They are trained to make you feel like you have something to hide.
They are trained to make you feel like you have something to hide.
A few years ago my bank would ring me up every couple of weeks and say "Hi, I am calling from your bank, we want to talk to Doctor Eval(), can you please verify your date of birth and we can get started?". They would get so pissed off when I wouldn't tell them. I was like, "how do I know you're from my bank?". (Banks seem to have stopped doing this now).
For companies which should be putting security at the centre of their business, they apparently have no idea that they're normalising phishing.
Yeah, this appears to have stopped, but was somewhat common a few years ago. My standard response was 'you called me, tell me who you are and I will call back on the official line'. They couldn't object to that. It was obviously some plan to 'ensure user privacy' that once it became known to one or two people with the authority to do something about it and the knowledge to know better it was quashed.
Now if only they would allow you to enable 2FA options that aren't SMS and also disable SMS. They don't understand that SMS is a terrible 2FA system isn't mitigated by 'but you can enable other things' if you cannot remove SMS as an option.
The NIST actually has great guidelines for digital identity authentication:
* https://pages.nist.gov/800-63-3/sp800-63-3.html
Don't blame the government -- they outlined an ideal way to do it on many levels of need. Blame the specific people who implemented that specific system.
* https://arstechnica.com/information-technology/2017/05/thiev...
* https://arstechnica.com/information-technology/2018/08/passw...
On the website:
1. you input a user ID
2. you input a password or PIN
3. you press a button that sends a SMS with an OTP code to the registered cellular number
4. you input this OTP code on the site
Even if someone can intercept the SMS, they wouldn't (shouldn't) have ID and PIN.
For another, what's the point in having 2FA if one of the factors is completely insecure? It's just an annoyance at that point, and a good way to ... tie your account to your phone number, which just coincidentally happens to be the primary key for most advertising tracking services. What a coincidence
The entire point of two-factor authentication is to provide an extra layer of security for when the first layer is compromised.
Having the possibility/capability of intercepting the SMS is only effective if the ID and PIN are already known, and while surely there are "other" ways to get them, the attacker needs all three.
From what I have read/seen, most if not all successful attempts to access someone else's bank account online go through some form of phishing.
The SIMjacking is the last barrier to access.
In most cases people reuse passwords and their login/password are known via any number of a million dumps of large websites whose dbs have been breached.
It doesn't have any security benefit for phishing like this, it's just one additional password input field.
Not true. FIDO and prevents this. The key is bound to the site you authorized it on, so inputting the key while connected to a phishing site will do nothing.
"Yes, I hear you typing in the PIN"
Oho, but that's a bit of security hole, isn't it?
"It's just beeps though, I can't tell what you typed"
Yeah but someone suitably skilled *could*, is my point!
"Yeah but it's just beeps, like this <beep beep beep beep>"
Okay and you typed 1 3 5 8.
"Uhhh... oh. Yes, I did. Uh, how did you do that?"
I've got an ear for it. This is absolutely not a criticism of you in any way and thanks for helping me demonstrate it, but could you get your supervisor to play this call to their manager and get back to me, once we're done with the call?
"Yes, I'll do that"
Awesome! Now these bank transfers...
They didn't call me back, but now call handlers transfer you to a totally different service to put a PIN in.
They equally hate the "we told you your computer would be ready in 3-5 days, but we haven't been able to reach you for the last 5 days to get your password since we determined it was a software issue and we couldn't go any further so it's still going to be another few days" experience.
So the default was to ask to make the experience as smooth as possible. But we were never instructed to pressure someone into giving up their password, just that we inform them upfront that without it all we can do is boot a test image to validate and that there's always the possibility software may play a part and still be a problem and we would want them to boot and confirm before leaving when they come to pick it up. Guest accounts were fine too. As was the customer giving us a formatted machine if they wanted. That was usually the best of the options because if the issue was present in a freshly formatted machine, we already rule out most / all of the software and we didn't have to deal with data loss issues (more than one customer signed the "I know I will likely lose data in this hard drive repair and I have a backup" line and then still pitched a fit when they did indeed lose data).
Apple had very strong rules about customer data privacy and snooping around was a good way to get fired (and I knew one person who did get fired for it). In fact, I've worked in health care and frankly Apple's rules for data privacy and secrecy (both theirs and their customers) was far more stringent than the health care job. HIPAA says protected info is any combination of identifying information AND medical information[1]. So your address and phone number, not PHI. A list of all your medications with nothing that identifies you, also not PHI. Technically your list of medications with your "patient number" could also be "not PHI" if the only thing there is no reasonable way for the patient number to be tied to identifying information without having access to the other protected data. At Apple, all data was considered private and confidential and anything that wasn't required to be kept for record keeping was to be shredded when it was no longer needed, regardless of whether that data could have ever been connected back to a customer.
Not to say that people don't abuse their access (again I knew someone who got fired for that), but at least in my time there they were very serious about only using the least access you needed and never told us to give anyone a hard time about wanting to keep their data private.
[1]: https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un...
Whether it's still like that I couldn't say. From the outside, it certainly seems like some of that infamous secrecy has been toned dow. Though whether that's culture/company change or the nature of being so big that even the smallest parts of your supply chain make noise I couldn't say. At the size and rate they've grown the retail business, there's also the possibility of just hiring so many "warm bodies" that embedding that culture is more difficult too.
And being fair to this study's subjects, I'm not sure you can even say much about the managers themselves. This sort of thing would be exceptionally easy for any half way competent tech to do without tipping off their manager. Apple might have the power and clout to heavily restrict what devices you bring into the back rooms, but I suspect your average local tech shop isn't doing bag checks and device checks on their employees. Who's really going to question the local tech carrying one more thumb drive than normal? And since these are customer machines, it's not like you have corporate MDM software installed that can report when an external storage device is plugged in.
I let him watched me type it in (on a cracked screen with a broken A key) and the proceeded to erasing all partitions before I left it with him.
It was preset to "fuck you", just in case.
(You do do backups, do you?)