Apple ID password reset exploit reportedly in the wild
news.cnet.com
news.cnet.com
I am thankful for the recent increase in 2-factor capabilities, and I encourage everyone to take advantage of them.
I'm thankful that I've done that, but of course it doesn't help when a FB friend helpfully sends me a "Happy Birthday" message on my real birthday or when my real birthday is available through so many public records. Sigh.
If it's done this badly, and this cumbersomely, there must be a law requiring it.
I'm guessing the 2-factor auth is tucked away under "Password and Security."
Which is hidden behind a bunch of inane "security questions" that I dreamt up years ago.
Not only am I unable to setup 2-factor auth, I can't even change my password!
They couldn't hide it behind an e-mail confirmation, or provide alternate options to login?
Obviously it's my fault for (A) not trying to change my AppleID password in nearly 10 years, and (B) not having systems in place to prevent this sort of thing... However, this is a service that basically has unchecked access to the associated credit card account. The fact that they don't even have a "Can't remember? Contact Support" link frustrates me.
I have no such option.
Their support docs mention something about a "backup e-mail address", which I can't setup w/o verifying my account, which I can't verify w/o answering these questions.
-___-; I'm just going to call Apple.
They could've done this better.
After it's enabled when you try to login it shows you a list of your registered devices and phone numbers and asks where you'd like the code sent.
So I guess I'll just be exposed to this for 3 days because Apple.