You choose, we deliver
If you are interested in this story, you might be interested in others from The Journal Gazette. Go to www.journalgazette.net/newsletter and pick the subjects you care most about. We'll deliver your customized daily news report at 3 a.m. Fort Wayne time, right to your email.

Business

  • Column: Hogs hurry higher
    Hog prices surged this week as the market prepared for Memorial Day weekend, typically a period of high demand.
  • Deadline looms for WANE-TV
    CBS programming could end at WANE-TV 15 if station owner LIN Media and Time Warner Cable don’t reach a retransmission agreement by a looming deadline.
  • World stocks stabilize after big sell-off
    MOSCOW (AP) — World stocks stabilized on Friday, a day after global markets dropped sharply on concerns global growth is slowing and the Federal Reserve could start scaling back its monetary stimulus.
Advertisement

Password safety boosted at Apple

SAN FRANCISCO - Apple is beefing up security for resetting user passwords after a journalist wrote about a hack affecting his personal data, highlighting possible weaknesses in the system protecting more than 400 million user accounts.

The company is temporarily suspending the ability to reset AppleID passwords over the phone while it takes steps to make the procedure more secure, said Natalie Kerris, a spokeswoman for Cupertino, Calif.-based Apple.

Mat Honan, a reporter for Wired, wrote Monday that hackers gained access to his account, erasing pictures and other data from his iPhone, iPad and MacBook, after resetting his password over the phone.

The incident highlighted potential vulnerabilities in AppleID, the verification needed for purchasing music, movies and applications from iTunes, as well as downloading software updates and accessing content on Apple’s iCloud Web-storage service, he said.

“This system can reset a password in one of two ways: Either have a password reset sent to an alternate e-mail address already on record or challenge the customer to answer security questions they had previously set up,” Kerris said. “When we resume over-the-phone password resets, customers will be required to provide even stronger identify verification to reset their password.”

Honan wrote that the hackers used the last four digits of his credit-card number and his home address to get a member of Apple’s tech-support staff to reset his password. He said the hackers got his credit-card information by first gaining access to his account at online retailer Amazon.com.

“The very four digits that Amazon considers unimportant enough to display in the clear on the Web are precisely the same ones that Apple considers secure enough to perform identity verification,” Honan wrote.

Advertisement