{"id":713,"date":"2008-07-08T13:30:51","date_gmt":"2008-07-08T12:30:51","guid":{"rendered":"http:\/\/www.itwriting.com\/blog\/713-apple-accused-of-security-blunder-highlights-cloud-risks.html"},"modified":"2008-07-08T13:30:51","modified_gmt":"2008-07-08T12:30:51","slug":"apple-accused-of-security-blunder-highlights-cloud-risks","status":"publish","type":"post","link":"https:\/\/www.itwriting.com\/blog\/713-apple-accused-of-security-blunder-highlights-cloud-risks.html","title":{"rendered":"Apple accused of security blunder; highlights cloud risks"},"content":{"rendered":"<p>According to <a href=\"http:\/\/blog.karppinen.fi\/2008\/07\/apple-just-gave-out-my-apple-i.html\">this post<\/a>, someone at Apple committed a huge security blunder, giving the password to someone\u2019s Apple ID to a third party. How was this accomplished? Someone emailed from an email account not associated with the Apple ID, and asked for the password. Apple apparently just reset the password and emailed it to the enquirer.<\/p>\n<p>I haven\u2019t verified the claim; but even if it is false, it highlights the risks of living the cloud life. Here\u2019s what victim Marko Karppinen emailed to Apple:<\/p>\n<blockquote>\n<p>Apparently based on a single-line email inquiry, you have allowed a third party access to:      <br \/>&#8211; My personal details       <br \/>&#8211; My personal email       <br \/>&#8211; All the files stored on my iDisk       <br \/>&#8211; Everything I&#8217;ve synchronized to .Mac, including my Address Book, Bookmarks, Keychain items, etc.       <br \/>&#8211; My credit card details as stored in my Apple Store profile       <br \/>&#8211; My iTunes Music Store Account       <br \/>&#8211; My ADC Premier membership, including the software seed key and other assets       <br \/>&#8211; The iPhone Developer Program&#8217;s Program Portal, including details of our development team<\/p>\n<p>Frankly, this makes me so angry that I can&#8217;t see straight.<\/p>\n<\/blockquote>\n<p>Simon Willison, whose blog <a href=\"http:\/\/simonwillison.net\/2008\/Jul\/8\/\">alerted me<\/a> to the incident, <a href=\"http:\/\/simonwillison.net\/2008\/Jun\/24\/openid\/\">mentioned a few weeks ago<\/a> the security problem inherent in any site which will email you a password:<\/p>\n<blockquote>\n<p>I have a very simple rule of thumb for whether or not a site should consider whitelisting OpenID providers: does the site offer a \u201cforgotten password\u201d feature that e-mails the user a login token? If it does, then the owners have already made the decision to outsource the security of their users to whoever they picked as an e-mail provider.<\/p>\n<\/blockquote>\n<p>Let\u2019s bear in mind too that email mostly travels through the internet as plain text, vulnerable to interception.<\/p>\n<p>Thought for the day: how much of your data is protected only by a simple username\/password combination, and presuming there is some, how well protected is that password itself?<\/p>\n<p>I imagine Apple will be tightening up its procedures, if the incident above is confirmed, since it was easily avoidable.<\/p>\n<div class=\"wlWriterSmartContent\" id=\"scid:0767317B-992E-4b12-91E0-4F059A8CECA8:378d68e7-f66b-470a-b280-ad70302d308d\" style=\"padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px\">Technorati tags: <a href=\"http:\/\/technorati.com\/tags\/apple\" rel=\"tag\">apple<\/a>, <a href=\"http:\/\/technorati.com\/tags\/security\" rel=\"tag\">security<\/a><\/div>\n","protected":false},"excerpt":{"rendered":"<p>According to this post, someone at Apple committed a huge security blunder, giving the password to someone\u2019s Apple ID to a third party. How was this accomplished? Someone emailed from an email account not associated with the Apple ID, and asked for the password. Apple apparently just reset the password and emailed it to the &hellip; <a href=\"https:\/\/www.itwriting.com\/blog\/713-apple-accused-of-security-blunder-highlights-cloud-risks.html\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Apple accused of security blunder; highlights cloud risks<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,75],"tags":[],"class_list":["post-713","post","type-post","status-publish","format-standard","hentry","category-apple","category-security"],"_links":{"self":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/713","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/comments?post=713"}],"version-history":[{"count":0,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/posts\/713\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/media?parent=713"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/categories?post=713"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itwriting.com\/blog\/wp-json\/wp\/v2\/tags?post=713"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}