Apple, Amazon Close Holes that Allowed Honan Hack

Latest Videos FromTom's Hardware
Jane McEntegart
Contributor

Jane McEntegart is a writer, editor, and marketing communications professional with 17 years of experience in the technology industry. She has written about a wide range of technology topics, including smartphones, tablets, and game consoles. Her articles have been published in Tom's Guide, Tom's Hardware, MobileSyrup, and Edge Up.

  • aftcomet
    As terrible as this is, it's quite ingenious.
    Reply
  • jhansonxi
    Most people learn the basics of this hack when they are kids - playing one parent against the other. Quite an interesting logical extension of it.
    Reply
  • internetlad
    fantastic use of social engineering. They knew how to manipulate the weak links (humans) to get the info they needed.

    It's a shame when a good portion of the scams and malicious software installations we see are directly related to the user clicking on something stupid because it tells them they have an infection, etc.
    Reply
  • Just goes to show as another example of how cloud systems are not proving themselves as safe.
    Reply
  • ddpruitt
    Has it occurred to anyone that Apple stores passwords as plain-text? I think they have bigger issues than just giving out passwords over the phone, they need a top down security audit.
    Reply
  • teh_chem
    ddpruittHas it occurred to anyone that Apple stores passwords as plain-text? I think they have bigger issues than just giving out passwords over the phone, they need a top down security audit.It was discovered that apple stores passwords in plain text?
    Reply
  • koga73
    I would think that Apple uses hashed passwords and probably just reset his pass to something new temporarily... However if this is the case then how did the hackers gain access to his gmail account unless Apple read his original plain text password to the hackers?

    "Because Honan's AppleID was linked to his Gmail account, the hacker was able to change that password"
    Reply
  • hax0red
    We called this social engineering back on AOL in late 90's early 2,000's. We used to do the same, 3 letters(shortest AOL screen name you could have without an exploit) considered "elite" lol. Internal AOL accounts were the biggest prize as it gave you the power of god in the AOL chats....so sad. lol.

    They eventually went to RSA secureid which stopped the internal AOL account pursuit short of having them sub7'd in which you could log their key presses @ login.
    Reply
  • lathe26
    The last 4 digits of your credit card have NEVER been secure. Almost every account I have where I pay a business via credit card displays these. Many receipts emailed to me have the last 4 digits. All of my paper receipts have the last 4 digits. Seriously, what were they thinking?
    Reply
  • I think the term manipulator is more appropriate than hacker. There was no hacking involved.
    Reply