Apple two-step verification uncovers dicey password reset flaw

Apple ID password reset page is down
One step forward, two steps back

Update: Apple said that it's working to correct the Apple ID password reset exploit that was discovered earlier today and forced the company to suspend its iForgot tool.

"Apple takes customer privacy very seriously," the company told The Verge. "We are aware of this issue, and working on a fix."

No timeframe for when Apple will restore the ability to reset account passwords was attached to the succinct statement.

Original story continues...

Apple's new two-step verification measure is more like one step forward, two steps back, as an exploit has been uncovered for people who haven't signed up for the new feature.

The only information required to reset a person's password is the email account associated with their Apple ID and their date of birth.

The password reset also requires pasting a modified URL into the address bar, according to The Verge, but this is a simple trick to figure out.

This relatively easy password reset method works whether someone has unauthorized access to Apple ID email account or not, and would allow them to hijack your Apple ID, iTunes or iCloud accounts.

Apple password reset page down

Apple's two-step verification method incorporates a pin that's sent to a "trusted device" like an iPhone using the Find My iPhone app or another device using an SMS text message.

Upgrading to this extra layer of security, required for account changes and making purchases from a new Apple device, is one way to avoid having your Apple account hacked.

However, it's not that straightforward, as there's a mandatory three-day waiting period before the new two-step verification feature is enabled on an account.

In response to this, Apple took down its iForgot password reset page, while some users have gone to lengths such as randomly picking a new birth date.

Obviously, none of these are acceptable measures going forward. TechRadar has asked to Apple for a comment about the security flaw and will update this story when the company responds.

TOPICS
Matt Swider
Latest in Computing Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ensure data security for your business
The complete data protection system for your business
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Latest in News
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies