Mac freezes over-the-phone password resets mainly because Honan hack (Updated).
An anonymous Apple employee confirmed Wired tonight that these people putting a 24-hour secure on over-the-phone password verification—a within Apple ID security that to cost Wired reporter Pad Honan an iPhone, ipad tablet, MacBook, several e-mail satisfied clientele, and two Twitter accounts worth of information over the weekend.
The hacker could take control of Honan’s range of Apple devices after gaining access to Honan’s iCloud and.Me account the password change made with the help of Apple tech support, as soon as hacker gave the rep Honan’s personal information, the last four digits of cards number, and the parallel billing address, which their hacker gleaned from Rain forest tech support. Earlier in a little while, Amazon said it would cease to allow customers to options and change account and also e-mail settings.
Yesterday, Apple publicly maintained while this nothing was wrong it’s security policies.”In this kind of is case, the customer’s data was compromised by a person that had acquired personal find out about the customer, ” Apple said in a statement.”In addition, we found that our own internal policies just weren’t followed completely.We are reviewing all of our processes for resetting account passwords to ascertain our customers�? data is included.”
But today, Wired’s Apple source told me that a 24-hour freeze on password resets is at effect at Apple VERY GOOD.The source “speculated that your freeze was establish to give Apple more time to see which security policies needed changing, if any, ” Interconnected reported.Wired confirmed the information if you try (and failing) to reset a password on the telephone with a customer ceremony representative.
“Right at the, our system does not allow us reset passwords, ” possibly the Apple rep told Involved.”I don’t know so , why.” Another Apple customer maintenance representative told Wired that passwords is able to be changed on the telephone if the user can also provide the serial number connected to a device that used password.
While Apple has claimed that it is “internal policies” would have prevented this particular attack had those policies been followed however letter, the new information suggests Apple is not completely sure that it could be security is beyond censure. For the proactive:check out Ars reporter Sean Gallagher’s post on auditing your internet security.
Update:Apple has now demonstrated to the New York Times like it has indeed stopped doing password resets on the telephone.
.
Category: Security

