> "None of the cases we have investigated has resulted from any breach in any of Apple’s systems"
Don't these lines contradict each other?
> "None of the cases we have investigated has resulted from any breach in any of Apple’s systems"
Don't these lines contradict each other?
I think the issue is that the previously posted Find My Iphone code didn't rate limit invalid logins and this was used to bruteforce creds. This is probably the real underlying issue and not any type of buffer overflow / exploit etc.
Systems aren't just technical (software), they involve human beings, feedback loops, interactions, etc. Apple's security systems are in fact weak, just not weaker than the norm.
Actually I think the Apple press release was poorly worded. This in particular:
>None of the cases we have investigated has resulted from any breach in any of Apple’s systems
There was indeed a breach in Apple's system, there just wasn't a system wide breach that compromised all accounts, just a select few.