Update: In a separate report, Wired notes Amazon has also modified its security policies and will no longer be accepting over-the-phone account changes.
According to an unnamed Apple employee familiar with the matter, the call-based password reset freeze will remain in effect for at least 24 hours and speculated the ban is meant to give Apple time to assess the situation, reports Wired.
The publication corroborated the tip with an AppleCare representative while trying to replicate the security exploit that allowed hackers access to Honan's iCloud, Twitter and Gmail accounts. Wired's most recent attempt failed, the representative said, because Apple had initiated system-wide "maintanence updates" which put a halt to changing AppleID passwords over the phone.
âRight now, our system does not allow us to reset passwords,â the AppleCare representative said. âI donât know why.â
On Friday, Honan's iCloud account was compromised, with hackers wiping data from his MacBook, iPad and iPhone and locking him out of other internet services. It was discovered later that the hackers' goal was to gain access to Honan's unique @mat Twitter feed.
Wired writer Mat Honan. | Source: Wired
The hackers allegedly used a combination of Amazon's credit card record keeping system, Apple's user authentication requirements and "social engineering" to gain entry into Honan's iCloud account.
"On Monday, we were able to call Apple, reset AppleID passwords over the phone, and gain access to iCloud accounts by supplying AppleCare representatives with a name, e-mail address, mailing address and the last four digits of a credit card number linked to an AppleID," Wired writes. "This is the exact same information hackers supplied Apple with on Friday to get a temporary password that gave them access to Honanâs iCloud account."
Because Honan's accounts were all tied together with credit card numbers and redundant email addresses, the hackers didn't have a hard time skirting existing security measures.
Apple released a statement on Monday, saying âwe found that our own internal policies were not followed completely.â The internal source, however, notes that if the Apple rep issued a temporary password based on the hacker-supplied AppleID, physical address and last four credit card digits, they would have "absolutely" been operating within Apple's instituted guidelines.
10 Comments
Amazon flinched too http://www.theverge.com/2012/8/7/3226322/amazon-security-phone-account-changes
So both services are basically saying if you forget your password, securit questions and don't keep your email address current you are screwed. In a way that is really foul customer service, but on the other, if they make this situation very very clear to all customers then it's not their fault if someone doesn't keep things accurate and current
[quote name="charlituna" url="/t/151802/apple-reportedly-puts-hold-on-over-the-phone-password-resets-in-response-to-hack-u#post_2164195"]So both services are basically saying if you forget your password, securit questions and don't keep your email address current you are screwed. In a way that is really foul customer service, but on the other, if they make this situation very very clear to all customers then it's not their fault if someone doesn't keep things accurate and current[/quote] I prefer to view it as, "We can't fix stupid." Store your credit card online at your own risk. Link account info at your own risk. Use common passwords at your own risk. Use cookies at your own risk. I've used Solip's Razor for a long time - to paraphrase - "Use false info for verification and recovery data" - as it is hard to guess lies.... Just keep track of them. I use the msecure app to securely keep track of the fibs.
Hell I have a tough enough time keeping track of the truth. For instance I've had security questions about what my first car was. Now I have to figure out if I answered with the make, the model or both. Ask me what my grandfathers name was. Did I put the full version or the shortened nick name version of his name. Thing is you have to be exact. I could get a question about what my name is wrong. If I say Joe and the computer has Joseph, I just failed that question.
I've used Solip's Razor for a long time - to paraphrase - "Use false info for verification and recovery data" - as it is hard to guess lies.... Just keep track of them. I use the msecure app to securely keep track of the fibs.
Forgot to include this quote in my post.