Live data from Hacker News

Welcome to the Cloud - "Your Apple ID has been disabled."

hanselman.com

61–70 of 109 posts

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#61
post #44

Earlier quoted context omitted.

Is this paid for by your employer, Microsoft or are you just doing this for fun? Apologies for the blunt question, but you've often run anti-Google, anti-Apple stories and are well known as a 'kept blogger'.

Scott is one of the rare biased, objective posters in the blogging world. He never tries to hide his love of Microsoft and its products, however he never makes unfounded, baseless accusations and always backs up his claims with real data. Consider these posts in recent history: http://www.hanselman.com/blog/ReviewMicrosoftTouchMouseForWi... (critical of MS hardware) http://www.hanselman.com/blog/HackersCanKillDiabeti…

What? Am I wrong? Was this post perceived as "too fanboyish"?

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#62

Given Apple's security practises are more Microsoft-2001 than Microsoft-2011, I'd hazard a guess that there's some sort of 0-day exploit hitting iOS devices themselves. Scott's not dumb though to fly without antivirus/firewalls on his own PCs. Your iPad/iPhone, on the other hand, are almost certainly running no antivirus and no firewall. Because who needs such inconveniences, eh?

Apple's security practices for Mac OS X could arguably be described historically as Microsoft-2006 (Lion would seem to be approaching Microsoft-2011), but to conflate that with IOS's security practices is disingenuous.

Here's a fairly recent presentation outlining some of the security practices around IOS 4:

http://trailofbits.com/2011/08/10/ios-4-security-evaluation/

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#63
post #52

Earlier quoted context omitted.

Dude, the word "Gruber" is a hyperlink in the article. Just click on it.

Where on Gruber's website is his relevance to the subject made clear? EDIT: No, seriously. If someone has no idea who Gruber is and they click through to his site, tell me where on the screen they would see information that answers the implicit question "Who is Gruber and why would him finding out about this problem aid its resolution".

You're right. It's not like the title of his page is "Gruber: Mac Fanboy #1"

I retract my snark, or at least a little bit of it.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#64
Well, his account was probably sold in china, it's common (at least it still was a few months ago) on taobao (the chinese ebay), they sell you "gift cards" to be used within 12h after purchase, it's in fact accounts. I guess that's why Apple started to ask CCV for purchases.

There's also a practice in China to use apps as a kind of fraud, or maybe money laundering. I've seen once a chinese wallpaper app, with each wallpaper for sale at $99, making thousands on the appstore.. when you think about it, it's easy to post an wallpaper app, set the price, and you get money through Apple, without any traces.

What I really hate about all this is that Apple still force you (or make it very difficult not to) to have a CC linked to your itunes account, even though you plan to never buy anything.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#65
post #37
post #30

Earlier quoted context omitted.

I very much doubt that assertion. Gruber complains quite a bit, I can’t recognize any pattern of Apple fixing specifically the problems he has faster.

Supporting evidence: the lack of Markdown support in the Mail app

Or on Apple discussion forums.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#66
post #60

Earlier quoted context omitted.

I am blaming Apple for: * the fact they "allow the purchase first" and "warn later." * their warning email has no fraud or dispute mechanism * I've never purchased a game like this so they my usage pattern should be a red flag Apple should have fraud systems as powerful and convenient as VISAs.

I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this. The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to…

What's utterly silly about not having a "purchase first, warn later" system in Apple's case is that that of unlike credit cards, Apple can literally undo the purchase. Apple has done a great job of making the App Store's FairPlay DRM invisible to users, but in the case of a fraudulent purchase, I would imagine it trivial to make that DRM quite plainly visible to the fraudulent purchaser.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#67
post #60

Earlier quoted context omitted.

I am blaming Apple for: * the fact they "allow the purchase first" and "warn later." * their warning email has no fraud or dispute mechanism * I've never purchased a game like this so they my usage pattern should be a red flag Apple should have fraud systems as powerful and convenient as VISAs.

I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this. The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to…

I don't seen the downside to verifying your account on a new device before being able to use it. If you have access to the appstore then you have access to Gmail and one simple email to say "Yeah, go ahead and let my friend's iPad buy this app on my account for 24 hours/7days/forever" is all it takes to prevent this sort of thing.

> We don't implement such paranoid measures either in other web-services or in real live, so I find it rather overblown to demand Apple does this.

Google Two-Factor Authentication, Facebook emails you when someone logs on using an unknown computer, Steam does the same, and I'm sure there are more examples.

It's only paranoia until something happens.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#68
post #41
post #6

Something similar happened to me a while back. I noticed that several smiley face/emoticon applications had been downloaded using my account. They removed my credit card from my account and drained my iTunes gift card. Apple caught the problem and e-mailed me to ask if it was me. I told them no. They disabled my account, refunded the gift card money, and asked me to write them once I was satisfied that my computer wa…

No doubt because you reused the non-trivial password and someone read it out of a stolen database. Password strength is a red herring. Password reuse is a far bigger problem then weak passwords.

Passwords in general are horribly broken. They're the worst conceivable way to authenticate, except for all the others. Solve this problem and you'll be the next Verisign, if not the next Microsoft.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#69
post #60

Earlier quoted context omitted.

I am blaming Apple for: * the fact they "allow the purchase first" and "warn later." * their warning email has no fraud or dispute mechanism * I've never purchased a game like this so they my usage pattern should be a red flag Apple should have fraud systems as powerful and convenient as VISAs.

I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this. The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to…

We don't implement such paranoid measures either in other web-services

Yes "we" do. Steam doesn't let you authenticate, let alone buy stuff, from a new computer without entering a code that they'll email to you. Takes all of ten seconds--start up Steam, go to my email client, paste the code in, done.

And it works great. So what's the complaint?

Post reply on HN