Top Banner
HACKING MAT HONAN Bill Condo // 12/12/2012 Thursday, December 13, 12
12

Hacking Mat Honan

Dec 04, 2014

Download

Documents

Bill Condo

 
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Hacking Mat Honan

HACKING MAT HONANBill Condo // 12/12/2012

Thursday, December 13, 12

Page 2: Hacking Mat Honan

WHO IS MAT HONAN?

Senior Writer at Wired

honan.net@mat

Thursday, December 13, 12

Page 3: Hacking Mat Honan

WHAT HAPPENED?

• Amazon.com Account Compromised

• Apple / iTunes Account Compromised

• Gmail Hacked

•Mac Wiped

• iPhone Wiped

• Twitter Account Stolen

Thursday, December 13, 12

Page 4: Hacking Mat Honan

TIMELINE• 4:33 p.m. Attacker calls Apple support, requests a reset without being able to answer the security questions. Reset email sent.

Data Required: E-mail address (website, Gmail), credit card number (via Amazon), billing address (whois).

• 4:50 p.m. Reset email arrives to me.com email, and sent to trash. Email then used to to set a new password.

• 4:52 p.m. Gmail password reset sent to me.com email. Attacker resets Gmail password, then notice email is sent to me.com.

• 5:00 p.m. iCloud’s Find My tool used to wipe Mat’s iPhone.

• 5:01 p.m. iCloud’s Find My tool used to wipe Mat’s iPad.

• 5:02 p.m. Twitter password reset email sent. Attacker sets a new Twitter password.

• 5:05 p.m. iCloud’s Find My tool used to wipe Mat’s MacBook Pro.

• 5:10 p.m. Mat calls Apple Care.

• 5:12 p.m. Attacker posts to Twitter. with Mat’s account.

Thursday, December 13, 12

Page 5: Hacking Mat Honan

FAILURES

• Amazon accounts can be easily compromised.

• Apple Care doesn’t enforce security questions.

Thursday, December 13, 12

Page 6: Hacking Mat Honan

WHAT’S REALLY NEEDED?

•Do you need remote wipe?

•Do you need to store credit cards?

•Do you need public whois info?

Thursday, December 13, 12

Page 7: Hacking Mat Honan

DO: BACKUP

• Consider both local snapshots and off-site backup options

• Time Machine (Mac) or Windows Backup (PC)

• Carbonite, BackBlaze, Mozy are some of the off-site options

• Test / Verify Backups

Thursday, December 13, 12

Page 8: Hacking Mat Honan

DO: SETUP 2ND EMAIL

• Consider a second email, one with a different prefix.

• Consider second factor authentication

• Different (stronger) password

Thursday, December 13, 12

Page 9: Hacking Mat Honan

FOLLOWUP: AMAZON

• Amazon updated their policy, removing the option for over-the-phone account settings changes (credit cards, emails, etc.)

Thursday, December 13, 12

Page 10: Hacking Mat Honan

FOLLOWUP: APPLE

• “We found that our own internal policies were not followed completely.” - Apple

• Apple suspends password change requests via the phone

Thursday, December 13, 12

Page 12: Hacking Mat Honan

COMMENTS?

@mavrck

[email protected]

Thursday, December 13, 12