Rodan

About

Username
Rodan
Joined
Visits
1
Last Active
Roles
member
Points
5
Badges
0
Posts
1
  • If you're getting dozens of password reset notifications, you're being attacked

    Apple has released a supplemental (Revised) firmware update to iOS 17.4.1 which I believe may be in response to these MFA bombing attacks but beware.

    After becoming aware of this update which can only be done via cable connection to your Mac and consulting a few others in the field I decided to apply it.  On connecting my iPhone 13 Pro Max currently running 17.4.1 to my M1 MBP and checking for updates there was indeed an update.

    I dutifully clicked "Update" and the download commenced.  On completion of the download installation began and proceeded roughly halfway before I received a Notification:
    The problem with this was the only option offered was to click "OK" resulting in; "There is a problem with the iPhone "iPhone", which requires it to be updated or restored."  And in the resulting dialogue I get; "The iPhone "iPhone" could not be restored. An unknown error occurred (9)."
    This put me into a loop.  Ejecting the iPhone resulted in DFU mode and reconnecting it put me back to, "There is a problem with the iPhone "iPhone", which requires it to be updated or restored."  Note the iPhone is now called, "iPhone", not "Rod's iPhone 13 Pro Max". 

    The only way I was able to get out of this was to employ a third party app that I had previously used to backup my iPhone and I was able to restore it using that.
    So, maybe I was just unlucky, a number of other people I've spoken to have successfully applied this "revision" although they all note it took an inordinately long time.  
    My point is, until this revision is released as an OTA (Over The Air) update I advise caution using it.  I nearly "bricked" my iPhone and I wouldn't want others to suffer the same fate.
    In the mean time as regards the MFA bombing attack you can always simply decline the offer to change your password as per this article on 9to5Mac;
    https://9to5mac.com/2024/03/28/protect-against-iphone-password-reset-attacks/

    muthuk_vanalingam