3 ms·
My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found m
by level 12y ago
My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found more personal information and iCloud accounts by going the contacts of each person they compromised.
That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't hard to do anymore.
- leephillips 12y agoI always put in made-up or nonsense information for the answers to the security questions, and store it all in the same encrypted file with my passwords. Seems more secure than using correct information that would not be hard for an attacker to discover. ("Then how will you get password recovery?" "I will never need that.")
- arrrg 12y agoI think it‘s quite easy to argue that when accounts are compromised because of security questions whoever implemented those questions is at fault. They are a convenient, if crap way to secure accounts. Apple and everyone else have to do better. (I suppose the good news is that you can actually protect yourself from this. However, how to protect themselves won’t reach most people, so in the big picture this is cold comfort. I do think it’s the job of the platform owner to make sure that users cannot easily leave themselves open to attacks. Most people don’t know about security, the platform owner does.)