Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

51–60 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#51

Isn't "stealing" inaccurate here? Copies were made, sure, but nothing was removed from their possession.

What word do you use when someone unrightfully gains possession of something that isn’t theirs?

Btw a lot of words in English have multiple meanings, and transform meaning over time, which can be confusing sometimes. For example, in baseball you steal a base, which was being protected by the other team, but you don’t remove the base from the field and run off with it.

I think steal works better than copy here, more accurately conveying meaning and intention, and unjust access.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#52

Earlier quoted context omitted.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house If the attacker was really not covering his tracks, perhaps Apple may have flagged hundreds of different iCloud account logins originating from the same location as something to look into?

That's not really a reliable/actionable signal overall - my previous employer had like 20,000 employees NATed behind a single IP.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#53

Earlier quoted context omitted.

A friend once pointed out that it's likely a majority of "amateur" porn is likely private content from hacked or stolen accounts and wasn't posted by the any of the parties depicted. He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.

I don't really understand why people even make their own porn, but that aside, I really don't understand why they would save it in the cloud.

If I take a photo or a video on my iPhone, it's uploaded to iCloud automatically, and afaik there is no way to remove it from iCloud while still keeping it in the photo library on the device without opting out of iCloud Photos entirely.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#54

>Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house in La Puente, Bossone said. The FBI got a search warrant and raided the house He goes through the trouble of phishing so many accounts and photos, only to access them directly from his own residence?

Sure. All he did was a social engineering by sending people an email asking for their password. There is no indication that he is actually technically competent.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#55

Earlier quoted context omitted.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house If the attacker was really not covering his tracks, perhaps Apple may have flagged hundreds of different iCloud account logins originating from the same location as something to look into?

IP NATing is a common thing done by most isps, you can literally have 100s or even thousands of users using the same ip.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#56
post #49
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

hunter2

all I see is ****

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#57
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#58
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Let me try - dmich87!@#

Yep, works perfectly.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#60
post #11
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

> Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools. They could start by following basic security. My kid's school sets everyone's passwords to various forms of "temp123" (same password for every kid) and often talks about them in cleartext. It sets a very bad example, and it occasionally gives me hives just thinking about it.

A friend worked at a UK government site that one week complained about an increase in "Russian" attempted intrusions and literally the next week issued an instruction in an unsigned email to all staff to change their password to a new password given in plaintext in the email.

The instruction, they thought, had to be a poor phishing attempt - but no, it was a genuine email from the IT department and the friend was punished (!!) for questioning the instruction and not immediately complying.

It may not have been the same password across the organisation but their's was reportedly word based and quite short.

Post reply on HN