TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

I got hacked, lost crypto and what it says about Apple’s security. Part 1

69 点作者 omnifischer超过 4 年前

11 条评论

caymanjim超过 4 年前
So, what does this say about Apple security? There&#x27;s a lot of speculation and insinuation that all the security lapses started with the purchase of a refurbished MacBook, but there&#x27;s zero evidence other than some coincidental timing. The author clearly wasn&#x27;t using many security precautions prior to being compromised. They had many interconnected accounts; reused passwords; limited use of 2FA; phone&#x2F;SMS-based 2FA in the few places they had it; no separate password for Chrome browser sync&#x27;s DB; no secure password management app; and kept the keys to their crypto accounts in the cloud. The list of compounded failures is long. There&#x27;s no reason to think this has anything to do with Apple at all.<p>They haven&#x27;t learned any lesson, either. Their advice after this? Turn your laptop off when you&#x27;re not using it (useless) and use Google Voice for 2FA. This is worse than useless; this is actively bad advice and you should not follow it.<p>The average user should install 1Password and use a TOTP application. Anyone can learn to do that, and it&#x27;s really all you need. More advanced users, those with particularly extreme security needs, and pedantic nerds can use YubiKeys, hardware wallets, self-hosted password vaults, PGP-encrypted backup codes, and other measures that are worth considering, but aren&#x27;t as approachable for everyone.
评论 #24885593 未加载
评论 #24917196 未加载
评论 #24885552 未加载
评论 #24890005 未加载
评论 #24885558 未加载
arboghast超过 4 年前
That article doesn’t say anything at all about Apple’s security.
评论 #24885644 未加载
pontifier超过 4 年前
Inevitable torrent of &quot;It was your fault for X, Y or Z reason&quot;.<p>Nobody is perfect.<p>Every system has known or unknown vulnerabilities.<p>We need to be building systems that are forgiving of errors, and store important data redundantly.<p>I&#x27;ve been wondering a lot about how to truly secure an identity. Is there a way to have a meaningful and secure digital life if all your devices could be compromised and your memory is not perfect? I wouldn&#x27;t want to trust my entire economic life to any single point of failure.
teknologist超过 4 年前
I&#x27;ve noticed that he has an app called &quot;Whoscall&quot; installed providing Caller ID in the Phone app. I wonder if this has access to Messages on the phone and is able to read&#x2F;upload SMS?<p>A quick search online suggests that this is a Chinese app.
评论 #24885862 未加载
jb1991超过 4 年前
&gt; Do not save passwords in your Chrome. Or, if you do, make sure your Google account has multiple levels of 2FA. SMS is not one of them.<p>I stopped using Chrome but now realize I never thought to check into what it has saved for me. I’ll have to check into that and erase it all if I can.
simonh超过 4 年前
Setting up a new device is a very vulnerable time. You’re downloading and installing new software and signing into all your accounts. It’s very easy to do the wrong thing, like click through the wrong dialog while you’re blasting through it all.
ksaitor超过 4 年前
Hi HN, the author of the article here.<p>Can someone explain how Telegram 2FA, Yahoo 2FA and Apple 2FA were bypassed?<p>Especially Apple 2FA - I received a 2FA call from Apple, picked it up, and the attacker logged in right after.<p>Please note, this was not a (typical) SIM swap. I was still receiving SMS and calls during the attack.<p>p.s. thanks for all the comments!
评论 #24893094 未加载
kmbfjr超过 4 年前
Why would you store cryto wallets in iCloud unencrypted? OS X makes it easy to create AES-256 encrypted sparsebundle disk images.
评论 #24885608 未加载
hacker_newz超过 4 年前
How was 2FA bypassed here?
评论 #24885917 未加载
foepys超过 4 年前
Well, not you key, not your money. Isn&#x27;t that what crypto currency advocates always tell us? Being your own bank carries high risks and in this case the risk got to the author.
fmajid超过 4 年前
The fact Apple uses SMS for 2FA tells you everything you need to know: it&#x27;s pure security theater.
评论 #24885830 未加载
评论 #24887280 未加载
评论 #24886084 未加载
评论 #24888913 未加载