Apple tech support helped hacker access Honan’s account

Mat Honan:

I know how it was done now. Confirmed with both the hacker and Apple. It wasn’t password related. They got in via Apple tech support and some clever social engineering that let them bypass security questions.

The good news is the hacker didn’t brute-force the password. The bad news… yeah.



20 thoughts on “Apple tech support helped hacker access Honan’s account

  1. You can’t expect that Apple will confirm this. So yes, this is speculation.

  2. Paul, Christopher: He pretty clearly writes “Confirmed with both the hacker and Apple” I don’t think it is speculation, and I don’t think we need another quote.

  3. If he called up Apple customer support and there was a record of a support call in which someone being let into his system, that would be confirming it.

  4. It sounds like Apple have already confirmed this (at least to Mat Honan), and now it is a private matter between himself and Apple – why did they let some random Joe get access to all his data, and give them the ability to wipe all his hardware clean?

    Also the hacker – just because you get the keys to someone’s front door, does not give you the right to go in and empty their house, or smear shit on the walls. I am sure what they did constitutes a criminal act.

    It’s up to Mat Honan to decide whether Apple is liable for the huge inconvenience and actual losses he suffered by their actions. (And while I am sure Apple are covered by the excessive T&Cs you have to click ‘Agree’ to when signing up for all their services, it would be a pretty dick move on their part not to accept at least some liability for what happened. I guess he’s just lucky they didn’t turn him into a HumanCentiPad …)

  5. That’s pretty scary to be honest. If it’s possible to bypass all my security precautions that easy—by which I mean with social engineering and a phone call—I really think Apple needs to rethink their account management strategies.

  6. And I thought last night’s take on this was bad enough. 🙁

    This certainly has me rethinking whether I want to use certain iCloud features in the future.

    I wonder what the enterprise/business users who have been persuaded to adopt Apple devices will be thinking when they read about this next week. I don’t think it’s going to be a happy conversation within enterprise.

    And if Apple ignores it completely, I think Microsoft will be licking their lips when they start trying to push their new mobile offerings later this year.

  7. Not to increase the fear here but a few years ago my AppleID info was changed accidentally by a family friend who only had an iPhone serial number and nothing else. They basically changed all the info of the AppleID the phone was registered to. Took me two years to get my ADC account fixed because they treated me like a “hacker” when trying to fix what they did to my account.

    Yeah.

    AppleIDs were never secure and now they’re important for a lot more people.

  8. It’s a bit hyperbolic to say Apple helped. If being socially engineered is helping, the half the telecoms industry were Mitnick’s accomplices.

    I don’t think any of the OS ecosphere companies will be too comfortable with this. How many of their call centre operatives or tech support are fully familiar with social engineering tricks? Probably not many as they haven’t been major targets so far.

  9. Was this a case of Apple truly “helping” a hacker, or did someone simply call the Apple support line and had all the answers to Mat’s secret questions and they reset the password for the caller?

    Also, what happened to the comments? Is Disqus gone?

  10. I agree. I would have preferred something like:

    Nasty, evil-doer hacker deceives sweet, innocent Apple tech support into making an honest mistake.

  11. So I have trouble scrounging up any sympathy at ALL for this guy. Let’s look at the facts, and how someone can put themselves in a position where they can be screwed so royally. Keep in mind this guy is a tech blogger at Gizmodo:

    He CHOSE to not make a SINGLE backupin the time he’s had his computer. On a mac, this couldn’t be easier. There’s basically a big massive Time Machine button that says ON- it takes care of the rest. Never mind off site storage, dropbox and a million other free options, etc – why would he not take advantage of Time Machine, the fastest and most dummy proof way to back anything up completely and automatically on a mac? External HDDS are dirt cheap. The fact that he had no backups at all is inexcusable, especially considering what industry he’s in.
    He CHOSE to retain the same password for ‘many, many years’ and never change it.
    He CHOSE to link up all his accounts, so that anyone who got access to his iCloud account could also get access to his gmail, twitter, etc. Again, negligent and excusable. I can’t even understand how someone would think this is a good idea.
    He CHOSE to turn on the find my device/remote wipe option on all his devices, knowing that if they were wiped he didn’t have a backup.

    I mean, I don’t know how careless and negligent one could be, especially someone that works and blogs about tech. If someone somehow got access to my iCloud account, the most that would happen is that I would have some downtime, as everything is backed up, and no, they could not access any of my other accounts. Did an Apple employee screw up? Maybe, maybe not- we don’t know the details yet. Perhaps anyone would have done the same thing if the hacker knew a ton of personal info about Matt and was convincing enough. Did Matt screw up? Yes, royally, and he should take responsibility for being so negligent, not Apple. Shit happens. That’s why you don’t keep your entire digital online and offline life behind one password, and never bother backing anything up. Lesson learned.

  12. … Because no one in a Google or DropBox or MSFT call centre could ever be fooled like the Apple worker was…

    Harry, there’s a golden rule: if it is information that is valuable then there is no where safe online. Don’t single out iCloud

  13. Possibly, but you’ve still got to appreciate the irony of a fairly successful tech writer being so easily compromised, whoever was at fault.

  14. The one detail the “victim” mentioned that stood out to me, he had ZERO backups at all!

Leave a Reply

Your email address will not be published. Required fields are marked *