Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

41–50 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#41
post #27
post #24

Earlier quoted context omitted.

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

Doesn't a popular iOS developer have the same information? UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though. edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard…

Would all of those millions install an application from the FBI knowing it gave them that information?

Just because I am ok with one organization having my information doesn't mean that I am ok with any others having the same.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#42
Refresh my memory - aren't the device tokens for the Apple Push Notification Service application-specific? That suggests this data comes from a single application, not Apple. The patchy personal information columns also suggests that this is a single (somewhat grabby) application's data store - presumably Apple would have more comprehensive records.

My wild speculation, assuming what we're told is true - the application developer shared this information with the NCFTA, who in turn shared it with the FBI. (After all, that's what the NCFTA does.) The application developer may have shared this information because they wanted the FBI to investigate a 'cybercrime' of some sort against them - who knows what, in-app purchase fraud? That could explain why the data ended up on this FBI agent's desktop.

EDIT: I refreshed my own memory - APNS tokens are device-specific, not device+app specific. I still think this is a single application's data dump, if the statement about sparse personal info is true.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#43

Haxxors, what can we lay people with no computationalizing skills do?

Get informed, and inform.

Then, one can hope, the government might actually be forced to engage in meaningful discussion about whether their ridiculously expensive and obviously damaging espionage programs make sense.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#44

I'm still somewhat unclear on the dangers involved with this leak (other than the likelihood of being tracked), but this link seems relevant: http://www.cultofmac.com/160248/what-the-hell-is-a-udid-and-...

Hmmm, it seems that despite removal of the personal info, there may be ways to link it back to partial profiles via OpenFeint... http://corte.si/posts/security/openfeint-udid-deanonymizatio...

also: http://corte.si/posts/security/udid-must-die/index.html

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#45

Haxxors, what can we lay people with no computationalizing skills do?

Get informed, and inform. Then, one can hope, the government might actually be forced to engage in meaningful discussion about whether their ridiculously expensive and obviously damaging espionage programs make sense.

It's far more likely that this data was willingly shared by an application developer who was the victim of a crime the FBI is investigating.

Not everything is a government conspiracy.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#46

Haxxors, what can we lay people with no computationalizing skills do?

Get informed, and inform. Then, one can hope, the government might actually be forced to engage in meaningful discussion about whether their ridiculously expensive and obviously damaging espionage programs make sense.

"Get informed, and inform." Straight up manifesto material. Gratzi!

"...engage in meaningful discussion.." It's hard to engage in meaningful dialogue with people who are so entrenched in their own views (BIG$$,BIGOIL,BIGGOVV-types) but we shall continue!

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#47
post #41
post #27

Earlier quoted context omitted.

Doesn't a popular iOS developer have the same information? UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though. edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard…

Would all of those millions install an application from the FBI knowing it gave them that information? Just because I am ok with one organization having my information doesn't mean that I am ok with any others having the same.

I'm presuming the FBI got the database from an App Developer. Not that the FBI released a popular iOS app.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#49
post #47
post #41

Earlier quoted context omitted.

Would all of those millions install an application from the FBI knowing it gave them that information? Just because I am ok with one organization having my information doesn't mean that I am ok with any others having the same.

I'm presuming the FBI got the database from an App Developer. Not that the FBI released a popular iOS app.

Uh, yes. I think that is a safe assumption that they did not compile the list themselves.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#50

I'm still somewhat unclear on the dangers involved with this leak (other than the likelihood of being tracked), but this link seems relevant: http://www.cultofmac.com/160248/what-the-hell-is-a-udid-and-...

Hmmm, it seems that despite removal of the personal info, there may be ways to link it back to partial profiles via OpenFeint... http://corte.si/posts/security/openfeint-udid-deanonymizatio... also: http://corte.si/posts/security/udid-must-die/index.html

Yep... well, based on this, I was able to fill in a UDID from the file and pull back an openfeint result. It didn't pull any sensitive information, but it worked. so seems to be real udids.
Post reply on HN