Archive for the 'Security' Category

The Pathetic Story of How To Hack a .Mac Account

Wednesday, July 9th, 2008

I came across this posting today: Apple just gave out my Apple ID password because somone asked. So with all the hype about how OS X is so great and secure, what happens when the problem is with Apple corporate itself?

Here’s an excerpt from the post:

I tried to log in to Apple Developer Connection this morning to find out that my password had been changed and the email associated with my account was now a yahoo.com address that wasn’t mine. Luckily, my “security question” was still the same, so I was able to reset the password and email address back.

Based on the emails that have appeared in my .Mac mailbox, this was accomplished by sending this classy one-liner to Apple:

am forget my password of mac,did you give me password on new email marko.[redacted]@yahoo.com

So a little crude social engineering to compromise your data. I’ve had and heard issues about Apple’s lack of a privacy policy, data destruction, and how they will handle repairs of their computers. But this is pretty bad.

I was a bit leary when I had to drop of my MacBook for repair and the guy asked me for my password that he proceeded to type into his “genius” computer. I was also concerned about what they would do with the backup they made of my hard drive. While I had no problems, it is apparent that the system is not setup to protect you. I remember dealing with Dell and Gateway, they’d ask you to remove your hard disk before sending in a laptop for repair.

Does anyone else have any Apple stories like this?

iTunes, Security, Airport, Safari, iPhone updates from Apple

Friday, August 3rd, 2007

Safari 3.0.3/Security update 2007-007: http://www.macrumors.com/2007/08/01/security-update-2007-007-safari-3-0-3/

iTunes 7.3.2: http://www.macrumors.com/2007/08/02/apple-releases-itunes-7-3-2/

iPhone Update 1.0.1: http://www.macrumors.com/2007/07/31/security-update-2007-007-iphone-update-1-0-1-released/

Airport Extreme Update 2007-004: http://www.macrumors.com/2007/07/31/airport-extreme-update-2007-004/

Mac OS 10.4.11 seeded to developers!

Friday, August 3rd, 2007

Yay, it’s official! There will be a 10.4.11 update for Tiger! Here’s the news article, which lists some fixes in the next release:

http://www.macrumors.com/2007/08/01/apple-seeds-mac-os-x-10-4-11-8s2138-8s138/

Anti-Theft from Apple

Thursday, July 26th, 2007

Nothing announced or official from Apple.  I think some clever anti-theft protection from Apple is long overdue.

“The patent, titled “Protecting electronic devices from extended unauthorized use,” outlines a technique that would allow a particular device to authenticate itself with certain, user-approved power supplies and devices so that it can only be charged by those devices.”

Full article, Apple anti-theft system would leave thieves powerless—literally, at Ars Technica.