Dave and I are "engineers of a certain age" and grew up listening to classic rock on KZEW and Q102 in D/FW. "Don't Fear the Reaper" was on heavy rotation on both stations. One of us said something like "Don't worry, you can't hurt the Repo and the Repo won't hurt you. Don't fear the Repo." And I think we both immediately started humming this Blue Öyster Cult favourite. It eventually grew into this.
Okay... I was able to talk to Quill? Quinn? at Apple Support who stepped me through the process of recovering an AppleId from a gmail account I no longer use. The key here was to remember the security questions, which, thankfully, I did. I don't know if there would have been a way to recover it had I forgotten them. Once I proved to the system I was the "real" owner of the AppleId at that account, I was able to add my phone number and change the security questions. Not sure why I wanted to do that last step, but it seems like I should change them (and then write down the answers on a piece of paper I put in a safe deposit box.)
The weird thing is I think I did all these things before. I did identify myself to the Support Rep (Quill? Quinn?) -- did they put this one account back in a state where it would allow me to reset? The world is filled with mystery.
Next we're going to see if I can apply for the position I originally wanted to apply for using this AppleId.
About 15 hours ago, I went through the process again and the response was (and I paraphrase) "tsk. tsk. do not annoy us with your password reset attempts. we're going to tell you more about how to recover in 15 hours." Again... annoying, but not horrible. If we're trying to make things difficult for bad actors, this isn't that big of an annoyance.
But at the end of the 24 hour waiting period, I still hadn't received an email from Apple at either of the email accounts I had used while trying to reset my AppleId. (The first is the one the AppleId was explicitly tied to and the second was an alt I use mostly for newsletters and subscribing to web site updates I'm halfway interested in. I used that because I couldn't remember if I had ever told Apple about that address.) And that seemed frustrating. You told me you were going to send me info about resetting my password, but you've welched on the deal.
And then I had a disturbing thought... Several years ago I created an AppleId with my work phone and a completely different throw-away gmail address. After digging up the password for that account, I logged in and sure enough... there's the email from Apple.
The only thing I can think is Apple tied my IP Address or location to all three email addresses involved and somehow conflated them together. I send a reset request from me@not-a-gmail-domain.com and get a response on havent_used_this_address_in_a_year@gmail.com. That is very, very weird.
But the good news is Apple says I only have to wait 7 days to reset the password on this account.
I've been thinking about getting back into writing code for the PinePhone I bought a few years ago. Maybe I will get a pre-paid t-mob or mint sim and try to create a new AppleId at a coffee shop on the far side of town.
I can't say this has filled me with a great deal of optimism. Obviously this isn't happening very often and I'm a corner case. Otherwise we would surely have heard from thousands of people saying "I can't log into my Apple account!" I'm also sure that when the Apple people were thinking through the process flows, they didn't assume I might try to reset my password while in the 24 hour iForgot wait state.
I had been a registered Apple Developer since the late 80s, though the email address in question was only attached to my dev account since around 2006. AppleIds as we know them have gone through changes... 2FA... removing questions... adding the ability to reset from an iProduct. My guess is my id was generated shortly after AppleIds became a thing. Then I stopped using it for a while and they changed the schema of the database holding AppleID details and maybe I didn't log in during some critical time frame. Then I tried to log in and got marked as a bad guy trying to attack the security of Apple's user credential integrity. I'm not... but of course, if I was I wouldn't admit it.
In any event, I'm sure my original AppleId is hopelessly horked. And that id was tied to the mobile number I've had since 1998. I suspect if I try to use that number again, apple will take a look at my IP geolocation, match it to previous attempts to recover the password and assume I'm again a bad guy trying to do bad things. If this hypothesis is correct, maybe my neighbors will have problems registering iProducts.
Apple can, of course, do whatever the heck it wants. I suspect they don't care enough to modify their processes because the number of people wedged in this state are vanishingly small. Millions (billions?) of AppleIds have been registered. Who cares if some dude from Seattle can't ever access Apple services with email or phone identifiers they want to use.
I suspect the answer to this is going to be:
a) spin up an entirely new email address. I don't think apple will have a problem with me using gmail as I'm sure they have millions of customers that already use it.
b) get a new phone number. Like I said, I was thinking about doing some coding on my PinePhonePro, so that's not a completely bad idea.
c) go across town to a coffee shop (or maybe the Apple store, do they have free wifi there?) and register a new AppleId.
d) NEVER FORGET THE PASSWORD I USED.
e) NEVER USE THAT AppleId AT MY HOME.
This is probably overkill, but Apple has successfully hidden the details of their user credential processes and I have to imply state and state transitions from their public behaviour. I really don't want to spent too much more time on this. (Now that I think about it... the problems we had with our dev certificate a few years back absolutely had the same "actual state is hidden behind an opaque wall of process" characteristic.)
All these problems are, I'm sure, Apple's way of limiting the effectiveness of social engineering attacks. And that's something I can respect. But if you're the by-catch of Apple's dragnet, it's absolutely annoying.
You can disregard the instructions for generating one [0] and just use the serial of your “Mac that hasn’t been booted since 2015.” I’ve been using one of of a long-dead long-gone G5 and prefer to use a real one from a computer I actually own (or owned).
Or use OpenCore Patcher to boot off of a usb stick and install a more recent version of macOS on your real mac. In this case. iMessage and iCloud should just work because it’ll pick up your genuine serial number.
[0] https://dortania.github.io/OpenCore-Post-Install/universal/i...
The likely issue you’re having on an older Mac and an older macOS is that it has an Apple root certificate that’s now expired and unable to register with either of those things. You’re SOL on anything prior to 10.10 Yosemite…. The apple root certs in 10.10 through 10.15 expired in 2019 and the installers for 10.10 through 10.15 were re-distributed by Apple with root certs expiring in 2029 [1] -
(internet recovery should download and reinstall the new updated version with updated root certs if yours shipped with at least 10.10 Yosemite. You have to use the hotkey for internet recovery - not the recovery partition on your HDD)
However….. OpenCore patcher will even let you install Tahoe, which doesn’t have this problem and will even get updates for another …(?) it’s the last Intel version , so whenever Apple says to hell with Intel I guess.
[1] https://tidbits.com/2019/10/28/redownload-archived-macos-ins...
This was about the same time I started de-applifying my life.
The irony is at the time I was performing a security review of the code that went into the QualComm baseband processor apple used for the original iPhone.
The first thing support.apple.com asks me to do (when I want to post a question) is to ask me to log in with my AppleId. My problem is that the AppleId that has always worked in the past no longer seems to work and when I try to create a new one, it says my mobile phone number is invalid.