Live data from Hacker News

Chinese authorities detain Apple employees suspected of selling customer data

hongkongfp.com

101–110 of 112 posts

Re: Chinese authorities detain Apple employees suspected of selling customer data

#101
post #93

Earlier quoted context omitted.

Correct me if I'm wrong but isn't this the same thing as turning iCloud backups off and doing local encrypted backups instead? It seems like a reasonable choice to me, if you don't want to store in iCloud you can keep it locally with a different encryption model.

Yes but only iCloud backups can happen automatically and wirelessly every night. For local backups you need to attach the phone to your laptop using your usb cable and click "back up" in iTunes manually every time.

This is not true. Wi-Fi Sync (that includes iTunes backup) is available since iOS 5[1]. It works automatically if phone is plugged in and computer used for back is online.

[1] http://osxdaily.com/2011/10/13/wi-fi-sync-for-iphone-ipad-io...

Re: Chinese authorities detain Apple employees suspected of selling customer data

#102
post #3

Oh snap. And Apple has been touting itself as the champion of privacy in comparison with Google, Facebook and Microsoft... This doesn't look good for them

It's not Apple's policy to sell information. This is employees engaging in criminal behavior. Still not good for Apple, but it's correctable (firing and pressing charges as appropriate; institute stronger internal policies on both hiring and information access). Facebook and Google can't stop selling our information without going out of business (or a major pivot).

Google doesn't sell our information.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#103
post #92

Earlier quoted context omitted.

You don't have any contact details in your profile; check mine and send me any details you can. I'll ping the appropriate people.

Also, we need your ss# and your keys

If HappyTypist isn't comfortable emailing my @apple.com email address they can file a bug at https://bugreport.apple.com and email me the bug # instead.

Assuming this story is true, I would personally like to catch the person responsible.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#104
post #59
post #43

Earlier quoted context omitted.

It's technological negligence if you set out to protect customers privacy, but your employees decide to steal it anyway, because they can.

By that argument, all theft is negligence.

Yes, and if this is indeed true, so what?

Re: Chinese authorities detain Apple employees suspected of selling customer data

#105
I find it odd that a company that touts user privacy (an immediate pivot when their iAds venture failed spectacularly) and security would have their user data so easily stolen. There is absolutely no way these corrupt Apple employees should have even had access to this type of sensitive information.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#106
post #101
post #93

Earlier quoted context omitted.

Yes but only iCloud backups can happen automatically and wirelessly every night. For local backups you need to attach the phone to your laptop using your usb cable and click "back up" in iTunes manually every time.

This is not true. Wi-Fi Sync (that includes iTunes backup) is available since iOS 5[1]. It works automatically if phone is plugged in and computer used for back is online. [1] http://osxdaily.com/2011/10/13/wi-fi-sync-for-iphone-ipad-io...

I stand corrected, I did not realize this supported automatic backups. It still requires your laptop to be on the same LAN though. It'd be nice if one could host a simple https server somewhere and configure the iOS unit to sync over the internet.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#107
post #24

Apple does not allow your iOS iCloud data to be encrypted in a manner where Apple cannot access it. As is alluded to in this article. Privacy advocates and privacy caring IT specialists have repeatedly asked Apple to offer such an option, but so far Apple has decided that regular people would turn such an option on, forget their password, then ask Apple for help and would be unhappy with their brand experience if App…

Nothing in the article suggests that iCloud data was compromised. It said

> users’ names, phone numbers, Apple IDs, and other data

Names, phone numbers, and Apple IDs just require access to directory services, doesn't need to touch iCloud at all. It doesn't say what "other data" is, but presumably that's not iCloud either, because it if was iCloud data that would be a much bigger headline and wouldn't have been omitted from the article.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#108
post #104
post #59

Earlier quoted context omitted.

By that argument, all theft is negligence.

Yes, and if this is indeed true, so what?

It means that any system or organization that isn't already perfectly secure is an embodiment of negligence.

Since that is impossible, all companies and all systems are negligence.

A term that applies to everyone means nothing.

Nevertheless you can say it and make businesses you don't like sound bad.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#109
post #66

So now after forcing Microsoft to have a Chinese version of Windows 10 without spyware, Blizzard forced to show the Overwatch loot boxes odds and this, we are living in a World where China, "Great Firewall" China is now the biggest advocate of users privacy. What is happening?

Hitler was also a fan of nature and animals...

So you know, even though China is a dictatorship it sometimes still does good things, like catch common criminals.

Re: Chinese authorities detain Apple employees suspected of selling customer data

#110

Can confirm. I've had someone contact me on snapchat and show me screenshots of Apple's internal tools and offer to run queries for $$$. He was willing turn off 2FA, change the email, and reset the password (thus, giving me access) for $$$$. He told me that he texts a friend who calls and pretends to be the customer in question, and texts him all the verification questions he has to ask as part of SOP. Many AppleCare…

Huh? With 2fa activated there are no verification questions on the account, it makes that very clear when you enable 2fa.
Post reply on HN