Major security hole allows Apple passwords to be reset


Recommended Posts

Apple yesterday rolled out two-step verification, a security measure that promises to further shield Apple ID and iCloud accounts from being hijacked. Unfortunately, today a new exploit has been discovered that affects all customers who haven't yet enabled the new feature. It allows anyone with your email address and date of birth to reset your password ? using Apple's own tools. We've been made aware of a step-by-step tutorial (which remains available as of this writing) that explains in detail how to take advantage of the vulnerability. The exploit involves pasting in a modified URL while answering the DOB security question on Apple's iForgot page. It's a process just about anyone could manage, and The Verge has confirmed the glaring security hole firsthand. Out of security concerns, we will not be linking to the website in question.

Needless to say, if you haven't enabled two-step verification for your Apple account, we urge you to waste no time in doing so. You can start the process here. Apple has also set up an FAQ page for any questions you may have. We've reached out to the company and will update this post accordingly upon the company's reply.

http://www.theverge.com/2013/3/22/4136242/major-security-hole-allows-apple-id-passwords-reset-with-email-date-of-birth

oh snap... :pinch:

update: "We've had a little more time to explore the hack and have yet more bad news to report. Yesterday a number of users were told they'd need to wait three days before enabling two-step verification. As a result, these accounts are fully vulnerable to the exploit. As of right now, the only surefire way these individuals can avoid the security threat is by change their birthdate on Apple's account settings page. This option is located at the bottom of "Password and Security.""

This topic is now closed to further replies.
  • Posts

    • PowerToys is getting a new window management utility by Taras Buria If you use PowerToys on Windows 11 or 10, you probably know that the app has quite a few utilities for window management. Fancy Zones, Always on Top, Crop and Lock, just to name a few. Soon, Microsoft will add another one, and fans of Alt + Tab should be excited. Proposed by Clint Rutkas, the module has a very simple idea: use a keyboard shortcut to toggle between windows within one app. For example, if you have four browser windows open, Alt + ` will let you switch between them just like Alt + Tab switches between all running apps. Here is the utility description from its GitHub pull request: Like other PowerToys utilities, Alt Window Cycle will offer shortcut customization. You will be able to use default shortcuts (Alt + ` for the next window or Alt + Shift + ` for the previous one) or remap them to something else. For now, there is no information on when Alt Window Cycle will arrive, so we will have to wait for the next PowerToys feature update (Microsoft usually pushes them on a monthly basis). Recently, Microsoft released version 0.100, which reworked the shortcuts guide, introduced an extension gallery for Command Palette, and more. Shortly after, version 0.100.1 arrived as a bug-fixing update. PowerToys is available on Windows 10 and 11, and you can get the app from the official GitHub repository, the Microsoft Store, or winget. Although Windows 10 is no longer supported, PowerToys developers currently do not plan to drop the now-unsupported operating system. And with Microsoft giving Windows 10 one more year in the Extended Security Update, you can expect PowerToys to remain available on Windows 10 for quite a while.
    • This is sadly what happens when a company tries to become political and focus on agendas outside gaming, the constant push of inclusivity and whatever the current thing was and box ticking, instead of simply focusing on what was a great game to many myself included, massive let down that a once great game company has ended up this way hopefully this will be a lesson to game devs from here on in to leave politics and agendas out of gaming
    • Prices for consumer electronic stink and will continue to stink for quite some time. If you're at all hesitant, just buy now because it's not getting better. (or buy used and save even more cash)
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      409
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      132
    4. 4
      Xenon
      73
    5. 5
      Michael Scrip
      73
  • Tell a friend

    Love Neowin? Tell a friend!