Live data from Hacker News

Welcome to the Cloud - "Your Apple ID has been disabled."

hanselman.com

81–90 of 109 posts

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#81
post #45

Earlier quoted context omitted.

I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea. They could always do something like what Steam does - the first time you try to buy something with a new device, you must enable it by typing in a code that is emailed to you. Apple's new-device-detection algorithm doesn't seem to…

> Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years. I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't hig…

FWIW, you can disable Steam Guard for your account in the preferences.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#82
post #31

Not to be un-empathetic here, but I'm more intrigued by the exploit vector than Apple's initial response to an individual. It's interesting that your account is getting exploited without the password being hacked. Does anyone have more details?

That was my question too: How, exactly (technically), did this happen?

Spoilers: his password got hacked.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#83
post #64

Well, his account was probably sold in china, it's common (at least it still was a few months ago) on taobao (the chinese ebay), they sell you "gift cards" to be used within 12h after purchase, it's in fact accounts. I guess that's why Apple started to ask CCV for purchases. There's also a practice in China to use apps as a kind of fraud, or maybe money laundering. I've seen once a chinese wallpaper app, with each wa…

This seems plausible, but I don't use the same passsword between sites. Hm...

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#84
Based on his story, I would guess that:

1 - someone got their hands on Apple's private encryption keys

2 - some got their hands on a list of Apple id's or device UDID's

3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar.

My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someone else's behalf.

Then again, it could also just be a reused password.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#85

Based on his story, I would guess that: 1 - someone got their hands on Apple's private encryption keys 2 - some got their hands on a list of Apple id's or device UDID's 3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar. My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someon…

If it was a reused password, I'm an idiot. But, I'm willing to assume I am an idiot. My point is two-fold:

1. Allowing new devices to buy stuff without two-factor auth is weak sauce. 2. The larger meta-point that when we rely on the cloud in a big way, it hurts when we are locked out.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#86
post #82
post #31

Earlier quoted context omitted.

That was my question too: How, exactly (technically), did this happen?

Spoilers: his password got hacked.

Must be via reuse, as they lock out after the third fail. My concern is that it was a site-unique password.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#87
post #69
post #60

Earlier quoted context omitted.

I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this. The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to…

We don't implement such paranoid measures either in other web-services Yes "we" do. Steam doesn't let you authenticate, let alone buy stuff, from a new computer without entering a code that they'll email to you. Takes all of ten seconds--start up Steam, go to my email client, paste the code in, done. And it works great. So what's the complaint?

Steam is the only service that I've tried to use that won't accept any of my credit card... I'm not in a common situation living in China with a French credit card registered with my chinese address but still, I only could pay two times successfully (after a lot of tries) and now I can't anymore (and one would think that it should have become easier since they didn't get any chargebacks when I did buy)

So, in a world where customers can easily chargeback fraudulent charges, I think having security measures that are too paranoid is a great way to lose customers for no real advantages to the customer security.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#88

Based on his story, I would guess that: 1 - someone got their hands on Apple's private encryption keys 2 - some got their hands on a list of Apple id's or device UDID's 3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar. My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someon…

If it was a reused password, I'm an idiot. But, I'm willing to assume I am an idiot. My point is two-fold: 1. Allowing new devices to buy stuff without two-factor auth is weak sauce. 2. The larger meta-point that when we rely on the cloud in a big way, it hurts when we are locked out.

If someone tried to buy an app "manually" using their own device and your account, they would need to know your email address and password. There's plenty websites out there that store password in plain text, some of them even email it to you so everyone can intercept it. Other sites use some encryption, but could be still be compromised.

The possibility I hinted at is that someone just "pretends" they have an iPhone and communicate with the Apple server directly. I don't know how their algoritm works, but it may be the case that they only need an Apple id and some secret key that is stored on the device. In that case asking the user for their password is just a way to protect the user when they lose their actual device. That would be pretty insecure from Apple's side. They should at least use the password to generate a key pair. (This doesn't necessarily require anyone to steal secret keys from Apple I just realize)

I completely agree with your second more general point. See also my comment on the Paypal thread: http://news.ycombinator.com/item?id=2880194

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#89
post #41

Earlier quoted context omitted.

No doubt because you reused the non-trivial password and someone read it out of a stolen database. Password strength is a red herring. Password reuse is a far bigger problem then weak passwords.

It was a password that I only used with iTunes, or at least, I thought it was. You may be correct. I'm more vigilant with my passwords these days.

Only one way to find out; go through all your accounts and try that password. Let us know...

Even if the password was unique to iTunes, a key logger on your computer could have intercepted it.

Does Apple always use HTTPS? Otherwise it might have been intercepted when you were on an insecure wifi network.

Re: Welcome to the Cloud - "Your Apple ID has been disabled."

#90
post #40
post #6

Something similar happened to me a while back. I noticed that several smiley face/emoticon applications had been downloaded using my account. They removed my credit card from my account and drained my iTunes gift card. Apple caught the problem and e-mailed me to ask if it was me. I told them no. They disabled my account, refunded the gift card money, and asked me to write them once I was satisfied that my computer wa…

I've only made multi-item purchases from iTunes a few times, but every time I've gotten a call from my credit card company within a couple hours. The last time they said that it's become so common for fraudulent activity on a card to start with a "run on iTunes", then move on to other online sites if the card still works. The only thing I would recommend to Scott Hansleman is to drop PayPal. They can be easier for sm…

There's a difference between someone using your creditcard to buy stuff on iTunes with a different iTunes account* and someone using your iTunes account to buy apps. In your case I'm guessing they did the first thing.

* = possibly not their own; they might own the apps that you're buying or make money through affiliate networks. And of course they could buy gift cards with your cards and sell them on eBay through another payment account.

Post reply on HN