"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.
Recent 'MFA Bombing' Attacks Targeting Apple Users
91–100 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#92I have hated Push MFA since it was introduced. How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.
You can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose. https://support.apple.com/en-gb/HT213154
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#93Earlier quoted context omitted.
I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.
Such a high risk of being locked out permanently is more than most people can stomach. Why can't they offer a last-resort option like showing up in person at an Apple Store with government-issued photo ID?
Your data and account ownership interest doesn’t disappear because of failure to possess the right sequence of bytes or a string. Can you imagine if your real estate or securities ownership evaporated because you didn't have the right password? Silliness.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#94Earlier quoted context omitted.
Personally, I encrypt my backup/recovery/setup keys in a CSV file using a password that I have memorized, and send them to family members to store in their accounts/cloud storage. But safety deposit boxes are a good choice too, just be careful to balance your own convenience. If you can't easily update your backups, you're really unlikely to include new accounts in them
That also means you can't easily update passwords.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#95Same problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.
The problem with adding rate limits, at least a global per user rate limit, is that you then create a new denial of service issue, preventing people from being able to recover their account.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#96Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#97Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#98(Don't get me wrong, let's go after Google, MS, Sony, et al too!!!)
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#99"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone…
I was unsure what this Recovery Key was: https://support.apple.com/en-us/109345 It is kind of scary too — lose the key and no one can get you back in to your account.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#100Earlier quoted context omitted.
Happened to me yesterday, I was baffled but then I found that you can request the one time password just using the email associated with the LinkedIn account, so the password wasn't compromised I have changed the password, main mail and in the privacy settings of LinkedIn removed the visibility of the email
Linkedin will silently change your visibility settings without your consent.