MacUpdate Weekend Sale :This weekend MacUpdate has slashed prices on Painter 12 and Painter Lite. Painter 12 retails for $429, but has been reduced by 54% to $199. Painter Lite has seen a 58% price cut from $69 to $29. Hurry, because these deals are only available until May 19th 2013.      
toggle

AAPL Stock: 433.26 ( -1.32 )

http://www.macnn.com/articles/12/08/08/move.comes.after.wired.reporter.hacked.ios.osx.devices.wiped/

Temporary ban placed on phone AppleID password resets

updated 02:10 am EDT, Wed August 8, 2012

 

Move comes after Wired reporter hacked; iOS, OSX devices wiped


On Tuesday, Apple ordered its telephone support staff to immediately cease AppleID password changes requests. The likely temporary change in procedure comes following the Wired reporter Mat Honan's identity hack over the weekend, resulting in completely deleted MacBook, iPad, iPhone, and GMail accounts as a result of an attacker tricking an AppleCare rep into resetting Honan's iCloud password, which started a chain of password reset procedures to access the next system, culminating in the reporter's Twitter accounts.

An Apple employee told Wired that the phone support password procedure change would last at least 24 hours, but MacNN was told that the block would be in place "as long as it takes" to update Apple's policies and procedures to prevent another event like the weekend's hack from taking place. The change follows changes to Amazon's security routine, which previously allowed hackers to gain control of an Amazon account as long as the name, email address, and mailing address was known.

Wired was attempting to recreate the events of the weekend hack when the block was discovered. The attempt failed, and the phone representative said that the company was undergoing "maintenance upgrades" that prevented password resets over the phone. The phone support technician directed all password reset requests to iforgot.apple.com. In a telephone conversation with support supervisors MacNN has discovered that the final identity verification procedure after the expiration of the temporary ban on phone password resets was "in discussion" at the executive level of Apple support.

Honan said he has confirmed with both Apple and the hacker that victimized him that his iCloud account was compromised by a "social engineering" trick with AppleCare. The hacker managed to get an AppleCare support staffer to skip security questions by providing information from Amazon, and then reset Honan's password, giving the hacker complete access to anything tied to Honan's iCloud account or email address. This included not only personal and Gizmodo Twitter accounts, but also Honan's GMail account, which was completely deleted.

The Find My iPhone app in the iOS sports a device erase feature and was used to perform remote wipes of Honan's Mac, iPhone, and iPad following iCloud seizure by the hacker. Apple admits to a failure to follow normal support procedures and rules which resulted in the hack.


by MacNN Staff

toggle

Comments

  1. hayesk

    Professional Poster

    Joined: 09-17-99

    The right thing to do is stick to the policy of requiring the user to answer the security questions before resetting the password. And if the security questions have been changed recently, then don't reset the password unless the caller can answer the old questions.

  1. blahblahbber

    Banned

    Joined: 02-01-05

    Originally Posted by hayeskView Post

    The right thing to do is stick to the policy of requiring the user to answer the security questions before resetting the password. And if the security questions have been changed recently, then don't reset the password unless the caller can answer the old questions.

    Let see how Apple deals with this blow once it resumes.... Maybe, just maybe we'll see a "We F'ed up" page. That would be honorable.

  1. Spheric Harlot

    Clinically Insane

    Joined: 11-07-99

    Originally Posted by blahblahbberView Post

    [QUOTE=hayesk;4182584]The right thing to do is stick to the policy of requiring the user to answer the security questions before resetting the password. And if the security questions have been changed recently, then don't reset the password unless the caller can answer the old questions.

    Let see how Apple deals with this blow once it resumes.... Maybe, just maybe we'll see a "We F'ed up" page. That would be honorable.[/quote]
    I’m pretty sure they’ve done the honorable thing and been in contact with everybody affected by this violation of internal guidelines…you know, that one guy…the journalist...

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

MacNN Sponsor

Recent Reviews

Brother HL-3170CDW LED Printer

We've mentioned before that we are far from a paperless society. For now, at least, there are tasks that require a piece of paper for ...

HTC One

It is hard to overstate just how critically important the HTC One is to the Taiwanese company’s fortunes. Despite its alarming decline ...

Samsung Galaxy S 4

Samsung's new flagship Android smartphone, the Galaxy S 4, faces even stiffer competition than its popular predecessor. With a five-in ...

toggle

Most Commented