Recent 'MFA Bombing' Attacks Targeting Apple Users
krebsonsecurity.com
Recent 'MFA Bombing' Attacks Targeting Apple Users
1–10 of 233 posts
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#2Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#3Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#4Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA.
[0] https://news.ycombinator.com/item?id=36133030
[1] https://news.ycombinator.com/item?id=34447883
[2] https://news.ycombinator.com/item?id=27310112
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#5Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#6Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#7Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
This has nothing to do with SIM swapping or phone numbers.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#8This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple.
As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone coercing/subverting Apple, be it law enforcement or a hacker) power to get access to our accounts. This obviously stopped the attackers dead in their track.
For similar reasons I set up advanced data protection as soon as it was available and disabled web access. Only trusted devices get to see our data, and only trusted devices get to enroll a new device.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#9Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
This has nothing to do with SIM swapping or phone numbers.
On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target:
https://iforgot.apple.com/password/verify/appleid
The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
Re: Recent 'MFA Bombing' Attacks Targeting Apple Users
#10Yet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinat…
This has nothing to do with SIM swapping or phone numbers.