Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

11–20 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#11
>The suspects, who worked in direct marketing and outsourcing for Apple in China [...]

Uh, would they be given unrestricted access to user data? Or does every Apple employee have access to this data and are left to exercise restraint?

And what about Apples claim that data is encrypted at rest?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#12

Can confirm. I've had someone contact me on snapchat and show me screenshots of Apple's internal tools and offer to run queries for $$$. He was willing turn off 2FA, change the email, and reset the password (thus, giving me access) for $$$$. He told me that he texts a friend who calls and pretends to be the customer in question, and texts him all the verification questions he has to ask as part of SOP. Many AppleCare…

Let em come out of the woodwork.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#14
This is always the argument that makes my friends and family call be paranoid in data privacy discussions: "Even if the company has good intentions when they collect your data, there's no telling who else might end up with access to it in the future."

Obviously this is bad overall, but at least now I can point to a specific example of this happening.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#15
> Reporters successfully obtained a trove of material on one colleague — including flight history, hotel checkouts and property holdings — in exchange for a payment of 700 yuan (US$100).

So it's not just email addresses / metadata from iCloud. This implies that 1) at least some iCloud data is stored unencrypted at rest, and 2) employees can query this data using internal tools.

This seems pretty bad.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#16

Hoping comments can resist the urge to turn this into an apple bashing thread. Having someone purposefully steal your data from the inside doesn't mean you don't care about privacy. They likely won't reveal anything but I'm curious how they could get the info out of Apple systems. Most companies of Apple's size lock down work stations to the point of slowing down workers efficiency to keep customer data safe. Especia…

The article author couldn't determine from the police statement if the criminals had access to just chinese customer data or foreign customer data as well. If the criminals had access to foreign customer data as well that would a failing on Apple's part (and might result in some sanction in Europe for example which has been placing more emphasis on the privacy of its citizens' data with American companies after the reveals from Snowden)

Re: Chinese authorities detain Apple employees suspected of selling customer data

#17
Suddenly potential workings behind celebrity nude photo exposure scandals, the most recent one just a month/weeks back, becomes more clear. Of course, brute forcing, weak passwords, or phishing, may still have happened, but this sure sounds convenient and perhaps not even expensive for hackers sharing the cost. It also sounds troubling with government staff exposure and all.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#18
post #3

Oh snap. And Apple has been touting itself as the champion of privacy in comparison with Google, Facebook and Microsoft... This doesn't look good for them

Being the victim of criminal behaviour, and not caring about other people's privacy are two very different things.

Caring about peoples privacy, and technological negligence that results in that privacy being impinged upon, are in fact the same issue.
Post reply on HN