Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think that might be too harsh. For people like us, customer service policies aren't normally included in "basic security". Obviously they should be. But my guess is that this kind of vulnerability exists all over the world in all sorts of industries.

In the US, at least, regulated banks have some security requirements that might prevent this (though I'm not sure). But outside of that my guess is that it's routine for a customer service agent to be able to make any modification to an account they want, without an extra authentication factor or supervision.

So yes: blame Apple. But be wary, they can't possibly be the only ones.



Yes, definitely blame Apple, no doubt about it. I'm still a little shocked that the last 4 cc digits constitutes 'security'. An easy alternative - which I think they already have - is the whole two security questions thing. I would feel much better - as a customer - if they used those.

This type of thing is going to happen more and more and the fact that remote wipe of all the devices happened totally negates any advantages of using cloud services. I mean, what's the point of having everything backed up remotely if

a) the backup is not current b) the same remote servers can wipe your devices at any time

In addition, it's possible the remote backups could be removed as well (although not sure about that for iCloud) and in that case, you might as well not back anything up and have a hard drive die (at least that could be recovered I suppose).

Apple needs to jump out in front of this asap and announce a policy change in regards to security in order to put people at ease. I'm glad this is making waves and I think there needs to be more noise about it in order to get them to change.


Well, If he had a backup (either remote or local) it wouldn't have mattered. It would mean a few hours spent with Time Machine, but he wouldn't lose his data. And a remote backup should not be "removable".

Also, don't ever expect Apple to do anything ASAP. Even if the whole world shouts at them, they won't say anything. They take their time to (hopefully) think this through.


>> Well, If he had a backup (either remote or local) it wouldn't have mattered.

For this specific thing, no. But this was a fairly blatant act by the hacker. What if they silently read your iCloud mail, or used the Find my iPhone functionality to stalk you.


They couldn't silently do anything. They won't give you passwords, they give you the ability to reset it. If the hacker were to reset it, the reporter would notice (as he wouldn't be able to use his account anymore). And I think Find my iPhone would cease working if the password saved by the app does not match what's stored in the cloud (i.e. hacker's bogus password).

In case of cookie sniffing, Google shines. They show you the IP addresses of people who have used your account recently. If you (or them) spot an stalker, you can reset the password. I don't know how effective that could be with 3G, but at least

---

That said, It's no secret that Apple's password system is absolute garbage. I had to reset it 5 times last month because someone was trying to get to my iCloud account (probably brute-force). Apple would de-activate my account and would require me to re-enter security questions and choose a "new" password that I haven't used in the past year. And every time I had to spend an hour typing the new password in my various devices. AND I WOULDN'T RECEIVE MAILS IN THE MEANTIME. Just ridiculous.


The security questions business is hard, too.

Many sites use things which are public information (mother's maiden name) but even question's like "Where were you on this important date?" or "what was your first car?" start to look pretty silly in the age of Facebook. Worse, a dropbox-loving facebooker who's checking his gmail account from his iPhone probably has enough information in many of those places to compromise the other accounts.


You should never give legit answers to these security questions. I just paste in the output of pwgen -s 32 1. This may make your account harder to "recover" but it also makes it harder to steal.


Yes, this is exactly what I do. I have interesting results sometimes;

  Bank: I'll just need you to confirm your mother's maiden...um...um
  Me: Yes, it's a long string of random characters, want me to read it?
  Bank: No, that's ok, thanks.
:/


For a compromise, you can add the correct answer but with a quirk. (that is easier, unless you forget the quirk)

like, put the first name in "Mother's maiden name", or the middle name, or swap their position

And you are right to treat it as a passsword


I've had plenty of banks ask me to call back later because I didn't meet all of their screening vectors for identity verification simply because I didn't have a certain piece of information available at the time.

Frustrating? Yes. But good security can't be transparent to the user.


Amazon was a great example of this for me. I was trying to get a phone I had purchased through them replaced, and they asked me what my "display name" was.

Now I had completely blanked on what that was.. was it my username? Was it my full name? Was it the beginning part of my email? gah, I'm on break outside a cafe and thought I could get this settled quick..

So the person on the phone, in quite a polite and understandable way, gave me a number to call back directly when I could remember it as I had passed all other verification steps. Had a moment of clarity and called back 2 seconds later and got on with it. They overnighted me a brand new phone.

I rate that interaction a 10/10. 9/10 if we can imagine a world of omniscient amazon that knows when I've received broken items..


Frustrating? Yes. But good security can't be transparent to the user.

Nearly always security is the opposite of convenience. Once people realise that you can be "more secure" or "more convenient" we'll all be better off. This implies to be "more secure" you must be "less convenient". It's always a trade off.


In the US, at least, regulated banks have some security requirements that might prevent this (though I'm not sure). But outside of that my guess is that it's routine for a customer service agent to be able to make any modification to an account they want, without an extra authentication factor or supervision.

The EU has data protection law, which means companies that store personal data are legally required to ensure it's safe. I wonder if Apple are in breech of the law here?


I'm not a lawyer, but technically the hacker didn't "hack" the computer systems. So I'd wager that you can't slap a data protection law. But on the other hand, they definitely are legally liable for even a social-engineered attack. Maybe they'll get hit with negligence?


EU Data protection law is not about "data in the computer sense" but personal information. It's not related to computers per se at all. If someone can just ring up and ask for personal information, that would be against the law. If customers personal details are written up in walls on their public offices, that would probably be illegal aswell.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: