Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

11–20 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#11
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

> Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools.

They could start by following basic security. My kid's school sets everyone's passwords to various forms of "temp123" (same password for every kid) and often talks about them in cleartext. It sets a very bad example, and it occasionally gives me hives just thinking about it.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#12
post #6

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

no

Edit: No if they use the same algorithm, but they could use other algorithm which are less abusable and no one would know the hashes in the database, so Yes I guess?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#13

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

> I named it the way I did to draw attention to this in context of CSAM enforcement...

From the site guidelines:

> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.

Just a reminder because if a mod ends up viewing this they will probably change the title back to the original.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#14
post #4

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

Scary indeed, slight correction, not the FBI [initially]; > A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure ... He was caught by random chance of this company.

If he was specifically going after famous women's accounts, I don't think it was so random, given that he went after hundreds of people and didn't cover his tracks at all. He was after celebrity photos, he was sloppy, people who try to defend against such attacks were going to catch him.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#15
post #9

Earlier quoted context omitted.

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

They would just get an email saying that icloudbackupsupport@gmail.com (his phony address) accessed the account immediately after giving their info to icloudbackupsupport@gmail.com. He could even have told them to expect and ignore such an email.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#16
post #9

Earlier quoted context omitted.

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

It’s better than nothing but still not great because the login area they present is too broad. For example, if you live in a large city and the phisher is somebody you know, seeing “New login from Your City” is not going to make you think twice.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#17
post #5

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

https://twitter.com/matthew_d_green/status/14299631415684014...

Absolutely: https://twitter.com/matthew_d_green/status/14299837034602045...

I assume each upload is tagged with device ID which first uploaded it etc. but maybe that can be spoofed as well?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#18
post #9

Earlier quoted context omitted.

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house

If the attacker was really not covering his tracks, perhaps Apple may have flagged hundreds of different iCloud account logins originating from the same location as something to look into?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#19
post #9

Earlier quoted context omitted.

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

Perhaps something in that 2FA request saying "Apple will only ask for your password in-person in a store or other authorized repair provider. Only allow this request if you know who requested it"?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#20
“I’m remorseful… but I have a family” he says hoping this doesn’t “ruin” his life. Fuck this guy. He knew what he was doing. He should have all the consequences both those from the court and professionally: who’s going to hire him now? Maybe someone in infosec but likely not ever again in tech.
Post reply on HN