3 ms·
In addition to the points outlined in the article, Apple is also at fault for issuing a temporary password when the caller failed to answer security questions c
by khill 14y ago
In addition to the points outlined in the article, Apple is also at fault for issuing a temporary password when the caller failed to answer security questions correctly:
From Honan's post:
"In response, Apple issued a temporary password. It did this despite the caller’s inability to answer security questions I had set up. And it did this after the hacker supplied only two pieces of information that anyone with an internet connection and a phone can discover."
Sounds like Apple support needs some lessons on social engineering prevention.
- danso 14y agoYou're right, but that is essentially Marco's point. My view is that Amazon did the same thing (let hackers add an email account, to which it sent the password reset), and required slightly less information to do so.
- crag 14y agoIt's called "human error". And it happens. A lot. I don't know how much training Apple provides to it's customer service reps (does Apple even run their own CS or is it farmed out?); but nothing can prevent "human error".
- prof_hobart 14y agoNothing can prevent human error. But systems can be set up in such a way that limits the risk of that human error causing failure. If the agent has to actually enter the answers before being able to issue a temporary password, then (assuming the author is correct) this particular problem wouldn't have happened.
- rhizome 14y ago"Human error" doesn't explain continuing the process after failing the security questions, unless by human error you mean merely that "someone did it."
- jasonlingx 14y agoIt's not human error. Their policy allowed for password resets given these 2 bits of information. Wired retried it and verified that it was indeed the case.
- sigkill 14y agoThere's this joke about hiring the cheapest security guard to watch over your most prized possession. I'm not only talking about the wages being paid to the Apple CSR, but also of their technical ability to know the value of the data they possess. Sure, if I was a facebook db admin I'd be semantically satiated with the data, but that doesn't mean it isn't important.
- mateja 14y agoI actually had a similar issue recently where I forgot my PayPal password and I didn't know the answers to my security questions. PayPal then sent me a pin through snail mail to the address they had on file. IMO, this bit of inconvenience is worth the added security.