6 ms·
Let's put an emphasis on the fact that this cannot be a technical limitation, as everyone else in the world manages to build websites that work on most devices,
by invaliduser 8y ago
Let's put an emphasis on the fact that this cannot be a technical limitation, as everyone else in the world manages to build websites that work on most devices, including android.
The appleid is a security nightmare anyway. I used to use an account, associated to an email I own, with a password I know, and still I can not log in, because it keeps asking the insecure "personal questions" that I never answer, because [generic privacy statement] and because I use a cryptagraphically secure password manager. As I did not save the personal questions I answered when signing up (tbh I probably just put garbage, as those are usually never asked when you know the password), and now I just cannot access it.
That's right, I own the email address and I know the password, and yet I cannot access my account. However, knowing who was my best friend when I was a teenager, or what was the name of my first pet are questions, in spite of being known by dozens of friends or acquaintances, that Apple requests as security measures needed to trust me as the owner of the acount.
Having them on the phone provides zero help, 1 year later, I still cannot access it. It's definitively lost, and I feel happy I do not have any important information stored on the apple cloud.
- eeeeeeeeeeeee 8y agoI have the same issue with my TD Ameritrade account. I have the correct email and password, but then it asks for a security question that I have no idea about. I can’t get in.
- groestl 8y agoMinor side note: do not put garbage into the answer boxes, use a completely random but plausible answer. One attack vector that is enabled by using random strings as response to "security" questions is telephone support: "I definitely did not answer that question, I just put garbage in!" Sadly, sometimes that works.
- KeepFlying 8y agoVery much this. I have made a point to give somewhat legitimate answers to these questions out of fear that a phone agent would ask them someday and that I could fall victim to exactly what you describe. Phone agents don't always have to actually enter the security questions to access your account. sometimes they can simply see the answers on their screen and are able to make a judgement call. Don't trust humans, especially not humans who are incentivized to help you as quickly as possible. Also its easier to say a word over the phone than it is to say a random string of letters numbers and symbols.
- eridius 8y agoJust use a password generator to generate a space-separated phrase.
- stronglikedan 8y agoI've given up and just started giving the same answer for all security questions.
- Elte 8y agoDamn, it seems I really dodged a bullet here. I was recently asked for security questions logging into a company account (iOS management account). Whoever created the account only jotted down the answers to two of the questions. It asked for precisely these two, and I was able to change the other without answering the third..
- yohannparis 8y agoI'm sure your password manager can save Security Questions? In mine I can add as many field as I want, so for every login that require security questions I answer them with 50 characters gibberish, and save them for later use.
- colejohnson66 8y agoThen when someone calls and they ask for the security question, the attacker just says it’s jibberish and they let them through. Choose 4 random words, not 50 random characters
- Severian 8y agoIf you saw my comment below, this is exactly the same issue I have. It's stupid, and I don't think I ever added security questions to begin with when I signed up to iTunes over 10 years ago.
- 4ad 8y agoIt's inexcusable how bad the iCloud system is, especially regarding authentication, however, I will note that if you enable 2FA you don't get an any of that security question nonsense anymore. (Yes, I know that you can't enable 2FA, but perhaps it is useful to someone else reading this).
- wila 8y agoHad the same thing, actually knew the security question answers as I had logged them. But according to the fine website they were wrong. Called apple. First time they told me "too bad" (took me about an hour to get that answer) Called them again and another apple employee pointed out that as long as you can login, you can enable 2FA via iCloud (something I'm not using either). Once 2FA is enabled the security questions can be bypassed. Not sure if that required them to change a setting, but from then on you _should_ be able to change anything else, including the security questions or assign another email address or add an extra one or..
- rhamzeh 8y agoThanks for the tip! After reading this, I tried it and it didn't work. Even jumped on a call with support and they told me there is no way to turn on 2FA without the security questions (at least for my account, maybe other accounts can). The shitty thing is you also delete your account or create a new one with the same email without knowing the security questions. Oh well :/ Still, thanks for the hope (short-lived as it was).
- wila 8y agoStrange as I can assure you that this is how I recovered the account. This was on macOS Sierra which might be part of it then System Preferences -> iCloud The first apple support person I talked to did not know how-to recover the account this way. So it does not seem to be in the scripts.
- Wowfunhappy 8y agoJust a general warning, if you leave two factor on for a set number of days (I can't recall the exact amount), it is impossible to turn off again.
- sjg007 8y agoApple's backend systems are a shit show. They work in a specific set of requirements but outside of their specific situations or via tech support are effectively useless.
- N0RMAN 8y agoSo in short: You failed saving your recovery credentials (Question + Answer) and you‘re blaming Apple for it?
- imtringued 8y agoWell he didn't.