Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

71–80 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#71

“I’m remorseful… but I have a family” he says hoping this doesn’t “ruin” his life. Fuck this guy. He knew what he was doing. He should have all the consequences both those from the court and professionally: who’s going to hire him now? Maybe someone in infosec but likely not ever again in tech.

A friend once pointed out that it's likely a majority of "amateur" porn is likely private content from hacked or stolen accounts and wasn't posted by the any of the parties depicted. He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.

I don't think that's likely at all. It seems like it would be far easier to find women who are willing to take their clothes off for money (something that has been relatively easy to find for centuries) than it would be to hack hundreds of devices in order to steal such pictures - if they happen to exist.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#72
post #33
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

This was also a common technique used in Runescape back in the day. Takes me back. The much more innocent version was all chatting "Press alt q q for free gold" in Warcraft 3. Alt+q+q was the keyboard shortcut to abandon the match, which I learned the hard way.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#73
post #62

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

The fact Apple missed logins to hundreds of accounts over time from a single ip registered probably to Spectrum or Verizon ISP is a little suspect. Then again, there are probably public ips with a nat with thousands of iphones behind it at times. This might be a really hard one to detect even though it's sloppy.

Companies regularly NAT many thousands of users behind a single public IP. Additionally non-profits, schools, and others often provide WiFi for their guests/students using a supposedly residential internet account or their ISP doesn't segment basic business IPs from residentials.

In any case flagging multiple accounts logging in from a single public IP is not as useful a signal as you might think.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#74
post #62

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

The fact Apple missed logins to hundreds of accounts over time from a single ip registered probably to Spectrum or Verizon ISP is a little suspect. Then again, there are probably public ips with a nat with thousands of iphones behind it at times. This might be a really hard one to detect even though it's sloppy.

Apple itself is currently obsoleting IP-based account theft heuristics with their iCloud VPN, so they might have stopped relying on it internally already :)

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#75
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

This just means cyber security advanced so much that the simpliest way to accomplish the goal is abusing human nature.

(IMHO human was always the weakest part in the security chain and this will not change looking at social engineering)

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#76
Interesting but not mentioned in article. What are the odds?

Today: > Hao Kuo Chi, 40, of La Puente, has agreed to plead guilty to four felonies

then also a Hao Kuo Chi who was 26 in March 2007.

from 2007 https://www.latimes.com/archives/la-xpm-2007-apr-12-me-geeks...

> The suit, filed in Los Angeles County Superior Court on behalf of Sarah Vasquez, 22, and her mother, Natalie Fornaciari, 46, both from city of Industry, alleges that Geek Squad technician Hao Kuo Chi, 26, placed his cellphone in Vasquez’s bathroom during a computer service call March 4 and recorded her showering.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#77

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

Comments like are so bizarre to me. Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same. So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.

Well Apple differentiates themselves on privacy. I would prefer to do business with a company that never looks at my data for any reason. The problem with on-device scanning is the implicit backdoor.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#78
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

It’s not too weird for 306 accounts to be using iCloud from the same IP, considering stadiums, universities, etc. It’s probably highly unusual for that many of them to do an account recovery… unless the IP is an Apple store.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#79
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

This was also a common technique used in Runescape back in the day. Takes me back. The much more innocent version was all chatting "Press alt q q for free gold" in Warcraft 3. Alt+q+q was the keyboard shortcut to abandon the match, which I learned the hard way.

In Brood War it was "press Alt-F4 to download faster" when someone wanted to boot the slow user on a dial-up modem.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#80
post #5

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

https://twitter.com/matthew_d_green/status/14299631415684014...

This Twitter account continues to debase discourse about the child safety proposals with FUD. It posted incorrect information about the proposal before launch and has continued with useless speculation. How many of the hypothesized threat models which don’t pan out has he formally redacted?

If you are worried about the security of iCloud, then that can be read as more reason to prefer client side scanning. Of course the tweets are ambiguous about logical implications so you can’t engage with them directly.

Post reply on HN