Hacker News new | ask | show | jobs
by thr0w__4w4y 3 days ago
Hate to do a hit & run post but here we go...

Both AT&T and Apple transferred (albeit both temporarily) ownership of my phone # (AT&T) and my Apple ID (OK you know the company) from purely social engineering.

The AT&T one was basically like this post. A phone call with a convincing person. Eventually (through threat of legal action) I was able to listen to the recorded call where it happened, and it was simultaneously infuriating and fascinating.

The Apple one was more sophisticated. Too much to write here, but essentially to pull it off all the thief needed to do was have Apple call my number on file and have me answer it. I suspect I know the attack vector, but all I got from Apple was a very quick reversal, not an apology but an acknowledgment, and an explicit message that the details on their end wouldn't / couldn't be shared b/c of corporate policy (which honestly I think makes some sense if a novel vulnerability via social engineering has been found & exploited).

"The meatbag in the loop is the weak link" is said often, isn't always true... but sometimes it is indeed.

N.b.: I work in firmware & electronics security & cryptography.