{"id":12459,"date":"2013-03-25T10:45:43","date_gmt":"2013-03-25T17:45:43","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=12459"},"modified":"2013-04-03T12:43:41","modified_gmt":"2013-04-03T19:43:41","slug":"apples-iforgot-page-updated-to-fix-vulnerability","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/","title":{"rendered":"Apple&#8217;s iForgot Page Updated to Fix Vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-12475\" title=\"forgot-password\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/forgot-password.png\" alt=\"\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/forgot-password.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/forgot-password-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/forgot-password-300x150.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>More password-related excitement from Apple! It was a very busy week: <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-ios-6-1-3-update-fixes-passcode-bug\/\">iOS 6.1.3 fixed a passcode flaw<\/a>, and almost immediately, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/return-of-the-passcode-flaw-in-ios-6-1-3\/\">another passcode flaw was found in that new version<\/a>. <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-now-allows-two-factor-authentication\/\">Apple ID added 2-Factor Authentication<\/a>, and then it was discovered that any accounts that had not implemented this new authentication were <a href=\"http:\/\/www.theverge.com\/2013\/3\/22\/4136242\/major-security-hole-allows-apple-id-passwords-reset-with-email-date-of-birth\">vulnerable to an exploit<\/a> that would potentially give an attacker access to that account with minimal information. Shortly after hearing this news, Apple disabled the password reset functionality, but it was found that this too left users vulnerable to a similar problem. At that point, they took the iForgot page down entirely.<\/p>\n<p>The iForgot password-reset required six steps to completely validate a user, but <a href=\"http:\/\/www.imore.com\/anatomy-apple-id-password-reset-exploit\">after entering only a user&#8217;s email and birthdate<\/a>, it would generate a URL that would allow an attacker to access their account. This bypassed additional verification, such as answering security questions.<\/p>\n<p>If you&#8217;ve ever wondered why security researchers get twitchy about people putting their birthdate on social networking sites, this is a good example of why. Few pieces of information by themselves are necessarily useful on their own, but the more information that&#8217;s easily available for you, the more tempting of a target you are. It&#8217;s not difficult to gather this information for most people if someone is suitably motivated to dig it up, but people who voluntarily provide this information in one location are the ever-tempting &#8220;low-hanging fruit.&#8221;<\/p>\n<p>Another solution to problems like these is much like the strategy of <a href=\"https:\/\/www.intego.com\/mac-security-blog\/your-secret-question-may-not-be-so-secret-easy-to-guess-password-retrieval-questions-you-should-avoid-and-why\/\">answering security questions with nonsensical information<\/a>. For many sites, you can use not your actual birthdate but another date in the same month. Of course, this does mean you have to remember an additional date.<\/p>\n<p>At the time of writing, Apple has fixed this flaw and we can all breathe freely. It&#8217;s unclear whether this was used in the wild, but if you would like more peace of mind, you may wish to change your password. And now&#8217;s a good time to add that <a href=\"https:\/\/www.intego.com\/mac-security-blog\/what-is-multi-factor-authentication-and-how-will-it-change-in-the-future\/\">2-Factor Authentication<\/a> if it&#8217;s available in your area!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was found in that new version. Apple ID added 2-Factor Authentication, and then it was discovered that any accounts that had not implemented this new authentication were vulnerable to an exploit that [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":12479,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7],"tags":[329,144],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple&#039;s iForgot Page Updated to Fix Vulnerability - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-03-25T17:45:43+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2013-04-03T19:43:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lysa Myers\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png\",\"width\":\"400\",\"height\":\"260\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/\",\"name\":\"Apple's iForgot Page Updated to Fix Vulnerability - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage\"},\"datePublished\":\"2013-03-25T17:45:43+00:00\",\"dateModified\":\"2013-04-03T19:43:41+00:00\",\"description\":\"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple&#8217;s iForgot Page Updated to Fix Vulnerability\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\"},\"headline\":\"Apple&#8217;s iForgot Page Updated to Fix Vulnerability\",\"datePublished\":\"2013-03-25T17:45:43+00:00\",\"dateModified\":\"2013-04-03T19:43:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage\"},\"wordCount\":343,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png\",\"keywords\":[\"iForgot\",\"Vulnerability\"],\"articleSection\":[\"Apple\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"caption\":\"Lysa Myers\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"Apple's iForgot Page Updated to Fix Vulnerability - The Mac Security Blog","og_description":"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was","og_url":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/","og_site_name":"The Mac Security Blog","article_published_time":"2013-03-25T17:45:43+00:00","article_modified_time":"2013-04-03T19:43:41+00:00","og_image":[{"width":"400","height":"260","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lysa Myers","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png","width":"400","height":"260"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/","name":"Apple's iForgot Page Updated to Fix Vulnerability - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage"},"datePublished":"2013-03-25T17:45:43+00:00","dateModified":"2013-04-03T19:43:41+00:00","description":"More password-related excitement from Apple! It was a very busy week: iOS 6.1.3 fixed a passcode flaw, and almost immediately, another passcode flaw was","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Apple&#8217;s iForgot Page Updated to Fix Vulnerability"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a"},"headline":"Apple&#8217;s iForgot Page Updated to Fix Vulnerability","datePublished":"2013-03-25T17:45:43+00:00","dateModified":"2013-04-03T19:43:41+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#webpage"},"wordCount":343,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png","keywords":["iForgot","Vulnerability"],"articleSection":["Apple"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/apples-iforgot-page-updated-to-fix-vulnerability\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","caption":"Lysa Myers"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/03\/iForgot-thumb.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-3eX","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/12459"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=12459"}],"version-history":[{"count":11,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/12459\/revisions"}],"predecessor-version":[{"id":12487,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/12459\/revisions\/12487"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/12479"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=12459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=12459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=12459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}