[HN Gopher] Tell HN: Apple refuses to delete a personal domain A...
       ___________________________________________________________________
        
       Tell HN: Apple refuses to delete a personal domain Apple ID that I
       didn't create
        
       I have a personal domain with catch-all email enabled. Someone
       signed up for an Apple ID with a scrambled (random) username on
       that domain, and I got notified about it on my inbox.  This happens
       every few months and I have usually ignored them because my
       understanding is that Apple wouldn't allow usage of that Apple ID
       if the email address is not verified. Since this happens every few
       months, I decided to act on it this time: instead of clicking on
       "verify now" on the email I received, I worked through the password
       reset flow and managed to set a new password to the account.
       However, attempting to delete the Apple ID account prompts for
       answers to security questions, which I don't have because I did not
       create the account in the first place.  There's a flow to reset
       security questions as well, but that prompts for an answer to the
       existing questions.  In chatting with an Apple support member,
       there's apparently a concept of "rescue email" which is different
       from the Apple ID and can be used to set new security question
       answers if the old ones are unknown. I don't get that option which
       indicates that the account doesn't have a rescue email set.  Since
       all of my available options are fruitless, I asked that the chat
       support member escalate my case to a higher-up and they offer to
       arrange of a phone support because supervisors seem to be available
       only on phone support. That's not ideal for me because I am a deaf
       person and I don't sign, and for the reason that I don't want my
       mobile number to be associated with this Apple ID that I didn't
       create.  At this point, I am curious to hear if anyone else has
       ever been in this situation and to understand how you've gotten out
       of it. I can't imagine that this is an isolated case.  Disabling
       catch-all on my domain isn't a solution because that'd just make me
       unaware of new accounts that are being created on my domain.
       Shouldn't Apple be hard-verifying the email address before allowing
       any type of usage?
        
       Author : archb
       Score  : 15 points
       Date   : 2022-11-26 20:37 UTC (2 hours ago)
        
       | clintonb wrote:
       | Why does it matter that the account exists?
        
       | gardenfelder wrote:
       | Somewhat similar: my email just happens to be ideal for people in
       | asia (read: S.Korea) to assume when they create accounts; one of
       | them actually somehow (nobody knows how) took over my Apple dev
       | account.
       | 
       | In my case, I got a real human on the phone and we walked through
       | reclaiming my own account; when I got in, I could see the
       | Korean's actual name, visa card, address, etc. I erased all that,
       | then setup 2 factor authentication.
       | 
       | Something like that happened on battle.net. They are not smart
       | enough to use email validation, so imagine my surprise when my
       | email was already used when I decided to sigh up. I managed to
       | reset the pwd, so that fellow will never be able to play again on
       | that account, but battle has not really been satisfactorily
       | responsive (the account seems rigged for talking in Korean, so
       | it's useless); I ended up using a different email.
       | 
       | Websites which don't use email validation are problematic.
       | 
       | But, Apple does pay attention. It does seem that they should pay
       | more attention to you and your specific case.
        
       | butz wrote:
       | Reminds me of the time when someone has created PlayStation
       | account using my email and I was unable to take over that
       | account, as I did not know answers to security questions.
       | 
       | Seriously, even large companies should've made email verification
       | mandatory not only in case of user error, but malicious, or just
       | plain annoying use of other people email address. Not to mention
       | getting account banned and unable to use your email on platform
       | when you might actually need it.
       | 
       | Back to the topic: now that you've changed password on account,
       | maybe you could just leave it as is, that way no one will be able
       | to re-create mentioned account again. Although that still leaves
       | the opportunity for malicious user trying to recover that
       | account, but I'd bet he doesn't know security answers either.
        
       ___________________________________________________________________
       (page generated 2022-11-26 23:01 UTC)