6 ms·
Apple ID password reset exploit reportedly in the wild
- Lightning 14y agoTaken off the frontpage: https://news.ycombinator.com/item?id=5424999 https://news.ycombinator.com/item?id=5424999
- mdaniel 14y agoWhile reading this, I originally thought that the birthday aspect would reduce the attack population for such an exploit, but then I remembered that all the major social networks have birthdays (and will display it, unless the privacy settings say otherwise). I am thankful for the recent increase in 2-factor capabilities, and I encourage everyone to take advantage of them.
- Anechoic 14y agoSince my earliest days on the internet and on the web in the early 1990's, I've always been nervous when services wanted by birthdate for (AFAICT) no good reason whatsoever. Since then, I've always used proxy dates as my "birthday" (dates that are easy for me to remember, but no one else knows) for services that don't legally require my real birthday (when filling out bank/govt forms, I will use my real DOB). I'm thankful that I've done that, but of course it doesn't help when a FB friend helpfully sends me a "Happy Birthday" message on my real birthday or when my real birthday is available through so many public records. Sigh.
- joshfraser 14y agoThey ask for legal reasons. To make sure you are older than 13 due to COPPA (Children's Online Privacy Protection Act).
- lawnchair_larry 14y agoThis would be much better satisfied with a checkbox.
- wnight 14y agoYes, or further, by simply reminding you "Using the service may be illegal if ..." and letting you make the decision. If it's done this badly, and this cumbersomely, there must be a law requiring it.
- eli 14y agoNo, it's not that you could get in trouble for being under 13... it's the site that could be breaking the law by collecting data on children (without parental consent).
- xk_id 14y agoIt is still not entirely clear to me why people allow the whole Facebook wall shenanigans. I've closed mine a long time ago, exactly because I never understood why would I want to mix in one place the public, the personal, and the intimate. The very idea of blurred boundaries is not sane, it's bound to keep creating problems (like the one you describe).
- jcoder 14y agoappleid.apple.com is where you go to set up 2-factor auth.
- drbawb 14y agoOh... boy... I'm guessing the 2-factor auth is tucked away under "Password and Security." Which is hidden behind a bunch of inane "security questions" that I dreamt up years ago. Not only am I unable to setup 2-factor auth, I can't even change my password! They couldn't hide it behind an e-mail confirmation, or provide alternate options to login? Obviously it's my fault for (A) not trying to change my AppleID password in nearly 10 years, and (B) not having systems in place to prevent this sort of thing... However, this is a service that basically has unchecked access to the associated credit card account. The fact that they don't even have a "Can't remember? Contact Support" link frustrates me.
- evan_ 14y agoI just enabled two-factor auth yesterday so I can't see the interface anymore but it seemed like there was a "Just email me" backup below the questions.
- drbawb 14y agoJust checked again. I have no such option. Their support docs mention something about a "backup e-mail address", which I can't setup w/o verifying my account, which I can't verify w/o answering these questions. -___-; I'm just going to call Apple.
- lucian1900 14y agoI see no options about 2fa even though I'm in the UK. Also, it doesn't seem to support OTP and I have an Android phone (I don't always have my iPad with me). They could've done this better.
- adestefan 14y agoWhen you enable 2FA you need to register at least one Apple device or a phone numbers that can receive SMSs. After that first device is added, then you can add more devices. So you can have both your iPad and phone number registered to receive the code. After it's enabled when you try to login it shows you a list of your registered devices and phone numbers and asks where you'd like the code sent.
- ary 14y agoIt's unfortunate that (at least in my experience) Apple makes you wait 3 days to enable two-factor auth. I'm still waiting and crossing my fingers that this gets patched ASAP.
- eridius 14y agoIt already got patched. Or rather, Apple disabled password reset functionality already. In fact, the article was already updated an hour ago to say that.
- k-mcgrady 14y agoThey only make you wait 3 days if you've modified any of your information recently. From what I've seen they've also taken down the site that contained the security flaw.
- smackfu 14y agoAlthough a lot of people have weak passwords that need to be updated to enable two factor... which apparently invokes the three day wait.
- deleted 14y ago[deleted]
- jschuur 14y agoI just activated it on two accounts (including one account that didn't have an Apple device attached, so I had to use an SMS device) and it worked right away.
- foobaut 14y agoAnd... another catastrophe where the perpetrator (Apple) will go unpunished. Well at least this time the victims aren't entirely innocent, since they gave money to the evil empire.