20 ms·
How Apple and Amazon Security Flaws Led to My Epic Hacking
- kunil 14y agoCan someone explain reasoning behind the implementation of those "remote wipes"? If Apple pulls a trigger, everything on my laptop erased when it is next online? I can't see any practical application for that.
- peejaybee 14y agoIt's to keep sensitive information from falling into the wrong hands.
- brown9-2 14y agoIt turns out, a billing address and the last four digits of a credit card number are the only two pieces of information anyone needs to get into your iCloud account. This is scary.
- cheald 14y agoEspecially given that that information is available to anyone you've ever used that credit card with. "Pay with your iCloud password" just doesn't have the same fuzzy feel, does it?
- mechanical_fish 14y agoI have actual work to do, work that I have been putting off too long, so let's try crowdsourcing this question on HN: What should one try to do to protect against this? Hypothetical actions to take: Make sure that an email address that's doing double-duty as a login identifier for a given service is unique to the service and appears nowhere on the web or in outgoing mail. Take particular care to have a "recovery" email address that is used for nothing else. Don't forward it to your regular mail, naturally. Enable two-factor auth for email if you possibly can. Have a credit card that is only used for online stuff. Can one get a second address that is used only as a billing address? How would one do that? (A P.O. box? Expensive! A friend's house? I fear that credit card companies will leak this address like a sieve no matter what I do.) EDIT: Startup wizards, here's a Minimum Viable Product: a credit card that can only be used for online accounts - which you must whitelist as you add them, via two-factor auth with your phone - and that features two billing addresses: The real one where the bills go and a dummy one that still validates. (Is that even legal under the CC rules? Sigh.) The other suggestions in the article: Disable Find my Mac, reduce coupling between your accounts… was there something else? Alas, nobody who isn't crazy paranoid is going to bother jumping through all these hoops. (I have tried to fight that paranoia but I think I'm losing that battle.)
- brown9-2 14y agoNot a solution, but I have a feeling Apple is going to be tightening their policy very soon. This story has gotten a lot of attention.
- ktizo 14y agorun your own server.
- bodyfour 14y ago...until the hacker calls up your registrar and convinces them to reset your domain management password.
- infinite8s 14y ago...in your closet
- danweber 14y agoHonestly, the credit cards are the easiest part. I'd much rather someone get my credit card number than my email account.
- Timothee 14y agoI agree with you but I think the idea of having a credit card just for online stuff is to limit the ways in which someone can get access to any information about your credit card, like the last 4 digits. For example, someone who finds your credit card receipt at a restaurant would get the digits of a different card and couldn't get access to your AppleID. It's actually a good idea. I'll think about doing that…
- foxylad 14y agoGive your parent's email as your recovery email address. If you need to reset, you can call them and talk them through clicking the link and resetting the password. The bad guys then have to crack your parents email account too, and being older they will be less likely to have daisy-chained Google, Apple and Amazon accounts.
- Spien 14y agoA lot of receipts contain the last 4 of the card used, it looks like most iCloud users are one garbage bag away from being compromised.
- suresk 14y agoGiven how central (for better or worse) of a role email plays in safeguarding other accounts, the hassle of 2-factor auth for it is feeling like less and less of an annoyance. About a month ago, one of my credit card accounts got hacked and was used to send money to someone else - the number itself wasn't compromised, it was the actual account. No doubt, the attackers tried to login and change my email password, but had to settle on the next best thing - spamming my email address with hundreds of emails per minute in an attempt to cover up the emails sent by my CC company. Fortunately, the spamming wasn't very sophisticated and it only took me 30 seconds to filter it all to trash. I was on the phone with my credit card company within 10 minutes of the attack, which mitigated some of the damage. I'm sure at some point weaknesses will be found in the 2-factor auth solution, but for now, it feels almost mandatory for important email accounts.
- irq 14y ago2-factor auth has been cracked before [1] and will be again until there is a standard on how to implement it. With implementations differing between companies, a cracker can play one org's weakness off another org. Like in this case, using the freely-available trailing 4 digit CC code from Amazon to get into Apple. If both companies agreed to a standard that made it obvious such practices were non-compliant, this wouldn't have happened. 1: http://blog.cloudflare.com/post-mortem-todays-attack-apparent-google-app http://blog.cloudflare.com/post-mortem-todays-attack-apparen...
- spacemanaki 14y ago> 2-factor auth has been cracked before I wish people would stop bandying this about as if there was an actual flaw in the 2-factor app or the protocol or crypto algorithms used. The linked breach was likely due to a social engineering attack on phone company support staff. Yes, it's concerning, and something Google and the phone companies should be investigating, but no, 2-factor auth wasn't "cracked." Someone who's more informed than I, is there really a weakness in smart-phone based two factor authentication if you choose NOT to use the SMS or voice based backup, out-of-band authentication option? I'm pretty sure that is an optional feature of Google's 2-factor auth, with printed backup codes being the alternative.
- danweber 14y agoWe need people to be able to regain access after losing a password, and we need only the right people to have that. This is a very hard problem. One thing that we should have is a "cool down" period. If you want to regain access to, say, your GMail account, then it will take 48 hours of waiting, and phone calls and emails will go out to your contacts before that is completed, so the real person has a chance to protest. I don't understand how the MacBook data was permanently lost. Even if the files were deleted in the OS, they are recoverable by disk utilities. Unless they were encrypted. Which just goes to say that when you think the solution to your problem is encryption, you don't understand your problem.
- prawn 14y agoIf you're trying to remote-wipe your computer so that a thief doesn't access your sensitive data, wouldn't you want the data to be lost permanently?
- danweber 14y agoCould be. But that's a very different problem. Old-school computer security breaks things down into the CIA categories: Confidentiality is for things you want secret. Integrity is for things you want to not be altered. Accessibility is for things you want to be able to reach. Honestly, very little of data requires confidentiality. Yet that's what encryption is usually used for. I would, by an order of magnitude, rather have a hacker gain access to my family photos than have them deleted beyond my ability to recover. I hate whole-disk encryption. In nearly everything in my life, the threat of losing access to my data is vastly worse than someone else accessing it.
- prawn 14y agoInteresting - hadn't heard that CIA thing before. I run a business. A good deal of what is on my laptop I would put in the confidentiality category. I guess apps and settings would come under integrity.
- 14y ago
- modularunit 14y agoCan we please get the entire internet to agree to stop using email addresses as usernames. It's not a user, its an email address!
- Dylan16807 14y agoHow is that going to help? Are people going to be expected to use a unique username per site? And password recovery is still going to let someone take over.
- modularunit 14y agoIt wont solve the problem, it also would not have prevented THIS issue. However -- many, many people use one email address for more or less everything in their lives. It's best if someone has no pieces of the puzzle, rather then have it half solved for them already. Especially when it's something like your first and last name as part of the address.
- pbreit 14y agoProbably not. Emails make terrific usernames because they are unique, easy to remember, double as a communication identifier and make registration slightly easier. And I'm not exactly sure how that would help in this situation. Are you suggesting that iCloud and Gmail login with usernames (different from your email address)?
- deleted 14y ago[deleted]
- pizza 14y agoWith every platform, there is compromise between convenience and security; when your platform has to reach many, many non-tech-y people, convenience is preferred.
- eupharis 14y agoThere are easy trade-offs one can make between convenience and security. For example, identity verification on the phone with the last four digits of a credit card (Apple). But then there are policies and technology that increase BOTH convenience and security. Say the difference between using SSH these days versus using, say, paper and an Enigma machine. The inconvenience of Google Authenticator is minimal and the security provided is huge.
- cubicle67 14y agoMy bank and a few other companies I deal with require some sort of pin/password in order to speak to someone over the phone. When I call, the conversation usually goes something like "Hello Mr 67, before we start I'll need your pin" "I have a pin?" "Yes, when you set up this account you were given a pin required for phone access" "Really? I have no idea what it is..." "That's ok. If you can just answer these other few questions. What's your mother's maiden name" [redacted] "and your birthdate" [also redacted] "thankyou Mr 67, now how can I help you today? ..."
- dkersten 14y agoThese "security" questions are usually, IMHO, the weakest link.
- jamesbritt 14y agoThat's why you make stuff up when initially providing the answers to be used.
- Groxx 14y agoand then immediately forget them, and discover that they weren't really necessary anyway and your <service> lets you in with other questions.
- a_bonobo 14y agoMy bank has a password - I never use that one anywhere else, but sometimes the bank calls me out of the blue to confirm some actions / bigger transactions and then I need it. Turns out, when I can't remember it they tell me the first 2 letters!
- infinite8s 14y agoThey must have some advanced crypto where the customer support person can only see the first 2 letters but the rest of password remains securely hashed...
- deleted 14y ago[deleted]
- rogerchucker 14y agohttp://whois.domaintools.com/emptyage.com http://whois.domaintools.com/emptyage.com reveals way too much about Mat Honan!
- thaumaturgy 14y agoAll the major registrars I know of offer free whois privacy services.
- rogerchucker 14y agoWhat does such a privacy service entail?
- thaumaturgy 14y agoAs far as setting it up, usually just a checkbox somewhere on the registrar's admin panel. As far as the results, all of the contact information in the public whois record is replaced with the registrar's contact information. They will forward information on to you if absolutely necessary. I keep whois privacy turned on for all my clients just to protect them from that damned Domain Registry of America scam.
- rogerchucker 14y agoSomebody else found out an iCloud flaw... http://m.smh.com.au/digital-life/consumer-security/aussie-exposes-icloud-flaw-but-apple-stays-silent-20120806-23pmx.html http://m.smh.com.au/digital-life/consumer-security/aussie-ex...
- Matt_Cutts 14y agoFor the people that want to turn on two-factor authentication on their Gmail account, here's how to do it: http://support.google.com/accounts/bin/answer.py?hl=en&topic=1056283&answer=185839 http://support.google.com/accounts/bin/answer.py?hl=en&t... I highly recommend it. Some of the common misperceptions I see: Myth: But what if my cell phone doesn't have SMS/signal? Reality: You can install a standalone program called Google Authenticator, so your cell phone doesn't need a signal. Myth: Okay, but what about if my cell phone runs out of power (added: or my phone is stolen)? Reality: You can print out a small piece of paper with 10 one-time rescue codes and put that in your wallet. Myth: Don't I have to fiddle with an extra PIN every time I log in? Reality: You can tell Google to trust your computer for 30 days and maybe even longer. Myth: I heard two-factor authentication doesn't work with POP and IMAP? Reality: You can still use two-factor authentication even with POP and IMAP. You create a special "application-specific password" that your mail client can use instead of your regular password. You can revoke application-specific passwords at any time. Myth: Okay, but what if I want to verify how secure Google Authenticator is? Reality: Google Authenticator is open-source: http://code.google.com/p/google-authenticator/ http://code.google.com/p/google-authenticator/ Hmm. Maybe I should throw this up on my blog too.
- almost 14y agoWell that answered all my misgivings about 2 factor with Gmail. I'm setting it up now. Thanks!
- xmpir 14y agoconvinced - i will set it up in a minute :)
- danielpal 14y agoAlthough enabling two-factor auth in gmail is great, I still fail to see how it would have protected his iCloud account. Sure his gmail account wouldn't have been compromised, but what about his his iCloud and twitter?. Why doesn't apple and twitter provide two-factor authentication? Why doesn't everyone do it this days?
- 14y ago
- nl 14y agoLast time HN discussed this story, I said "turn on 2-factor authentication for your Google account". Unsurprisingly, I got the exact reaction I'm seeing here when it has been suggested: lots of questions about how it works, people who think their situation is unique so it won't work for them, and people complaining than SMS is insecure. 1) Don't ask anymore questions. Try it out, if you hate it turn it off. 2) Your situation almost certainly isn't unique. You get 10 codes to print out, you can have (revokable) application-specific passwords that don't require the token. Try it!! 3) Use the smartphone application. Don't ask any more questions - just try it out!
- LVB 14y agoDefinitely print the codes! As a newbie I didn't, and as luck (or a 1/30 chance) would have it, I forgot my phone at home the same day my 30-day login window expired at work. Not a huge deal but a bit of a PITA, and there really was no way to log in until after I got home (which is obviously the point). Now I have some codes squirreled away in a couple key locations.
- draven 14y agoSame here, I changed my phone provider and the details on how to activate my new subscription were sent to my gmail account. When I connected to my GMail account the session had timed out. This was some kind of cyclic dependency: I needed my phone to get the details on how to make the phone working. I felt incredibly stupid. So... print the codes! (I managed to get the information by visiting GMail from my Linux box where the login didn't expire, but still)
- pooriaazimi 14y agoPrint 2 copies of the the codes and take a screenshot of that page. Then type "gpg -c sensitive.png" and use the same password as your gmail account to secure it. Then put "sensitive.png.gpg" in "~/.ssh" or another place out of the way and forget about it, until the day comes that you'll need it.
- smackfu 14y agoThis seems like poor advice. If people have questions, they should be addressed, not "oh don't worry your pretty little head, smart people came up with this." Like the discussion about app-specific passwords above was very informative to me... all it takes is one of those getting sniffed or read off disk and someone can suck down all your email. Not exactly "fire and forget" security.
- steve8918 14y agoI'm sorry for the journalist who lost all of his digital information, but I think/hope that this article will have a huge impact in terms of how the security practices for all large companies with an Internet presence, will behave. The fact that they pieced together all this information from multiple sources, including Amazon's ability to add credit cards over the phone, to getting the billing address through domain name registration, to hacking into Apple iCloud really makes me feel... I guess depressed is the word. We really have no control over our own data security. I've been super paranoid about things like identity theft, and I got my identity stolen, which is something I've been dealing with over the past 2 years or so. Somehow, my birthdate, addresses, etc were all wrong, and I had to jump through hoops to get it changed. As well, I currently have an unpaid credit card linked to my account, and the credit agencies and the collection agency won't remove it. The collection agency required me to submit 3 copies of my signature, a police record, copies of my identification, etc, before they'll remove it, even though THEY were the ones who made the mistake. I went to the police station to file a report, but they needed documentation that I didn't have, since I had already changed most of the information through the credit agencies. At this point, I froze all my accounts through the credit agencies, and I've given up. The safety of my email, etc, is something that I also take extremely seriously, and now I'm being told that there's a possibility of being hacked via clever hackers piecing together information from various sources, each of which have different security procedures. We literally have no data security except "security through obscurity", meaning that the likelihood of being randomly hacked is low, but if someone wants your account, they can and will get it, pretty easily it seems. The industry NEEDS to standardize on very rigid set protocols on things like what information they give out, how accounts are reset, how things like credit cards are added to accounts, what information they leak, etc. This is ridiculous.
- voxx 14y agoFirst, the title misled me to believe that the author had exploited something. Second, I'm tired of hearing about this guy who finds it unbelievable that people back up their important data every so often and uses Apple products.
- gatordan 14y agoI don't have a blog and I don't know the proper convention for those "Show/Ask HN" posts so I suppose a comment here is the next best thing because my question is related. After reading the "Yes, I was Hacked. Hard." post I updated several of my passwords and found that Netflix enforces a 10 character limit on their passwords. Does anyone have an idea why or how this could be the case? I would find it very ironic if they did this to save a few bits per user in their database considering they're a media streaming company.
- damian2000 14y agoVery likely its just some sort of limit imposed by a security API or library call. Definitely not a way to save space. Its really idiotic - they should be extending it out to longer than that, but there are still some banks around that impose shorter limits than this (8 chars) so they are in good company.
- stuff4ben 14y agoit boils down to "who do you trust?" Ultimately you have to take some responsibility in ensuring the safety of your data and be cognizant of the weaknesses of each link. I backup my data onto an external HD. In the event of fire or that HD being lost or stolen, I have online backups of everything but video. I also have an older external HD backup stored at my parents house 2 hours away. I trust myself to an extent and the cloud to an extent, but never either absolutely. My life is not Google or iCloud or Dropbox or Drobo.
- rogerchucker 14y agoMost important lesson as far as reducing vulnerability to social engineering is concerned: whatever service we subscribe to - we should always find out about their account retrieval process. In other words, we should always ask "what is the password retrieval process for the new account you just opened?" This sounds like a big task and one where not all scenarios can be covered. But I think this is a good first step - as long as we are still dealing with passwords, federated identity, half-masked credit card #'s and security questions. I think this exercise would help us be careful about our choice of passwords, answers, email ids. What would be the most obvious downsides to this approach?
- brudgers 14y ago>"the very four digits that Amazon considers unimportant enough to display in the clear on the web are precisely the same ones that Apple considers secure enough to perform identity verification" I don't see how this is an Amazon security flaw. The last four digits of my credit card is printed on receipts from just about every merchant I transact credit card purchases with. Treating such public information as if it is a PIN places the flaw clearly in Apple's court.
- throwaway8675 14y ago> First you call Amazon and tell them you are the account holder, and want to add a credit card number to the account. All you need is the name on the account, an associated e-mail address, and the billing address. Amazon then allows you to input a new credit card. (Wired used a bogus credit card number from a website that generates fake card numbers that conform with the industry’s published self-check algorithm.) Then you hang up. > Next you call back, and tell Amazon that you’ve lost access to your account. Upon providing a name, billing address, and the new credit card number you gave the company on the prior call, Amazon will allow you to add a new e-mail address to the account. From here, you go to the Amazon website, and send a password reset to the new e-mail account. This allows you to see all the credit cards on file for the account — not the complete numbers, just the last four digits. But, as we know, Apple only needs those last four digits. We asked Amazon to comment on its security policy, but didn’t have anything to share by press time. > And it’s also worth noting that one wouldn’t have to call Amazon to pull this off. Your pizza guy could do the same thing, for example. If you have an AppleID, every time you call Pizza Hut, you’ve giving the 16-year-old on the other end of the line all he needs to take over your entire digital life. This part seems relatively bad: > Amazon will allow you to add a new e-mail address to the account. From here, you go to the Amazon website, and send a password reset to the new e-mail account.
- brudgers 14y agoWhat I would say is that Amazon's security is in keeping with the recourse their customers have in regards to the transactions Amazon conducts - i.e. credit cards have fraud protection and disputed charges can be challenged and the money refunded when fraudulent charges are made. Amazon has balanced costs, risks and benefits for their stockholders. The wiping of the author's devices was purely due to the level of Apple's security - a level which Apple established based upon the interests of their stockholders. To hold Amazon to a standard which protects Apple's customers (as the article implies) just doesn't hold water - Apple implemented remote wipe, Amazon didn't.
- SCdF 14y agoI wonder, do any of these company send defensive communications when people try to unlock things like this? Yes, I made that phrase up. So here's what I mean: - "Amazon then allows you to input a new credit card." <-- Amazon should then send an email confirming this to your email address, a txt to your phone, and a smoke signal to your Tipi. - "Next you call back, and tell Amazon that you’ve lost access to your account.", email, phone, Tipi. And a waiting period. - When you call Apple's tech support, again: email, phone, Tipi. Maybe I'm missing the obvious flaw in this plan, but since customer support (humans) seems to be one of the main weak links, it would make sense for presume that's where people will attack, and to then attempt to reach out with all communication mediums possible to make sure you're talking to the real deal.
- macspoofing 14y ago>If I had some other account aside from an Apple e-mail address, or had used two-factor authentication for Gmail, everything would have stopped here. Are you sure? Do you trust the minimum wage customer service reps of your phone company to not be susceptible to social engineering?
- mick_dundee 14y agoTwo-factor authentication is important for online security (and not just email accounts), but there are other lessons to be learned from Mat Honan's misfortune. I'm probably more extreme in my practices than most people, but I'm OK with the inconviences. - You can't rely on companies providing online services to have your best interests as their best interests. - Take security seriously because if you don't you won't know about an attack until it's done. - Don't use a vendor's all-in-one services. - Don't use "the cloud" as a backup source. - Back up frequently. - Don't use one email account for everything. - Have an email account that is used for recoveries and nothing else... and keep it obscure. e.g: x90x90recovx@someotherhost.com - Don't use personal credit cards for online purchases. - If it's an option, don't store credit card details against your account; choose to manually enter it every time. - Don't use the same credit card for multiple sources of online shopping/billing/etc. - Don't give real answers to "security questions", such as your mother's maiden name or the name of your first pet. - Don't provide real personal information (address, contact number, etc) to online services when you create an account. - Don't use Facebook, Twitter, etc irresponsibly. - Shutdown if you're not at your computer. - Encrypt your data.
- TwoBit 14y agoCan somebody explain to me how it is that two-factor authentication would have prevented the hacker from seeing the author's recovery email address? Why would Google allow anybody to see your recovery email address without a password, and why would two-factor authentication prevent it. The author never explained this.
- btb 14y agoThe scariest part of this article IMO is how there now is a recipe posted for getting into any amazon account. Imagine all the damage/harassment they could do once in there, buy all kinds of stuff and have it sent to you. Spin up 20 EC2 instances and use them to perform illegal activites etc, while burning up cash on your credit card. That to me seems much worse than having an imac wiped.
- metafunctor 14y agoSome banks provide a service which allows you to create unique credit card numbers without actually having to get separate physical credit cards. Kind of like application-specific passwords, but for credit cards. See here: https://www.citibank.com/us/cards/gen-content/messages/van/index.htm https://www.citibank.com/us/cards/gen-content/messages/van/i... Separate credit card numbers for Amazon and Apple would have prevented this hack.
- raverbashing 14y agoThis This would be much more effective than the "Verified by Visa" theatre. "Virtual credit cards" with a limit and maybe even vendor limited (for example, create a virtual card and add some sort of vendor id for Amazon) Too bad it can't be used for anything, for example, some airlines require you present your CC when traveling (if it's your cc and you're traveling)
- mike-cardwell 14y ago"Moreover, if your computers aren’t already cloud-connected devices, they will be soon." I disagree. You can and will (for the foreseeable future) be able to choose a computer/configuration that doesn't allow some remote third party to run arbitrary code on it or wipe it. His devices were all wiped because he let a third party have that level of access.
- cookiecaper 14y agoThe fact is that Apple and Amazon have far more confused customers than targets for social engineering attacks. They are always going to have an "I forgot everything about myself and my account, please let me in!" option. All cloud service providers are going to have this. With this in mind, it may not be wise to remotely link your MacBook such that it can be wiped by Apple Central Command. Do people seriously do that? A phone is maybe kind of reasonable for this kind of thing (only kind of), but your actual laptop? Is this a requirement of new versions of OS X or something? I don't know who would set this up willingly. Any local data that you want to keep from attackers should be stored as ciphertext. Your secret key should be encrypted with a strong passphrase. Most thieves, even high-level corporate espionage-type thieves, won't know how to use GPG in the first place, but if they do, if you've done it right they won't be able to get in. From the perspective of keeping ourselves safe in a world where all data is kept on (or hooked up to a remote control at) the server of a big faceless corporation, all plaintext should be considered public info. Just because they haven't published or leaked it yet doesn't mean they won't, and it doesn't mean that anyone with an interest can't go in and take it, or that they won't wreak havoc for an ultimately minor goal (like access to Twitter). Encryption and backup. The two constantly repeated, never honored mantras whose inconveniences have plagued computer users for decades now. If people did these things correctly, hacks would rarely matter or jeopardize significant amounts of data. This is a field that is ripe for system-level disruption; Time Machine kind of helped with the backup, but we still don't have anything decent for layman's crypto (perhaps because the business models of companies are now so dependent on reading our information and selling it back to interested parties).
- Someone 14y ago"Encryption and backup. [...] If people did these things correctly, hacks would rarely matter [...] This is a field that is ripe for system-level disruption" Encryption and backups set in stone. An attacker may not be able to read your encrypted backups, but if he can delete them, you still won't be happy. I think the only feasible solution is that of online, write-only backups. They need to be online so that devices can backup themselves when they deem that necessary; you cannot trust users to do any manual backup task. They need to be write-only because, otherwise, with online backups, an attacker could wipe all your backups. Semi-write only, in the form of "deleting backups older than a year" or "delay any deletes by a month" (to give the user time to report his phone to be stolen) or "delete only after three-factor authentication" probably is acceptable. "perhaps because the business models of companies are now so dependent on reading our information and selling it back to interested parties" I think it is because online backup looks too pricey. People keep comparing the price of online storage to that of hard disks. For example Dropbox is about $1 per GB of storage per year. You can buy a SSD disk or a laptop for less than $1 per GB of storage. As this example shows, current solutions also do not protect well against attacks. I am not sure that the options of having your own cloud, or of making a cloud with others (peer-to-peer backups) will make sense to Joe consumer. Users may not want yet another device at home, likely will not have the upload bandwidth (yet), and are a risk factor with respect to operations on such a device. A home device probably would have to be a custom device, not a PC. Users cannot be trusted to operate it in ways that keeps their data secure, so you must make it impossible for them to operate it.
- sschueller 14y agoHow can he not press charges against 'Phobia' and any of his stupid script kiddy friends? Maybe the police is too stupid to do anything and the FBI has too much other shit do to but isn't there any legal way to get these bastards?
- mike-cardwell 14y agoHe probably doesn't want to risk further attacks. If he did want to get the police involved, I bet the attacker wouldn't be too difficult to find with all the services they logged into and phone calls they made. I mean, they could have used Tor for all of their Internet activity, but I bet they still used their home land line to make the phone calls.
- forcer 14y ago"The disconnect exposes flaws in data management policies endemic to the entire technology industry, and points to a looming nightmare as we enter the era of cloud computing and connected devices." This disconnect is unfortunately not limited only to tech industry. Every receipt you get while you pay with your credit card offline, will display some part of your credit card number. The crazy thing is that there is no standard for it and everyone picks different numbers! If you collect your receipts and then throw them all at once without destroying them - anybody can put the numbers together. I would say this is a much bigger problem and has been around here for ages!
- mike-cardwell 14y agoJust logged into Amazon account and removed all of the cards I have on record. Suggest everyone else does the same.
- infinite8s 14y agoThat doesn't matter for the purposes of the crack. With your name, billing address and email the cracker was able to add a new credit card number
- jarek 14y agoDon't forget to remove the credit card information from iCloud/.Me too.
- dendory 14y agoEveryone focuses on Gmail 2-factor, but that should be added as an option for any online service. It's trivial for any web developer to use the Google Authenticator to offer 2-factor auth for your own service in just a few minutes. I made a demo a while back in less than an hour, all open source. http://dendory.net/twofactors http://dendory.net/twofactors
- sriramk 14y agoThe scary bit (well, one of many) is how easy it is to get access to someone's Amazon account by just knowing their email address and billing address. That lets you buy anything, see their entire order history and probably gives you access to all of AWS.
- AlwaysWatching 14y agoIf they try to add a new address, Amazon will ask for the payment method to be re-entered.
- shalmanese 14y agoI think a lot of people are missing the forest from the trees in this discussion. The real interesting question is not how he got hacked, it's why it doesn't happen more often? None of the tricks listed in the article are particularly time sensitive, the fundamental patterns behind this hack go back at least several years and they relate to fundamental design interactions between complex systems that are difficult to impossible to change. So given all this, why him? why now? The answer doesn't have anything to do with how he should have set up 8 factor authentication or how he should have had a Swahili-numeric password. The answer is that his hacker had extremely atypical motivations and that's the reason his life got destroyed. The goal of this hacker was to pwn this guy's short, valuable twitter account. It's unlikely there's really any other hacker in the world who has that goal which is why such attacks are so rare. For most hackers, there's some sort of rational ROI calculation and if the ROI is negative, the hack isn't worth doing. Nerds often have a hard time seeing that security is a holistic system. It's often comprised of many flawed layers that are layered in depth to provide a statistically secure system. In real life, security comes from being able to push down the ROI through institutional mechanisms rather than personal ones. Credit cards are designed to be stolen and recovered from, investigations are able to target key players in the field and tough penalties means that the negative effects outweigh the positive gains. All this has lead to a black market rate of merely $2 - $3 per stolen credit card, meaning that there's not much motivation to hack in the first place. Nerds naturally have a libertarian bent which makes them more inclined to believe encryption and technology is the solution to the problem when, in reality, it's a beefed up police state and American hegemonic decisions that can span the globe.
- rmc 14y agoMost people are nice?
- smackfu 14y agoA smart hacker just steals the info, doesn't wipe out the data and reveal themselves.
- cbs 14y ago>it's why it doesn't happen more often? It does. It happens all the time. Most victims don't have the luxury of writing a wired article about it and are stuck picking up the pieces on their own.
- chmars 14y agoUseful advice via http://notes.kateva.org/2012/08/net-security-is-completely-broken.html http://notes.kateva.org/2012/08/net-security-is-completely-b...: 'We need to give Schneier a few drinks and get him to talk about this again. Failing that: Backup for Darwin's sake. Don't enable remote wipe of Mac OS X hardware. Just encrypt it. Use Google two-factor (two-step verification) if you are a geek and can stomach it. Fear the Cloud. Keep the data you value most close to you. Don't use iCloud. Don't trust Apple to get anything right that involves the Internet and/or Identity. Not being Schneier my advice isn't worth much, but fwiw I suspect the "solution" is: Get rid of the secret security question. Strictly limit password resets. If someone lost last access, charge them $50 to go to bank, post office or notary to establish their identity. Incorporate biometrics (thumb print and speech probably).'
- rmc 14y agoSome regions have data protection laws. This means in some places the standard security questions (like "What's your mother's maiden name?") are not enough to protect people's personal data. (Which is good). However such laws also include access. You cannot use disproportionate means to require access. Biometrics would probably not be legal to protect things like photos etc.
- donohoe 14y ago"Epic Hacking"? A whole lot of damage was done, yes - but a "epic hack"? Don't think so. epic: heroic; majestic; impressively great
- deleted 14y ago[deleted]
- tjoff 14y agoWhen you perform a remote hard drive wipe on Find my Mac, the system asks you to create a four-digit PIN so that the process can be reversed. But here’s the thing: If someone else performs that wipe — someone who gained access to your iCloud account through malicious means — there’s no way for you to enter that PIN. That sounds more like remote encryption to me. And a four digit PIN is easy to brute force (assuming that it isn't asking apple for the decryption key once entered (which means you need internet access do reverse it)).
- ksolanki 14y agoMost of the "security questions" can be answered by looking at the Facebook profile (of the person or his/her friends -- at least some have the info public). A motivated hacker can possibly crack even bank accounts using the facebook profile. The account/security is indeed in a big mess.
- setandbma 14y agoDoes this scare you?