TechNeate.com iPhoneate.com QueComico.com MiamiGlobalRadio.com

Apple has already fixed a bug in Find My iPhone

by iNeate / September 1, 2014 11:07 AM EDT
Find-My-iPhone

Once again, Apple's security has been criticized and breached . It all started, as reported yesterday online, with a number of leaked nude photos of celebrities. A hacker exploited a vulnerability in the Find My iPhone service using malicious code, which generated a way to guess users' passwords until the correct one was found.

Until now, this was the most common way to hack an account, on any service, but the script sped up the process and hit the target, which also helped the company discover the bug and fix it.

The code was freely distributed to anyone who wanted to use it, which also makes iCloud services insecure and allows people with the correct password to access any of Apple's user services.

Although the code was published online and Twitter users were the first to access it via GitHub , the company fixed the problem by locking accounts for failed attempts to log in to a service with the wrong password.

The Twitter user responsible for creating and distributing the code publicly confirmed via a Tweet that the script is no longer functional.

hackapp

The problem with Find My iPhone is that it doesn't send notifications to users after several unsuccessful attempts to log into the account, nor does it automatically lock accounts, allowing attackers to continue trying to brute-force their way into the account.

Once an attacker gains access to an account, they can access other services such as data, email, contacts, photos, etc. Those affected by this hack attempt can recover their Apple services password by visiting iforgot.apple.com