Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

91–100 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#91
post #79

Earlier quoted context omitted.

maybe an enterprise location or school that bought in bulk?

Wouldn't the devices' names still be changed when individual members of the enterprise/school activated them?

Devices being used in a kiosk-like or other setting in which they are mostly not being used by people who would be responsible for activating them?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#92

I have found my own UDID - I can confirm these are real UDID's - and now I want to know why an FBI agent had my (a brit) UDID on their laptop.

Have you ever traveled to the US with that handset and did you buy it new?

I haven't traveled to the US with this particular handset. I got a replacement handset a few months ago on the insurance. The serial number makes it seem like it was assembled in week 31 of 2011, so what happened to it before it got into my hands I'm not quite sure.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#93
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

Another important money quote: we trimmed out other personal data as, full names, cell numbers, addresses, zipcodes, etc. not all devices have the same amount of personal data linked. some devices contained lot of info. So the release "just" contains UDID's and zip codes.

Actually, it appears to only be UDID's, APNS tokens, device name, and device type.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#94
post #26

Putting a file of user data on a laptop is a fireable offense at at any reputable organization. Sad that the FBI is less careful about user data protection than consumer Internet companies.

Kinda odd isn't it. My organization issued me a laptop to store all the confidental financial data I work with.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#96
post #57

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

> Surely this is illegal. So? Pretty sure torture and car bombing innocent women and children is also illegal. http://en.wikipedia.org/wiki/1985_Beirut_car_bombing

We're talking about the FBI, not the CIA. You know, the same FBI that walked from Gitmo because detainee constitutional rights were being violated when they were being tortured.

I'd love to read the warrant that granted this disclosure. If one doesn't exist I'd love to hear Apple's reasoning for releasing a 12 million + user database to LE without being legally obliged to do so.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#97

Refresh my memory - aren't the device tokens for the Apple Push Notification Service application-specific? That suggests this data comes from a single application, not Apple. The patchy personal information columns also suggests that this is a single (somewhat grabby) application's data store - presumably Apple would have more comprehensive records. My wild speculation, assuming what we're told is true - the applicat…

I doubt that they are a single app's data. Look at the repeat of certain Device names (try "Abo Mossa") and check their UDIDs - those UDIDs show an incremental pattern in their first 3 digits. This tells me: (a) those devices were bought in bulk and (b) those devices were never sold to one person - since the Device names were unchanged [assumption is that a regular customer cannot own so many devices]. I just don't s…

you're right. the pattern is weird. and it shows up a lot (see Admin's iPad, Ahmed's iPhone etc...)

EDIT: unless... is it just a side effect of how the data was exported? Sorted on Username, then on UDID

Ya, the more I look at it, the more I think it's just secondary sorting on UDID

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#98
post #62

interestingly enough, top ten ios devices names: 42797 'iPhone' 5191 'iPod touch' 3136 '“Administrator”的 iPad' 2202 '“Administrator”的 iPhone' 1534 'Owner’s iPad' 1453 ' iPhone' 1309 'Administrator’s iPad' 1196 'Administrator’s iPhone' 1141 'PdaTX.Net' 1058 'John’s iPad'

If you look at the UDID's for the '“Administrator”的 iPad's or '“Administrator”的 iPhone's, there seems to be an incremental pattern in their first 2-3 digits. Does that mean these devices were purchased/ordered in bulk and hence belong to some reseller? In which case, these must not have been sold to people and thus we don't see change in the Device names maybe? And thus the claim that this came from one or two apps s…

I replied elsewhere. Isn't it possible this is just a side-effect of how the data was exported?

Primary sort is by username. Secondary sort is by UDID.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#99
post #57

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

> Surely this is illegal. So? Pretty sure torture and car bombing innocent women and children is also illegal. http://en.wikipedia.org/wiki/1985_Beirut_car_bombing

There's always one person in the comments section that leaves a comment that couldn't be any further disconnected from the discussion. As pointed out you're getting confused with the CIA, it even quite clearly says in the Wikipedia article you linked: "...a failed assassination attempt organized by the American CIA and British intelligence"

Lets not make this situation out to sound worse than it is. The FBI having access to 12 million UDID's and user information which apparently had holes in it anyway is nowhere near as bad as innocent civilians being killed and seriously injured. It's bad, but not that bad, calm down.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#100
post #85

Looks like they've got Obama's iPad: thea:Downloads admin$ cat ./iphonelist.txt | grep -i obama '473d6e1ebf0b100ed172ce5f69c97ba6c8f12ad5','766a23201c6089be11845bfef624dbaada68be52155079850951836e9373e5cd','hobamain','iPad' 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','Obama','iPad'

Openfeint shows that 'Obama' last played 'Fishing Fun 2' curl 'https://api.openfeint.com/users/for_device.xml?udid=c63e008e6271c3ac128eb6a242a9817528b6baef true 160 1479631313 165632 Fishing Fun 2 false Player 1479631313

Seriously? Personal info about the President was leaked? Not that this particular instance looks like a big deal. Doesn't the NSA secure the President's communication? That must be carrer-impacting-embarrassing for someone.
Post reply on HN