http://krebsonsecurity.com/2013/04/swatting-incidents-tied-to-id-theft-sites/
Brian provides more details on his specific case, but most interesting part to me, was the fact that TTY are not supposed to keep records.
I probably should have realized that before, I thought main point was it made it easier for attacker to spoof phone number/location for SWATting.
Esports & Computer Security Blog. For SC2 tournaments see clocks immediately below. Starts with Korean time at upper left, moves west around the world till you end with PDT/PST clock for Anaheim USA. I earn a small referral fee if you click the occasional Amazon links and then purchase item. It does not affect the purchase price. For more information see "Amazon Associates" link below & left of clocks.
Showing posts with label Mat Honan. Show all posts
Showing posts with label Mat Honan. Show all posts
Wednesday, April 17, 2013
Wednesday, March 20, 2013
Security & Hacking: "Microsoft confirms compromise of “high-profile” Xbox Live accounts"
Source & full story at http://arstechnica.com/security/2013/03/hackers-that-took-over-xbox-live-accounts-may-be-behind-ddos-attack-on-ars/ :
This ties in with Brian Kreb's recent blog post, http://krebsonsecurity.com/2013/03/the-obscurest-epoch-is-today/ were he details what he has learned so far about person(s) that SWATted him.
Oddly those people appear to have been involved in the hack or social engineering attack against Mat Honan, which Honan wrote about http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard and a later more polished article (link is good, but you may need to refresh sometimes to get it to work) http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/.
To see all my posts about the Mat Honan Hack click this Mat Honan Label, additional Labels can be found at bottom left of every post, and in Label Cloud at left side of Blog.
"We are aware that a group of attackers are using several stringed social engineering techniques to compromise the accounts of a handful of high-profile Xbox LIVE accounts held by current and former Microsoft employees," Microsoft officials said in a statement sent to Ars. "We are actively working with law enforcement and other affected companies to disable this current method of attack and prevent its further use."
This ties in with Brian Kreb's recent blog post, http://krebsonsecurity.com/2013/03/the-obscurest-epoch-is-today/ were he details what he has learned so far about person(s) that SWATted him.
Oddly those people appear to have been involved in the hack or social engineering attack against Mat Honan, which Honan wrote about http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard and a later more polished article (link is good, but you may need to refresh sometimes to get it to work) http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all/.
To see all my posts about the Mat Honan Hack click this Mat Honan Label, additional Labels can be found at bottom left of every post, and in Label Cloud at left side of Blog.
Tuesday, September 18, 2012
Security & Hacking: "ID Theft Service Tied to Payday Loan Sites"
Article at http://krebsonsecurity.com/2012/09/id-theft-service-tied-to-payday-loan-sites/
Everyone who isn't fully aware of the sad, frightening realities of Hacking, should really read Brian Krebs' article linked above, for those that don't know Brian was a reporter for The Washington Post for several years, he knows his topic very well.
This reminds me of the Mat Honan hack or Social Engineering attack that happen not that long ago, I hope a lot of people read Brian Krebs' article, and start making noise to their Banks, Schools, Legislators, etc.
If your not familiar with Mat Honan case see Mat Honan Targeted, and click this link for response by Apple & Amazon.
There really isn't any information about you a motivated criminal Hacker can't find out, so those elements should not be used to give control of accounts to someone over the phone or net.
There is no perfect solution yet that I am aware of, best thing for institutions like banks, that I know, is to make people come in to a Brick & Mortar location, and provide current picture ID from Government/Military, not just asking them over phone or Net for SSN or Mother's Maiden name.
For more blog posts on similar topics, click either label Security or Hacking, those labels can be found in Label cloud at left side of blog.
Labels can also be found at bottom left of every post.
Stay Safe,
Cliff
Everyone who isn't fully aware of the sad, frightening realities of Hacking, should really read Brian Krebs' article linked above, for those that don't know Brian was a reporter for The Washington Post for several years, he knows his topic very well.
This reminds me of the Mat Honan hack or Social Engineering attack that happen not that long ago, I hope a lot of people read Brian Krebs' article, and start making noise to their Banks, Schools, Legislators, etc.
If your not familiar with Mat Honan case see Mat Honan Targeted, and click this link for response by Apple & Amazon.
There really isn't any information about you a motivated criminal Hacker can't find out, so those elements should not be used to give control of accounts to someone over the phone or net.
There is no perfect solution yet that I am aware of, best thing for institutions like banks, that I know, is to make people come in to a Brick & Mortar location, and provide current picture ID from Government/Military, not just asking them over phone or Net for SSN or Mother's Maiden name.
For more blog posts on similar topics, click either label Security or Hacking, those labels can be found in Label cloud at left side of blog.
Labels can also be found at bottom left of every post.
Stay Safe,
Cliff
Tuesday, August 7, 2012
Security & Hacking: Ongoing Reactions to Mat Honan's Hacking & Reporting
If you haven't hear about Mat Honan's Apple ID being Hacked, and the Hacker using that access to remote wipe Mat's iPhone, iPad, & Macbook, see Mat Honan Targeted.
The Hacker(s) used vulnerabilities in Amazon's Customer Service to gain access to Mat's account there, so they could see the last 4 digits of his credit cards.
Because those Credit Card numbers were the only thing Apple required for getting access to Apple ID account wihtout password, that you couldn't find with Google.
The other information need to access Hack Apple account was Name, Email, and Billing address for account your were hacking.
Amazon was first to respond to this http://arstechnica.com/security/2012/08/amazon-fixes-security-flaw-hackers-used-against-wireds-mat-honan/
Followed later by Amazon http://arstechnica.com/security/2012/08/apple-freezes-over-the-phone-password-resets-in-response-to-honan-hack/
I really hope that Apple & Amazon adds two factor authentication as a result of this.
I prefer Yubikey for Two Factor Authentication, but I believe temporary password texted to cell phone is more popular form of Two Factor Authentication among most people, mainly because they don't have to buy another device.
With Cell Phone Text, you get a second, temporary Password or Pin that you have to enter in addition to your main password.
Normally these temporary Passwords are only valid for a few minutes, if you don't use it before it expires you have to request a new one.
The Hacker(s) used vulnerabilities in Amazon's Customer Service to gain access to Mat's account there, so they could see the last 4 digits of his credit cards.
Because those Credit Card numbers were the only thing Apple required for getting access to Apple ID account wihtout password, that you couldn't find with Google.
The other information need to access Hack Apple account was Name, Email, and Billing address for account your were hacking.
Amazon was first to respond to this http://arstechnica.com/security/2012/08/amazon-fixes-security-flaw-hackers-used-against-wireds-mat-honan/
Followed later by Amazon http://arstechnica.com/security/2012/08/apple-freezes-over-the-phone-password-resets-in-response-to-honan-hack/
I really hope that Apple & Amazon adds two factor authentication as a result of this.
I prefer Yubikey for Two Factor Authentication, but I believe temporary password texted to cell phone is more popular form of Two Factor Authentication among most people, mainly because they don't have to buy another device.
With Cell Phone Text, you get a second, temporary Password or Pin that you have to enter in addition to your main password.
Normally these temporary Passwords are only valid for a few minutes, if you don't use it before it expires you have to request a new one.
Security & Hacking Updated: Mat Honan Targeted
I posted about this story the other day, VOD interview/discussion at http://twit.tv/show/this-week-in-tech/365
Mat Honan also talks about it on his Blog at http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard
Since I wrote about this, Honan's has written an article How Apple and Amazon Security Flaws Led to My Epic Hacking, were he explains how the hack was done, and how this vulnerability still exists.
Strongly suggest reading the whole story, but the key aspects of the hack are as follows:
Couple of things stand out to me, besides Apple's horrible policy, if at all possible, don't associate emails or Credit Cards between Apple and any other company that you do online or phone ordering with, because Apple considers the last four numbers of your credit card to be more than a password, since you can reset valid passwords with that information!
Maybe only use a prepay Card with Apple? Not sure how else to protect your Apple accounts from being hacked this way.
Mat Honan also talks about it on his Blog at http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard
Since I wrote about this, Honan's has written an article How Apple and Amazon Security Flaws Led to My Epic Hacking, were he explains how the hack was done, and how this vulnerability still exists.
Strongly suggest reading the whole story, but the key aspects of the hack are as follows:
- "My [Honan's] Twitter account linked to my personal website, where they found my Gmail address."
- "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com. Jackpot. "
- "Since he already had the e-mail, all he needed was my billing address and the last four digits of my credit card number to have Apple’s tech support issue him the keys to my account. "
- "He got the billing address by doing a whois search on my personal web domain."
- Then Hacker calls Amazon & adds bogus Credit Card number to account, since they can do this with just Name, billing address, and email associated with the Amazon account.
- Call Amazon back & say can't get into account, Amazon will let you in with: Name, Billing Address, Email, and Bogus Credit Card numbers Hacker just added. Then you can add new email to account and see last four Credit Card numbers of every Card on that Account. So you now have the keys to the Apple account.
Couple of things stand out to me, besides Apple's horrible policy, if at all possible, don't associate emails or Credit Cards between Apple and any other company that you do online or phone ordering with, because Apple considers the last four numbers of your credit card to be more than a password, since you can reset valid passwords with that information!
Maybe only use a prepay Card with Apple? Not sure how else to protect your Apple accounts from being hacked this way.
Subscribe to:
Posts (Atom)