Apple ID password? Change it now!

If you are an Apple user with an iCloud account, you are advised to change your Apple ID immediately.

A spate of  hijacking attacks have targeted iCloud logins.

Both the NSW Police and the Australian government’s Stay Smart Online service have advised that all Apple users should change their Apple ID password.

Users are also advised to set a passcode on their iPhones and tablets or passwords on their Mac laptops and desktops.

Users have reported that their phones or systems have locked unexpectedly, after which they receive a message on their screen stating that their device has been, ‘Hacked by Oleg Pliss’ and an email from ‘Find My iPhone’. In order to unlock the device, the message indicates that they should pay a ransom via PayPal, emailing the payment code to the hotmail account “lock404”!

If a hacker has set a new passcode lock on an Apple device, it is possible to bypass it by using one of the methods suggested by Apple. Some of these require erasing, resetting or restoring your device from a backup (if you have saved one).

The Lost Mode function is a vulnerability. This can be switched off via iCloud.

How to change your Apple ID / iCloud password

  1. Go to My Apple ID
  2. Click “Manage your Apple ID” and sign in
  3. If you have two-step verification turned on, you’ll be asked to send a verification code to the trusted device associated with your Apple ID. If you’re unable to receive messages at your trusted device, follow the guidelines for what to do if you can’t sign in with two-step verification
  4. Click “Password and Security
  5. In the “Choose a new password” section, click “Change Password”
  6. Enter your old password, then enter a new password and confirm the new password. Click “Save when done”

In addition to changing passwords, IT security experts strongly recommend instituting “two-factor authentication” on Apple ID accounts. Turning on two-factor authentication reduces the possibility of someone accessing or making unauthorised changes to your account information.

Two-factor authentication adds a second layer of security as it requires both a password and a separate verification code sent to a phone (or other trusted device), which must then be entered into the mobile device, before it is permitted access to the account.

Learn about two-factor authentication.

This latest issue comes less than a month after the major “Heartbleed” vulnerability was disclosed (on 7 April) after remaining undetected for two years!

“Heartbleed is a bug in OpenSSL. Hackers can exploit Heartbleed to get raw text from emails, instant messages, passwords, even business documents — anything a user sends to a vulnerable site’s server.”

Read about the most contagious malware released at the turn of the century.

At Digital Tsunami, we strongly recommend regularly changing passwords as a standard precautionary measure.

All users should implement the highest level of security, including no less than: individual high-security passwords in a combination of at least 8 (preferably 12 or more) characters, containing at least one lower case character, one capital, one numeral and where accepted, special characters (such as ^+>&*#/%). These should not be formatted to resemble or contain a word and should not be used across all sites. It is exceptionally important that passwords for banking sites not be shared.

If your bank is not yet using two-factor authentication, comprised of a username and password PLUS a ‘token’ (random code generator device) or code sent to your to cellphone, it is time to consider changing banks!

At least one backup generic email address (Gmail, Hotmail, Yahoo, etc.) should be created, to enable communications in case your domain name becomes infected and email on that domain is blocked or unusable. This email can also be used to retrieve passwords for an email account on your corporate domain.

Digital Tsunami constantly monitors and audits the security of our clients and our private clouds. We conduct frequent security audits, to ensure that we were taking all possible measures to protect client assets.

Read about some of the security measures Digital Tsunami applies to web hosting and specifically to WordPress site hosting.

Talk to Digital Tsunami
 about security for your web hosting.

References:

smh.com.au/digital-life/consumer-security/
staysmartonline.gov.au/alert_service/
appleid.apple.com

Recommended security vendors:

Symantec.com
McAfee.com
TrendMicro.com

From Our Clients

Quotation Mark

With a brief timeline to ensure we had a web presence and launch coinciding with our 10 year anniversary, Digital Tsunami delivered. On time. On budget. Great Effort!

Grant C. Duff
Head of Marketing
Sydney, NSW, Australia
Solvay Pharmaceuticals
Quotation Mark

We are very pleased with the end result. It was good to have you pushing us along for material in order that we met the agreed completion deadline - you certainly are good project managers!

Mike A Rawbone
Managing Director
Hong Kong
HR Associates
Quotation Mark

You have demonstrated patience, perseverance, attention to detail and a rare ability to perceive what was needed even when we didn't. We are delighted with the site, it performs and looks great and our enquiry rate since it superseded our previous website has already increased by 20%.

David Chapman
Operations Manager
Bankstown, NSW, Australia
Aerospace Aviation
Quotation Mark

We have been a client of Digital Tsunami now for a number of years.

As an ASX listed company, we seek reliability with our suppliers. Digital Tsunami have proven they are reliable and trustworthy multiple times.

We host multiple websites and services through them, and use them for technical and creative work.

There has never been an issue, they are always on top of all technical details, and simply provide the best possible solution around a given budget, and get things right first time. Clearly they have excellent quality controls and that shows in their services.

Adam Connell
Marketing Executive
Adelaide, SA, Australia
Quotation Mark

Digital Tsunami has supported us for many years now, and we continue to be impressed by the standard of service and advice. We not only get quality web design and implementation, but also honest feedback and suggestions which are crucial to the final product.

Digital Tsunami is able to discuss ideas with us and then develop them into a practical solution online, and this ‘team’ effort ensures the results are of the highest quality.

When our website is the first thing people look to when making an assessment on our company, I’m pleased to know that we have Andrew and his team behind us.

Roger Christie
Web Project Manager
Sydney, NSW, Australia
error: We appreciate that you value our content. You are welcome to link to this page, but content is copyright protected.