Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #29056 > unrolled thread

iCloud Hacked Article

Started byFred Moore <fmoore@gcfn.org>
First post2012-08-06 17:46 -0400
Last post2012-08-08 04:31 +0000
Articles 20 on this page of 135 — 26 participants

Back to article view | Back to comp.sys.mac.system


Contents

  iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-06 17:46 -0400
    Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-06 21:54 +0000
      Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:33 -0400
        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:47 -0400
          Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:05 -0400
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:05 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:20 -0400
            Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 00:08 +0000
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 20:40 -0400
        Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-07 13:20 +1200
      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-07 10:48 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 12:34 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 12:58 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-08 14:30 -0400
              Re: iCloud Hacked Article MC <copespaz@mapca.inter.net> - 2012-08-08 17:18 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:19 +0000
    Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-06 23:21 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:15 -0400
          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:24 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:29 -0400
        Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 05:41 +0000
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:11 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:22 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:31 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 08:28 +0200
      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:19 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:30 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:15 +0000
        Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-08 08:11 -0400
      Re: iCloud Hacked Article David Lesher <wb8foz@panix.com> - 2012-08-07 18:26 +0000
    Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 00:26 -0400
      Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 00:31 -0400
        Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 20:16 -0400
          Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-08 12:28 +1200
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:13 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:16 +0200
              Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:56 -0400
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 09:46 -0400
                  Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 10:35 -0400
                    Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 12:41 -0400
                      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 14:15 -0400
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 14:57 -0400
                  Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 16:25 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:51 -0400
          Re: iCloud Hacked Article Larry Gusaas <larry.gusaas@gmail.com> - 2012-08-07 18:34 -0600
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 20:41 -0400
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-08 01:49 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:29 +0000
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:25 +0000
                Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:57 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
    Re: iCloud Hacked Article Jeff N <jeff+no.spam@jnadeau.com> - 2012-08-07 00:01 -0700
      Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 03:48 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:49 +0200
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 21:52 +0200
            Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 17:33 -0400
              Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 16:44 -0500
              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 18:09 -0400
                Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 18:33 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 19:26 -0400
                    Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 19:19 -0500
                    Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 21:07 -0400
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 11:14 -0400
                        Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-08 13:11 -0400
                          Re: iCloud Hacked Article me@home.spamsucks.ca (Király) - 2012-08-09 04:56 +0000
                    Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 21:48 +0000
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:50 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:15 -0400
                          Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-08 20:16 -0500
                          Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:22 -0400
                      Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 07:03 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 10:57 -0400
                          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 12:29 -0400
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:50 -0500
                              Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:53 -0400
                                Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-11 20:18 -0500
                                  Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 21:44 -0400
                                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 23:35 -0400
                          Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 19:00 -0400
                Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:19 +0200
            Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 23:06 -0400
              Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:26 +0200
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 10:59 +0000
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 16:27 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:29 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:25 -0400
                    Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 13:30 -0400
                      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 14:49 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 15:05 -0400
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 15:55 -0400
                        Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:53 -0500
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 20:30 -0400
                            Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-09 17:50 -0700
                              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-10 09:15 -0400
                                Re: iCloud Hacked Article Warren Oates <warren.oates@gmail.com> - 2012-08-10 10:18 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:49 -0700
                              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 10:50 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:48 -0700
                                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 12:21 -0400
                                    Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 10:00 -0700
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-10 13:23 -0500
                      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:54 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-12 20:14 -0400
      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 08:50 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:55 +0200
          Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 15:17 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:28 +0000
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:39 +0200
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 10:44 -0400
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 14:59 +0000
                  Re: iCloud Hacked Article Richard Kettlewell <rjk@greenend.org.uk> - 2012-08-09 10:50 +0100
                Re: iCloud Hacked Article Michael Vilain <vilain@NOspamcop.net> - 2012-08-08 17:40 -0700
                  Re: iCloud Hacked Article Jim Janney <jjanney@shell.xmission.com> - 2012-08-09 07:55 -0600
                    Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:40 -0400
              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:15 -0400
                Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:42 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:19 +0000
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 15:44 +0000
                  Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 18:36 -0400
                    Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:21 -0400
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 21:09 -0400
                    Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 05:34 +0000
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:45 -0400
                        Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 17:39 +0000
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 11:12 -0400
                  Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 01:08 +0000
      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:59 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:31 +0000

Page 1 of 7  [1] 2 3 4 5 6 7  Next page →


#29056 — iCloud Hacked Article

FromFred Moore <fmoore@gcfn.org>
Date2012-08-06 17:46 -0400
SubjectiCloud Hacked Article
Message-ID<fmoore-F586C0.17460606082012@news.eternal-september.org>
Thought folks here would be interested in this article I saw on 
Macintouch:

Yes, I was hacked. Hard.
<http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

At 4:50 PM, someone got into my iCloud account, reset the password and 
sent the confirmation message about the reset to the trash. My password 
was a 7 digit alphanumeric that I didnšt use elsewhere. When I set it 
up, years and years ago, that seemed pretty secure at the time. But itšs 
not. Especially given that I've been using it for, well, years and 
years. My [guess is they used brute force to get the password]<-[this 
bit negated in the original] (see update) and then reset it to do the 
damage to my devices.

The backup email address on my Gmail account is that same .mac email 
address. At 4:52 PM, they sent a Gmail password recovery email to the 
.mac account. Two minutes later, an email arrived notifying me that my 
Google Account password had changed.

At 5:00 PM, they remote wiped my iPhone
At 5:01 PM, they remote wiped my iPad
At 5:05, they remote wiped my MacBook Air.
A few minutes after that, they took over my Twitter.
[...]
Update Three: I know how it was done now. Confirmed with both the hacker 
and Apple. It wasnšt password related. They got in via Apple tech 
support and some clever social engineering that let them bypass security 
questions. [...]

[toc] | [next] | [standalone]


#29059

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-06 21:54 +0000
Message-ID<slrnk20f7p.10nl.g.kreme@mbp55.local>
In reply to#29056
In message <fmoore-F586C0.17460606082012@news.eternal-september.org> 
  Fred Moore <fmoore@gcfn.org> wrote:
> Thought folks here would be interested in this article I saw on 
> Macintouch:

> Yes, I was hacked. Hard.
> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

*HE* was hacked. iCoud was not hacked.

> Update Three: I know how it was done now. Confirmed with both the hacker 
> and Apple. It wasn¹t password related. They got in via Apple tech 
> support and some clever social engineering that let them bypass security 
> questions. [...]

That is worrisome.

-- 
I SAW NOTHING UNUSUAL IN THE TEACHER'S LOUNGE Bart chalkboard Ep. 8F17

[toc] | [prev] | [next] | [standalone]


#29066

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-08-06 20:33 -0400
Message-ID<50206268$0$1209$c3e8da3$50776f34@news.astraweb.com>
In reply to#29059
>> Yes, I was hacked. Hard.
>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>


I can understand the iPhone being wiped since there is a "wipe the
iPhone" function on iCloud.

But how can a laptop be wiped ? Is there also a "wipe my laptop"
function on iCloud ? If not, what exactly is being deleted from the laptop ?

Are we just talking about  a sync for iTunes and iPhoto and iCal and
Contacts ? (which make the laptop's libraries match the empty libraries
on iCloud). ?


If you suspect wrong doing, I guess the first thing would be to turn off
wi-fi at your router before opening the laptop, and then disabling that
iCloud thingy on the laptop.


Reading the article, I kept thiniing "just take your SIM out and ut it
in another phone". But then the writer admitted being with that old CDAM
stuff (Sprint).

Anyone know if an iPhone wipe has the power/auhority to muck with the
SIM card ?  I guess it can erase contacts stored on SIM. But for the
rest, I am not sure it can really disable the SIM card.

[toc] | [prev] | [next] | [standalone]


#29072

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-08-06 20:47 -0400
Message-ID<502065a9$0$1249$c3e8da3$b23f186d@news.astraweb.com>
In reply to#29066
More info now available in a Wired article:

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/

##
The very four digits that Amazon considers unimportant enough to display
in the clear on the Web are precisely the same ones that Apple considers
secure enough to perform identity verification.?
##

(talking about credit card numbers)

[toc] | [prev] | [next] | [standalone]


#29098

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 01:05 -0400
Message-ID<barmar-4A49CE.01055107082012@news.eternal-september.org>
In reply to#29072
In article <502065a9$0$1249$c3e8da3$b23f186d@news.astraweb.com>,
 JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:

> More info now available in a Wired article:
> 
> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/
> 
> ##
> The very four digits that Amazon considers unimportant enough to display
> in the clear on the Web are precisely the same ones that Apple considers
> secure enough to perform identity verification.?
> ##
> 
> (talking about credit card numbers)

That's pretty amazing. Amazon is conforming to industry common practice: 
it's quite standard for receipts to include the last 4 digits of the 
credit card used, so that the customer has a reminder of which CC they 
used.  Apple is clearly wrong in using this part of the CC# in their 
authentication process, they should at least ask for the entire CC#.

But this whole debacle mostly highlights how difficult it is to do 
reliable identity verification over the phone.  Companies could be more 
stringent, but it will be a big inconvenience for the 99% of callers who 
really are who they say they are.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29105

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 01:26 -0400
Message-ID<070820120126081347%nospam@nospam.invalid>
In reply to#29098
In article <barmar-4A49CE.01055107082012@news.eternal-september.org>,
Barry Margolin <barmar@alum.mit.edu> wrote:

> That's pretty amazing. Amazon is conforming to industry common practice: 
> it's quite standard for receipts to include the last 4 digits of the 
> credit card used, so that the customer has a reminder of which CC they 
> used.  Apple is clearly wrong in using this part of the CC# in their 
> authentication process, they should at least ask for the entire CC#.

the hacker couldn't answer the security questions. the call should have
ended at that point. it was obvious he was not who he said he was.

[toc] | [prev] | [next] | [standalone]


#29108

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-07 06:05 +0000
Message-ID<slrnk21c0t.17rs.g.kreme@mbp55.local>
In reply to#29105
In message <070820120126081347%nospam@nospam.invalid> 
  nospam <nospam@nospam.invalid> wrote:
> In article <barmar-4A49CE.01055107082012@news.eternal-september.org>,
> Barry Margolin <barmar@alum.mit.edu> wrote:

>> That's pretty amazing. Amazon is conforming to industry common practice: 
>> it's quite standard for receipts to include the last 4 digits of the 
>> credit card used, so that the customer has a reminder of which CC they 
>> used.  Apple is clearly wrong in using this part of the CC# in their 
>> authentication process, they should at least ask for the entire CC#.

> the hacker couldn't answer the security questions. the call should have
> ended at that point. it was obvious he was not who he said he was.

Exactly. Although I am sure there are plenty of legitimate callers who
also can't, but in that case, Apple should fallback to other methods.
Like, say, a iMessage to your iPhone. Or, failing that, a mailed letter
to your address with a reset code.

Using billing address and last for of CC is not acceptable.

-- 
Oh! I thought they smelled bad on the *outside*!

[toc] | [prev] | [next] | [standalone]


#29110

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 02:20 -0400
Message-ID<070820120220055514%nospam@nospam.invalid>
In reply to#29108
In article <slrnk21c0t.17rs.g.kreme@mbp55.local>, Lewis
<g.kreme@gmail.com.dontsendmecopies> wrote:

> >> That's pretty amazing. Amazon is conforming to industry common practice: 
> >> it's quite standard for receipts to include the last 4 digits of the 
> >> credit card used, so that the customer has a reminder of which CC they 
> >> used.  Apple is clearly wrong in using this part of the CC# in their 
> >> authentication process, they should at least ask for the entire CC#.
> 
> > the hacker couldn't answer the security questions. the call should have
> > ended at that point. it was obvious he was not who he said he was.
> 
> Exactly. Although I am sure there are plenty of legitimate callers who
> also can't, 

tough shit. that's what the security questions are for. 

just look at what they do for file vault:
<http://km.support.apple.com/library/APPLE/APPLECARE_ALLGEOS/HT4790/HT47
90_StoreKey----en.png>

  Apple can only decrypt the recovery key using exact answers. If you
  cannot provide these answers, then Apple will be unable to access the
  key. Answer attempts may be restricted.

no key, no data. 

> but in that case, Apple should fallback to other methods.
> Like, say, a iMessage to your iPhone.

what if you don't have an iphone? or if you do, if you don't use
imessage?

> Or, failing that, a mailed letter
> to your address with a reset code.

that's one possibility.

> Using billing address and last for of CC is not acceptable.

true.

[toc] | [prev] | [next] | [standalone]


#29163

From"John Varela" <newlamps@verizon.net>
Date2012-08-08 00:08 +0000
Message-ID<51W5y0sPNk52-pn2-sIUvEiWGJlcN@localhost>
In reply to#29098
On Tue, 7 Aug 2012 05:05:51 UTC, Barry Margolin 
<barmar@alum.mit.edu> wrote:

> But this whole debacle mostly highlights how difficult it is to do 
> reliable identity verification over the phone.  Companies could be more 
> stringent, but it will be a big inconvenience for the 99% of callers who 
> really are who they say they are.

What's really ridiculous is this: I handle all our family's 
financial matters. When I call some company to have some change made
to an account that is in my wife's name, they insist they have to 
talk to her. So she comes on, lets them hear a woman's voice, and 
then they let me do whatever. For all they know, we're in the middle
of a divorce, I am stripping her accounts, and the woman they spoke 
to is my girlfriend.

-- 
John Varela

[toc] | [prev] | [next] | [standalone]


#29169

FromDavoud <star@sky.net>
Date2012-08-07 20:40 -0400
Message-ID<070820122040381832%star@sky.net>
In reply to#29163
Barry Margolin:
> > But this whole debacle mostly highlights how difficult it is to do 
> > reliable identity verification over the phone.  Companies could be more 
> > stringent, but it will be a big inconvenience for the 99% of callers who 
> > really are who they say they are.

John Varela:
> What's really ridiculous is this: I handle all our family's 
> financial matters. When I call some company to have some change made
> to an account that is in my wife's name, they insist they have to 
> talk to her. So she comes on, lets them hear a woman's voice, and 
> then they let me do whatever. For all they know, we're in the middle
> of a divorce, I am stripping her accounts, and the woman they spoke 
> to is my girlfriend.

You and Mr. Margolin both have it right. In my capacity as pro bono
Internet and/or new-computer-set-up guy for seniors, I go to peoples'
homes to work for them. They trust me because they learned about me
from friends whom they trust; I do not advertise. Sometimes it is
necessary to call the ISP for information, and they do ask for Mrs. Doe
to confirm that I am authorized to have the information. What a joke.
But I couldn't help these folks without that ease of access.

I have a record of all of these folks' passwords, of course. I have to
keep them because I give them non-trivial passwords and they can't be
expected to remember them all, and sometimes they lose the printed copy
that I gave them (unless it's taped to the computer display). I keep
the passwords in a folder encrypted by Exces <http://excesapp.com> with
a complex password that I have memorized and also stored, not on any
computer, but in two physically secure locations.

Personally, whom do you trust? I trust my wife and my wife trusts me.
Each of us has access to the login information for all of our accounts,
from banks to CU's to brokerages to mail and shopping, so each can act
on the other's instructions from afar without having to transmit login
information in the clear or say it on the phone.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29074

Fromdempson@actrix.gen.nz (David Empson)
Date2012-08-07 13:20 +1200
Message-ID<1kogkes.5tcjfcsqlzibN%dempson@actrix.gen.nz>
In reply to#29066
JF Mezei <jfmezei.spamnot@vaxination.ca> wrote:

> >> Yes, I was hacked. Hard.
> >> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> 
> 
> I can understand the iPhone being wiped since there is a "wipe the
> iPhone" function on iCloud.
> 
> But how can a laptop be wiped ? Is there also a "wipe my laptop"
> function on iCloud ? If not, what exactly is being deleted from the laptop ?

There is a "Find My Mac" feature. I have it turned off. If I go to
enable it there is a warning sheet which says "Find My Mac is part of
iCloud and helps you locate, lock or erase a lost Mac".

I haven't experimented with it to see the full details, but based on how
it works for the iPhone I expect that the "Erase" will do either of two
things:

(a) If the volume is encrypted with FileVault 2, it will destroy the
master key, immediately losing access to all data on the volume.

(b) If the volume is not encrypted with FileVault 2, it will have to
erase individual files or block erase the volume. It probably tries to
delete everything, but perhaps starts with files in the home folders.

Based on the description in the article, it sounds like it was deleting
files.

I'd have expected a restart to the recovery partition so that all files
or the volume could be erased without having some locked due to being in
use.

> Are we just talking about  a sync for iTunes and iPhoto and iCal and
> Contacts ? (which make the laptop's libraries match the empty libraries
> on iCloud). ?

No. The wording implies the Mac is erased.

> If you suspect wrong doing, I guess the first thing would be to turn off
> wi-fi at your router before opening the laptop, and then disabling that
> iCloud thingy on the laptop.

Just turn off Find My Mac if you are concerned about losing the contents
of your Mac due to a similar hack.

> Reading the article, I kept thiniing "just take your SIM out and ut it
> in another phone". But then the writer admitted being with that old CDAM
> stuff (Sprint).
> 
> Anyone know if an iPhone wipe has the power/auhority to muck with the
> SIM card ?  I guess it can erase contacts stored on SIM. But for the
> rest, I am not sure it can really disable the SIM card.

An iPhone with no SIM connected to a WiFi network that has Internet
access could be remotely erased via Find My iPhone. The SIM card and
cellular connectivity just makes it far easier as it is more likely to
have Internet access.

-- 
David Empson
dempson@actrix.gen.nz

[toc] | [prev] | [next] | [standalone]


#29139

FromFred Moore <fmoore@gcfn.org>
Date2012-08-07 10:48 -0400
Message-ID<fmoore-1953A2.10485607082012@news.eternal-september.org>
In reply to#29059
In article <slrnk20f7p.10nl.g.kreme@mbp55.local>,
 Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:

> In message <fmoore-F586C0.17460606082012@news.eternal-september.org> 
>   Fred Moore <fmoore@gcfn.org> wrote:
> > Thought folks here would be interested in this article I saw on 
> > Macintouch:
> 
> > Yes, I was hacked. Hard.
> > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> 
> *HE* was hacked. iCoud was not hacked.

_He_ had an account on iFog. His account on _iFog_ was accessed without 
authorization. Both HE and iFOG were hacked, unless you're saying every 
single users on iFog has to be hacked for iFog to be considered hacked. 
Apple gave out a temporary password when it shouldn't have. (And, yes, 
Amazon was complicit in the whole affair.)


-- 
Republicans blaming Obama for the national debt and the state of the 
economy are like an arsonist blaming the fire department for the fire.

[toc] | [prev] | [next] | [standalone]


#29142

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 12:34 -0400
Message-ID<barmar-2C75D2.12344607082012@news.eternal-september.org>
In reply to#29139
In article <fmoore-1953A2.10485607082012@news.eternal-september.org>,
 Fred Moore <fmoore@gcfn.org> wrote:

> In article <slrnk20f7p.10nl.g.kreme@mbp55.local>,
>  Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:
> 
> > In message <fmoore-F586C0.17460606082012@news.eternal-september.org> 
> >   Fred Moore <fmoore@gcfn.org> wrote:
> > > Thought folks here would be interested in this article I saw on 
> > > Macintouch:
> > 
> > > Yes, I was hacked. Hard.
> > > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> > 
> > *HE* was hacked. iCoud was not hacked.
> 
> _He_ had an account on iFog. His account on _iFog_ was accessed without 
> authorization. Both HE and iFOG were hacked, unless you're saying every 
> single users on iFog has to be hacked for iFog to be considered hacked. 
> Apple gave out a temporary password when it shouldn't have. (And, yes, 
> Amazon was complicit in the whole affair.)

I think most people would interpret "iCould was hacked" to mean a more 
general intrusion into iCloud. It doesn't have to be "every" user, but 
something relatively widespread.  If you found a credit card receipt on 
the ground, no one would make a big deal that "credit card numbers have 
been stolen".

This particular hack involved a chain of several acts involving 
different services: Amazon, Twitter, Gmail, DNS registration, and 
finally Apple. These all had to be linked to get into just this one 
user's account.

Admittedly, similar steps could be used to target someone else. But this 
doesn't reveal a general, cookbook process that can be used to get into 
many people's accounts.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29143

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 12:58 -0400
Message-ID<070820121258516495%nospam@nospam.invalid>
In reply to#29142
In article <barmar-2C75D2.12344607082012@news.eternal-september.org>,
Barry Margolin <barmar@alum.mit.edu> wrote:

> Admittedly, similar steps could be used to target someone else. But this 
> doesn't reveal a general, cookbook process that can be used to get into 
> many people's accounts.

sure it does. all someone needs is knowing a person's icloud account,
last 4 digits of their credit card and address and they're in. 

hopefully apple changes things and makes it significantly more
difficult, but as of right now it's fairly easy to do.

[toc] | [prev] | [next] | [standalone]


#29209

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-08 14:30 -0400
Message-ID<barmar-173578.14301308082012@news.eternal-september.org>
In reply to#29143
In article <070820121258516495%nospam@nospam.invalid>,
 nospam <nospam@nospam.invalid> wrote:

> In article <barmar-2C75D2.12344607082012@news.eternal-september.org>,
> Barry Margolin <barmar@alum.mit.edu> wrote:
> 
> > Admittedly, similar steps could be used to target someone else. But this 
> > doesn't reveal a general, cookbook process that can be used to get into 
> > many people's accounts.
> 
> sure it does. all someone needs is knowing a person's icloud account,
> last 4 digits of their credit card and address and they're in. 

I still wouldn't call this "hacking iCloud". That's like saying that if 
someone guessed your password, they hacked iCloud.

Yes, it means that getting into someone's iCloud account is easier than 
it should be, but that's not the same as hacking the system in general.  
The system is working as intended, they just intended the wrong thing.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29212

FromMC <copespaz@mapca.inter.net>
Date2012-08-08 17:18 -0400
Message-ID<copespaz-832AAC.17180808082012@news.eternal-september.org>
In reply to#29209
In article <barmar-173578.14301308082012@news.eternal-september.org>,
 Barry Margolin <barmar@alum.mit.edu> wrote:

> Yes, it means that getting into someone's iCloud account is easier than 
> it should be, but that's not the same as hacking the system in general.  
> The system is working as intended, they just intended the wrong thing.

They just announced some changes: 

http://money.cnn.com/2012/08/08/technology/apple-amazon-hack/?source=cnn_
bin

-- 

"If you can, tell me something happy."
- Marybones

[toc] | [prev] | [next] | [standalone]


#29181

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 04:19 +0000
Message-ID<slrnk23q67.vfq.g.kreme@mbp55.local>
In reply to#29142
In message <barmar-2C75D2.12344607082012@news.eternal-september.org> 
  Barry Margolin <barmar@alum.mit.edu> wrote:

> This particular hack involved a chain of several acts involving 
> different services: Amazon, Twitter, Gmail, DNS registration, and 
> finally Apple. These all had to be linked to get into just this one 
> user's account.

> Admittedly, similar steps could be used to target someone else. But this 
> doesn't reveal a general, cookbook process that can be used to get into 
> many people's accounts.

Yes, it does because many people do exactly the kind of *STUPID* *SHIT*
that Mat did, and that Amazon and Apple were complicit in. 

-- 
I WILL NOT INSTIGATE REVOLUTION Bart chalkboard Ep. 7G06

[toc] | [prev] | [next] | [standalone]


#29081

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-08-06 23:21 -0400
Message-ID<jvq1jh$pga$1@dont-email.me>
In reply to#29056
On 08-06-2012 17:46, Fred Moore wrote:
> Thought folks here would be interested in this article I saw on
> Macintouch:
>
> Yes, I was hacked. Hard.
> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

And people laughed at me when I said I didn't want my life in iCloud.

-- 
Wes Groleau

   “Two things are infinite, the universe and human stupidity.
    But I'm not so sure about the universe.”
                                — Albert Einstein

[toc] | [prev] | [next] | [standalone]


#29092

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-07 04:49 +0000
Message-ID<slrnk217hu.17rs.g.kreme@mbp55.local>
In reply to#29081
In message <jvq1jh$pga$1@dont-email.me> 
  Wes Groleau <Groleau+news@FreeShell.org> wrote:
> On 08-06-2012 17:46, Fred Moore wrote:
>> Thought folks here would be interested in this article I saw on
>> Macintouch:
>>
>> Yes, I was hacked. Hard.
>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

> And people laughed at me when I said I didn't want my life in iCloud.

Well, there are several things he did wrong.

#1 was using his Apple ID email for anything else.

I have unique emails for Amazon, Apple ID, Yahoo, Google, Ebay, Paypal,
World of Warcraft, buy.com, DropBox, woot, and just about any other
online service. Not only are they unique, but they are spread out over
several domains. While someone getting into one of my accounts would be
able to cause some damage, they would not be able to rampage through all
my services.

#2 was using the same address for his domain registration as his credit
card billing address. Rent a PO Box or something if you don't have an
office. You don't want anyone looking you up having your home address
*anyway*.

#3 was not running Time Machine

#4 was not having a completely separate off-line and/or off-site backup of
the files he considered most important (like his photos).

There are issues that have been exposed that are problematic, such as
Apple accepting simply a billing address and last 4 of credit card to
give anyone access. There are security questions for a reason, they
should be using them.

Amazon's security hole is even worse, to my mind, in allowing you to add
an unverified credit card to an account and then using it to unlock the
account.

-- 
He was Igor, son of Igor, nephew of several Igors, brother of Igors and
cousin of more Igors than he could remember without checking up in his
diary. Igors did not change a winning formula. {Footnote: Especially if
it was green, and bubbled.}

[toc] | [prev] | [next] | [standalone]


#29102

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 01:15 -0400
Message-ID<barmar-121D7C.01150007082012@news.eternal-september.org>
In reply to#29092
In article <slrnk217hu.17rs.g.kreme@mbp55.local>,
 Lewis <g.kreme@gmail.com.dontsendmecopies> wrote:

> Amazon's security hole is even worse, to my mind, in allowing you to add
> an unverified credit card to an account and then using it to unlock the
> account.

Yeah, that was pretty funny.  It suggests something like this could work:

Caller: I need to change my account password.
Amazon: OK, what would you like to change it to?
Caller: Make it "YourPwned"
Amazon: Done.
Caller: Now I'd like to buy something, and bill it to my registered 
credit card.
Amazon: Sure, what's your password?

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


Page 1 of 7  [1] 2 3 4 5 6 7  Next page →

Back to top | Article view | comp.sys.mac.system


csiph-web