180 karma · joined August 20, 2015
Very fun to do on that friend.com website, as well.
That said...scummy move by Apple. They tend to be a little more thoughtful in their refresh schedule, so I was caught off guard.
I loved this piece; sometimes I think of reviewing past memories as akin to rewatching a familiar show. There are no surprises, so even the hardest plot-twists have less anxiety associated with them.
Point people to an alternative. Not just in the vague direction of The Lemmiverse or Squabbles or whatever; if your sub is going dark, you should have somewhere to receive all your refugees.
Even better if the mods coordinate so that all subs are pointing to the same place(s).
Even a shared Discord would have been a big step up imo.
This protest was just gone about the wrong way.
That was a rough day.
Isn't that alone sufficient to demonstrate complete iCloud account takeover?
Agreed that this should not be taken as proof that the other reset flow was not vulnerable, but to me it seems like two separate issues.
However, the first half of the article focuses on him successfully being able to reset the password on any iCloud account that hadn't been used to log in to an Apple device.
Being able to remotely change the password of an iCloud account should earn him the full $100,000 reward, even if it is only on some subset of iCloud accounts.
An SEO consultant walks into a bar, pub, speakeasy, drinking hall, club.
Other than that, just some bespoke Tasker automations and some hotkeys on my computer. Reading through this thread makes me feel like a rookie, though.