Hacker News new | ask | show | jobs
by cantsingh 1830 days ago
I think you are misunderstanding what he has achieved. There is a secondary attack that he theorizes was possible and patched by Apple before he demonstrated an ability to exploit it. I agree that he should not receive any bounty reward for this (theoretical) attack.

However, the first half of the article focuses on him successfully being able to reset the password on any iCloud account that hadn't been used to log in to an Apple device.

Being able to remotely change the password of an iCloud account should earn him the full $100,000 reward, even if it is only on some subset of iCloud accounts.