Earlier quoted context omitted.
I can sympathize with you. But even suspect credit fraud is also "purchase first" "warn later". Refusing to let a new device purchase anything without a thorough check is a ridiculous idea. They could always do something like what Steam does - the first time you try to buy something with a new device, you must enable it by typing in a code that is emailed to you. Apple's new-device-detection algorithm doesn't seem to…
> Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years. I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't hig…
Welcome to the Cloud - "Your Apple ID has been disabled."
81–90 of 109 posts
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#82Not to be un-empathetic here, but I'm more intrigued by the exploit vector than Apple's initial response to an individual. It's interesting that your account is getting exploited without the password being hacked. Does anyone have more details?
That was my question too: How, exactly (technically), did this happen?
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#83Well, his account was probably sold in china, it's common (at least it still was a few months ago) on taobao (the chinese ebay), they sell you "gift cards" to be used within 12h after purchase, it's in fact accounts. I guess that's why Apple started to ask CCV for purchases. There's also a practice in China to use apps as a kind of fraud, or maybe money laundering. I've seen once a chinese wallpaper app, with each wa…
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#841 - someone got their hands on Apple's private encryption keys
2 - some got their hands on a list of Apple id's or device UDID's
3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar.
My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someone else's behalf.
Then again, it could also just be a reused password.
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#85Based on his story, I would guess that: 1 - someone got their hands on Apple's private encryption keys 2 - some got their hands on a list of Apple id's or device UDID's 3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar. My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someon…
1. Allowing new devices to buy stuff without two-factor auth is weak sauce. 2. The larger meta-point that when we rely on the cloud in a big way, it hurts when we are locked out.
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#86Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#87Earlier quoted context omitted.
I have a problem with most these arguments. You're suggesting that they should not have allowed the purchase. I would be highly annoyed if Apple didn't allow me to purchase from a different device. I see no reason for Apple to outright refuse this. The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to…
We don't implement such paranoid measures either in other web-services Yes "we" do. Steam doesn't let you authenticate, let alone buy stuff, from a new computer without entering a code that they'll email to you. Takes all of ten seconds--start up Steam, go to my email client, paste the code in, done. And it works great. So what's the complaint?
So, in a world where customers can easily chargeback fraudulent charges, I think having security measures that are too paranoid is a great way to lose customers for no real advantages to the customer security.
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#88Based on his story, I would guess that: 1 - someone got their hands on Apple's private encryption keys 2 - some got their hands on a list of Apple id's or device UDID's 3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar. My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someon…
If it was a reused password, I'm an idiot. But, I'm willing to assume I am an idiot. My point is two-fold: 1. Allowing new devices to buy stuff without two-factor auth is weak sauce. 2. The larger meta-point that when we rely on the cloud in a big way, it hurts when we are locked out.
The possibility I hinted at is that someone just "pretends" they have an iPhone and communicate with the Apple server directly. I don't know how their algoritm works, but it may be the case that they only need an Apple id and some secret key that is stored on the device. In that case asking the user for their password is just a way to protect the user when they lose their actual device. That would be pretty insecure from Apple's side. They should at least use the password to generate a key pair. (This doesn't necessarily require anyone to steal secret keys from Apple I just realize)
I completely agree with your second more general point. See also my comment on the Paypal thread: http://news.ycombinator.com/item?id=2880194
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#89Earlier quoted context omitted.
No doubt because you reused the non-trivial password and someone read it out of a stolen database. Password strength is a red herring. Password reuse is a far bigger problem then weak passwords.
It was a password that I only used with iTunes, or at least, I thought it was. You may be correct. I'm more vigilant with my passwords these days.
Even if the password was unique to iTunes, a key logger on your computer could have intercepted it.
Does Apple always use HTTPS? Otherwise it might have been intercepted when you were on an insecure wifi network.
Re: Welcome to the Cloud - "Your Apple ID has been disabled."
#90Something similar happened to me a while back. I noticed that several smiley face/emoticon applications had been downloaded using my account. They removed my credit card from my account and drained my iTunes gift card. Apple caught the problem and e-mailed me to ask if it was me. I told them no. They disabled my account, refunded the gift card money, and asked me to write them once I was satisfied that my computer wa…
I've only made multi-item purchases from iTunes a few times, but every time I've gotten a call from my credit card company within a couple hours. The last time they said that it's become so common for fraudulent activity on a card to start with a "run on iTunes", then move on to other online sites if the card still works. The only thing I would recommend to Scott Hansleman is to drop PayPal. They can be easier for sm…
* = possibly not their own; they might own the apps that you're buying or make money through affiliate networks. And of course they could buy gift cards with your cards and sell them on eBay through another payment account.