voice

Hear a new voice.

Navigation
  • Home
  • Tech
  • Gaming
  • Food
  • Drink
  • Books
  • Movies
  • TV
  • Religion
  • Politics
  • Society

Apple fixes FaceTime “security flaw” server-side

  • Posted on October 21, 2010
  • by Josh
  • in Feature, Tech

Along with Apple’s FaceTime beta release came a new iTunes Store account security flaw. While people were poking around in the app, they noticed that they could easily access their iTunes Store accounts right from the app. In doing so, they’re able to update their account settings without re-entering the iTunes Store password. To make matters worse, the application automatically saves your username and password even if you sign out — as demonstrated in the Gallery of pictures attached to this post.

While the original intention of this post was to show you a quick fix through the removal of a .plist, it seems Apple has beaten me to the quick fix punch. First, the easy… yet annoying fix:

Go to your User Folder / Library / Preferences and delete com.apple.FaceTime.plist

That will reset the settings for the app and clear out your password. If you’re like me, you probably played with this app as soon as possible. This meant that I installed FaceTime and signed into my iTunes Store account on a friend’s machine so I could test it out. I obviously didn’t want to leave them with access to my stuff so I immediately went to remove the .plist. So that’s one fix, but guess what Apple did to fix the issue…

They blocked FaceTime access to the iTunes Store servers completely. If you were to go into FaceTime preferences and click Account, you’ll see two options available: Change Location and View Account. Go ahead, click View Account. The next page will attempt to load but immediately bounce you back to the Account preferences panel. It’s a sneaky work around to a potentially serious security flaw. I’m actually impressed that Apple knocked that out so quickly. Here’s betting that we’ll see an updated version of FaceTime sooner rather than later.

Special thanks goes to Christopher Nice for additional verification.

 

  • Tweet
  • Tags: account, account fix, apple fixed facetime, digg, face time, facetime, facetime security flaw, fix, flaw, itunes account, itunes store account, security, security flaw, server fix

    About Josh

    I am Josh, and I write.
    View all posts by Josh →
    ← Apple introduces FaceTime for Mac (beta)
    Adobe reveals a switchable HTML5 video player →
    • Latest
    • Popular
    • Comments
    • Tags
    • Xbox OneXbox One Leaves the Door Open for Innovation May 22, 2013
    • New Facebook IconFacebook New Friend Reports – Hide “is now friends with” spam May 11, 2013
    • Reeder IconTwitter : RSS :: MS Paint : Adobe Illustrator March 14, 2013
    • Mountain Dew KickstartNew breakfast drink – Mountain Dew Kickstart March 12, 2013
    • Tomb Raider 2013Tomb Raider 2013 thoughts from Sean Caspian March 11, 2013
    • Mafia Live! Family Codes February 14, 2009
    • Apple cripples iBooks for jailbreakers – Updated February 15, 2011
    • Cydia Packages Available for 2.0 August 12, 2008
    • Simplify Media — Stream Songs to Your Mobile Device August 25, 2008
    • Verizon iPhone 4 cannot be unlocked February 4, 2011
    • Josh Carr Hi AJ,I just wanted to reach back out and offe
    • Jewelia You are quite welcome, and please post as God brin
    • Josh Awesome words of encouragement. Thank you so much
    • Jewelia Maybe everything has to die for you to be truely f
    • Amy Jensen Hey josh.....I too was heavily involved in church
    $4.99 $9.99 4th generation iphone android Apple Apple iPad App Reviews app store AT&T dev-team Entertainment flash Free google HTML5 iBooks iOS iPad ipad apps iPhone iphone 4 iphone 4G iPhone OS iPod touch issues iTunes jailbreak musclenerd no flash Productivity Pwnage pwnage tool Rant redsn0w SDK Social Networking square squareup steam steam for mac Stupid system-on-a-chip Unlock Utilities verizon
    Tweets by @neweciov

    About

    voice

    This blog began in 2008 as Cocoa Touch Apps -- an app review website before iTunes had app reviews. It continues to evolve with our editor's writing habits. In this latest version, eciov has great content ranging from technology to politics. We're working on ideas for a weekly podcast as well. We don't encourage anyone to read our archives; just stick to the new stuff... it's infinitely better.

    Related Projects

    • Drift Management Accelerating Web Presence Drift Management Accelerating Web Presence
    • Rocky Mountain Mac Repair iPad, iPhone, iPod and Mac Repair. Rocky Mountain Mac Repair iPad, iPhone, iPod and Mac Repair.

    Social Media

    voice

    © 2013. All rights reserved. Written & edited by Josh Carr.