Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

61–70 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#61

Earlier quoted context omitted.

A friend once pointed out that it's likely a majority of "amateur" porn is likely private content from hacked or stolen accounts and wasn't posted by the any of the parties depicted. He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.

I don't really understand why people even make their own porn, but that aside, I really don't understand why they would save it in the cloud.

Most likely the thrill of it. They might not even be aware of saving it to the cloud. Maybe they used their phone on a stand to record and iCloud or OneDrive or Google Photos just synced it automatically.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#62

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

The fact Apple missed logins to hundreds of accounts over time from a single ip registered probably to Spectrum or Verizon ISP is a little suspect. Then again, there are probably public ips with a nat with thousands of iphones behind it at times. This might be a really hard one to detect even though it's sloppy.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#63

Isn't "stealing" inaccurate here? Copies were made, sure, but nothing was removed from their possession.

What word do you use when someone unrightfully gains possession of something that isn’t theirs? Btw a lot of words in English have multiple meanings, and transform meaning over time, which can be confusing sometimes. For example, in baseball you steal a base, which was being protected by the other team, but you don’t remove the base from the field and run off with it. I think steal works better than copy here, more a…

I think the reason "steal" can feel strange here is that we've spent the last 15 years arguing that copyright infringement is "not stealing" because the original creator has not been deprived of anything.

The phrase "not stealing" is almost exclusively used in this context on HN: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#64
post #59

Doesn't icloud have built in 2FA from an unrecognized device?

Yes, and it's heavily pushed. But if this scam really goes that deep in manipulation/phishing:

> but he managed to get victims to give him the iCloud passwords he needed to download their data.

Then he might have been able to get victims to allow his access.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#66
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

So all he needed do to avoid being caught was use a VPN?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#67
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

> Even tech savvy people get tricked into clicking links or downloading attachments.

Like Jim Browning, the Youtuber famous for scamming scammers, who recently fell for a phishing scam himself and ended up deleting his Youtube account. (https://news.slashdot.org/story/21/07/28/2023241/youtube-cha...)

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#68
post #6

Earlier quoted context omitted.

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

Do you think that Apple is going to decide whether a big dump of CSAM was uploaded by that user or a hacker and act differently based on that investigation, or just send it to LEO and let them sort it out?

Seems like there could be some legal ramifications from the choice to bypass law enforcement under certain circumstances

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#69
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

To be fair, phishing is just the path of least resistance due to overall security improvements getting rid of other low-hanging fruit. If security became worse overall, phishing would fall a bit more out of favor.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#70
post #6

Earlier quoted context omitted.

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

This comment assumes that Apple does a lot of heavy lifting to exonerate individuals who are found with CSAM beyond just reporting them to law enforcement.

Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?

Post reply on HN