.
> When you set up a recovery key, you turn off Apple's standard account recovery process. > However, if you lose your recovery key and can’t access one of your trusted devices, you'll be locked out of your account permanently. I considered it before but I think it's just too much risk as I rely heavily on iCloud. On the other hand, I don't see the risk with the current method if you're smart enough not to fall for th…
The security researcher in the article was concerned about accidently confirming the prompt on his watch. I don't think its a matter of being "smart enough". Human error can easily creep in when dismissing 10's or 100's of prompts.