Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

21–30 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#21
post #5

Earlier quoted context omitted.

https://twitter.com/matthew_d_green/status/14299631415684014...

Absolutely: https://twitter.com/matthew_d_green/status/14299837034602045... I assume each upload is tagged with device ID which first uploaded it etc. but maybe that can be spoofed as well?

There's no real reason to assume this is true, because Apple's systems didn't detect hundreds of accounts being accessed from a single, home IP...

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#22

“I’m remorseful… but I have a family” he says hoping this doesn’t “ruin” his life. Fuck this guy. He knew what he was doing. He should have all the consequences both those from the court and professionally: who’s going to hire him now? Maybe someone in infosec but likely not ever again in tech.

A friend once pointed out that it's likely a majority of "amateur" porn is likely private content from hacked or stolen accounts and wasn't posted by the any of the parties depicted.

He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#23

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

Comments like are so bizarre to me.

Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same.

So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#24
post #14
post #4

Earlier quoted context omitted.

Scary indeed, slight correction, not the FBI [initially]; > A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure ... He was caught by random chance of this company.

If he was specifically going after famous women's accounts, I don't think it was so random, given that he went after hundreds of people and didn't cover his tracks at all. He was after celebrity photos, he was sloppy, people who try to defend against such attacks were going to catch him.

We've seen more decentralized and sophisticated attacks of the same type against iCloud ("the fappening" etc.) which were kept mostly private for years before being made public.

The fact that those hacks quickly were flushed from the news cycle without a bunch of public lawsuits etc. makes me suspect Apple very proactively went out and made settlements with the more high profile victims of those hacks. Of course, I have no proof of this at all, so it's purely speculation, but it was odd to see almost nothing come out of those hacks.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#25
post #6

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought.

Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot.

And then in this case they aren't hacking the phone but the account which means Apple is going to notice a set of photos coming from an IP address they haven't seen used from that account before.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#26
post #14

Earlier quoted context omitted.

If he was specifically going after famous women's accounts, I don't think it was so random, given that he went after hundreds of people and didn't cover his tracks at all. He was after celebrity photos, he was sloppy, people who try to defend against such attacks were going to catch him.

We've seen more decentralized and sophisticated attacks of the same type against iCloud ("the fappening" etc.) which were kept mostly private for years before being made public. The fact that those hacks quickly were flushed from the news cycle without a bunch of public lawsuits etc. makes me suspect Apple very proactively went out and made settlements with the more high profile victims of those hacks. Of course, I h…

> without a bunch of public lawsuits

Apple is not at fault here though.

These people have clicked on a phishing email no different to a banking or retail one.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#27
post #6

Earlier quoted context omitted.

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

Not giving it 10 seconds of thought seems common in most HN reactions to the whole CSAM thing.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#28
>Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house in La Puente, Bossone said. The FBI got a search warrant and raided the house

He goes through the trouble of phishing so many accounts and photos, only to access them directly from his own residence?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#29

“I’m remorseful… but I have a family” he says hoping this doesn’t “ruin” his life. Fuck this guy. He knew what he was doing. He should have all the consequences both those from the court and professionally: who’s going to hire him now? Maybe someone in infosec but likely not ever again in tech.

A friend once pointed out that it's likely a majority of "amateur" porn is likely private content from hacked or stolen accounts and wasn't posted by the any of the parties depicted. He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.

I don't really understand why people even make their own porn, but that aside, I really don't understand why they would save it in the cloud.
Post reply on HN