Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That infamous case was the result of poor password use followed by an unguarded login page with no retry limit. This isn’t meant to victim blame, but it’s to also point out Apple too was a victim on this, they have a far stronger commitment to privacy compared to other companies.


Sure, but these celebrities completely outsourced their security to Apple because they trusted Apple.

"Apple knows best"... but clearly not because Apple should have had rate limiting for password login attempts to stop password brute-forcing attacks.

As for the far stronger commitment to privacy, I'm not so sure. Apple seems reluctant at times to patch zero-days which has been covered on the front page of HN.


>... rate limiting for password login attempts...

Good news then I suppose. They did, that's not what happened. People abused password reset, with the canonical example being Paris Hilton using her dog's name as a security question.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: