3 ms·
From my point of view I believe I can be trusted to reset my Apple ID quickly. I'm very security conscious which is why unlocking my Apple ID does not unlock '
by icu 5y ago
From my point of view I believe I can be trusted to reset my Apple ID quickly. I'm very security conscious which is why unlocking my Apple ID does not unlock 'everything about me'. As I mentioned in a previous reply, I get it now... if you did trust Apple with everything about yourself, you would see the delay as reasonable security.
However, I just don't trust Apple that much because they are at the end of the day a huge corporation that couldn't give a monkey's if my data was compromised. I'm a little guy and Apple isn't going to apologise or make it right if something catastrophic happened. The Fappening is case and point. These celebrities trusted Apple and completely outsourced their security only to find their privacy violated in shocking horror.
So, I understand where you're coming from, but it's a step too far for me.
- cassonmars 5y agoThat infamous case was the result of poor password use followed by an unguarded login page with no retry limit. This isn’t meant to victim blame, but it’s to also point out Apple too was a victim on this, they have a far stronger commitment to privacy compared to other companies.
- icu 5y agoSure, but these celebrities completely outsourced their security to Apple because they trusted Apple. "Apple knows best"... but clearly not because Apple should have had rate limiting for password login attempts to stop password brute-forcing attacks. As for the far stronger commitment to privacy, I'm not so sure. Apple seems reluctant at times to patch zero-days which has been covered on the front page of HN.
- Godel_unicode 5y ago>... rate limiting for password login attempts... Good news then I suppose. They did, that's not what happened. People abused password reset, with the canonical example being Paris Hilton using her dog's name as a security question.
- deleted 5y ago[deleted]
- bigiain 5y ago> From my point of view I believe I can be trusted to reset my Apple ID quickly. A different, devil’s advocate perspective, might be that if you forgot you Apple ID credentials, you should not be trusted to reset your Apple ID. I have passwords from 15+ years ago in my password safe. I have never needed to reset my Apple ID. The other thing to consider, is whether you’d be happy for an attacker to reset your Apple ID quickly. Apple lose a lot of credibility when iCloud started raining celebrity nudes to 4chan. They care less about you specifically as a user than they do about whole classes of users who’re much more likely to be phished and social engineered than you believe yourself to be…
- icu 5y agoAs mentioned previously, the last Apple product I purchased was the iPad Gen 1 (2010). However, my security consciousness changed post Snowden (2013) and I devoted time and effort to study and implement strong infosec. This was about when I stopped using my Apple ID (so I'd estimate it's been about 8 years). That said, bragging that you haven't changed your passwords from 15+ years ago, even if they are securely stored, makes me question how serious you take your security. I change my passwords regularly, and it's accepted that this is best practice. As to your comment about an attacker being able to reset my password quickly, I think I should be given the option to if I wanted, or be allowed to provide KYC like passport or driving licence to fast track it. If I was a celebrity I might want to opt in to 'slow track' plus KYC verification. My point is about not having the option because it's Apple's way or the highway.
- Godel_unicode 5y ago> it's accepted that this is best practice It is absolutely not, and hasn't been for several years (source; I'm on the industry panel for many security standards). Every serious security standard (NIST, DoD, GCHQ, etc) say that choosing a strong password is important, but that periodically changing it brings at best no benefit. The overwhelming consensus in security is that using strong cryptographic secrets is the only really secure way to authenticate. Buy some kind of the tamper evident secret store and get on with your life. If you allow people to opt-out of security, they will do so and then scream when there's a breach that they made inevitable. Look at the discussion around HSTS for as many examples of this as you please; users cannot be trusted with their own security, they will at best leverage outdated and badly wrong guidance from years ago. More often, they will choose Summer2021 as a password and 000000 as a pin.
- lotsofpulp 5y ago> The Fappening is case and point. These celebrities trusted Apple and completely outsourced their security only to find their privacy violated in shocking horror. The fappening happened because people got spearphished into sending others their account passwords. That jump started the 2FA push, but there is not much a company can do if you willingly give your authentication details to someone else. If anything, the fact that apple does not allow passwords to be reset haphazardly and makes you wait 7 days means they go out of their way to prevent regular people from being victims, possibly a result of the fappening.
- deleted 5y ago[deleted]