Security hole allows Apple passwords to be reset with only email, date of birth
theverge.com
theverge.com
This had better be Apple's priority zero today.
Edit: When a critical hole is discovered in a system that manages the identity of the 400M wealthiest people on Earth, I'd expect this story to be ranking a little higher than page three on HN.
Apple has disabled password reset, so at least they've managed to control the exploit before it got out of hand.
I recently had to report my iPod stolen to the cops. It's a testament to both how often cops have to deal with stolen iDevices and how confusing the Apple homepage is, that I had to have the cop walk me through how to login to my account on the Apple homepage to get to the device information he needed.
The domains apple.com, store.apple.com, secure2.store.apple.com (which you go to after you've logged in), and iforgot.apple.com all seem to use different templates, sometimes even different metrics and external code files. I wonder how much of what seems to be a unified storefront is actually a bunch of balkanized subdomains?