{"id":2438,"date":"2016-09-27T02:38:34","date_gmt":"2016-09-27T06:38:34","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2438"},"modified":"2019-11-15T14:57:17","modified_gmt":"2019-11-15T11:57:17","slug":"security-questions-are-insecure","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/security-questions-are-insecure\/2438\/","title":{"rendered":"Apple ID g\u00fcvenlik sorusu nas\u0131l hacklenir"},"content":{"rendered":"<p>2012\u2019nin ba\u015flar\u0131nda bir MacBook\u2019um vard\u0131. O zaman aletler hakk\u0131nda pek bilgili de\u011fildim ve ba\u015fka bir Apple \u00fcr\u00fcn\u00fc alma plan\u0131m yoktu. Bilgisayar\u0131 \u00e7al\u0131\u015ft\u0131rd\u0131m ve Apple kimli\u011fi olu\u015fturdum. \u0130stenildi\u011fi gibi parola se\u00e7tim ve birka\u00e7 g\u00fcvenlik sorusu doldurdum.<\/p>\n<p>D\u00f6rt y\u0131l sonra, bir iPad sat\u0131n ald\u0131m. Bunun yan\u0131nda birka\u00e7 ilgi \u00e7ekici uygulama da sat\u0131n ald\u0131m (Bir k\u0131sm\u0131 i\u015f arkada\u015flar\u0131m taraf\u0131ndan \u00f6nerilmi\u015f <a href=\"https:\/\/www.kaspersky.com\/blog\/best-tablet-games-for-kids\/9985\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">listedendi<\/a>). Hesab\u0131m bana g\u00fcvensiz gelmeye ba\u015flad\u0131 ve hesab\u0131m\u0131 koruma hakk\u0131nda d\u00fc\u015f\u00fcnmeye ba\u015flad\u0131m. Bu sebeple <a href=\"https:\/\/www.kaspersky.com\/blog\/what_is_two_factor_authentication\/5036\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">iki a\u015famal\u0131 korumay\u0131<\/a> aktif etmeye karar verdim. <\/p>\n<p>Pek kolay olmad\u0131; Apple de\u011fi\u015fiklik yapmam i\u00e7in g\u00fcvenlik sekmesinde bulunan g\u00fcvenlik sorular\u0131na do\u011fru cevaplar vermem gerekiyordu. Ve benim girdi\u011fim cevaplar do\u011fru de\u011fildi. <\/p>\n<p>G\u00fcvenlik sorular\u0131n\u0131 de\u011fi\u015ftirmeye \u00e7al\u0131\u015ft\u0131\u011f\u0131mda, bu tarz i\u015fler i\u00e7in eklenilen ikinci mail adresimi onaylanmad\u0131\u011f\u0131n\u0131 g\u00f6rd\u00fcm. Apple\u2019\u0131n do\u011frulanmam\u0131\u015f mail adreslerini niye kabul etti\u011fini hala anlam\u0131\u015f de\u011filim, ama bir \u015fekilde kabul etti, ve b\u00f6ylelikle sonsuz bir d\u00f6ng\u00fc ba\u015flatt\u0131.<\/p>\n<p>Emaili Onayla  se\u00e7ene\u011fine birka\u00e7 defa t\u0131klad\u0131m ama herhangi bir onay maili alamad\u0131m. Her \u015fey ters gidiyordu. Teknik destek almak i\u00e7in de iyi bir zaman de\u011fildi, bu i\u015ften kurtulmam\u0131n tek yolu vard\u0131 \u2013 kendi g\u00fcvenlik sorumu hacklemeliydim. <\/p>\n<p><strong>Sorular\u0131 nas\u0131l hackledim <\/strong><br>\nD\u00f6rt y\u0131l \u00f6nce se\u00e7ti\u011fim soru o kadar da zor de\u011fildi. Ama cevap hakk\u0131nda d\u00fc\u015f\u00fcn\u00fcrken, \u015funu fark ettim ki \u00f6zge\u00e7mi\u015fime ya da sosyal medya hesaplar\u0131ma bakan biri cevab\u0131 ulabilirdi. <\/p>\n<p><em><br>\n-\u0130lk i\u015f yerin neresiydi? <\/em><br>\nBu sorunun do\u011fru yan\u0131t\u0131n\u0131 bulabilece\u011finiz en g\u00fczel yer LinkedIn<\/p>\n<p><em>-Annen ve baban nas\u0131l tan\u0131\u015ft\u0131?<\/em><br>\nAnnem ve babam b\u00fcy\u00fcd\u00fc, tan\u0131\u015ft\u0131 ve benim do\u011fdu\u011fum \u015fehirde evlendiler. Bir\u00e7ok insan\u0131n hayat hikayesi ayn\u0131d\u0131r. Ve bir\u00e7ok insan sosyal a\u011flara nereli oldu\u011funu yazar (Ve genellikle sosyal a\u011flar insanlardan bunu yazmas\u0131n\u0131 ister!). Bu soru da pek g\u00fcvenli de\u011fildi.<\/p>\n<p><em>-\u00c7ocuklu\u011funuzdaki favori kitab\u0131n\u0131z hangisiydi?<\/em><br>\n\u00c7ocukken birka\u00e7 favori kitab\u0131m vard\u0131 ama en olas\u0131 cevap J.R.R. Tolkien\u2019in Hobbit kitab\u0131yd\u0131. Di\u011fer sorular\u0131n cevaplar\u0131 gibi, bu da s\u0131r de\u011fil: Bir, bu kitap \u00e7ok pop\u00fcler. \u0130ki, \u00fcniversite arkada\u015flar\u0131m ve s\u0131n\u0131f arkada\u015flar\u0131m Hobbit hakk\u0131nda bir\u00e7ok yaz\u0131 yazd\u0131\u011f\u0131m\u0131, \u00f6devlerimde bahsetti\u011fimi bilirler. Hatta yar\u0131m b\u0131rakt\u0131\u011f\u0131m tezim Hobbit\u2019in Rus\u00e7a 11 terc\u00fcmesi hakk\u0131ndayd\u0131! Sonu\u00e7 olarak, cevab\u0131mla ilgili t\u00fcm hat\u0131rlamam gereken \u015fey nas\u0131l yazd\u0131\u011f\u0131m\u0131 hat\u0131rlamakt\u0131 \u2013 \u201cThe Hobbit ya da There and Back Again\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2016\/09\/06013918\/security-questions-screenshot-en.jpg\" alt=\"security-questions-screenshot-en\" width=\"1280\" height=\"800\" class=\"alignnone size-full wp-image-2440\"><\/p>\n<p>T\u00fcm cevaplar\u0131 do\u011fru biliyorsam parolalar neden e\u015fle\u015fmedi? Basit: Hesab\u0131m\u0131n anadili \u0130ngilizceydi, bunun da anlam\u0131 \u015fu, sorular \u0130ngilizce g\u00f6z\u00fck\u00fcyordu. Ama d\u00f6rt y\u0131l \u00f6nce, bu sorular Rus\u00e7ayken cevap verdim. Dili de\u011fi\u015ftirip ayn\u0131 cevaplar\u0131 yazd\u0131m, e\u015fle\u015ftiler. Ama dili de\u011fi\u015ftirmeyen insanlar i\u00e7in bile g\u00fcvenlik sorular\u0131 ger\u00e7ekten sorun olabilir: B\u00fcy\u00fck harf kulland\u0131 m\u0131, k\u0131saltma kulland\u0131 m\u0131, takma isim kulland\u0131 m\u0131.. <\/p>\n<p>\u0130yi bir g\u00fcvenlik sorusu ve cevab\u0131 nas\u0131l olmal\u0131 diye d\u00fc\u015f\u00fcnmeye ba\u015flad\u0131m. <\/p>\n<p><strong>\u0130yi bir g\u00fcvenlik sorusu nedir? Listeden soru se\u00e7meniz gerekirse, hangisini se\u00e7melisiniz? <\/strong><br>\n\u015eu <a href=\"http:\/\/goodsecurityquestions.com\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">be\u015f kriter<\/a> ile iyi soru ile k\u00f6t\u00fc soruyu birbirinden ay\u0131rabilirsiniz.<br>\n1-<strong>Anla\u015f\u0131lmazl\u0131k<\/strong> \u2013 sorunun cevab\u0131n\u0131n ara\u015ft\u0131r\u0131lmas\u0131 ya da tahmin edilmesi zor olmal\u0131. \u00d6rne\u011fin, bankalar\u0131n vazge\u00e7ilmesi \u2018annenizin k\u0131zl\u0131k soy ad\u0131\u2019 \u00e7ok k\u00f6t\u00fc bir soru. Bu sorunun cevab\u0131n\u0131 bulabilece\u011finiz binlerce yol var.<br>\n2-<strong>Tutarl\u0131l\u0131k<\/strong> \u2013 cevap zamanla de\u011fi\u015fmemeli. Bu y\u00fczden \u2018Favori\u2019 sorular\u0131n\u0131zdan vazge\u00e7in: Favori i\u015finiz, yeme\u011finiz, m\u00fczik grubunuz, filminiz, tatil yeriniz y\u0131llar i\u00e7erisinde de\u011fi\u015febilir.<br>\n3<strong>-Hat\u0131rlanabilirlik<\/strong> \u2013 parolalar\u0131m\u0131z\u0131 pek s\u0131k tekrar yazmam\u0131z gerekmez, ama g\u00fcvenlik sorular\u0131m\u0131z\u0131 \u00e7ok daha nadir kullanma durumunda kal\u0131r\u0131z. \u0130lk \u00f6\u011fretmeninizi \u015fimdilik iyi hat\u0131rl\u0131yor olabilirsiniz ancak otuzlar\u0131n\u0131zda \u2013 hatta atm\u0131\u015flar\u0131n\u0131zda \u2013 hat\u0131rlaman\u0131z \u00e7ok daha zor olabilir. M\u00fcmk\u00fcnse bir iki on y\u0131ll\u0131k zaman dilimi i\u00e7erisinde unutmayaca\u011f\u0131n\u0131z bir \u015fey olsun.<br>\n4-<strong>Basitlik<\/strong> \u2013 baz\u0131 sorular\u0131n\u0131z\u0131n birden \u00e7ok do\u011fru cevab\u0131 olabilir. \u0130lk \u00f6p\u00fcc\u00fc\u011f\u00fcn\u00fcz\u00fc nerede ald\u0131n\u0131z? Mesela New York. Do\u011fru cevap \u201dNew York\u201d, \u201cNew York City\u201d, \u201cCentral Park\u201d hatta daha farkl\u0131 bir se\u00e7enek de olabilir. Kolayl\u0131kla yan\u0131lg\u0131ya d\u00fc\u015febilece\u011finiz \u015feylerden uzak durun, birka\u00e7 \u015fekilde yan\u0131tlayabilece\u011finiz sorular\u0131 kullanmay\u0131n.<br>\n5-<strong>Se\u00e7enekli sorular<\/strong> \u2013 cevab\u0131 evet ya da hay\u0131r olan sorular son derece g\u00fcvensizdir. Sizin hakk\u0131n\u0131zda hi\u00e7bir \u015fey bilmeyen bir yabanc\u0131n\u0131n bile %50 do\u011fru cevap verme \u015fans\u0131 vard\u0131r! \u0130yi bir g\u00fcvenlik sorusuna verilebilecek sonsuz alternatif olmal\u0131 \u2013 ve siz do\u011fru cevab\u0131 bilen tek ki\u015fi olmal\u0131s\u0131n\u0131z.<br>\n<strong><br>\nSosyal medya oltalama sald\u0131r\u0131lar\u0131na dikkat edin <\/strong><br>\nEminiz sosyal medyada garip anketlere, testlere denk gelmi\u015fsinizdir. Mesela \u201cilk 7 i\u015f yeriniz\u201d ya da \u201cilk u\u00e7ak seyahatiniz\u201d. Bu tarz testlere verilen cevaplar sosyal m\u00fchendisler i\u00e7in de\u011ferli hazinelerdir. Ve bu tarz sorular\u0131n \u00e7\u0131k\u0131\u015f kaynaklar\u0131 genellikle su\u00e7lular olurlar. <\/p>\n<p><post href=\"https:\/\/www.facebook.com\/howardgr\/posts\/10153905111253178\"><\/post><\/p>\n<p>E\u011fer isterseniz en basit g\u00fcvenlik sorular\u0131n\u0131 bile tahmin edilmesi imkans\u0131z hale getirebilirsiniz \u2013 \u201cannenizin k\u0131zl\u0131k soy ad\u0131\u201d sorusuna XCU*(&amp;S1042! olarak cevap verebilirsiniz \u2013 ancak ne yazd\u0131\u011f\u0131n\u0131z\u0131 hat\u0131rlaman\u0131z gerekecektir. <\/p>\n<p>Daha iyi bir fikir olarak \u015f\u00f6yle yapabilirsiniz, annenizin k\u0131zl\u0131k soy ad\u0131n\u0131 al\u0131n. Mesela \u201c<strong>Y\u0131lmaz<\/strong>\u201c. Sesli harfleri \u00e7\u0131kart\u0131n: <strong>ylmz<\/strong>. Annenizin do\u011fum tarihini aralara serpi\u015ftirin. <strong>04y08l80mz<\/strong>. Harika bir fikir de\u011fil ama orijinalinden daha iyi bir fikir. <\/p>\n<p>Bu y\u00f6ntem, bu tarz sorulara verilebilecek en do\u011fru cevaplard\u0131r. \u00d6rne\u011fin bankan\u0131z\u0131 arad\u0131\u011f\u0131n\u0131zda annenizin k\u0131zl\u0131k soyad\u0131n\u0131 tekrarlad\u0131k\u00e7a bu kombinasyonunuzu hat\u0131rlayabilecek ve akl\u0131n\u0131zdaki bilgiyi tazeleyebileceksiniz. <\/p>\n<p>Sonu\u00e7 olarak, hesab\u0131n\u0131z\u0131 koruyabilece\u011finiz bir\u00e7ok g\u00fcvenlik y\u00f6ntemi mevcut \u2013 \u00f6rne\u011fin <a href=\"https:\/\/www.kaspersky.com\/blog\/what_is_two_factor_authentication\/5036\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">iki a\u015famal\u0131 onaylama<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>2012\u2019nin ba\u015flar\u0131nda bir MacBook\u2019um vard\u0131. O zaman aletler hakk\u0131nda pek bilgili de\u011fildim ve ba\u015fka bir Apple \u00fcr\u00fcn\u00fc alma plan\u0131m yoktu. Bilgisayar\u0131 \u00e7al\u0131\u015ft\u0131rd\u0131m ve Apple kimli\u011fi olu\u015fturdum. \u0130stenildi\u011fi gibi parola se\u00e7tim<\/p>\n","protected":false},"author":522,"featured_media":2439,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[1006,500,744,1007,686],"class_list":{"0":"post-2438","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-apple-id","9":"tag-gizlilik","10":"tag-guvenlik","11":"tag-guvenlik-sorusu","12":"tag-kisisel-veri"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/security-questions-are-insecure\/2438\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/security-questions-are-insecure\/7658\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/security-questions-are-insecure\/7660\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/security-questions-are-insecure\/7687\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/security-questions-are-insecure\/9102\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/security-questions-are-insecure\/8950\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/security-questions-are-insecure\/13004\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/security-questions-are-insecure\/6075\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/security-questions-are-insecure\/6557\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/security-questions-are-insecure\/5398\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/security-questions-are-insecure\/8723\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/security-questions-are-insecure\/12630\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/security-questions-are-insecure\/13004\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/security-questions-are-insecure\/13004\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/apple-id\/","name":"Apple ID"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/522"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2438"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2438\/revisions"}],"predecessor-version":[{"id":7140,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2438\/revisions\/7140"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2439"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}