Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

31–40 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#31
I have been thinking about "nudes" (which I will use as a shorthand to describe digital images of a person sans clothing, almost always taken by that person) in terms of cultural evolution. A couple of years ago I mentioned, on HN, that I knew Jenni, of JenniCam, before the "cam," back when she was just experimenting with this new digital camera device. And then they became more and more available.

For a brief time there was a kind of explosion of said nudes. I could be on Yahoo Chat and women would just send them, unsolicited, and I think that was the era of people not realizing that nudes can get around, like any other secret, once you let go of them. My guess is that probably came to an end roughly ten years ago or so, and people now hold onto them tightly, which is probably much more reasonable.

People still take nudes, and pass them on, but I think there is a level of discretion that has increased, although I know some women who mention being pestered for such by men they know. Still, these images are on cameras and cloud storage and such, and for the life of me I do not get the hunger that drives such a risky behavior as getting into hacked iCloud accounts versus, I don't know, average sources of free nudes? Poor judgment of course abounds in so many reported crimes but ... how does one even trawl more than half a million photos for nudes? Was he planning on going through them individually? Was he going to make a neural net to scan for skin?

I just find the whole thing a little baffling in this day and this age.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#32
post #9
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

Not just better education around security practices, but better understanding around control of your content, where it's stored, what happens to content when you press that button in an app. I don't want to victim blame here, and this guy is a total creep, but the victims uploaded their nudes to the Internet. At that point, the cat was out of the bag.

Part safely using the Internet is having the knowledge and being aware of where (in your apps) the boundary is between your local device and the global network that everyone has access to. People need to understand: When you sync to a cloud service, you're sending your content to someone's computer unknown to you. Yes, in this case, it's Apple's computer, but that didn't stop this guy. Once you sync something online, it's out of your hands, and on the Internet now.

I personally treat all cloud services as if they were accessible publicly and anonymously, and will inevitably be printed in my local newspaper, and only upload content to those services where I am comfortable with that level of exposure.

EDIT: To clarify, I wish applications would stop blurring the line between "on my device" and "on the Internet". I've used applications where, to an unsophisticated user, the save dialog looks like it's saving to their computer but it's actually in the cloud. Add to it all these apps that try to be helpful by seamlessly (and invisibly) keeping local content in sync with the cloud versions and you have a recipe for disasters like this. Have an explicit "upload this thing to the Internet" button, please!

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#33
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

You mean like this?

EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM.

Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅

I can see it, but you can't. Try it!!!!

An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#34
post #33
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Edit: just tried this it DOES NOT work, don't do it

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#35
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Edit: just tried this it DOES NOT work, don't do it

if you actually did, you should change your password now. And pick a more secure one. (not going to try if what you posted actually works...)

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#36
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Edit: just tried this it DOES NOT work, don't do it

*Facepalm* What were you thinking?!

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#37
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Google will alert the account owner (across all channels -- devices they own, and Gmail) when there's a login from a new device. Doesn't Apple do the same?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#38

Earlier quoted context omitted.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house If the attacker was really not covering his tracks, perhaps Apple may have flagged hundreds of different iCloud account logins originating from the same location as something to look into?

There isn’t enough information in the linked article to reveal the attacker’s methods. Do you have further information or are you speculating?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#39
post #35

Earlier quoted context omitted.

Edit: just tried this it DOES NOT work, don't do it

if you actually did, you should change your password now. And pick a more secure one. (not going to try if what you posted actually works...)

It doesn't. DO NOT TRY. I was just giving an example of a classic scam, and I can't believe someone actually tried it.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#40

Earlier quoted context omitted.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

It’s better than nothing but still not great because the login area they present is too broad. For example, if you live in a large city and the phisher is somebody you know, seeing “New login from Your City” is not going to make you think twice.

If you refuse to think, even when prompted, that's on you. You should think about whether you logged in from the city and device/OS named in the alert.
Post reply on HN