
The Perils of Going Passwordless

Matt McQueen · 4 min read
I mentioned previously, in my life update in July, that I had completed an introductory course in cybersecurity. I really enjoyed the course, and it's made me rethink my use of social media, and delete my accounts in some cases.
I've also pre-ordered the book Threat-Driven Software Development, published by Microsoft Press, which should arrive by the end of the month. I have a feeling that this subject will only get more important, and that the war to defend online services from modern threat actors has just begun.
It's a coincidence, of course, but since completing that course I feel that I have been under attack. It's possible that everyone is having the same issues as me, but don't be surprised if you encounter any of the following issues.
The first example started before I did the course, and it has continued since then, with a frequency of at least once per day. I have a Microsoft account, and they give you the option of going passwordless, so you have no password to forget.
In practice you have to use an authenticator application on your mobile phone, so you log in with your email address, and you get an alert on your phone, which normally asks you for a number displayed on the web site to gain access. It works really well, except that anyone who knows your email address can try to log in as you, resulting in your phone's authenticator asking you to authenticate, which is really annoying. There seems to be no way of avoiding this. There is also the danger of authenticator fatigue causing you to accidentally authenticate the login.
There is a Microsoft Q&A about this.
The second example has been happening for the past few weeks. It's similar to the Microsoft one, but this time it's Apple. For this one, you get a text message from 51472 saying, for example "Your Apple Account Code is: 123543. Don't share it with anyone". This is real, and it is from Apple. However, you then immediately get a phone call from someone claiming to represent Apple support. They then attempt to get that number from you. It's a hacking attempt and shouldn't be ignored. I would advise you to change your password in this case.
The third example is different, and probably more dangerous. In August, I got a phone call from someone who identified himself as Damian Ross, and said he was calling from the Metropolitan Police Cybersecurity Unit. He explained that I wasn't in any trouble, but they had arrested someone in London in connection with a cybercrime incident, and on a search of their hard drive my details had come up.
I was already suspicious of this, and told him so. His response was to say he could email me details to prove who he was, and to remember to check my junk mail folder. He would do this while we were still on the call.
Sure enough, the email arrived in my junk mail folder. This, of course, meant that whoever this was knew my mobile phone number and my email address - he didn't ask me for my email address on the call.
There were a few issues with the email. It did look very official, with the Metropolitan Police logo. It had a case reference number, said Damian was the officer in charge, that he was a DCI, and it included a warrant number.
However, the email was from noreply@met - not a real email address, and certainly not one used by the Metropolitan Police. In addition, if this scenario did happen for real, the Metropolitan Police would not be phoning you.
I told him he was a scammer, and he thanked me for my time and dropped the call.
"Damian" was a very good actor, and very convincing. I think his trick would work on a lot of people, and I've got no doubt that the next step would be to say that my bank account had been compromised, and that he could help to transfer my money to a "safe" account.
This means, of course, that there has been a leak at some point which revealed my phone number and email address together.
I've now had several similar calls. I use a setting on my iPhone to screen calls. If you call me, and your number isn't in my mobile's phone book, you will get an answering service asking who you are and why you are calling. Once you leave that, my phone will ring and I'll be able to read a transcript of whatever you said before deciding whether or not to answer the call. I generally block these phone numbers. It would be helpful if you could block calls where caller id has been withheld, but that isn't possible unless you block any number not in your phone book.
So, be careful out there. It really is a dangerous world we live in.


