Hacker News new | ask | show | jobs
by res0nat0r 4307 days ago
No as I can try and guess your login credentials and that is a perfectly acceptable and valid workflow which isn't exploiting anything.

I think the issue is that the previously posted Find My Iphone code didn't rate limit invalid logins and this was used to bruteforce creds. This is probably the real underlying issue and not any type of buffer overflow / exploit etc.