HN2new | past | comments | ask | show | jobs | submitlogin

When it prompts you to log in, it will pull up your appleID for you, but it gets it wrong. It will pull up some random other appleID...sometimes an old one you created for iTunes using a hotmail account you haven't checked since 2004, but sometimes a completely random other person's appleID. The authentication is unpredictable too...my wife has successfully signed on to her current account using an old password and successfully signed on to an old account using her new accounts password. Most of the time she can't sign on at all.


How is that even possible? What could be the possible rationale for keeping old passwords stored? Crazy.


You're assuming it's intentional. The first thing that comes to my mind is inconsistent state between multiple authentication servers.


Normally it would to be prevent users from reusing their most recent N passwords, for security. I don't believe Apple does that anywhere, though.


I suppose thinking about it, as long as they're hashed and salted, it's less of a problem... but it's still crazy that the system could fail that way.


I can confirm that they do.


Sign on to what? iCloud? Is there a forum thread or discussion somewhere that actually describes this in more details?

I've never gotten this before.





Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: