Apple Suspends Over-the-Phone AppleID Password Resets
wired.com
wired.com
Sorry, not that epic. Yes, multiple steps were required but the biggest issue in security once again was the human element.
Epic would be finding the flaws in SSL/TLS that allows you to generate a valid cert for any domain (Moxie Marlinspike) or a bug in DNS that is such cause for concern that people have to upgrade their infrastructure (Dan Kaminsky) or intercepting GSM calls (Chris Paget) while making the device believe it is on a legitimate network.
This hack came down to social engineering and using flaws in two companies verification systems. That isn't epic. People have been calling companies and people on the phone for decades and having them hand over information without proper identification/verification. The guys stuff got remote erased, well damn, the system worked as it was supposed to work ... other than that the right person wasn't at the controls ... remote wipe worked as expected.
Yes, changes have to be made, and yes security and verification of identity has to be made more secure when there is a lot at stake, but this hack was by no means epic.
Remote wipe is NOT enabled by default.
Especially on the iPhone/iPad where a lost device (i.e. behind the couch or something) is far more common than a stolen one.
And it's not enabled by default.
Epic status is irrelevant. It was effective. It should not be. Full stop.
I think that denigrating the significance of these "low sophistication" attacks is fundamentally the same error as venerating the importance of single-points of technological complexity independent of the end-to-end security of a system. It makes it easier to change the response from "oh crap, we got hacked so hard!" to "well, we just got socially engineered, ANYBODY can do that, no big deal". Social engineering is going to remain firmly in the "epic hack" category for the foreseeable future, even in a future age of quantum computers, synthetic consciousness, and ubiquitous use of one-time-pad encryption.
Your approach does leae users open to there own hindsight and if you lost a device you might in some situations reset the password first and then thing about remotely wiping the device and in those situations you will be a bit erked. That said it would be nice to at least have that option, options are nice as they allow the user to pick the level of control they want, more options more choice. Still be nice if a device being remote wiped checked its location and went - oi hang on your at home I need to verify this first, scary but doable.
That's the downside of Apple being so close to perfect. We expect perfection from them at all times. And when they make a mistake, it seems 100x more outrageous than if it were any other company.
Don't get me wrong, they made a terrible mistake in this case, but Amazon has gotten off lightly in comparison.
And, while Apple is very good, they are nowhere near perfect - especially when it comes to online services. Apple fans playing the victim card for them is just as tiring as people jumping all over them when they slip up.
Precisely. Go to any mall, restaurant, or shopping center in the U.S. and you're bound to find at least one discarded receipt with the last four digits of the shopper's credit card number on it, possibly with their name and/or signature.
May not work any more though.
Using nearly-public information, the attacker was able to convince a human to grant access to the victim's account, and therefore to destroy the victim's data.
If the compromise of an iCloud account had merely given the attacker access to the @me.com address, I don't think Apple would be receiving nearly as much bad press. Email accounts are compromised all the time, usually with no more damage than some spam mail sent to friends.
Similarly, if the attacker had gained remote-wipe ability by some elaborate deception, customers would be more willing to cut Apple a break. Suppose Apple accepted passports as a recovery mechanism, and the attacker showed up to an Apple store in person with a forged US passport. That would sell a lot of newspapers, sure, but Apple would be blameless.
http://www.youtube.com/watch?v=GQb_Q8WRL_g
http://www.youtube.com/watch?NR=1&feature=endscreen&...
The downside to selling people on the idea that your platform is secure and infallible is that people will hold you up to it.
Yes, I would be very annoyed if an account which had personal information, a history of purchases, and was linked to my credit got hacked (e.g. by social engineering). However, I would be even more annoyed if my laptop and phone got remote-wiped due to the same type of hacking.
But to be honest, I haven't been following the story that closely, so I am happy to be proven wrong on the perceived difference between the social engineering of Amazon vs Apple support .
Your Apple cloud password, however, is supposed to be secret.
### Amazon actually gave the attacker full control of the Amazon account. ###
All the attacker had to do was simply call amazon and ask to add a new credit card, the only verification was billing address. The attacker called back in 5 mins asking to change the email account on file, which required the last 4 digits of the fake card just added. The attacker then did a password reset.
Basically, most people don't realize Amazon had a HUGE GAPING wide whole in their security. Any attacker could steal any ones Amazon account! These are accounts that have thousands of dollars of affilate money, AWS servers running major web sites, credit cards on file, etc.
So yes, the fact that Amazon gave the last 4 digits out isn't a big deal, you are right. These numbers are printed on receipts. However, the fact that they gave the whole account away is a big deal.
Your CC can only be used for validation if you made a purchase with it.
That could be a handy additional service to offer, but they'd still have to provide a non-in-store method for all the people who don't, so it wouldn't be any more secure.
Adding (or worse, substituting) a serial number helps, but seems insecure in the event of a lost/stolen phone. A device serial number, plus all the already mentioned info: name, address, last 4 characters of a credit card, are all reasonably easy to extract from a stolen phone. Would be nice if some piece of info not usually stored on a phone were required. I suppose that a lost phone is already a security breach, but any containment would be an improvement.
(Two big loopholes on the Mac side are guest accounts and the recovery partition. Both of those offer ways to get your machine's serial number which do not require the attacker to log into your account.)
I can't find anywhere on my phone where the serial number's printed, though. The numbers on the back are not the phone's serial number.
Of course they offer two factor authentication.
And yes I mean different user names even if it is required to be a valid email id. If you use gmail, you can use "yourid+RandomNumberOrAnything@gmail.com" as the email address. This is additional protection against remote hackers since guessing the account name of one account doesn't get you the names of accounts on other services.
And yes ABSOLUTELY NO reason to not have 2 factor auth for your google account.
Honan owned up to not backing up, for example. Would it have been an "epic hack" if he could restore up to date data because he had a time machine backup?