New Apple ID Exploit Allows Others To Reset Your Password; Here’s How To Protect Yourself


Apple may have finally added two-factor authentication, but a new exploit is putting Apple IDs at risk in a way that two-factor authentication can’t necessarily fix. Here’s what you need to know.

The Verge is reporting that a new exploit, involving a small URL trick on Apple’s iForgot page, will let anyone reset your password using just your email address and your date of birth. Since this information is so easy to come by, that means there are a lot of people that could change your Apple ID password. Two-step authentication would fix the problem, but as of right now, a lot of people aren’t able to sign up for the new security feature. Ironically, Apple is citing “security reasons” for making people wait a certain number of days before they can sign up.

So how can you fix the problem if you haven’t already enabled two-factor authentication? Change your date of birth to a fake date that only you can remember. Hopefully, Apple will fix the problem soon, and you’ll be able to change it back. But for now, head to your account settings page on Apple’s web site and change your birthday under the “Password and Security” menu. Hit the link to read more.

Major security hole allows Apple passwords to be reset with only email address, date of birth [The Verge]


The Cheapest NBN 50 Plans

Here are the cheapest plans available for Australia’s most popular NBN speed tier.

At Lifehacker, we independently select and write about stuff we love and think you'll like too. We have affiliate and advertising partnerships, which means we may collect a share of sales or other compensation from the links on this page. BTW – prices are accurate and items in stock at the time of posting.

Comments


6 responses to “New Apple ID Exploit Allows Others To Reset Your Password; Here’s How To Protect Yourself”

Leave a Reply