Icloud got hacked

Out of context: Reply #39

  • Started
  • Last post
  • 151 Responses
  • ernexbcn0

    Seems the passwords were bruteforced, as in guessed from lists of passwords available online and tested against iCloud servers.

    Websites and services usually delay repeated attempts when entering passwords and even lock accounts temporarily when suspicious activity is detected, it seems there was a server related to Apple ID where you could point your bruteforce lists against which wasn't protected with these delays and lockouts.

    http://thenextweb.com/apple/2014…

    So not really hacked, more like script kiddies guessing passwords.

    • a good password manager which generates gigantic passwords of random letters and numbers help mitigate these attacksernexbcn
    • I use 1Password, it's great.ernexbcn
    • – ernexbcn I'm calling the police.ApeRobot
    • That qualifies as a 'hack'. Not particularly elegant or sophisticated in its deployment, but a hack nonetheless.detritus
    • hack, maybe, but is it really a flaw in Apple's service?monospaced
    • it is a flaw because it should block multiple attempts of wrong passwordsernexbcn
    • I see.monospaced

View thread