31 ms·
Recent 'MFA Bombing' Attacks Targeting Apple Users
- rekoil 3y agoAt some point the ability to trigger these prompts (or ones like them, like the Bluetooth-based setup new device prompts that were in the news last year) on Apple devices is itself the problem right? Obviously it must be possible to reset ones password, but from the article it's apparently possible to make 30 requests to reset ones password in a short amount of time. What possible non-malicious reason could there be for that to happen?
- gruez 3y agoNone, it's just that they haven't bothered adding a check for them. This isn't necessarily an indictment of them. It make sense in hindsight, but between sprints, OKRs/KPIs, and promotion packets, it's easy to let non-sexy functionality like these slip through the cracks.
- forgotmyinfo 3y agoIt's distressing and sad that we've come to expect so little from the trillion-dollar market cap companies to which we are beholden to participate in modernity.
- zubairshaik 3y agoIt's not as alarming if we just reframe it. Apple's software is written by developers, like many HN readers, and they follow similar interal processes. There is nothing inherent about having a large market cap that makes everyone involved superhuman. Some issues always slip through the cracks. I'm surprised to see this comment on HN where many readers see how the sausage is made. There's no secret sauce, no matter how far up in FAANG/MANGA you get.
- chefandy 3y agoI've been too immersed in university happenings recently. It took me clicking on the link and reading until "password reset feature" to realize that this wasn't some bizarre phishing attack involving Masters of Fine Arts degrees.
- fennecbutt 3y agoB-but iPhones are secure and are the best and Apple spends so much money on security to keep us safe and don't need any government/EU oversight at all. Proof that Apple's "it's for your own good" has always just been marketing. (Don't get me wrong, let's go after Google, MS, Sony, et al too!!!)
- ghodith 3y agoI don't see where EU regulations would have helped in this case.
- WarOnPrivacy 3y agohe received a call on his iPhone that said it was from Apple support. "I said I would call them back and hung up," Chris said, demonstrating the proper response to such unbidden solicitations." We're long-conditioned to assume that calling a large company and reaching a human will be difficult to impossible - and if we succeed, it will be an unpleasant experience. Much more so for a major tech company. As far as this scam succeeds, it's partially due to intentional business designs.
- someguydave 3y agoThis is true, and it is because the public is mostly too inept to be responsible for themselves
- WarOnPrivacy 3y ago> This is true, and it is because the public is mostly too inept to be responsible for themselves So why is an inept public responsible for major corps choices to mostly remove phone-to-human cust svc - and not corp poisoning by MBAs?
- metanonsense 3y agoA few weeks ago, we had a major problem with our Apple developer account (which is registered to my name). For days, I tried everything to avoid calling customer support (for the above reasons) and only agreed when our release team started panicking. I was more than surprised how incredibly good Apple‘s support team was. Recovering from the problem was quite difficult (and the circumstances that lead to it made me question Apple’s SW dev capabilities), but the support experience was simply perfect.
- JohnMakin 3y agomy mfa applications do not work on any other device, even if it’s restored from icloud. However, this would still be incredibly concerning.
- tanelpoder 3y agoThere's an important omission in the article and the top comments here don't mention it either: Accidentally tapping "Allow" does not allow the attacker to change the password on their web browser. When you tap Allow on your device, you are shown the 6-digit pin on your device and you can use it to change your password on your device. The final part of the attack is that the attacker calls you using a spoofed Apple phone number and asks you to read out the 6-digit pin to them. If you choose to give out the 6-digit pin to the attacker over an incoming phone call, then they can use it in their browser to reset your password. It's surprising that Krebs chose to omit this little detail in the security blog and instead seemed to confirm that someone could completely give away access to their account while sleeping.
- WheatMillington 3y agoHe describes this in the very first paragraph of the article: >Assuming the user manages not to fat-finger the wrong button on the umpteenth password reset request, the scammers will then call the victim while spoofing Apple support in the caller ID, saying the user’s account is under attack and that Apple support needs to “verify” a one-time code.
- rootusrootus 3y agoThat seems to be an entirely different point. Krebs suggests repeatedly that all you need to do to get hacked is click "Allow" in the push notification. This is demonstrably false. "Assuming the user manages not to fat-finger the wrong button" means "assuming the user clicks Don't Allow". They call on the phone to try and convince the user to say Allow next time. Of course that's kinda BS too, because the only time "Allow" gives you a six digit code is if you successfully authenticate your apple ID on a new device. If you get the reset password dialog, the result of Allow is not a six digit code, it just allows you to reset the password. Yourself. On your device.
- WheatMillington 3y agoAre you reading the second half of the sentence I posted? Sorry but I'm not understanding where you are coming from - Krebbs lays out clearly in the first paragraph how the attack works and you seem to be deliberately ignoring that.
- chatmasta 3y ago> he received a call on his iPhone that said it was from Apple Support (the number displayed was 1-800-275-2273, Apple’s real customer support line) This happened to me exactly once, and it was two days after I ordered a new MacBook from the online Apple Store. Since I was expecting a shipment, I almost picked it up. But instead I called Apple Support myself, and asked if they had called me, and they said they had not.
- gnicholas 3y agoDid you order right after a new model was released (as many people do), or did they just get lucky in calling you soon after you placed an order?
- chatmasta 3y agoIt was in December 2020, so maybe? I can't remember. I had just incorporated an Inc. (and received seed funds, but those weren't publicly available or announced), so maybe some of that info was a trigger. But it was surprisingly well-timed, for sure. It was within three days of placing the order. I suppose it could have also been as simple as "it's Christmas shopping time." I remember what was most surprising was seeing the caller ID, which I think was actually "Apple Inc," and which was saved as a contact in my phone.
- rootusrootus 3y agoThis seems like it is entirely a human problem, not any kind of technical failure. The fix is the same as it always was -- people need to be trained to say no by default, do not trust inbound calls ever, and never ever share your credentials. If you follow that advice, this attack poses no risk other than annoyance. If you do not give your password to the creep who calls you claiming to be apple support, you will be okay.
- dimgl 3y ago> people need to be trained to say no by default, do not trust inbound calls ever This really sucks though. It basically means that our current phone system is inherently broken and something that was potentially useful before is no longer useful due to malicious actors.
- ascorbic 3y agoA system that lets an attacker send hundreds of push notifications, effectively making a phone unusable until you click "allow" is a technical failure. So is one that lets an attacker spoof Apple's caller ID. Sure, that one is a failure with caller ID in general, but it's not beyond Apple's ability to special-case its own numbers.
- shuntress 3y agoIt still seems wrong to me that we, as a society, have basically accepting this level of crime as just a constant sort of background noise in daily life.
- kevrmoore 3y agoThis happened to me about 2 yrs ago. It catches you off guard when you receive a spoofed call from Apple Care as you are being bombarded with PW reset requests from your iCloud. Of course, the hacker is really good and answers all the Apple-related questions fluidly. I believe my account data came from the big Ledger hack, so they were targeting crypto holders. iCloud security was so weak back then!
- lilianaalba9 3y ago[dead]
- cyari6908 3y ago[dead]
- paul_h 3y agoThe fatigue part: if you clicked allow, and the hackers called you for the second step, but you responded "I understand you're a hacker and are wanting to steal from me in some way, but I am only going to give you incorrect pin numbers, so please stop with the reset dialogs and update your database not to try it again with me" .. would they stop? /s
- CodeWriter23 3y agoI think the way the attacker probes if victim is using an iPhone is they Message SPAM using Beeper-style use of Messages servers and interpreting error codes.
- MaxSamuel 3y agoI am posting this review here because I want to be of help to everyone out there, who in one or two ways has been scammed by online bitcoin investment platforms. After going through a lot to recover my bitcoin although many people told me it’s impossible. If you've lost your bitcoin as a result of investing in binary options, trading platforms, your account was hacked or other bitcoin related scams or lost money to scammers online in whichever ways then You’re not alone. I lost $97,950 to skyrockettrade. Being a scam victim myself, I tried several means to recover my funds all to no avail, till I came across a Cyber Asset Recovery. He literally saved my life, all i lost to these fake investors skyrockettrade was recouped in just a few days (a total of $97,950 USD was recovered, Kindly send a message to the contact below if you’ve been in such situations and you are seeking to recover your funds
- alessiabeatrice 3y ago[dead]
- gabykatherine 3y ago[dead]
- type_Ben_struct 3y agoI’m still disappointed by Apples implementation of security keys. I want to be able to prevent all 2FA methods other than security keys, but it still seems possible in certain flows to authorise a new login with another iOS device making it vulnerable to this attack.
- lloeki 3y agoInteresting. I was contemplating moving to security keys (which according to the setup flow "replaces verification codes" but IIUC you're saying one can still fall back to verification codes in some flows?
- dm 3y agoWhat flows have you found not to use security keys?
- ThePowerOfFuet 3y agoAll of them.
- antihero 3y agoJust change over to using HSMs instead of push. https://support.apple.com/en-gb/HT213154 https://support.apple.com/en-gb/HT213154
- EasyMark 3y agoIf I was doing something that needed heavy security, but I'm just a boring average joe. My critical accounts are protected by TOTP on one (backed up) device only, other things are kind of "good enough" with passkeys and passwords. If I ever become a criminal mastermind or double agent I'll probably dive into such methods though.
- 2OEH8eoCRo0 3y agoYubiKeys aren't HSMs, Yubico sells an HSM though. https://www.yubico.com/product/yubihsm-2-series/yubihsm-2-fips/ https://www.yubico.com/product/yubihsm-2-series/yubihsm-2-fi...
- Zetobal 3y agoSame problem with Instagram it's insane that so many giant companies have no rate limits in their recovery flows.
- WatchDog 3y agoThe problem with adding rate limits, at least a global per user rate limit, is that you then create a new denial of service issue, preventing people from being able to recover their account.
- faeriechangling 3y agoIf you’re getting DOSed by identical prompts you already can’t recover your account since you’ll likely hit the wrong prompt. There’s no protection here against an MFA fatigue attack attempt.
- EasyMark 3y agoit wouldn't be hard to add to the app though. obviously if you get a flood it's bullshit and more than a couple can be ignored. It's not rocket surgery
- forgotmyinfo 3y agoYou're telling me Facebook, with its billions of dollars and leetcode interviews, can't figure this out? That is outside the realm of computable functions?
- tdudhhu 3y agoWhy? You can rate limit the business logic but still show the user the default flow. For example: if a user is requesting a reset password link 10 times a minute you can just send the link one time but display everytime that a reset link was sent by email.
- WatchDog 3y agoThis flow is a bit different from a password reset email, it's a notification with a direct call to action, allow or deny. You can't debounce them like you can with a reset password email flow. With a typical password reset email, the actual password resetting is done by the user after they click the link in the email, only someone with access to the email can proceed, and they can only proceed on the same device that they clicked the email link. In this flow, there is no further on-device interaction.
- rvz 3y agoYet another reason why phone number verification is the most insecure way to verify users and it doesn't matter if a company like Apple is using it or your bank using so called 'Military grade encryption'. The point still stands [4] with countless examples [0] [1] [2] [3]. Unless you want your users to be SIM swapped, there is no reason to use phone numbers for logins, verification and 2FA. [0] https://news.ycombinator.com/item?id=36133030 https://news.ycombinator.com/item?id=36133030 [1] https://news.ycombinator.com/item?id=34447883 https://news.ycombinator.com/item?id=34447883 [2] https://news.ycombinator.com/item?id=27310112 https://news.ycombinator.com/item?id=27310112 [3] https://news.ycombinator.com/item?id=29254051 https://news.ycombinator.com/item?id=29254051 [4] https://www.issms2fasecure.com https://www.issms2fasecure.com
- saagarjha 3y agoThis has nothing to do with SIM swapping or phone numbers.
- isoprophlex 3y agoTFA talks specifically about a victim buying a brand new phone, registering a new appleid, and getting MFA bombed immediately when putting in his old SIM...
- klabb3 3y ago> and getting MFA bombed immediately when putting in his old SIM... I think it’s technically unrelated to the SIM, but rather to create the new Apple ID he used his existing (compromised, lol) phone number for “verification” or something. Which is weird in a way because then Apple must allow multiple accounts per phone number?
- jasode 3y ago>phone numbers. On the official Apple reset form, the "phone number" is one of the id options the hackers can use to MFA bomb the target: https://iforgot.apple.com/password/verify/appleid https://iforgot.apple.com/password/verify/appleid The gp proposes a different "private identification string" that's not public. Public IDs such as "email address" or "phone number" are susceptible to what this article is talking about.
- lloeki 3y ago"recent"? This happened to me and my wife (each starting a few days apart) in 2021, or maybe 2022 but no later. It started with a couple requests a day, then ramped up to every hour or something. IIRC we also both got a couple SMS claiming to be from Apple. As soon as it ramped up I set up both accounts to use recovery keys, which is a move I had planned anyway on grounds that it should not be in Apple's (or someone coercing/subverting Apple, be it law enforcement or a hacker) power to get access to our accounts. This obviously stopped the attackers dead in their track. For similar reasons I set up advanced data protection as soon as it was available and disabled web access. Only trusted devices get to see our data, and only trusted devices get to enroll a new device.
- fortran77 3y agoWow! You'd think they'd rate limit these! Once you've done it twice, go to once every 15 minutes, then hour, then 4 hours, than day, etc. Like bad logins.
- nilsherzig 3y agoThat would allow me to log you out of your accounts
- prepend 3y agoNo, it would affect login status. Just a delay between reset attempts. No reset actually occurs until one prompt is accepted.
- WorldMaker 3y agoKrebs notes that the recovery form does have some form of CAPTCHA on them, which mostly just goes to show that CAPTCHA systems are a poor and increasingly deficient rate limiter. ETA: Also from a user experience even once a week between attempts is still enough to deeply annoy a user getting popups on their devices. This is one of those cases where rate limits probably still can't solve the user irritation.
- deleted 3y ago
- _def 3y agoI wonder how long it will take until another goal of these phone calls will be to gather enough samples to convincingly clone your voice.
- Sarkie 3y agoGood fucking point this
- ted_bunny 3y agoBad comment, this. Just upvote.
- rvz 3y agoExactly this. Another reason to not to use phone (or the numbers) calls to verify users even with so called 'voice identification or voice ID' which can easily be broken with advanced voice cloning.
- _def 3y agoRecently I was baffled how far we've come with this. It doesn't work perfectly, but could be enough to fool someone. Just one pip install and a short voice sample away: https://github.com/coqui-ai/TTS https://github.com/coqui-ai/TTS
- ManBeardPc 3y agoThere is already a variant where they try to get someone to say „yes“ and just use a recording of it to use as „proof“ that you agreed to some contract.
- nebula8804 3y agoOMG that explains so much. I kept getting these calls where they would ask "Am I speaking with the head of the household?"...crap
- 3y ago
- honzaik 3y agoI am confused. What does happen after clicking allow? Does Apple just provide a password reset form to the person on the iForgot website or does it show up only on the device?
- viktorcode 3y agoI think it will show you the confirmation code on the device. Then the scammer will call to learn the code.
- chrisjj 3y ago> even though I have my Apple watch set to remain quiet during the time I’m usually sleeping at night, it woke me up with one of these alerts. So... Apple Watch "quiet" is broken??
- brookst 3y agoI find sleep focus mode much more reliable than the silent switch. It’s confusing they have both.
- aareet 3y agoI think it is just a transition period until they can get rid of models with the switch in their lineup. Since the action button is now configurable, it could soon turn back into just focus modes as the configurable way to silence your phone
- prmoustache 3y agoI have hated Push MFA since it was introduced. How hard is it to just type a code really. In the end to fight against push bombing you end up with push notification that ask you for a code anyway.
- deleted 3y ago[deleted]
- gruez 3y agoAt least on for icloud sign ins (not sure about password resets, too lazy to check), clicking "allow" doesn't allow the sign in, it only displays a 6 digit code that you have to enter to log in.
- antihero 3y agoYou can instead opt to use HSMs for your Apple ID MFA. I have 3x YubiKeys in various locations for this exact purpose. https://support.apple.com/en-gb/HT213154 https://support.apple.com/en-gb/HT213154
- gruez 3y agoThey mention "FIDO® Certified* security keys", this presumably means physical keys only, and not soft keys like the ones that keepassxc/bitwarden provides? If so that might be too much of a hassle for me. I care about my security, but I don't care enough to drop $100 on 3 separate security keys, and finding 3 separate places to keep them secure.
- hocuspocus 3y agoYou need two keys, not three. But yes I wish you could use one hardware key as backup and one software key for day-to-day usage, or at least the security key in a trusted device (up to you to have a circular dependency to your main device or not).
- someguydave 3y agoIt does not help you when a trusted device is stolen, the yubikeys can be disabled if they unlock your phone or device
- mavamaarten 3y agoI've been getting these on my LinkedIn account since a couple of days. Every few hours I get an email with a magic login link. They seem legitimate, originating from various locations around the globe.
- donovanallen 3y agoIt's been Uber for me
- standing_user 3y agoHappened to me yesterday, I was baffled but then I found that you can request the one time password just using the email associated with the LinkedIn account, so the password wasn't compromised I have changed the password, main mail and in the privacy settings of LinkedIn removed the visibility of the email
- azinman2 3y agoWhat I don’t get is what is the ploy here. I’m getting them too, but have no indication my email is hacked. Therefore what’s happening?
- pinebox 3y agoLinkedin will silently change your visibility settings without your consent.
- estiaan 3y agoDo you have a source for that? Or any more info? It’s not that I doubt it, I ask because some details like my work email, job title and place of employment has been leaking into the hands of marketing companies and I an trying to figure out how.
- forgotmyinfo 3y agoYour own company could've sold it to data brokers. Look into Equifax's Work Number score, it includes fun things like where you worked and how much you made. But no, let's not unionize or anything.
- mcintyre1994 3y agoThat message is horribly designed if it allows a password reset to happen on any other device after you click allow. It specifically says "Use this iPhone to reset". I'd have assumed it asks the person who clicked allow to set a new password, on the same device they clicked allow. Then again if it shows on the watch too (and isn't just mirroring a phone notification, since it ignores quiet mode), I can't imagine the idea is you click allow on your watch and then type a password on its keyboard?
- fortran77 3y ago> That message is horribly designed if it allows a password reset to happen on any other device after you click allow This was a lifesaver when my 90 year old mother forget her iMac password (and I forgot that I had created a second admin account on her machine.) After getting locked out of the iMac, we were able to reset it because we were able to get into her iPad (which she forgot the pin to, but fortunately we found it written down.)
- xsmasher 3y agoI don't think there's any danger in clicking "allow." There's still a 2FA step after that, and then you have to choose a new password. All of the danger comes from the phone call, where they presumably try to wheedle the 2FA code from you.
- woadwarrior01 3y agoQuite shocking how oblivious a lot of ostensibly tech savvy people are to the existence of hardware security tokens. Yubikeys have been around for over 15 years now, although Apple only added support for hardware tokens recently. https://support.apple.com/en-us/HT213154 https://support.apple.com/en-us/HT213154
- recursive 3y agoI know they exist. I just don't really know how they work or what they do.
- someguydave 3y agoThey don’t help in the case that your unlocked phone is stolen
- woadwarrior01 3y agoDo you not have auto-lock enabled on your phone?
- nerdjon 3y agoThe lack of rate limiting is surprising, either on the server side or the OS side (or both). I mean they already lock my iPhone after too many failed attempts with my passcode and it gets longer each time, I feel like the lock here should be the same. A better prompt would also go a long way.