Christopher Bouzy
A
thread 1/2
⛔️📢I have released a statement regarding a security incident that we were notified about earlier this morning.

You can also read the full statement here: https://help.spoutible.com...
10:03 AM - Feb 04, 2024
Avatar Avatar Avatar
0
92
309
Christopher Bouzy
A
thread 2/2
Today at 1 PM EST, we will discuss this incident and address your concerns.

Join us here: https://spoutible.com/pod/...
10:03 AM - Feb 04, 2024
6
89
Apple Freak
A
Saw this from Troy's writeup and had to make an account. That disclosure report minimizes what was leaked so hard I'd call it actively deceptive. No, the passwords themselves weren't leaked, but when you include the actual unsalted hashes, 2FA seeds, and PW reset codes, is that really any better?
In response to Christopher Bouzy.
11:04 AM - Feb 05, 2024
1
1
Apple Freak
A
In response to Apple Freak.
For the tech averse, this means that even without access to your email, anyone can reset your password and take over your account, even with 2FA enabled. And, even then, it'd be easy enough to decrypt your password from what was leaked and get your original password in plaintext.

That's abysmal.
11:13 AM - Feb 05, 2024
0
3

 

{{ notificationModalContent }} {{ promptModalMessage }}