Live data from Hacker News

AppleID password brute force proof-of-concept

github.com

21–30 of 83 posts

Re: AppleID password brute force proof-of-concept

#21
post #11

I don't know if this was the attack used in the hack, but it is really, really bad news for Apple. The public is not going to trust iCloud any more. I'm pretty sure Apple will drop iWallet from the keynote, or it'll end up like their maps.

I think you're on a roll there.

You sure Apple won't also get rid of TouchID as well ?

Re: AppleID password brute force proof-of-concept

#23

It's sad that there aren't legal requirements for security hardening. There are massive corporations which retain sensitive information that are low hanging fruit for script kiddies.

There is if a company promises the kind of security in marketing, though. SnapChat got slapped (and just that) for promising ephemeral messaging: http://www.ftc.gov/news-events/press-releases/2014/05/snapch....

Re: AppleID password brute force proof-of-concept

#24

Dictionary attacks are incredibly effective. Humans have a hard time coming up with unique passwords.

It'd be nice if Windows/OSX/iOS/Android came with 1Password out of the box. It's both easier to use and more secure than manual passwords, which is a rare combination.

Re: AppleID password brute force proof-of-concept

#25

Does anyone else prefer to entirely avoid signing up for an Apple ID? I absolutely refuse to do so, and therefore use only software that doesn't require it. I suspect I'm not entirely alone out here on the sidelines...

Is it actually possible to use an iDevice without one?

Re: AppleID password brute force proof-of-concept

#26
post #24

Dictionary attacks are incredibly effective. Humans have a hard time coming up with unique passwords.

It'd be nice if Windows/OSX/iOS/Android came with 1Password out of the box. It's both easier to use and more secure than manual passwords, which is a rare combination.

Safari on OSX & iOS does do random password suggestions, out of the box.

Re: AppleID password brute force proof-of-concept

#29

It's sad that there aren't legal requirements for security hardening. There are massive corporations which retain sensitive information that are low hanging fruit for script kiddies.

idk, I can imagine the recent celebrity leaks would sue Apple for allowing those pictures to be distributed. Of course, I'm sure Apple's got a clause in its iCloud T&C's that makes them deny liability.

Re: AppleID password brute force proof-of-concept

#30
post #25

Does anyone else prefer to entirely avoid signing up for an Apple ID? I absolutely refuse to do so, and therefore use only software that doesn't require it. I suspect I'm not entirely alone out here on the sidelines...

Is it actually possible to use an iDevice without one?

I guess he also does not use hardware that require AppleID either.
Post reply on HN