Hacker News new | ask | show | jobs
by 0x0 1933 days ago
Are you saying anyone can disable anyone else's appleid by just hammering https://appleid.apple.com with their email address and bogus password?
1 comments

Exactly correct.

"If you or someone else enters your password, security questions, or other account information incorrectly too many times, your Apple ID automatically locks to protect your security and you can't sign in to any Apple services."

There is then an immediate unlock option with a trusted device or recovery key etc. There are other recovery methods if you don't have 2FA. If you don't have 2FA you are in security question land, which is more heavily rate limited even beyond this for recovery.