Earlier quoted context omitted.
If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?
They would just get an email saying that icloudbackupsupport@gmail.com (his phony address) accessed the account immediately after giving their info to icloudbackupsupport@gmail.com. He could even have told them to expect and ignore such an email.
Man steals 620k photos from iCloud accounts from home without Apple noticing
91–100 of 149 posts
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#92Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#93It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…
Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#94It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…
Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.
Is that "phishing"? Those actions should be secure to perform in a browser. The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something.
Of course, that security model sometimes has holes, but if for example clicking the link enables an XSS attack, I'd call it (primarily) an XSS attack. Same story if downloading an attachment did much more than just creating a file on disk.
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#95Earlier quoted context omitted.
It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…
This comment assumes that Apple does a lot of heavy lifting to exonerate individuals who are found with CSAM beyond just reporting them to law enforcement. Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#96Earlier quoted context omitted.
It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…
Do you think that Apple is going to decide whether a big dump of CSAM was uploaded by that user or a hacker and act differently based on that investigation, or just send it to LEO and let them sort it out? Seems like there could be some legal ramifications from the choice to bypass law enforcement under certain circumstances
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#97It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…
It’s not too weird for 306 accounts to be using iCloud from the same IP, considering stadiums, universities, etc. It’s probably highly unusual for that many of them to do an account recovery… unless the IP is an Apple store.
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#98Earlier quoted context omitted.
Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.
> tricked into clicking links or downloading attachments Is that "phishing"? Those actions should be secure to perform in a browser. The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something. Of course, that security model sometimes has holes, but if for example clicking the link enables an XSS attack, I'd call it (primaril…
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#99How does this amount to only four felonies?! Our system is so abysmally bad at understanding crimes of scale, especially when they happen over the internet. If he burgled 4,700 houses, it would be a lot more than four felonies.
Re: Man steals 620k photos from iCloud accounts from home without Apple noticing
#100Earlier quoted context omitted.
Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.
Apple makes phishing easier by always prompting the user their apple account password. Do anything including installing free apps and it requires the password.