Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
Sign in. It’s quick, free and it’s up to you.
An account is an optional way to support the work we do. Find out more.
A SECURITY FLAW on iCloud has been patched after the creator of a hacking tool claimed it could bypass its security.
iDict, which was released on New Year’s Day, claimed it could exploit a flaw in Apple’s security and guess a user’s password repeatedly.
As a way of preventing brute force attacks, sites allow a certain number of attempts for logins until it locks someone out, but the maker of iDict claimed its tool bypassed this.
By using a list of commonly used passwords, it would be able to keep guessing until it hit the right one. Its creator, @pr0x13, claimed they had released the tool publically “so Apple will patch it,” and called the bug “painfully obvious.”
The problem was fixed the next day (2 January) with its creator tweeting that those using it were causing iCloud accounts to be locked.
When iCloud was attacked in 2014, accounts of celebrities like Jennifer Lawrence, Mary Elizabeth Winstead, and Kate Upton were compromised and numerous nude photographs were leaked as a result.
After the incident, Apple’s CEO Tim Cook said that it would introduce two-step verification and alert users whenever someone tries to restore their iCloud account.
To embed this post, copy the code below on your site
have your say