Exploit Allows Users to Continue to Compromise Apple Users' Passwords
March 22, 2013 3:32 PM
comment(s) - last by
All that's needed to reset a password is a user's AppleID, date of birth, and email
Apple, Inc. (
), a company
infamous for weak security
brazen arrogance regarding its safety
, has been in the spotlight for the wrong reasons of late. Its policies last year allowed
a huge hack
on Gizmodo blogger and prize-winning journalist Mat Honan, whose Apple accounts were compromised via lax password recovery features.
The hack caused Apple to embark on
a series of security changes
, which made it harder for remote users to retrieve a password that possibly wasn't theirs. The latest step was to install two-step verification, a new process that sends a code to your device.
Apple began rolling out the new two-step authentication (
users' Apple IDs
this week. Users can
Apple's 2-step ID verification.
But unfortunately Apple's own "
" tool remains online, which allows you to reset a user's password that hasn't upgraded to enable two-step validation. All that is needed is a user's Apple ID, email, and date of birth (the Apple ID arguably being the hardest to obtain, but potentially gained through phishing or other methods).
If you have a list of a person's past addresses (freely available via a variety of private investigator databases), you can get a user's Apple ID via a secondary recovery form on the page.
Use the first and last name, plus past addresses to recover the AppleId.
Use the email, recovered AppleID, and birth date to reset the password.
[Image Source: 9 to 5 Mac]
The exploit was
9 to 5 Mac
with the above description of the exploit, pointing curious folks on where to go to try it out.
In an update
reveals more bad news. The site's Chris Welch writes:
Yesterday a number of users were told they'd need to wait three days before enabling two-step verification. As a result, these accounts are fully vulnerable to the exploit. As of right now, the only surefire way these individuals can avoid the security threat is by change their birthdate on Apple's account settings page.
Changing your birthdate to a fake date would stymie users who snagged your birthdate from various public databases or social media sites like Facebook, Inc. (
9 to 5 Mac
This article is over a month old, voting and posting comments is disabled
RE: Sigh...here we go again
3/25/2013 6:16:37 AM
Its a lot of opinion when it comes down to it. I put up with Android for years and got tired of waiting for its numerous problems to get fixed. Your list of features that can be found in the cheapest devices isn't convincing, and for me it isn't worth the tradeoffs. You either don't really use your phone very much or you have very low standards.
I've been coming to AT since 1999, pretty old school. You don't need to be here long though to see that AT is extremely balanced while DT isn't. Of course you see no reason for DT to change, you eat it all up while pretending to be disappointed in an attempt to look fair.
You are right that I am visiting the wrong site. Maybe AT will remove it from the sidebar someday.
RE: Sigh...here we go again
3/25/2013 8:20:10 AM
I meant I saw no reason for me to change sites, I visit through Anandtech as well. I agree DT has gone downhill and has pretty much become the tech equivalent of tabloid journalism... But much of the news is still news.
"We shipped it on Saturday. Then on Sunday, we rested." -- Steve Jobs on the iPad launch
Apple, Amazon Change Security Policies After Hack Attack on Journalist
August 8, 2012, 12:00 PM
Apple, Amazon's Weak Security Allows Huge Hack of Gizmodo Reporter
August 7, 2012, 12:28 PM
Apple to Update iTunes with iCloud Integration, Music Sharing
June 28, 2012, 5:07 PM
Kaspersky Labs: Apple's Security 10 Years Behind Microsoft
April 26, 2012, 7:39 AM
Mac Gets The Girl In New Anti-Microsoft Ad
May 13, 2009, 9:33 AM
Report: Apple to Unveil "iWatch" at iPhone 6 Event on September 9
August 27, 2014, 2:00 PM
Reports: Snapchat is Now Worth $10B, Cofounders are Billionaires to Be
August 27, 2014, 9:30 AM
Tim Cook Says iPad Sales Have Merely Hit a Temporary “Speed Bump”
August 27, 2014, 9:16 AM
ZOTAC Announces Diminutive ZBOX PI320 pico
August 27, 2014, 9:00 AM
Verizon Wireless' VoLTE Service Tiptoes Closer to Launch
August 26, 2014, 3:21 PM
5.5” LG G3 Stylus to Make Its Debut at IFA 2014, Will Feature Budget Specs/Pricing
August 26, 2014, 9:00 AM
Most Popular Articles
New Photos Show “Assembled” iPhone 6, Protruding Camera Ring
August 20, 2014, 2:32 PM
Leaked Qualcomm Roadmap: 20 nm 64-bit Octacore Smartphone SoCs Cometh
August 20, 2014, 11:38 AM
Microsoft's Surface 2 Tablet Family Gets a $100 Price Cut
August 25, 2014, 1:16 AM
Report: Microsoft to Announce Windows 9 on September 30
August 21, 2014, 11:20 AM
From HULC to FORTIS: the Evolution of Lockheed Martin's Incredible Exosuit
August 22, 2014, 12:45 PM
Latest Blog Posts
Space Terrorism is a Looming Threat For the United States
Apr 23, 2014, 7:47 PM
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information