Print 43 comment(s) - last by MaulBall789.. on Mar 29 at 9:56 AM

All that's needed to reset a password is a user's AppleID, date of birth, and email

Apple, Inc. (AAPL), a company infamous for weak security and brazen arrogance regarding its safety, has been in the spotlight for the wrong reasons of late.  Its policies last year allowed a huge hack on Gizmodo blogger and prize-winning journalist Mat Honan, whose Apple accounts were compromised via lax password recovery features.  

The hack caused Apple to embark on a series of security changes, which made it harder for remote users to retrieve a password that possibly wasn't theirs.  The latest step was to install two-step verification, a new process that sends a code to your device.

Apple began rolling out the new two-step authentication (FAQ) for users' Apple IDs this week.  Users can go here to apply.

Apple two step
Apple's 2-step ID verification.

But unfortunately Apple's own "iForgot" tool remains online, which allows you to reset a user's password that hasn't upgraded to enable two-step validation.  All that is needed is a user's Apple ID, email, and date of birth (the Apple ID arguably being the hardest to obtain, but potentially gained through phishing or other methods).  

If you have a list of a person's past addresses (freely available via a variety of private investigator databases), you can get a user's Apple ID via a secondary recovery form on the page.

Step 1: Use the first and last name, plus past addresses to recover the AppleId.

Step 2: Use the email, recovered AppleID, and birth date to reset the password.
[Image Source: 9 to 5 Mac]

The exploit was first reported/validated on by The Verge.  9 to 5 Mac went live with the above description of the exploit, pointing curious folks on where to go to try it out.

In an update The Verge reveals more bad news.  The site's Chris Welch writes:

Yesterday a number of users were told they'd need to wait three days before enabling two-step verification. As a result, these accounts are fully vulnerable to the exploit. As of right now, the only surefire way these individuals can avoid the security threat is by change their birthdate on Apple's account settings page.

Changing your birthdate to a fake date would stymie users who snagged your birthdate from various public databases or social media sites like Facebook, Inc. (FB).

Sources: Apple, 9 to 5 Mac, The Verge

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

RE: we go again
By ppardee on 3/22/2013 6:40:43 PM , Rating: 3
Not like normal people and MSNBC?

When people bash Fox News, it says two damning things about them. 1) They are mental slaves to the progressive party (which is slowly eating the Democrat party), and 2) they are so naive that they believe that Fox News is the only media outlet that has a political agenda.

EVERY media outlet spins the truth to try to get you to believe what they want. DT has an agenda, too. Looking at Tiffany's AGW stories will tell you that. But when it comes to Apple, DT calls a spade a spade. Apple has some good products and ideas (or so I'm told), but they also make some dumb moves. Ignoring security is one. They will report on the good and the bad.

It has been said in the past that PCs are like houses with bars on the windows in the bad part of town and Apples are like houses out in the country with no locks on the doors. Crime has come to the country and Apple still can't figure out they have to lock their stuff up. They WON'T until it hurts their bottom line.

Does your mom let you get away with stealing a candy bar because your friend stole a whole box of them? Apple is at fault for their security holes. Amazon's lax security does not excuse Apple's refusal to put proper time into risk mitigation.

RE: we go again
By ppardee on 3/22/2013 6:41:45 PM , Rating: 1
Sorry, I shouldn't bash Tiffany. She has gotten a lot better at being objective lately.

RE: we go again
By Shadowself on 3/22/2013 7:30:20 PM , Rating: 5
When people bash Fox News, it says two damning things about them.
Not necessarily. It could just be that they don't like extremism in their reporting. "Fair and balanced" is neither fair nor balanced if you have to dredge up pure crap to show "the other side". If you consider a radical-liberal-moderate-conservative-reactionary scale from 0 to 100 in that order, I'd consider most media in the 35 to 45 range. Fox news sits squarely in the 80+ range. Fox executives have repeatedly gone on the record over the years stating this simple fact very clearly. If you're into that range and want information that strongly supports that position, Fox is the perfect source for you. However, don't suggest that anyone who thinks Fox news is blatantly biased is naive about media agendas.

But when it comes to Apple, DT calls a spade a spade.
Absolutely not true. A couple of the authors on DT have a very clear anti Apple agenda and rarely refrain from pursuing it -- from inaccurate headlines to telling only half the story to not bothering to learn what reality is.

Apple has some good products and ideas (or so I'm told), but they also make some dumb moves. Ignoring security is one.
Absolutely true. Apple has done some truly stupid things. Remember the hockey puck mouse? It was equivalent in its stupidity, in my opinion, to Microsoft's Bob. Most people never heard of the horror stories of Apple's design years ago for one of its PowerMac systems that was designed so badly that it was virtually impossible to upgrade the RAM without losing some skin from your fingers. Blood on the motherboard--now that's intelligent design work! And even today, Apple has not fixed the stupidity of how iOS integrates with PCs or even Macs to merge contact data -- it's been bad since the first iPhone and Apple still has not fixed it. The list goes on and on and on.

However, in this case Apple is not ignoring security. They're just taking, at least in my personal opinion, a much, much to lax approach to implementing it. Is the approach any worse than Google or many other online systems? No, in fact in many cases it is the exact same approach. However, as I mentioned above, Apple setting up a security system that can take up to three days to take effect is truly asinine. Someone should be fired for setting up such a lame implementation scheme, but I doubt they will.

They will report on the good and the bad. [with regard to Apple]
When was the last time that DT reported a simple positive story about Apple or its products without some negative comment or spin thrown in on the side. Similarly, out of the last five years of reporting, what percentage of stories on DT that had Apple mentioned in them had something bad to say about Apple? If you only read the DT stories (and ignored the posts by readers) you'd think Apple was one of the most morally corrupt company on the planet; you'd think Apple had (and has) the worst design staff on the planet.

RE: we go again
By Reclaimer77 on 3/22/2013 7:58:38 PM , Rating: 1
I love it when someone bashes Fox. It allows me to instantly dismiss them as a Liberal, and therefor an idiot, without ever having to find out through a lengthy and frustrating discussion.

Especially those who mimic the populist "Faux" misnomer. Right off the bat tells you he's not only a Liberal moron, but a poser lacking critical thinking. How many of these people actually viewed Fox themselves and formed their own opinion? Very few. Which makes them weak minded.

RE: we go again
By superflex on 3/23/2013 10:44:38 AM , Rating: 2
The bashers of Fox News missed the Pew Research study which found MSNBC was 85% opinion and 15% actual news compared to Fox's 55% opinion and 45% news.
Oh, the horror.

RE: we go again
By Armageddonite on 3/23/2013 11:53:46 AM , Rating: 5
Someone else doing wrong does not redeem one's own misdeeds...a lesson that many devotees of conservative media ignore. Even if someone else is more wrong than you, that doesn't make you right.

That said, I totally ignore Fox News and MSNBC to an equal degree, also the Huffington Post and the Drudge Report, etc. When it comes to news I try to find the most objective perspective available. I rotate between Reuters, CNN and BBC News, and I waste no time on opinion pieces. When it comes to partisan pandering, it's a waste of time...the people who believe it already agree, and the people who don't believe it just ignore it.

RE: we go again
By gmyx on 3/25/13, Rating: 0
"There is a single light of science, and to brighten it anywhere is to brighten it everywhere." -- Isaac Asimov

Latest Headlines
Inspiron Laptops & 2-in-1 PCs
September 25, 2016, 9:00 AM
The Samsung Galaxy S7
September 14, 2016, 6:00 AM
Apple Watch 2 – Coming September 7th
September 3, 2016, 6:30 AM
Apple says “See you on the 7th.”
September 1, 2016, 6:30 AM

Most Popular Articles5 Cases for iPhone 7 and 7 iPhone Plus
September 18, 2016, 10:08 AM
Laptop or Tablet - Which Do You Prefer?
September 20, 2016, 6:32 AM
Update: Samsung Exchange Program Now in Progress
September 20, 2016, 5:30 AM
Smartphone Screen Protectors – What To Look For
September 21, 2016, 9:33 AM
Walmart may get "Robot Shopping Carts?"
September 17, 2016, 6:01 AM

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki