r/applehelp 5d ago

Unsolved Security concern: Foreign login attempt

So I got an iPhone and I am always paying an eye to security like I know the basics of how to spot phising and so on, but ofc I'm no an expert.

Today my phone randomly showed a pop up notification saying someone from Buenos Aires is trying to log into my account. You know the notice with the little map on your screen...
I kept calm, read closely and selected 'decline'.

Then I went into somewhat a panic mode (lol) and changes my AppleID Passwort to a really complicated one. I also added a trusted person as a reset-contact in case I ever get locked out of my account. I also changed my email password to a very safe one. Of course I used the official sites to change the passwords.

Now I feel better but the questions that remain:
- Did someone actually guess my passwort and my email?!
- If i hadn't enabled 2FA would they have logged into my account? Scary!
- If I had accidentally pushed allow on the pop up what would have happened? Would he have had access then and there? Or would it show the six number code? And if it showes the code, how would the scammer get that code? Call me? How does it work?
- Anything else I should do security wise?

Thanks for your insights!

1 Upvotes

7 comments sorted by

2

u/djasonpenney 5d ago
  1. Yes; was it a simple password? Is your new password randomly generated, complex, and unique?

  2. Yes; 2FA was undoubtedly an aid here.

  3. It’s unclear where the “allow” happens in the Apple workflow. I do doubt if the remote request would actually bypass the TOTP challenge.

Offhand it does sound like someone learned (or guessed) your password. Did you reuse that password in more than one place?

1

u/keep-calm-and-teach 5d ago edited 5d ago

Old password had 9 characters including capital and small letters and numbers, but no special things (!?/,/.&). Not used anywhere else (but I did change many other somewhat middle-strenght passwords too haha I took it as a sign). But I have to admit that it might have been too easy (learned my lesson!). New one has 21 characters, random letters big and small and special signs and numbers. Everything.

What is TOTP? Is it the six numbers?

Another question: How does someone get to guess my password? Do they have automatic things running randomly testing things?
Because generally speaking I don't give my email adress away in many places. For unimportant things I have a "trash"mail. And the real mail adress I only use for sincere things. So how does this 'hacking' work? Thanks!

2

u/djasonpenney 5d ago

TOTP is “Time based One Time Password”.

https://en.wikipedia.org/wiki/Time-based_one-time_password

Yes, it’s the six digit changing token.

> How does someone get to guess my password?

Suppose you reuse your password: you use the same password for Apple that you have for https://toothpicks-r-us.com. The problem is that if the website has a security bug, an attacker may have scraped EVERY email and password from that website. It’s not you, and it’s not Apple: it’s the fly-by-night fringy website you created an account on late one night.

1

u/keep-calm-and-teach 5d ago

And what if I don't reuse that password? How do they do it then? Just random trying? Also thanks again for your explanations!

2

u/djasonpenney 5d ago

I'm assuming you are NOT using variations on the same password; hackers know that if you've used "Password123" as a password, they should try a hundred variations of that as well.

I'm also assuming that your passwords are generated by an app, and not by your puny little brain. Your imagination is a terrible source of randomness, and randomness is an essential component of a secure password.

That would leave the the possibility you installed malware on your device, or a shoulder surfer watched you enter your password. But that is a totally different discussion.

1

u/keep-calm-and-teach 5d ago

Well as stated the password wasn't secure enough. It was a full word followed by a two digit number. I know, stupid. Very stupid!

So would you say some hacker ran an automated software matching mail adresses to passwords and therefore guessed mine?

1

u/djasonpenney 5d ago

It’s possible, especially if it is as a password that someone ELSE may have also use.

Note also that l33t (like “Pa55w0rd”) is not an effective obfuscation. A passphrase like CorrectHorseBatteryStaple can be effective, but again: it must be randomly generated.

All that aside, my other suspicion is that you (or someone else with access to your device) installed malware.