Apple tech support handed over an iCloud password. Erasure ensued.


Recommended Posts

This weekend played host to a twisting, turning tale of hacking woe, which captured headlines primarily because of some unpleasant tweets sent from the hacked Twitter account of tech blog Gizmodo. But at the heart of the story is something far more worrying ? the deception of Apple tech support, and the subsequent access of an iCloud account.

While the story appears to start with the hacking of Gizmodo?s Twitter account, this was really a bonus for those hacking Mat Honan, a writer for Wired. Control of Gizmodo?s Twitter account was soon regained, but it was only the beginning of Honan?s problems.

Writing on his own blog, Honan describes how his iPhone, iPad and MacBook Air were systematically compromised and remote wiped using iCloud, and his Google account deleted too.

Because his Google account was linked to his Twitter account, which in turn was linked to Gizmodo?s Twitter ? Honan had previously written for the site ? offensive tweets were sent by the hackers. This is the point where the story went public.

Honan speculated that his iCloud account, where the problems all began, had been hacked using ?brute force,? where someone systematically enters possible passwords until the correct one is discovered. However, this wasn?t the case, as both AppleCare and the hacker have said the account was breached using ?social engineering.?

Trust gained using social engineering

In essence, social engineering involves a criminal lying about their identity and building trust to gain information from a third party, in this case AppleCare.

What?s interesting here is that no matter how secure you think your accounts are, or how strong your password is, it won?t matter if the person at the end of a telephone helpline is manipulated into handing it over to someone that?s not really you.

This will inevitably cause people to rethink how they use iCloud, and whether Apple?s security is good enough to protect all that important data. Before hands are thrown up in despair, Tony Bradley, writing for PCAdvisor.co.uk, has a very different story to tell concerning AppleCare. He describes a dogged refusal to handover any information at all, even with proof that he was who he said he was, indicating that either Honan?s experience is isolated, or that the criminals were really, really good.

Additionally, the attack will also ? once again ? highlight the importance of backing up data, encrypting data stored in the cloud, and taking care over linking online accounts together.

However, although these precautions may have limited Honan?s pain, they probably wouldn?t have prevented it happening in the first place. Infamous social engineer and hacker Kevin Mitnick said ?If you want to protect your network, you cannot rely on technology alone,? and this applies here too.

Let?s see if Apple has a response to this hack, and whether it will also need to work to regain its customers trust, especially as it?s so close to providing iCloud email addresses.

Source:

http://www.digitaltr...cloud-password/

Another good read on the story:

http://www.newstates...t-happening-you

EDIT: It was a password reset. More details on Tom's hardware:

http://www.tomshardw...Care,16642.html

Doesn't apple salt their passwords?

What?s interesting here is that no matter how secure you think your accounts are, or how strong your password is, it won?t matter if the person at the end of a telephone helpline is manipulated into handing it over to someone that?s not really you.

It looks like they have access to the passwords.

Terrible that they did this. If he is unable to recover the data on his MacBook Air I would seriously sue Apple.

As bad as I feel for that.. in the end, my sympathy stops as he never did backups.

He'd have been just as screwed if it was stolen, or fried in a power surge, or whatever... Backup Backup Backup..

Read the article, Apple is as much to blame as Amazon and Google in this. The "hackers" would never have been able to do all that damage without the security failure of Amazon and Google.

Where does the article say that? Which article? What security failure? :huh:

Where does the article say that? Which article? What security failure? :huh:

How Apple and Amazon Security Flaws Led to My Epic Hacking

http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking

The article shows that it's extremely easy to get (partial) credit card numbers from Amazon tech support and that Google Accounts shows your secondary email addresses (almost) unobfuscated...

I'm not saying that Apple is not to blame, but the hacker got the most useful piece of info from Amazon.

How Apple and Amazon Security Flaws Led to My Epic Hacking

http://www.wired.com...t-honan-hacking

The article shows that it's extremely easy to get (partial) credit card numbers from Amazon tech support and that Google Accounts shows your secondary email addresses (almost) unobfuscated...

I'm not saying that Apple is not to blame, but the hacker got the most useful piece of info from Amazon.

I could't fin the bit about Google there, but the issue with the 4 CC digits is cetainly epic :pinch:

I could't fin the bit about Google there, but the issue with the 4 CC digits is cetainly epic :pinch:

The part about Google is mentioned in a number of related articles (see below). The Google Account recovery page gives away the email addresses configured for account recovery.

The chain of calamity began with the hackers finding Honan's Gmail address via his linked personal webpage off the @mat Twitter account and assuming correctly that it was the email address for his Twitter account. With that detail, they could go to the account recovery page for Gmail and -- without actually attempting to break into his account -- see a partial email address "[email protected]" already configured for account recovery. It doesn't take a rocket scientist to guess what the missing letters are there, and once they knew Honan's Gmail password reset would be heading for iCloud, they knew they had an easy path ahead.

Source: http://www.tuaw.com/2012/08/06/mat-honan-details-the-amazon-and-apple-security-flaws-that-let-h/

This topic is now closed to further replies.
  • Posts

    • Google pitches Spanner as one database for all AI agents with these new featues by Karthik Mudaliar Google Cloud is introducing new features within Spanner, its distributed database, as a place where enterprises should keep their data, using which AI agents could make smarter and better decisions. In a detailed blog post, Google highlighted quite a few features coming to Spanner, including relational data, graph relationships, vector search, key-value access, full-text search, and operational analytics together in one database architecture. Google says that today's systems aren't well-made for AI agents. There could be data that is present in one system, search indexes in another, embeddings in a vector database, and relationship data in a graph database. This fragmentation isn't great for AI agents to do their jobs because they don't have access to all of this data in one place. This is where Google is positioning Spanner as a solution. Spanner is already a globally distributed relational database with strong consistency, and Google wants its customers to see it as a broader data layer for AI applications. The company introduced something called Spanner Graph, along with integrated vector search, full-text search, a Cassandra-compatible key-value endpoint, and a columnar engine for analytical queries on operational data. Google also added that its ScaNN-powered vector search can support indexes with more than 10 billion vectors, while the columnar engine can make some analytical scans up to 200 times faster. All of this isn't just exclusive to the Google Cloud Platform, and there's support for multi-cloud as well. This comes via Spanner Omni, which Google says is a downloadable, containerized version of Spanner that can run on Kubernetes and in environments outside Google Cloud, including Microsoft Azure and AWS, and even on-premises infrastructure as well as edge deployments. Google says that customers who are interested in the full-featured edition should contact the company, and there's no word on commercial availability or separate pricing. Those interested can read the full blog by Google Cloud, which details these features individually.
    • Kalmuri 4.2.5 by Razvan Serea Kalmuri is your all-in-one, portable screen capture and recording solution designed for speed, simplicity, and flexibility. Whether you need a full-screen snapshot, a custom area, a scrolling webpage, or smooth video recording, Kalmuri delivers with ease. Capture text instantly from images with built-in OCR, keep floating images on top for quick reference, and use the precise color picker for perfect design matching. Customize hotkeys to work your way and share results instantly with built-in upload options. Kalmuri runs without installation, making it ideal for USB use, and offers an intuitive interface that’s easy to learn. Kalmuri key features: Video recording support (designation of whole screen and area) Whole screen, active program, window control, area application Extract text from images using optical character recognition (OCR). Support for PNG, JPG, WEBP, BMP, GIF file formats MP4 video recording powered by FFmpeg for high-quality results Full web page capture Share the captured image on the web Color extraction function Printer output Hotkey settings Adjustable via keyboard for area capture (Arrow key, Ctrl+Arrow key, Shift+Arrow key) File name format (sequential, datetime) Free to use it at work, at home, in government offices, at school, etc. Using Kalmuri portable for video recording Kalmuri’s portable version doesn’t include FFmpeg, which is required for video recording. Without it, you’ll get an “error FFmpeg.exe not found” message. To fix this, download FFmpeg from the provided link, extract it, and place FFmpeg.exe in Kalmuri’s folder. Kalmuri will then recognize it automatically, allowing you to start recording in high quality instantly. Kalmuri 4.2.5 changelog: Fixed an intermittent crash when using Area Capture Improved stability for Area Capture and screen recording Resolved a capture issue that could occur right after startup Download: Kalmuri 4.2.5 | 24.2 MB (Freeware) Download: Kalmuri Portable 4.2.5 | 2.1 MB View: Kalmuri Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • They have lots of info on me, I have a facebook account and have done so for years, it was the thing to have then. My phone number is not on it. I don't have the Facebook app on my phone these days, just the messenger part, and only for a couple of people to contact me, most will text me via SMS or phone. I agree, Meta, like others, even without an account will know something about me. Just have to try and keep some things private Also, never saw the need for Whatsapp, people used to ask for me to join it, but as I said to them, I have SMS and a phone, use that, or email
  • Recent Achievements

    • First Post
      rosiecharles earned a badge
      First Post
    • Reacting Well
      Juan Dela earned a badge
      Reacting Well
    • Week One Done
      Collagen Project earned a badge
      Week One Done
    • Reacting Well
      Wakeen1966 earned a badge
      Reacting Well
    • Rookie
      Almohandis went up a rank
      Rookie
  • Popular Contributors

    1. 1
      +primortal
      514
    2. 2
      +Edouard
      272
    3. 3
      PsYcHoKiLLa
      143
    4. 4
      Steven P.
      98
    5. 5
      macoman
      54
  • Tell a friend

    Love Neowin? Tell a friend!