Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

21–30 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#21
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

Is there any evidence that this data comes from the source they claim?

And is there some way to validate these are real UDIDs?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#22
The fact that there is a column for APNS (Apple Push Notifications) suggests that this is a database dump from an iPhone app that supports push notifications. APNS tokens are generally tied to a specific app so it may be possible to figure out what app leaked their database.

The "NCFTA" seems to deal with identity theft. (Ironic)

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#23
post #8

Earlier quoted context omitted.

It proves that the author of the rant is the leaker of the data, not just some guy linking to data someone else posted. It also causes all the data to be released atomically even if it took a while to upload to all the places.

> It proves that the author of the rant is the leaker of the data, not just some guy linking to data someone else posted. I don't see what would stop you from stating the password to a file you didn't upload.

because you wouldn't know the password before the public announcement, and after the announcement it doesn't matter.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple.

From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." (http://www.ncfta.net/)

Is Apple willingly sharing personal information with the FBI through the NCFTA?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#25
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

holy shit.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#27
post #24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

Doesn't a popular iOS developer have the same information?

UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though.

edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard for push notifications).

http://developer.apple.com/library/mac/#documentation/Networ...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#28

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

I was confused by the writing style as well. It seems to be almost intentional. I wonder if it's a way of avoiding any style or nuances that could be attributed to a single person. Almost like a cut and paste ransom note.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#30
As an Australian I am intrigued by the following:

just a comment: we are still waiting for published news about the $ 2 billions worth loans Assad has taken from Russia, mentioned on the syrian mails and also about the transfer of money to austrian banks etc.... and also cocks... So, don't be lazy journos and look for them.

Any one have any additional info on that?

EDIT: Derp...thanks for the correction. I read too fast. Still intrigued if anyone knows anything more.

Post reply on HN