Apple faulty on .Mac social engineering attack

Published on:

Marko Karppinen: Apple just gave out my Apple ID password because someone asked.

I tried to log in to Apple Developer Connection this morning to find out that my password had been changed and the email associated with my account was now a yahoo.com address that wasn't mine. Luckily, my "security question" was still the same, so I was able to reset the password and email address back.

Based on the emails that have appeared in my .Mac mailbox, this was accomplished by sending this classy one-liner to Apple:

am forget my password of mac,did you give me password on new email marko.[redacted]@yahoo.com
To which Apple reacted by doing the only reasonable thing - saying Sir, Yes Sir! and handing my account over.

Crazy and outrageous story.