Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.sys.mac.system > #29056 > unrolled thread
| Started by | Fred Moore <fmoore@gcfn.org> |
|---|---|
| First post | 2012-08-06 17:46 -0400 |
| Last post | 2012-08-08 04:31 +0000 |
| Articles | 20 on this page of 135 — 26 participants |
Back to article view | Back to comp.sys.mac.system
iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-06 17:46 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-06 21:54 +0000
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:33 -0400
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:47 -0400
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:05 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:05 +0000
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:20 -0400
Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 00:08 +0000
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 20:40 -0400
Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-07 13:20 +1200
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-07 10:48 -0400
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 12:34 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 12:58 -0400
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-08 14:30 -0400
Re: iCloud Hacked Article MC <copespaz@mapca.inter.net> - 2012-08-08 17:18 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:19 +0000
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-06 23:21 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:15 -0400
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:24 -0400
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:29 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 05:41 +0000
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:11 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:22 +0000
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:31 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 08:28 +0200
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:19 -0400
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:30 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:15 +0000
Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-08 08:11 -0400
Re: iCloud Hacked Article David Lesher <wb8foz@panix.com> - 2012-08-07 18:26 +0000
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 00:26 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 00:31 -0400
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 20:16 -0400
Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-08 12:28 +1200
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:13 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:16 +0200
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:56 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 09:46 -0400
Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 10:35 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 12:41 -0400
Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 14:15 -0400
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 14:57 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 16:25 -0400
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:51 -0400
Re: iCloud Hacked Article Larry Gusaas <larry.gusaas@gmail.com> - 2012-08-07 18:34 -0600
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 20:41 -0400
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-08 01:49 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:29 +0000
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:25 +0000
Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:57 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
Re: iCloud Hacked Article Jeff N <jeff+no.spam@jnadeau.com> - 2012-08-07 00:01 -0700
Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 03:48 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:49 +0200
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 21:52 +0200
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 17:33 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 16:44 -0500
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 18:09 -0400
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 18:33 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 19:26 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 19:19 -0500
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 21:07 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 11:14 -0400
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-08 13:11 -0400
Re: iCloud Hacked Article me@home.spamsucks.ca (Király) - 2012-08-09 04:56 +0000
Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 21:48 +0000
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:50 -0400
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:15 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-08 20:16 -0500
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:22 -0400
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 07:03 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 10:57 -0400
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 12:29 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:50 -0500
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:53 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-11 20:18 -0500
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 21:44 -0400
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 23:35 -0400
Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 19:00 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:19 +0200
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 23:06 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:26 +0200
Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 10:59 +0000
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 16:27 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:29 -0400
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:25 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 13:30 -0400
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 14:49 -0400
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 15:05 -0400
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 15:55 -0400
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:53 -0500
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 20:30 -0400
Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-09 17:50 -0700
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-10 09:15 -0400
Re: iCloud Hacked Article Warren Oates <warren.oates@gmail.com> - 2012-08-10 10:18 -0400
Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:49 -0700
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 10:50 -0400
Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:48 -0700
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 12:21 -0400
Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 10:00 -0700
Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-10 13:23 -0500
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:54 -0400
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-12 20:14 -0400
Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 08:50 -0400
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:55 +0200
Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 15:17 -0400
Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:28 +0000
Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:39 +0200
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 10:44 -0400
Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 14:59 +0000
Re: iCloud Hacked Article Richard Kettlewell <rjk@greenend.org.uk> - 2012-08-09 10:50 +0100
Re: iCloud Hacked Article Michael Vilain <vilain@NOspamcop.net> - 2012-08-08 17:40 -0700
Re: iCloud Hacked Article Jim Janney <jjanney@shell.xmission.com> - 2012-08-09 07:55 -0600
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:40 -0400
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:15 -0400
Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:42 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:19 +0000
Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 15:44 +0000
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 18:36 -0400
Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:21 -0400
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 21:09 -0400
Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 05:34 +0000
Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:45 -0400
Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 17:39 +0000
Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 11:12 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 01:08 +0000
Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:59 -0400
Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:31 +0000
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
| From | Fred Moore <fmoore@gcfn.org> |
|---|---|
| Date | 2012-08-06 17:46 -0400 |
| Subject | iCloud Hacked Article |
| Message-ID | <fmoore-F586C0.17460606082012@news.eternal-september.org> |
Thought folks here would be interested in this article I saw on Macintouch: Yes, I was hacked. Hard. <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> At 4:50 PM, someone got into my iCloud account, reset the password and sent the confirmation message about the reset to the trash. My password was a 7 digit alphanumeric that I didnšt use elsewhere. When I set it up, years and years ago, that seemed pretty secure at the time. But itšs not. Especially given that I've been using it for, well, years and years. My [guess is they used brute force to get the password]<-[this bit negated in the original] (see update) and then reset it to do the damage to my devices. The backup email address on my Gmail account is that same .mac email address. At 4:52 PM, they sent a Gmail password recovery email to the .mac account. Two minutes later, an email arrived notifying me that my Google Account password had changed. At 5:00 PM, they remote wiped my iPhone At 5:01 PM, they remote wiped my iPad At 5:05, they remote wiped my MacBook Air. A few minutes after that, they took over my Twitter. [...] Update Three: I know how it was done now. Confirmed with both the hacker and Apple. It wasnšt password related. They got in via Apple tech support and some clever social engineering that let them bypass security questions. [...]
[toc] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-06 21:54 +0000 |
| Message-ID | <slrnk20f7p.10nl.g.kreme@mbp55.local> |
| In reply to | #29056 |
In message <fmoore-F586C0.17460606082012@news.eternal-september.org> Fred Moore <fmoore@gcfn.org> wrote: > Thought folks here would be interested in this article I saw on > Macintouch: > Yes, I was hacked. Hard. > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> *HE* was hacked. iCoud was not hacked. > Update Three: I know how it was done now. Confirmed with both the hacker > and Apple. It wasn¹t password related. They got in via Apple tech > support and some clever social engineering that let them bypass security > questions. [...] That is worrisome. -- I SAW NOTHING UNUSUAL IN THE TEACHER'S LOUNGE Bart chalkboard Ep. 8F17
[toc] | [prev] | [next] | [standalone]
| From | JF Mezei <jfmezei.spamnot@vaxination.ca> |
|---|---|
| Date | 2012-08-06 20:33 -0400 |
| Message-ID | <50206268$0$1209$c3e8da3$50776f34@news.astraweb.com> |
| In reply to | #29059 |
>> Yes, I was hacked. Hard. >> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> I can understand the iPhone being wiped since there is a "wipe the iPhone" function on iCloud. But how can a laptop be wiped ? Is there also a "wipe my laptop" function on iCloud ? If not, what exactly is being deleted from the laptop ? Are we just talking about a sync for iTunes and iPhoto and iCal and Contacts ? (which make the laptop's libraries match the empty libraries on iCloud). ? If you suspect wrong doing, I guess the first thing would be to turn off wi-fi at your router before opening the laptop, and then disabling that iCloud thingy on the laptop. Reading the article, I kept thiniing "just take your SIM out and ut it in another phone". But then the writer admitted being with that old CDAM stuff (Sprint). Anyone know if an iPhone wipe has the power/auhority to muck with the SIM card ? I guess it can erase contacts stored on SIM. But for the rest, I am not sure it can really disable the SIM card.
[toc] | [prev] | [next] | [standalone]
| From | JF Mezei <jfmezei.spamnot@vaxination.ca> |
|---|---|
| Date | 2012-08-06 20:47 -0400 |
| Message-ID | <502065a9$0$1249$c3e8da3$b23f186d@news.astraweb.com> |
| In reply to | #29066 |
More info now available in a Wired article: http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/ ## The very four digits that Amazon considers unimportant enough to display in the clear on the Web are precisely the same ones that Apple considers secure enough to perform identity verification.? ## (talking about credit card numbers)
[toc] | [prev] | [next] | [standalone]
| From | Barry Margolin <barmar@alum.mit.edu> |
|---|---|
| Date | 2012-08-07 01:05 -0400 |
| Message-ID | <barmar-4A49CE.01055107082012@news.eternal-september.org> |
| In reply to | #29072 |
In article <502065a9$0$1249$c3e8da3$b23f186d@news.astraweb.com>, JF Mezei <jfmezei.spamnot@vaxination.ca> wrote: > More info now available in a Wired article: > > http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/ > > ## > The very four digits that Amazon considers unimportant enough to display > in the clear on the Web are precisely the same ones that Apple considers > secure enough to perform identity verification.? > ## > > (talking about credit card numbers) That's pretty amazing. Amazon is conforming to industry common practice: it's quite standard for receipts to include the last 4 digits of the credit card used, so that the customer has a reminder of which CC they used. Apple is clearly wrong in using this part of the CC# in their authentication process, they should at least ask for the entire CC#. But this whole debacle mostly highlights how difficult it is to do reliable identity verification over the phone. Companies could be more stringent, but it will be a big inconvenience for the 99% of callers who really are who they say they are. -- Barry Margolin, barmar@alum.mit.edu Arlington, MA *** PLEASE post questions in newsgroups, not directly to me ***
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-07 01:26 -0400 |
| Message-ID | <070820120126081347%nospam@nospam.invalid> |
| In reply to | #29098 |
In article <barmar-4A49CE.01055107082012@news.eternal-september.org>, Barry Margolin <barmar@alum.mit.edu> wrote: > That's pretty amazing. Amazon is conforming to industry common practice: > it's quite standard for receipts to include the last 4 digits of the > credit card used, so that the customer has a reminder of which CC they > used. Apple is clearly wrong in using this part of the CC# in their > authentication process, they should at least ask for the entire CC#. the hacker couldn't answer the security questions. the call should have ended at that point. it was obvious he was not who he said he was.
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-07 06:05 +0000 |
| Message-ID | <slrnk21c0t.17rs.g.kreme@mbp55.local> |
| In reply to | #29105 |
In message <070820120126081347%nospam@nospam.invalid> nospam <nospam@nospam.invalid> wrote: > In article <barmar-4A49CE.01055107082012@news.eternal-september.org>, > Barry Margolin <barmar@alum.mit.edu> wrote: >> That's pretty amazing. Amazon is conforming to industry common practice: >> it's quite standard for receipts to include the last 4 digits of the >> credit card used, so that the customer has a reminder of which CC they >> used. Apple is clearly wrong in using this part of the CC# in their >> authentication process, they should at least ask for the entire CC#. > the hacker couldn't answer the security questions. the call should have > ended at that point. it was obvious he was not who he said he was. Exactly. Although I am sure there are plenty of legitimate callers who also can't, but in that case, Apple should fallback to other methods. Like, say, a iMessage to your iPhone. Or, failing that, a mailed letter to your address with a reset code. Using billing address and last for of CC is not acceptable. -- Oh! I thought they smelled bad on the *outside*!
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-07 02:20 -0400 |
| Message-ID | <070820120220055514%nospam@nospam.invalid> |
| In reply to | #29108 |
In article <slrnk21c0t.17rs.g.kreme@mbp55.local>, Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > >> That's pretty amazing. Amazon is conforming to industry common practice: > >> it's quite standard for receipts to include the last 4 digits of the > >> credit card used, so that the customer has a reminder of which CC they > >> used. Apple is clearly wrong in using this part of the CC# in their > >> authentication process, they should at least ask for the entire CC#. > > > the hacker couldn't answer the security questions. the call should have > > ended at that point. it was obvious he was not who he said he was. > > Exactly. Although I am sure there are plenty of legitimate callers who > also can't, tough shit. that's what the security questions are for. just look at what they do for file vault: <http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT4790/HT47 90_StoreKey----en.png> Apple can only decrypt the recovery key using exact answers. If you cannot provide these answers, then Apple will be unable to access the key. Answer attempts may be restricted. no key, no data. > but in that case, Apple should fallback to other methods. > Like, say, a iMessage to your iPhone. what if you don't have an iphone? or if you do, if you don't use imessage? > Or, failing that, a mailed letter > to your address with a reset code. that's one possibility. > Using billing address and last for of CC is not acceptable. true.
[toc] | [prev] | [next] | [standalone]
| From | "John Varela" <newlamps@verizon.net> |
|---|---|
| Date | 2012-08-08 00:08 +0000 |
| Message-ID | <51W5y0sPNk52-pn2-sIUvEiWGJlcN@localhost> |
| In reply to | #29098 |
On Tue, 7 Aug 2012 05:05:51 UTC, Barry Margolin <barmar@alum.mit.edu> wrote: > But this whole debacle mostly highlights how difficult it is to do > reliable identity verification over the phone. Companies could be more > stringent, but it will be a big inconvenience for the 99% of callers who > really are who they say they are. What's really ridiculous is this: I handle all our family's financial matters. When I call some company to have some change made to an account that is in my wife's name, they insist they have to talk to her. So she comes on, lets them hear a woman's voice, and then they let me do whatever. For all they know, we're in the middle of a divorce, I am stripping her accounts, and the woman they spoke to is my girlfriend. -- John Varela
[toc] | [prev] | [next] | [standalone]
| From | Davoud <star@sky.net> |
|---|---|
| Date | 2012-08-07 20:40 -0400 |
| Message-ID | <070820122040381832%star@sky.net> |
| In reply to | #29163 |
Barry Margolin: > > But this whole debacle mostly highlights how difficult it is to do > > reliable identity verification over the phone. Companies could be more > > stringent, but it will be a big inconvenience for the 99% of callers who > > really are who they say they are. John Varela: > What's really ridiculous is this: I handle all our family's > financial matters. When I call some company to have some change made > to an account that is in my wife's name, they insist they have to > talk to her. So she comes on, lets them hear a woman's voice, and > then they let me do whatever. For all they know, we're in the middle > of a divorce, I am stripping her accounts, and the woman they spoke > to is my girlfriend. You and Mr. Margolin both have it right. In my capacity as pro bono Internet and/or new-computer-set-up guy for seniors, I go to peoples' homes to work for them. They trust me because they learned about me from friends whom they trust; I do not advertise. Sometimes it is necessary to call the ISP for information, and they do ask for Mrs. Doe to confirm that I am authorized to have the information. What a joke. But I couldn't help these folks without that ease of access. I have a record of all of these folks' passwords, of course. I have to keep them because I give them non-trivial passwords and they can't be expected to remember them all, and sometimes they lose the printed copy that I gave them (unless it's taped to the computer display). I keep the passwords in a folder encrypted by Exces <http://excesapp.com> with a complex password that I have memorized and also stored, not on any computer, but in two physically secure locations. Personally, whom do you trust? I trust my wife and my wife trusts me. Each of us has access to the login information for all of our accounts, from banks to CU's to brokerages to mail and shopping, so each can act on the other's instructions from afar without having to transmit login information in the clear or say it on the phone. -- I agree with almost everything that you have said and almost everything that you will say in your entire life. usenet *at* davidillig dawt cawm
[toc] | [prev] | [next] | [standalone]
| From | dempson@actrix.gen.nz (David Empson) |
|---|---|
| Date | 2012-08-07 13:20 +1200 |
| Message-ID | <1kogkes.5tcjfcsqlzibN%dempson@actrix.gen.nz> |
| In reply to | #29066 |
JF Mezei <jfmezei.spamnot@vaxination.ca> wrote: > >> Yes, I was hacked. Hard. > >> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> > > > I can understand the iPhone being wiped since there is a "wipe the > iPhone" function on iCloud. > > But how can a laptop be wiped ? Is there also a "wipe my laptop" > function on iCloud ? If not, what exactly is being deleted from the laptop ? There is a "Find My Mac" feature. I have it turned off. If I go to enable it there is a warning sheet which says "Find My Mac is part of iCloud and helps you locate, lock or erase a lost Mac". I haven't experimented with it to see the full details, but based on how it works for the iPhone I expect that the "Erase" will do either of two things: (a) If the volume is encrypted with FileVault 2, it will destroy the master key, immediately losing access to all data on the volume. (b) If the volume is not encrypted with FileVault 2, it will have to erase individual files or block erase the volume. It probably tries to delete everything, but perhaps starts with files in the home folders. Based on the description in the article, it sounds like it was deleting files. I'd have expected a restart to the recovery partition so that all files or the volume could be erased without having some locked due to being in use. > Are we just talking about a sync for iTunes and iPhoto and iCal and > Contacts ? (which make the laptop's libraries match the empty libraries > on iCloud). ? No. The wording implies the Mac is erased. > If you suspect wrong doing, I guess the first thing would be to turn off > wi-fi at your router before opening the laptop, and then disabling that > iCloud thingy on the laptop. Just turn off Find My Mac if you are concerned about losing the contents of your Mac due to a similar hack. > Reading the article, I kept thiniing "just take your SIM out and ut it > in another phone". But then the writer admitted being with that old CDAM > stuff (Sprint). > > Anyone know if an iPhone wipe has the power/auhority to muck with the > SIM card ? I guess it can erase contacts stored on SIM. But for the > rest, I am not sure it can really disable the SIM card. An iPhone with no SIM connected to a WiFi network that has Internet access could be remotely erased via Find My iPhone. The SIM card and cellular connectivity just makes it far easier as it is more likely to have Internet access. -- David Empson dempson@actrix.gen.nz
[toc] | [prev] | [next] | [standalone]
| From | Fred Moore <fmoore@gcfn.org> |
|---|---|
| Date | 2012-08-07 10:48 -0400 |
| Message-ID | <fmoore-1953A2.10485607082012@news.eternal-september.org> |
| In reply to | #29059 |
In article <slrnk20f7p.10nl.g.kreme@mbp55.local>, Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > In message <fmoore-F586C0.17460606082012@news.eternal-september.org> > Fred Moore <fmoore@gcfn.org> wrote: > > Thought folks here would be interested in this article I saw on > > Macintouch: > > > Yes, I was hacked. Hard. > > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> > > *HE* was hacked. iCoud was not hacked. _He_ had an account on iFog. His account on _iFog_ was accessed without authorization. Both HE and iFOG were hacked, unless you're saying every single users on iFog has to be hacked for iFog to be considered hacked. Apple gave out a temporary password when it shouldn't have. (And, yes, Amazon was complicit in the whole affair.) -- Republicans blaming Obama for the national debt and the state of the economy are like an arsonist blaming the fire department for the fire.
[toc] | [prev] | [next] | [standalone]
| From | Barry Margolin <barmar@alum.mit.edu> |
|---|---|
| Date | 2012-08-07 12:34 -0400 |
| Message-ID | <barmar-2C75D2.12344607082012@news.eternal-september.org> |
| In reply to | #29139 |
In article <fmoore-1953A2.10485607082012@news.eternal-september.org>, Fred Moore <fmoore@gcfn.org> wrote: > In article <slrnk20f7p.10nl.g.kreme@mbp55.local>, > Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > > > In message <fmoore-F586C0.17460606082012@news.eternal-september.org> > > Fred Moore <fmoore@gcfn.org> wrote: > > > Thought folks here would be interested in this article I saw on > > > Macintouch: > > > > > Yes, I was hacked. Hard. > > > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard> > > > > *HE* was hacked. iCoud was not hacked. > > _He_ had an account on iFog. His account on _iFog_ was accessed without > authorization. Both HE and iFOG were hacked, unless you're saying every > single users on iFog has to be hacked for iFog to be considered hacked. > Apple gave out a temporary password when it shouldn't have. (And, yes, > Amazon was complicit in the whole affair.) I think most people would interpret "iCould was hacked" to mean a more general intrusion into iCloud. It doesn't have to be "every" user, but something relatively widespread. If you found a credit card receipt on the ground, no one would make a big deal that "credit card numbers have been stolen". This particular hack involved a chain of several acts involving different services: Amazon, Twitter, Gmail, DNS registration, and finally Apple. These all had to be linked to get into just this one user's account. Admittedly, similar steps could be used to target someone else. But this doesn't reveal a general, cookbook process that can be used to get into many people's accounts. -- Barry Margolin, barmar@alum.mit.edu Arlington, MA *** PLEASE post questions in newsgroups, not directly to me ***
[toc] | [prev] | [next] | [standalone]
| From | nospam <nospam@nospam.invalid> |
|---|---|
| Date | 2012-08-07 12:58 -0400 |
| Message-ID | <070820121258516495%nospam@nospam.invalid> |
| In reply to | #29142 |
In article <barmar-2C75D2.12344607082012@news.eternal-september.org>, Barry Margolin <barmar@alum.mit.edu> wrote: > Admittedly, similar steps could be used to target someone else. But this > doesn't reveal a general, cookbook process that can be used to get into > many people's accounts. sure it does. all someone needs is knowing a person's icloud account, last 4 digits of their credit card and address and they're in. hopefully apple changes things and makes it significantly more difficult, but as of right now it's fairly easy to do.
[toc] | [prev] | [next] | [standalone]
| From | Barry Margolin <barmar@alum.mit.edu> |
|---|---|
| Date | 2012-08-08 14:30 -0400 |
| Message-ID | <barmar-173578.14301308082012@news.eternal-september.org> |
| In reply to | #29143 |
In article <070820121258516495%nospam@nospam.invalid>, nospam <nospam@nospam.invalid> wrote: > In article <barmar-2C75D2.12344607082012@news.eternal-september.org>, > Barry Margolin <barmar@alum.mit.edu> wrote: > > > Admittedly, similar steps could be used to target someone else. But this > > doesn't reveal a general, cookbook process that can be used to get into > > many people's accounts. > > sure it does. all someone needs is knowing a person's icloud account, > last 4 digits of their credit card and address and they're in. I still wouldn't call this "hacking iCloud". That's like saying that if someone guessed your password, they hacked iCloud. Yes, it means that getting into someone's iCloud account is easier than it should be, but that's not the same as hacking the system in general. The system is working as intended, they just intended the wrong thing. -- Barry Margolin, barmar@alum.mit.edu Arlington, MA *** PLEASE post questions in newsgroups, not directly to me ***
[toc] | [prev] | [next] | [standalone]
| From | MC <copespaz@mapca.inter.net> |
|---|---|
| Date | 2012-08-08 17:18 -0400 |
| Message-ID | <copespaz-832AAC.17180808082012@news.eternal-september.org> |
| In reply to | #29209 |
In article <barmar-173578.14301308082012@news.eternal-september.org>, Barry Margolin <barmar@alum.mit.edu> wrote: > Yes, it means that getting into someone's iCloud account is easier than > it should be, but that's not the same as hacking the system in general. > The system is working as intended, they just intended the wrong thing. They just announced some changes: http://money.cnn.com/2012/08/08/technology/apple-amazon-hack/?source=cnn_ bin -- "If you can, tell me something happy." - Marybones
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-08 04:19 +0000 |
| Message-ID | <slrnk23q67.vfq.g.kreme@mbp55.local> |
| In reply to | #29142 |
In message <barmar-2C75D2.12344607082012@news.eternal-september.org> Barry Margolin <barmar@alum.mit.edu> wrote: > This particular hack involved a chain of several acts involving > different services: Amazon, Twitter, Gmail, DNS registration, and > finally Apple. These all had to be linked to get into just this one > user's account. > Admittedly, similar steps could be used to target someone else. But this > doesn't reveal a general, cookbook process that can be used to get into > many people's accounts. Yes, it does because many people do exactly the kind of *STUPID* *SHIT* that Mat did, and that Amazon and Apple were complicit in. -- I WILL NOT INSTIGATE REVOLUTION Bart chalkboard Ep. 7G06
[toc] | [prev] | [next] | [standalone]
| From | Wes Groleau <Groleau+news@FreeShell.org> |
|---|---|
| Date | 2012-08-06 23:21 -0400 |
| Message-ID | <jvq1jh$pga$1@dont-email.me> |
| In reply to | #29056 |
On 08-06-2012 17:46, Fred Moore wrote:
> Thought folks here would be interested in this article I saw on
> Macintouch:
>
> Yes, I was hacked. Hard.
> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
And people laughed at me when I said I didn't want my life in iCloud.
--
Wes Groleau
“Two things are infinite, the universe and human stupidity.
But I'm not so sure about the universe.”
— Albert Einstein
[toc] | [prev] | [next] | [standalone]
| From | Lewis <g.kreme@gmail.com.dontsendmecopies> |
|---|---|
| Date | 2012-08-07 04:49 +0000 |
| Message-ID | <slrnk217hu.17rs.g.kreme@mbp55.local> |
| In reply to | #29081 |
In message <jvq1jh$pga$1@dont-email.me>
Wes Groleau <Groleau+news@FreeShell.org> wrote:
> On 08-06-2012 17:46, Fred Moore wrote:
>> Thought folks here would be interested in this article I saw on
>> Macintouch:
>>
>> Yes, I was hacked. Hard.
>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> And people laughed at me when I said I didn't want my life in iCloud.
Well, there are several things he did wrong.
#1 was using his Apple ID email for anything else.
I have unique emails for Amazon, Apple ID, Yahoo, Google, Ebay, Paypal,
World of Warcraft, buy.com, DropBox, woot, and just about any other
online service. Not only are they unique, but they are spread out over
several domains. While someone getting into one of my accounts would be
able to cause some damage, they would not be able to rampage through all
my services.
#2 was using the same address for his domain registration as his credit
card billing address. Rent a PO Box or something if you don't have an
office. You don't want anyone looking you up having your home address
*anyway*.
#3 was not running Time Machine
#4 was not having a completely separate off-line and/or off-site backup of
the files he considered most important (like his photos).
There are issues that have been exposed that are problematic, such as
Apple accepting simply a billing address and last 4 of credit card to
give anyone access. There are security questions for a reason, they
should be using them.
Amazon's security hole is even worse, to my mind, in allowing you to add
an unverified credit card to an account and then using it to unlock the
account.
--
He was Igor, son of Igor, nephew of several Igors, brother of Igors and
cousin of more Igors than he could remember without checking up in his
diary. Igors did not change a winning formula. {Footnote: Especially if
it was green, and bubbled.}
[toc] | [prev] | [next] | [standalone]
| From | Barry Margolin <barmar@alum.mit.edu> |
|---|---|
| Date | 2012-08-07 01:15 -0400 |
| Message-ID | <barmar-121D7C.01150007082012@news.eternal-september.org> |
| In reply to | #29092 |
In article <slrnk217hu.17rs.g.kreme@mbp55.local>, Lewis <g.kreme@gmail.com.dontsendmecopies> wrote: > Amazon's security hole is even worse, to my mind, in allowing you to add > an unverified credit card to an account and then using it to unlock the > account. Yeah, that was pretty funny. It suggests something like this could work: Caller: I need to change my account password. Amazon: OK, what would you like to change it to? Caller: Make it "YourPwned" Amazon: Done. Caller: Now I'd like to buy something, and bill it to my registered credit card. Amazon: Sure, what's your password? -- Barry Margolin, barmar@alum.mit.edu Arlington, MA *** PLEASE post questions in newsgroups, not directly to me ***
[toc] | [prev] | [next] | [standalone]
Page 1 of 7 [1] 2 3 4 5 6 7 Next page →
Back to top | Article view | comp.sys.mac.system
csiph-web