4 ms·
Can you elaborate on how the phone-based recovery mechanism is grossly insecure - I am genuinely curious…
by ashildr 4y ago
Can you elaborate on how the phone-based recovery mechanism is grossly insecure - I am genuinely curious…
- fmajid 4y agoWell, the OP said the thieves were able to change the phone number on the account, for starters. Even without changing the number, phone numbers are easy to hijack. The security of the scheme depends on how gullible a cell phone company customer service rep is, or how corrupt a phone shop employee is who is willing to do a "SIM swap" for the crooks. See Brian Krebs' website for a description of the process and how it was used to empty crypto wallets. Furthermore, telecom standards were designed by committee and rely mostly on security by obscurity. The SS.7 system used to carry text messages has no encryption or authentication and no security whatsoever, which is how Russia or Saudi Arabia have been using it to track dissidents in the US through their phones. Even if you don't have access to the SS7 network, you can also intercept them over the radio waves using about $1000's worth of PC and electronics because spy agencies have gimped the encryption standards to make them easy to tap.
- ashildr 4y agoIIRC changing the phone number associated to an AppleID involves knowing the device code, the AppleID passcode or having access to another device with 2FA. I may be wrong and I have multiple devices with 2FA activated, so my mileage may vary because of this. I’d always expect 2 factors to be necessary to make changes to my account. If changing the phone number with activated 2FA is possible without one of these elements present I’d consider it an oversight. I consider the SMS mostly a tool to make sure the user has access to the new phone number while setting it up and does not misstype. Since OP mentions a 4-digit smear code I am not convinced that Apples security is the weakest link.