Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

81–90 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#81
post #11
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

> Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools. They could start by following basic security. My kid's school sets everyone's passwords to various forms of "temp123" (same password for every kid) and often talks about them in cleartext. It sets a very bad example, and it occasionally gives me hives just thinking about it.

I worked at an ed tech company that provided services for schools and this was very common in my experience.

Schools wanted to store the students' passwords in clear text in an excel basically to get less complaints from parents.

Students didn't store their password after logging in. If they needed to log in again they did not know (or did not care) how to reset their passwords. Then the problem would fall unto the parents which would then complain to the school.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#82
post #67

Earlier quoted context omitted.

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

> Even tech savvy people get tricked into clicking links or downloading attachments. Like Jim Browning, the Youtuber famous for scamming scammers, who recently fell for a phishing scam himself and ended up deleting his Youtube account. ( https://news.slashdot.org/story/21/07/28/2023241/youtube-cha... )

Has that been resolved yet? I'm really curious what advice he gives based on that experience.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#83

Earlier quoted context omitted.

This was also a common technique used in Runescape back in the day. Takes me back. The much more innocent version was all chatting "Press alt q q for free gold" in Warcraft 3. Alt+q+q was the keyboard shortcut to abandon the match, which I learned the hard way.

In Brood War it was "press Alt-F4 to download faster" when someone wanted to boot the slow user on a dial-up modem.

+++ATH0

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#84
post #37
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Google will alert the account owner (across all channels -- devices they own, and Gmail) when there's a login from a new device. Doesn't Apple do the same?

I had this idea for a service just the other night : a means of overlaying real time messages and alerts direct to any app you are using at the time. Kind of Class 0 "flash" SMS.

EDIT : it chould be a OS graphics layer service capable of drawing alerts on your active window. But I don't see why display manufacturers couldn't make this useful : the number of screens and applications anyone is logged into at any one time is increasing, and the primary screens we're using commonly have Windows Hello and Face ID type of biometric capabilities, which would be very useful for establishing the likelihood of unlawful access elsewhere.

EDIT 2: So Apple has a good position from which to offer this kind of "where are you working from?" heuristic check available to other security system software.

EDIT 3: Biometric presence data as a service to increase security for administration changes and logins hasn't come to my attention as being explored yet. I'm semi retired and extremely interested in this area if anyone is interested in a wider discussion in London - not burdened with any expectations or intentions and able to arrange professional legal cover if desired / necessary - I am interested in derivative applications for services that don't yet exist

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#85
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

Seems so naive that you'd do such a thing from your home without any type of security like a VPN.

The guy probably was the only one in the group doing this and was led to believe by the others that it was completely safe.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#86
post #62

Earlier quoted context omitted.

The fact Apple missed logins to hundreds of accounts over time from a single ip registered probably to Spectrum or Verizon ISP is a little suspect. Then again, there are probably public ips with a nat with thousands of iphones behind it at times. This might be a really hard one to detect even though it's sloppy.

Companies regularly NAT many thousands of users behind a single public IP. Additionally non-profits, schools, and others often provide WiFi for their guests/students using a supposedly residential internet account or their ISP doesn't segment basic business IPs from residentials. In any case flagging multiple accounts logging in from a single public IP is not as useful a signal as you might think.

Given that the accused was arrested in 2007 for similar sex crimes while a Geek Squad employee, one must imagine that he’s been up to this for years.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#87
post #67

Earlier quoted context omitted.

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

> Even tech savvy people get tricked into clicking links or downloading attachments. Like Jim Browning, the Youtuber famous for scamming scammers, who recently fell for a phishing scam himself and ended up deleting his Youtube account. ( https://news.slashdot.org/story/21/07/28/2023241/youtube-cha... )

This is eye opening for me.

I am very careful when it comes to phishing scams, but I guess one cannot be 100% vigilant all the time. One slip and you can fall prey.

And this is why having multiple layers of security is important. Even if you get phished, it can prevent further damage.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#88
post #49
post #33

Earlier quoted context omitted.

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

hunter2

Bearing in mind 10,000 [0], for anyone who's confused, hunter2 is a reference to an irc conversation submitted to bash.org back in 2004ish, the definitive "paste your password" thing.

http://bash.org/?244321

[0] https://xkcd.com/1053/

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#89
post #67

Earlier quoted context omitted.

> Even tech savvy people get tricked into clicking links or downloading attachments. Like Jim Browning, the Youtuber famous for scamming scammers, who recently fell for a phishing scam himself and ended up deleting his Youtube account. ( https://news.slashdot.org/story/21/07/28/2023241/youtube-cha... )

Has that been resolved yet? I'm really curious what advice he gives based on that experience.

The channel is back in full, see the followup video: https://www.youtube.com/watch?v=YIWV5fSaUB8

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#90
post #37
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Google will alert the account owner (across all channels -- devices they own, and Gmail) when there's a login from a new device. Doesn't Apple do the same?

Apple makes me authenticate the new login using a six digit code from one of my other Apple devices, which is generated if I hit "Yes" in answer to a push notification asking if it's really me trying to log in. All logged in devices get the notification, and then upon a successful login all devices get notified of the new login.
Post reply on HN