Nice blog post by @LaxmanMuthiyah. All the details check out, it sounds like Apple had a massive vulnerability in their iCloud infrastructure and downplayed the severity. With passwords that are way too short, rate limiting is your only line of defense.

