That's absurd.
This should make every iCloud user reeeeeaally nervous.
That's absurd.
This should make every iCloud user reeeeeaally nervous.
Very few, if any, defenses against social engineering, other than (A) Not allowing it, or (B) Requiring a Notarized-registered-letter of identification to start the process.
I'm a fan of using Notaries for password resets. Particularly to my email account, as it's the most valuable thing I own. Double-notarize in the event of two-factor resets. Make it a HUGE burden. Lock me out of email for a week or two if required, but don't give anyone access to my email.
The long times it takes for them to even answer a mail (if at all) would probably give a heads-up to anything fishy going on in your account. Secondly, unless your account is actually worth the wait, they would probably try to attack an easier target instead of Google or Facebook.
I think neither of these is the solution. If you can't talk to a human you'll never get help if you're locked out. If human support is available, there is always a chance they'll hand over your account to some scammer. Two-factor authentication means you'll be screwed if your second medium is unavailable or highjacked.
Maybe the only way to protect yourself is having independent (offline?) backups that only can control. Sadly, that's not an option regarding a lot of walled-garden services such as Facebook or iCloud.
When Facebook was still granting new users access by checking that their email matched a school's domain, I was able to make accounts at multiple schools by sending a forged email (claiming to originate from the school domain) to Facebook support saying something like: "I never received the confirmation email. Will you please activate my account at fakename@targetschool.edu?"
And it worked 90% of the time.
I wonder how many websites nowadays would be susceptible to a targeted and personalized forged email to customer service (especially since emails are frequently used to prove account ownership).
"Sir, we are just going to need to send an SMS to your phone number"
"Ok which number is that.. "
"it is the 065 488 48.."
"..that is my old work phone, which I no longer have access to"
Works all the time. The tip with social engineering is to ask for a little at a time. You don't call up and say "I don't have my phone, email, password, and nor do I know my mothers maiden name.. please let me into my account"
You take it all a step at a time and give it a narrative, just like a real user in the predicament would (and I have been in the predicament and called Apple). Works almost every time.
Makes you wonder if offering accessible customer service, at scale, eventually it's not even the guy on the phone that's the problem. The policy person cries uncle.
Social engineering will always work.
They removed the copy on their website that claimed that "Macs don't get PC Viruses"[1]. They disabled automatic execution of Java Applets in response to Flashback[2]. The introduction of Gatekeeper and the App Store model shows their intention for reducing the vectors average users can install random software (which reduces rogue installations like Flashback). ASLR is fully implemented in Lion now, and the inclusion of FileVault 2 suggests they are aware of and trying to mitigate offline attacks[3]
Regardless if you think this is enough, it does show that they are doing something. For every couple steps forward in closing a security issue, issues such as this article show that more could be done. Security is hard, no OS or company will ever be Perfectly Secure(tm). Apple is not "doing nothing". Claiming that they aren't is an uneducated answer, claiming that they could do more and be more transparent about it is a more valid argument.
[1] http://www.wired.com/wiredenterprise/2012/06/mac_viruses/ [2] http://support.apple.com/kb/HT5242 [3] http://www.securitynewsdaily.com/960-apple-mac-osx-lion-secu...
Almost everything is sandboxed and there are no known viruses out there (for devices that haven't been jailbroken).
Jailbreaks are still possible (like you said nothing is perfectly secure), but have been slowed down to a point where hackers wait for a big OS release, before they decide to burn the exploits.
I had the misfortune to lock myself out of my bank account once or twice and the process for unlocking it was so dreadful (a 30 minutes interrogation with questions like "when and where did I make my last ATM transaction") that since then I keep the required sensitive info in a GPG encrypted file so that I never have to call them again. Other equally frustrated but less tech savvy customers are probably doing the same with post-it notes. Is this an improvement?
Security at the bank seems discretionary at best.
No, it is a cost benefit decision. Do you know they don't check the signature on cheques or credit card transactions? Heck I bet if you mail in a change of address they will go ahead and do it, possibly sending something to your old address.
The reality is that fraud is at low levels compared to legitimate transactions. Putting in lots of extra hoops just makes the legitimate transactions harder, and chances are it won't affect those trying to commit fraud since they have a wide variety of things to try while tellers don't (eg fake id in this case).
In this specific case, anyone coming into the branch is on security cameras inside and out. TV shows, the Internet and technology make it increasingly easier to match up the footage with real people. And the bank doesn't bear the full costs of any investigation since they are passed off to the police/FBI.
If you ran the bank would you add a dollar in expenses and one minute per transaction that has a 10% chance of catching fraud, and fraud occurs one in every 25,000 transactions? Would you have the same measures in every branch across the country or have their expense and severity proportional to the amount of fraud that does actually happen at any location?
Despite what we see in films and TV shows, bank robbery is pitiful way to not make money:
http://www.thefiscaltimes.com/Articles/2012/06/11/Why-Robbin...
http://crimeblog.dallasnews.com/2009/04/new-bank-robbery-sta...
1) Cost benefit analysis and discretionary security is not mutually exclusive. It's cost benefit analysis ergo discretionary security.
2) Crime pays. You just have to be sophisticated and powerful enough to not be indicted. (TARP?)
The interesting thing about your comment is when you apply your logic towards combating terrorism. The cumulative harm of prevention of terrorism outweighs the damage and death caused by the terrorism itself. The 'cost-benefit analysis' must take into account the 'positive' externalities for those who advocate those policies.
For 2) white collar crime certainly has shorter prison sentences in the US. It is a little harder to apportion blame as directly as with a bank robber. The general cause of problems has been the US government bailing out creditors. Because of that creditors have been laxer in their standards, had lower oversight and a greater tolerance for risk. This is virtually US government policy and has been going on since the 1984 rescue of the creditors of Continental Illinois. Ultimately fixing this involves fixing the US government and the corruption of Congress - see Lawrence Lessig's talk about they operate around money - and smaller things like regulatory capture.
The response to 9/11 has been to massively amplify the original effects, giving a huge return on investment to Al-Qaeda. In the positive column has been some of the security theatre - the appearance of improved security will be reassuring to some people. But everything else has been negative - the government expenditures, making new enemies in Iraq and Afghanistan, the loss of freedom for Americans, the massive invasive spying on Americans, the use of "terrorism" as an excuse for inexcusable things, the loss of American prestige (Guantanamo Bay isn't good PR), the additional friction on American life in both time and money (try taking a flight) and the list goes on.
I don't want to belittle 9/11, but the same number of people die each and every single month on American roads. It happened that same month, and every month since.
IMHO it would be a far better remembrance to the victims if we said "fuck you" to the perpetrators and lived free and open lives despite them, rather than the crippling effects that did happen.
Very few are murders. Murders and accidents are not the same thing and not equally bad.
One difference: if you don't do anything about accidents, the rate stays the same. If you don't do anything about murder and just let it happen, the rate goes up as more people realize they can get away with it and serial killers or terrorists get more bold.
Yes. Without the strict checks by your bank, none of their customers would be secure. With their checks in place, some, including you, are now secure.
Improve Apple ID Security
- To help ensure the security of your Apple ID, choose three security questions and answers.
Just random because I don't have challenge responses on record, or immediate low-hanging fruit in response to this breach?
My solution at the moment is to remove every passwords from icloud. There're some nice scripts online - just did that and blogged about it on http://en.blog.guylhem.net/post/28778777551/icloud-remove-ke...
It's obvious it can't be trusted until 2-way auth is implemented. hell - if I manage to forget my password and loose my cellphones and homephone numbers, I WANT my icloud data to be gone for good!