Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

61–70 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#61
post #24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

what kind of verification do you have that the file was pulled from an FBI computer?

could anonymous have hacked this information from Apple or a carrier themselves? what information is present that they didn't do that?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#62
interestingly enough, top ten ios devices names:

  42797 'iPhone'    
  5191 'iPod touch'
  3136 '“Administrator”的 iPad'
  2202 '“Administrator”的 iPhone'
  1534 'Owner’s iPad'
  1453 ' iPhone'
  1309 'Administrator’s iPad'
  1196 'Administrator’s iPhone'
  1141 'PdaTX.Net'
  1058 'John’s iPad'

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#63
Looks like they've got Obama's iPad:

thea:Downloads admin$ cat ./iphonelist.txt | grep -i obama '473d6e1ebf0b100ed172ce5f69c97ba6c8f12ad5','766a23201c6089be11845bfef624dbaada68be52155079850951836e9373e5cd','hobamain','iPad' 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','Obama','iPad'

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#64
post #2

DL links for the lazy: http://freakshare.com/files/6gw0653b/Rxdzz.txt.html http://u32.extabit.com/go/28du69vxbo4ix/?upld=1 http://d01.megashares.com/dl/22GofmH/Rxdzz.txt http://minus.com/l3Q9eDctVSXW3 https://minus.com/mFEx56uOa http://uploadany.com/?d=50452CCA1 http://www.ziddu.com/download/20266246/Rxdzz.txt.html http://www.sendmyway.com/2bmtivv6vhub/Rxdzz.txt.html

Here's another mirror: http://www.mediafire.com/download.php?vkyeta7zytgqyhi

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#65
This is huge. I've been fearing this kind of leak for a long time. If you're unsure why this is huge, here are some posts of mine on this issue showing de-anonymization, complete takeover of social media accounts, and more:

De-anonymizing UDIDs with OpenFeint: http://corte.si/posts/security/openfeint-udid-deanonymizatio...

A survey of how UDIDs are used: http://corte.si/posts/security/apple-udid-survey/index.html

Why the Apple UDID had to die: http://corte.si/posts/security/udid-must-die/index.html

I've often been asked what I thought the worst-case scenario is regarding the mis-management of UDIDs. My answer has always been that a large UDID database leaking would be a privacy catastrophe...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#66

Earlier quoted context omitted.

This is the stated reason for the release - to have people ask why an agent has 12m UDID numbers on his laptop. They released 1m out of the 12m UDIDs so that they can guarantee a statistical sample that can be verified, while preserving a bit of privacy. Along with the UDIDs were other columns with an assortment of personal data, although there were a lot of holes.

How large would a 12m line long .csv file be? Not sure how many bytes per entry, but it would be of the order of gigabytes.

It would probably compress well

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#67
post #20
post #17

Earlier quoted context omitted.

true, but in this case the password contains "antis3c" [Antisec], the group that is responsible.

So download it, decrypt it, and pick a different password. Takes a couple minutes, tops. And if your 'release' gets more attention than the original, how does the original prove that's what happened, or even get heard?

You can see who came first, the internet knows.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#70
post #52
post #47

Earlier quoted context omitted.

I'm presuming the FBI got the database from an App Developer. Not that the FBI released a popular iOS app.

The FBI stole an Instapaper server in an unrelated raid http://blog.instapaper.com/post/6830514157

So Marco Arment could go all CSI for us and let us know whether the sample corresponds to info he retained and which would have been on the server at the time.
Post reply on HN