Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #29056 > unrolled thread

iCloud Hacked Article

Started byFred Moore <fmoore@gcfn.org>
First post2012-08-06 17:46 -0400
Last post2012-08-08 04:31 +0000
Articles 20 on this page of 135 — 26 participants

Back to article view | Back to comp.sys.mac.system


Contents

  iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-06 17:46 -0400
    Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-06 21:54 +0000
      Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:33 -0400
        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:47 -0400
          Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:05 -0400
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:05 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:20 -0400
            Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 00:08 +0000
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 20:40 -0400
        Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-07 13:20 +1200
      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-07 10:48 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 12:34 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 12:58 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-08 14:30 -0400
              Re: iCloud Hacked Article MC <copespaz@mapca.inter.net> - 2012-08-08 17:18 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:19 +0000
    Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-06 23:21 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:15 -0400
          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:24 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:29 -0400
        Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 05:41 +0000
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:11 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:22 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:31 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 08:28 +0200
      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:19 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:30 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:15 +0000
        Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-08 08:11 -0400
      Re: iCloud Hacked Article David Lesher <wb8foz@panix.com> - 2012-08-07 18:26 +0000
    Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 00:26 -0400
      Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 00:31 -0400
        Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 20:16 -0400
          Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-08 12:28 +1200
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:13 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:16 +0200
              Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:56 -0400
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 09:46 -0400
                  Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 10:35 -0400
                    Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 12:41 -0400
                      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 14:15 -0400
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 14:57 -0400
                  Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 16:25 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:51 -0400
          Re: iCloud Hacked Article Larry Gusaas <larry.gusaas@gmail.com> - 2012-08-07 18:34 -0600
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 20:41 -0400
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-08 01:49 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:29 +0000
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:25 +0000
                Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:57 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
    Re: iCloud Hacked Article Jeff N <jeff+no.spam@jnadeau.com> - 2012-08-07 00:01 -0700
      Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 03:48 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:49 +0200
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 21:52 +0200
            Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 17:33 -0400
              Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 16:44 -0500
              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 18:09 -0400
                Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 18:33 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 19:26 -0400
                    Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 19:19 -0500
                    Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 21:07 -0400
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 11:14 -0400
                        Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-08 13:11 -0400
                          Re: iCloud Hacked Article me@home.spamsucks.ca (Király) - 2012-08-09 04:56 +0000
                    Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 21:48 +0000
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:50 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:15 -0400
                          Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-08 20:16 -0500
                          Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:22 -0400
                      Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 07:03 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 10:57 -0400
                          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 12:29 -0400
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:50 -0500
                              Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:53 -0400
                                Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-11 20:18 -0500
                                  Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 21:44 -0400
                                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 23:35 -0400
                          Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 19:00 -0400
                Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:19 +0200
            Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 23:06 -0400
              Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:26 +0200
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 10:59 +0000
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 16:27 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:29 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:25 -0400
                    Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 13:30 -0400
                      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 14:49 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 15:05 -0400
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 15:55 -0400
                        Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:53 -0500
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 20:30 -0400
                            Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-09 17:50 -0700
                              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-10 09:15 -0400
                                Re: iCloud Hacked Article Warren Oates <warren.oates@gmail.com> - 2012-08-10 10:18 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:49 -0700
                              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 10:50 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:48 -0700
                                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 12:21 -0400
                                    Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 10:00 -0700
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-10 13:23 -0500
                      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:54 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-12 20:14 -0400
      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 08:50 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:55 +0200
          Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 15:17 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:28 +0000
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:39 +0200
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 10:44 -0400
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 14:59 +0000
                  Re: iCloud Hacked Article Richard Kettlewell <rjk@greenend.org.uk> - 2012-08-09 10:50 +0100
                Re: iCloud Hacked Article Michael Vilain <vilain@NOspamcop.net> - 2012-08-08 17:40 -0700
                  Re: iCloud Hacked Article Jim Janney <jjanney@shell.xmission.com> - 2012-08-09 07:55 -0600
                    Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:40 -0400
              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:15 -0400
                Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:42 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:19 +0000
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 15:44 +0000
                  Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 18:36 -0400
                    Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:21 -0400
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 21:09 -0400
                    Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 05:34 +0000
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:45 -0400
                        Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 17:39 +0000
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 11:12 -0400
                  Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 01:08 +0000
      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:59 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:31 +0000

Page 2 of 7 — ← Prev page 1 [2] 3 4 5 6 7  Next page →


#29130

FromDavoud <star@sky.net>
Date2012-08-07 09:24 -0400
Message-ID<070820120924276969%star@sky.net>
In reply to#29102
Barry Margolin:
> Yeah, that was pretty funny.  It suggests something like this could work:
> 
> Caller: I need to change my account password.
> Amazon: OK, what would you like to change it to?
> Caller: Make it "YourPwned"
> Amazon: Done.
> Caller: Now I'd like to buy something, and bill it to my registered 
> credit card.
> Amazon: Sure, what's your password?

Reality:

Sorry, we don't change passwords by phone. Go on-line and log into your
account. If you have forgotten your password just answer the security
questions and enter the e-mail address associated with the account.

But I don't have the e-mail address, either.

Then I can't help you. You will have to go on line and set up a new
account using a valid e-mail address and a new credit card.

*****

Amazon does not ask for passwords on the telephone. You should know
that.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29133

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 09:29 -0400
Message-ID<barmar-C118EF.09291607082012@news.eternal-september.org>
In reply to#29130
In article <070820120924276969%star@sky.net>, Davoud <star@sky.net> 
wrote:

> Barry Margolin:
> > Yeah, that was pretty funny.  It suggests something like this could work:
> > 
> > Caller: I need to change my account password.
> > Amazon: OK, what would you like to change it to?
> > Caller: Make it "YourPwned"
> > Amazon: Done.
> > Caller: Now I'd like to buy something, and bill it to my registered 
> > credit card.
> > Amazon: Sure, what's your password?
> 
> Reality:
> 
> Sorry, we don't change passwords by phone. Go on-line and log into your
> account. If you have forgotten your password just answer the security
> questions and enter the e-mail address associated with the account.
> 
> But I don't have the e-mail address, either.
> 
> Then I can't help you. You will have to go on line and set up a new
> account using a valid e-mail address and a new credit card.
> 
> *****
> 
> Amazon does not ask for passwords on the telephone. You should know
> that.

I know, I was jokingly extrapolating from what actually happened. They 
allowed a credit card to be added with weak authentication, then allowed 
that very same credit card number to be used as part of a supposedly 
stronger authentication later.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29104

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 01:26 -0400
Message-ID<070820120126061213%nospam@nospam.invalid>
In reply to#29092
In article <slrnk217hu.17rs.g.kreme@mbp55.local>, Lewis
<g.kreme@gmail.com.dontsendmecopies> wrote:

> >> Thought folks here would be interested in this article I saw on
> >> Macintouch:
> >>
> >> Yes, I was hacked. Hard.
> >> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> 
> > And people laughed at me when I said I didn't want my life in iCloud.
> 
> Well, there are several things he did wrong.

blame the victim, i see. he actually did very little wrong. 

apple willingly gave a temporary password to someone posing as him,
using easily obtained information. that's *really* *bad*.

however, had he not had everything linked together, the damage would
have been quite a bit less.

it was unfortunate he didn't have a backup of his macbook, but that
would only have let him recover data, not prevent the hack from
occurring.

> #1 was using his Apple ID email for anything else.

nonsense. most people use their normal email address. there is no
warning to use a special email address. more importantly, it would not
have prevented the hack.

it's unfortunate that apple ids are email addresses though, since it
makes it exceedingly difficult to change them.

> #2 was using the same address for his domain registration as his credit
> card billing address. Rent a PO Box or something if you don't have an
> office. You don't want anyone looking you up having your home address
> *anyway*.

that would not have prevented the hack. his address could be obtained
in other ways.

> #3 was not running Time Machine

that would not have prevented the hack. it would only have helped him
recover lost data. that's all.

> #4 was not having a completely separate off-line and/or off-site backup of
> the files he considered most important (like his photos).

that would not have prevented the hack. it would only have helped him
recover lost data. that's all.

> There are issues that have been exposed that are problematic, such as
> Apple accepting simply a billing address and last 4 of credit card to
> give anyone access. There are security questions for a reason, they
> should be using them.
> 
> Amazon's security hole is even worse, to my mind, in allowing you to add
> an unverified credit card to an account and then using it to unlock the
> account.

both of those are the problem. apple and amazon have shitty security.

[toc] | [prev] | [next] | [standalone]


#29106

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-07 05:41 +0000
Message-ID<slrnk21al1.17rs.g.kreme@mbp55.local>
In reply to#29104
In message <070820120126061213%nospam@nospam.invalid> 
  nospam <nospam@nospam.invalid> wrote:
> In article <slrnk217hu.17rs.g.kreme@mbp55.local>, Lewis
> <g.kreme@gmail.com.dontsendmecopies> wrote:

>> >> Thought folks here would be interested in this article I saw on
>> >> Macintouch:
>> >>
>> >> Yes, I was hacked. Hard.
>> >> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>> 
>> > And people laughed at me when I said I didn't want my life in iCloud.
>> 
>> Well, there are several things he did wrong.

> blame the victim, i see. he actually did very little wrong. 

He did many things wrong. SOme are understandable, others are not.

> apple willingly gave a temporary password to someone posing as him,
> using easily obtained information. that's *really* *bad*.

Yes, I said that.

> however, had he not had everything linked together, the damage would
> have been quite a bit less.

I said that too.

> it was unfortunate he didn't have a backup of his macbook, but that
> would only have let him recover data, not prevent the hack from
> occurring.

Right. "Only" having the first year of baby pictures of his daughter and
"only" having last pictures of family that had died. The lack of backups
is *entirely* on his shoulders and I have trouble having any sympathy
for that.

>> #1 was using his Apple ID email for anything else.

> nonsense. most people use their normal email address. there is no
> warning to use a special email address. more importantly, it would not
> have prevented the hack.

There's *plenty* of warnings, and yes it would have. Re-read. The hack
started with them seeing that he had an Apple ID linked to his Amazon
account. They were able to get the last 4 digits from getting into
Amazon, that and the domain info gave them access to his APple ID, and
that got them "the keys to the kingdom."

>> #2 was using the same address for his domain registration as his credit
>> card billing address. Rent a PO Box or something if you don't have an
>> office. You don't want anyone looking you up having your home address
>> *anyway*.

> that would not have prevented the hack. his address could be obtained
> in other ways.

Maybe. Maybe not. That is certainly one of the easiest ways, and is the
method that was used.

>> #3 was not running Time Machine

> that would not have prevented the hack. it would only have helped him
> recover lost data. that's all.

Yeah, that's "all". That's a pretty big fucking *all*.

>> #4 was not having a completely separate off-line and/or off-site backup of
>> the files he considered most important (like his photos).

> that would not have prevented the hack. it would only have helped him
> recover lost data. that's all.

Ibid.

-- 
The older you get the more you need the people you knew when you were
young.

[toc] | [prev] | [next] | [standalone]


#29109

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 02:11 -0400
Message-ID<070820120211536004%nospam@nospam.invalid>
In reply to#29106
In article <slrnk21al1.17rs.g.kreme@mbp55.local>, Lewis
<g.kreme@gmail.com.dontsendmecopies> wrote:

> >> Well, there are several things he did wrong.
> 
> > blame the victim, i see. he actually did very little wrong. 
> 
> He did many things wrong. SOme are understandable, others are not.

very little of what he did would have prevented it from happening. he
could have reduced the damage though. 

the problem is how easy it is to hack an apple id.

> > apple willingly gave a temporary password to someone posing as him,
> > using easily obtained information. that's *really* *bad*.
> 
> Yes, I said that.

*that* is the entire problem.

> > however, had he not had everything linked together, the damage would
> > have been quite a bit less.
> 
> I said that too.

however, you said even more that was rubbish.

> > it was unfortunate he didn't have a backup of his macbook, but that
> > would only have let him recover data, not prevent the hack from
> > occurring.
> 
> Right. "Only" having the first year of baby pictures of his daughter and
> "only" having last pictures of family that had died. The lack of backups
> is *entirely* on his shoulders and I have trouble having any sympathy
> for that.

having a backup would not have prevented the hack from occurring.

it's still a huge hassle to restore everything (several hours gone) and
he may still have lost some work, up until the last point at which time
machine took a snapshot.

> >> #1 was using his Apple ID email for anything else.
> 
> > nonsense. most people use their normal email address. there is no
> > warning to use a special email address. more importantly, it would not
> > have prevented the hack.
> 
> There's *plenty* of warnings, 

where does it say on the apple id sign up page to use an email you
don't normally use????

> and yes it would have. Re-read. The hack
> started with them seeing that he had an Apple ID linked to his Amazon
> account. 

actually it didn't, but when have facts mattered to you.

it started with twitter, because he had a 3 character twitter name.
that made him a desirable target. 

from that, they found he used gmail, hit the gmail recovery page and
found an obscured secondary email address, however, what was obscured
was easily guessed, which happened to be a .me address. since they knew
how to hack apple ids, their next step was obtaining the information to
do just that.

> They were able to get the last 4 digits from getting into
> Amazon, that and the domain info gave them access to his APple ID, and
> that got them "the keys to the kingdom."

all they needed was the last four digits and an address to gain access
to the apple id, and that information is not hard to find.

just about *everyone* you buy something from using a credit card has
that information, particularly online where they need the address to
verify the card. 

> >> #2 was using the same address for his domain registration as his credit
> >> card billing address. Rent a PO Box or something if you don't have an
> >> office. You don't want anyone looking you up having your home address
> >> *anyway*.
> 
> > that would not have prevented the hack. his address could be obtained
> > in other ways.
> 
> Maybe. Maybe not. That is certainly one of the easiest ways, and is the
> method that was used.

no maybe about it. just about *everyone* you buy something from using a
credit card has that information.

> >> #3 was not running Time Machine
> 
> > that would not have prevented the hack. it would only have helped him
> > recover lost data. that's all.
> 
> Yeah, that's "all". That's a pretty big fucking *all*.
> 
> >> #4 was not having a completely separate off-line and/or off-site backup of
> >> the files he considered most important (like his photos).
> 
> > that would not have prevented the hack. it would only have helped him
> > recover lost data. that's all.
> 
> Ibid.

all that would have done is saved his photos and whatever else was on
it.

he still would have been hacked. *that* is the problem.

[toc] | [prev] | [next] | [standalone]


#29111

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-07 06:22 +0000
Message-ID<slrnk21d16.17rs.g.kreme@mbp55.local>
In reply to#29109
In message <070820120211536004%nospam@nospam.invalid> 
  nospam <nospam@nospam.invalid> wrote:
> In article <slrnk21al1.17rs.g.kreme@mbp55.local>, Lewis
> <g.kreme@gmail.com.dontsendmecopies> wrote:

>> >> Well, there are several things he did wrong.
>> 
>> > blame the victim, i see. he actually did very little wrong. 
>> 
>> He did many things wrong. SOme are understandable, others are not.

> very little of what he did would have prevented it from happening. he
> could have reduced the damage though. 

> the problem is how easy it is to hack an apple id.

>> > apple willingly gave a temporary password to someone posing as him,
>> > using easily obtained information. that's *really* *bad*.
>> 
>> Yes, I said that.

> *that* is the entire problem.

Amazon is certainly a big player in the problem, so it's not the entire
problem, no.

> it started with twitter, because he had a 3 character twitter name.
> that made him a desirable target. 

The HACK did not start with twitter, the desire to hack him did.

> from that, they found he used gmail, hit the gmail recovery page and
> found an obscured secondary email address, however, what was obscured
> was easily guessed, which happened to be a .me address. since they knew
> how to hack apple ids, their next step was obtaining the information to
> do just that.

Which they obtained from AMAZON.

-- 
The very existence of flame-throwers proves that some time, somewhere,
someone said to themselves, You know, I want to set those people over
there on fire, but I'm just not close enough to get the job done.

[toc] | [prev] | [next] | [standalone]


#29115

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 02:31 -0400
Message-ID<070820120231417282%nospam@nospam.invalid>
In reply to#29111
In article <slrnk21d16.17rs.g.kreme@mbp55.local>, Lewis
<g.kreme@gmail.com.dontsendmecopies> wrote:

> >> > apple willingly gave a temporary password to someone posing as him,
> >> > using easily obtained information. that's *really* *bad*.
> >> 
> >> Yes, I said that.
> 
> > *that* is the entire problem.
> 
> Amazon is certainly a big player in the problem, so it's not the entire
> problem, no.

in this instance yes, but the credit card & address could have been
obtained from another source. for example, 

<http://money.cnn.com/2012/04/02/technology/global-payments-breach/index.
htm>
  A data breach at a payments processing firm has potentially
  compromised up to 1.5 million credit and debit card numbers from all
  of the major card brands.

> > it started with twitter, because he had a 3 character twitter name.
> > that made him a desirable target. 
> 
> The HACK did not start with twitter, the desire to hack him did.

actually it did start with twitter, and that was their hacking goal.

the rest was incidental damage and there was no desire to hack *him* in
particular. he just happened to have a desirable twitter name.

> > from that, they found he used gmail, hit the gmail recovery page and
> > found an obscured secondary email address, however, what was obscured
> > was easily guessed, which happened to be a .me address. since they knew
> > how to hack apple ids, their next step was obtaining the information to
> > do just that.
> 
> Which they obtained from AMAZON.

and if he didn't have an amazon account, they could have obtained that
info elsewhere.

[toc] | [prev] | [next] | [standalone]


#29114

FromPaul Sture <paul@sture.ch>
Date2012-08-07 08:28 +0200
Message-ID<s4p6f9-7qh.ln1@news1.chingola.ch>
In reply to#29106
On Tue, 07 Aug 2012 05:41:53 +0000, Lewis wrote:

> Right. "Only" having the first year of baby pictures of his daughter and
> "only" having last pictures of family that had died. The lack of backups
> is *entirely* on his shoulders and I have trouble having any sympathy
> for that.

He's Senior Writer for wired.com.  He should know better.

<http://www.wired.com/gadgetlab/author/mathonan/>

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#29128

FromDavoud <star@sky.net>
Date2012-08-07 09:19 -0400
Message-ID<070820120919460127%star@sky.net>
In reply to#29081
Fred Moore:
> > Yes, I was hacked. Hard.

Wes Groleau:
> And people laughed at me when I said I didn't want my life in iCloud.

I don't have Mr. Moore's original post in front of me, but I seem to
recall there was something in there about the multiple use of the same
weak password.

mydogrover can get you hacked. Try pasting My#3&Dogs&$roveR! into the
box at http://www.grc.com/haystack.htm to check its security. Minimum
attack time: far greater than the life-span of the Universe.

-- 
I agree with almost everything that you have said and almost everything that
you will say in your entire life.

usenet *at* davidillig dawt cawm

[toc] | [prev] | [next] | [standalone]


#29134

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 09:30 -0400
Message-ID<barmar-E4968A.09302607082012@news.eternal-september.org>
In reply to#29128
In article <070820120919460127%star@sky.net>, Davoud <star@sky.net> 
wrote:

> Fred Moore:
> > > Yes, I was hacked. Hard.
> 
> Wes Groleau:
> > And people laughed at me when I said I didn't want my life in iCloud.
> 
> I don't have Mr. Moore's original post in front of me, but I seem to
> recall there was something in there about the multiple use of the same
> weak password.

No, it was multiple uses of the same email address, not password.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29180

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 04:15 +0000
Message-ID<slrnk23pvc.vfq.g.kreme@mbp55.local>
In reply to#29128
In message <070820120919460127%star@sky.net> 
  Davoud <star@sky.net> wrote:
> Fred Moore:
>> > Yes, I was hacked. Hard.

> Wes Groleau:
>> And people laughed at me when I said I didn't want my life in iCloud.

> I don't have Mr. Moore's original post in front of me, but I seem to
> recall there was something in there about the multiple use of the same
> weak password.

There was *no* password hacking involved. Amazon gave access to the
account with no password, and then apple reset the AppleID password with
the info available from Amazon.

> mydogrover can get you hacked. Try pasting My#3&Dogs&$roveR! into the
> box at http://www.grc.com/haystack.htm to check its security. Minimum
> attack time: far greater than the life-span of the Universe.

Would have made *zero* difference in this case.

-- 
Outside of a dog, a book is a man's best friend. Inside of a dog, it's
too dark to read.

[toc] | [prev] | [next] | [standalone]


#29198

FromTom Stiller <tom_stiller@yahoo.com>
Date2012-08-08 08:11 -0400
Message-ID<tom_stiller-8F6C30.08111608082012@news.individual.net>
In reply to#29128
In article <070820120919460127%star@sky.net>, Davoud <star@sky.net> 
wrote:

> Fred Moore:
> > > Yes, I was hacked. Hard.
> 
> Wes Groleau:
> > And people laughed at me when I said I didn't want my life in iCloud.
> 
> I don't have Mr. Moore's original post in front of me, but I seem to
> recall there was something in there about the multiple use of the same
> weak password.

No, the hackee's mistake was in linking several accounts so that access 
to one gave the hacker a leg up on hacking the others.

-- 
PRAY, v.  To ask that the laws of the universe be annulled in behalf
of a single petitioner confessedly unworthy. -- Ambrose Bierce

[toc] | [prev] | [next] | [standalone]


#29146

FromDavid Lesher <wb8foz@panix.com>
Date2012-08-07 18:26 +0000
Message-ID<jvrmlh$f59$1@reader1.panix.com>
In reply to#29081
Wes Groleau <Groleau+news@FreeShell.org> writes:

>On 08-06-2012 17:46, Fred Moore wrote:
>> Thought folks here would be interested in this article I saw on
>> Macintouch:
>>
>> Yes, I was hacked. Hard.
>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

>And people laughed at me when I said I didn't want my life in iCloud.

Note he had zero backups, FSVO "backup" where he physically
had the backup media in his possession. 

	Why bother, I have all this cloud stuph; what
	could ever go wrong...wrong...wrong...

He also {stupidly, IMHO} interlinked everything so one
card brought down his whole house...
-- 
A host is a host from coast to coast.................wb8foz@nrk.com
& no one will talk to a host that's close........[v].(301) 56-LINUX
Unless the host (that isn't close).........................pob 1433
is busy, hung or dead....................................20915-1433

[toc] | [prev] | [next] | [standalone]


#29084

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-07 00:26 -0400
Message-ID<jvq5co$6tm$4@dont-email.me>
In reply to#29056
On 8/6/12 5:46 PM, Fred Moore wrote:
> Thought folks here would be interested in this article I saw on
> Macintouch:
>
> Yes, I was hacked. Hard.
> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

Even Apple can't defend against lousy passwords.

[toc] | [prev] | [next] | [standalone]


#29088

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 00:31 -0400
Message-ID<070820120031314747%nospam@nospam.invalid>
In reply to#29084
In article <jvq5co$6tm$4@dont-email.me>, Justin
<justin@nobecauseihatespam.edu> wrote:

> > Thought folks here would be interested in this article I saw on
> > Macintouch:
> >
> > Yes, I was hacked. Hard.
> > <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> 
> Even Apple can't defend against lousy passwords.

it wasn't a lousy password. in fact, his password made no difference
whatsoever. 

apple *gave* the hacker a new, temporary password.

apple and amazon (where he got enough info to fool apple) are entirely
to blame for really shitty security.

read more here:
<http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/a
ll/1>

[toc] | [prev] | [next] | [standalone]


#29164

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-07 20:16 -0400
Message-ID<jvsb5c$q33$3@dont-email.me>
In reply to#29088
On 8/7/12 12:31 AM, nospam wrote:
> In article <jvq5co$6tm$4@dont-email.me>, Justin
> <justin@nobecauseihatespam.edu> wrote:
>
>>> Thought folks here would be interested in this article I saw on
>>> Macintouch:
>>>
>>> Yes, I was hacked. Hard.
>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>
>> Even Apple can't defend against lousy passwords.
>
> it wasn't a lousy password. in fact, his password made no difference
> whatsoever.
>
> apple *gave* the hacker a new, temporary password.

Wrong.
His original password was guessed, with that he (they?) gained enough 
information to go through the password reset procedure pretending to be 
the victim.

Didn't score very high on the reading comprehension part of the SAT, now 
did you?

[toc] | [prev] | [next] | [standalone]


#29167

Fromdempson@actrix.gen.nz (David Empson)
Date2012-08-08 12:28 +1200
Message-ID<1koicze.183t8lri6808lN%dempson@actrix.gen.nz>
In reply to#29164
Justin <justin@nobecauseihatespam.edu> wrote:

> On 8/7/12 12:31 AM, nospam wrote:
> > In article <jvq5co$6tm$4@dont-email.me>, Justin
> > <justin@nobecauseihatespam.edu> wrote:
> >
> >>> Thought folks here would be interested in this article I saw on
> >>> Macintouch:
> >>>
> >>> Yes, I was hacked. Hard.
> >>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
> >>
> >> Even Apple can't defend against lousy passwords.
> >
> > it wasn't a lousy password. in fact, his password made no difference
> > whatsoever.
> >
> > apple *gave* the hacker a new, temporary password.
> 
> Wrong.
> His original password was guessed, with that he (they?) gained enough
> information to go through the password reset procedure pretending to be
> the victim.

You are wrong. No passwords were guessed.

> Didn't score very high on the reading comprehension part of the SAT, now
> did you?

Nor did you, or the chinese whispers of reporting have mutated the story
and misled you into thinking this was a guessed password, or you've read
an earlier report in which the victim assumed his password was guessed,
which he later corrected.

Here is the victim's article describing the hack in detail, including
having got details from one of the hackers. The hackers did not guess
any of his passwords.

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/

The hackers tricked Apple into giving them a temporary password to the
victim's iCloud account, then they used that to log in and change to a
new permanently password only they knew. From there all other services
were hacked by using password recovery mechanisms that were linked to
the iCloud account's e-mail address.

-- 
David Empson
dempson@actrix.gen.nz

[toc] | [prev] | [next] | [standalone]


#29187

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-08 01:13 -0400
Message-ID<jvssid$98u$1@dont-email.me>
In reply to#29167
On 8/7/12 8:28 PM, David Empson wrote:
> Justin <justin@nobecauseihatespam.edu> wrote:
>
>> On 8/7/12 12:31 AM, nospam wrote:
>>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>>> <justin@nobecauseihatespam.edu> wrote:
>>>
>>>>> Thought folks here would be interested in this article I saw on
>>>>> Macintouch:
>>>>>
>>>>> Yes, I was hacked. Hard.
>>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>>
>>>> Even Apple can't defend against lousy passwords.
>>>
>>> it wasn't a lousy password. in fact, his password made no difference
>>> whatsoever.
>>>
>>> apple *gave* the hacker a new, temporary password.
>>
>> Wrong.
>> His original password was guessed, with that he (they?) gained enough
>> information to go through the password reset procedure pretending to be
>> the victim.
>
> You are wrong. No passwords were guessed.

Wrong.

[toc] | [prev] | [next] | [standalone]


#29193

FromPaul Sture <paul@sture.ch>
Date2012-08-08 11:16 +0200
Message-ID<hbn9f9-gs62.ln1@news1.chingola.ch>
In reply to#29167
On Wed, 08 Aug 2012 12:28:55 +1200, David Empson wrote:

> Here is the victim's article describing the hack in detail, including
> having got details from one of the hackers. The hackers did not guess
> any of his passwords.
> 
> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/

On my first look at that article I didn't notice the page numbers at the 
bottom so missed 3/4 of the story.  There's also an option to see the 
whole report on one page.

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#29231

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-09 02:56 -0400
Message-ID<jvvmuf$fn6$1@dont-email.me>
In reply to#29193
On 8/8/12 5:16 AM, Paul Sture wrote:
> On Wed, 08 Aug 2012 12:28:55 +1200, David Empson wrote:
>
>> Here is the victim's article describing the hack in detail, including
>> having got details from one of the hackers. The hackers did not guess
>> any of his passwords.
>>
>> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/
>
> On my first look at that article I didn't notice the page numbers at the
> bottom so missed 3/4 of the story.  There's also an option to see the
> whole report on one page.
>

I read the whole thing, and iCloud itself was not hacked.

Now keep on failing.

[toc] | [prev] | [next] | [standalone]


Page 2 of 7 — ← Prev page 1 [2] 3 4 5 6 7  Next page →

Back to top | Article view | comp.sys.mac.system


csiph-web