Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

31–40 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#32

As an Australian I am intrigued by the following: just a comment: we are still waiting for published news about the $ 2 billions worth loans Assad has taken from Russia, mentioned on the syrian mails and also about the transfer of money to austrian banks etc.... and also cocks... So, don't be lazy journos and look for them. Any one have any additional info on that? EDIT: Derp...thanks for the correction. I read too f…

Austrian banks.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#34
post #22

The fact that there is a column for APNS (Apple Push Notifications) suggests that this is a database dump from an iPhone app that supports push notifications. APNS tokens are generally tied to a specific app so it may be possible to figure out what app leaked their database. The "NCFTA" seems to deal with identity theft. (Ironic)

APNS tokens are generally tied to a specific app so it may be possible to figure out what app leaked their database

This isn't true, APNS device tokens are shared among apps on a device. The only time a device will have more than one device token is if it's being used for development.

This isn't to say that Apple couldn't correlate the device tokens by looking for shared apps with active APNS entitlements.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#35

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

I was confused by the writing style as well. It seems to be almost intentional. I wonder if it's a way of avoiding any style or nuances that could be attributed to a single person. Almost like a cut and paste ransom note.

I wouldn't be surprised in the slightest. A lot of work has been done on adversarial stylometry recently, for precisely this reason.

ccc presentation: http://www.youtube.com/watch?v=-b0Ta9h62_E

EDIT: also as grumpysimon says, it's a proud tradition going back decades.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#36

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

I was confused by the writing style as well. It seems to be almost intentional. I wonder if it's a way of avoiding any style or nuances that could be attributed to a single person. Almost like a cut and paste ransom note.

It's elite (or 1337 if you will). It's supposed to sound cool. All the underground computer groups have talked like that since the early warez/cracking/phreaking scene.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#37
Question: is it possible for a malicious hacker to use this information for anything? E.g. sending rogue push notifications to a user, or tracking down a user's additional personal information by knowing his/her device UDID or APNs token?

I sincerely hope both the U.S. government and Apple address this. I'd also be interested in hearing why Apple chose to have hardware coded unique ids for each device.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#38
post #24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

>Is Apple willingly sharing personal information with the FBI through the NCFTA?

Define "willingly."

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#40
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

Another important money quote:

    we trimmed out other personal data as, full names, cell     
    numbers, addresses, zipcodes, etc. not all devices have 
    the same amount of personal data linked. some devices
    contained lot of info.
So the release "just" contains UDID's and zip codes.
Post reply on HN