Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

91–100 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#91
post #15

Earlier quoted context omitted.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?

They would just get an email saying that icloudbackupsupport@gmail.com (his phony address) accessed the account immediately after giving their info to icloudbackupsupport@gmail.com. He could even have told them to expect and ignore such an email.

There should be a request for approving the login attempt, and if you say yes, you get a six digit code to enter on the device trying to connect. Then when that succeeds, you get another push notification about it succeeding.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#92
I am no fan of apple but this man used phishing attacks to gain access to just 306 icloud accounts. That hardly seams a significant failing on apples part. He used the credentials of the victims so I'm not really clear how rate limiting should have played a role, you should be limited from accessing your own account?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#93
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

Apple makes phishing easier by always prompting the user their apple account password. Do anything including installing free apps and it requires the password.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#94
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

> tricked into clicking links or downloading attachments

Is that "phishing"? Those actions should be secure to perform in a browser. The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something.

Of course, that security model sometimes has holes, but if for example clicking the link enables an XSS attack, I'd call it (primarily) an XSS attack. Same story if downloading an attachment did much more than just creating a file on disk.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#95

Earlier quoted context omitted.

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

This comment assumes that Apple does a lot of heavy lifting to exonerate individuals who are found with CSAM beyond just reporting them to law enforcement. Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?

The negative PR from a false accusation would be expensive. On top of the judgement itself, and you know that Apple has deep enough pockets that someone will be looking for a big score.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#96
post #68

Earlier quoted context omitted.

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

Do you think that Apple is going to decide whether a big dump of CSAM was uploaded by that user or a hacker and act differently based on that investigation, or just send it to LEO and let them sort it out? Seems like there could be some legal ramifications from the choice to bypass law enforcement under certain circumstances

Depends on if they think the public will buy their claim of "we just let law enforcement sort it out." If they think the public will blame them for the false accusation, they are incentivized to avoid letting it happen.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#97
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

It’s not too weird for 306 accounts to be using iCloud from the same IP, considering stadiums, universities, etc. It’s probably highly unusual for that many of them to do an account recovery… unless the IP is an Apple store.

It's not weird for 1000 users to be simultaneously connected via the same IP because of CGNAT. This is where you would have to do something like browser fingerprinting to try to work out if they are the same person.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#98

Earlier quoted context omitted.

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

> tricked into clicking links or downloading attachments Is that "phishing"? Those actions should be secure to perform in a browser. The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something. Of course, that security model sometimes has holes, but if for example clicking the link enables an XSS attack, I'd call it (primaril…

The cross site requests thing has thankfully been fixed. Modern browsers will soon (or already do?) stop sending another sites cookies when making a request from a different domain.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#99
> 4,700 with iCloud user IDs and passwords

How does this amount to only four felonies?! Our system is so abysmally bad at understanding crimes of scale, especially when they happen over the internet. If he burgled 4,700 houses, it would be a lot more than four felonies.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#100
post #93

Earlier quoted context omitted.

Phishing is one of the most common entry points of cyberattacks. Even tech savvy people get tricked into clicking links or downloading attachments.

Apple makes phishing easier by always prompting the user their apple account password. Do anything including installing free apps and it requires the password.

This helps the user remember their password. Forgetting your apple id password makes all of your apple devices essentially bricks as you need it to unlink your account or factory reset.
Post reply on HN