Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

111–120 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#113

Earlier quoted context omitted.

I was confused by the writing style as well. It seems to be almost intentional. I wonder if it's a way of avoiding any style or nuances that could be attributed to a single person. Almost like a cut and paste ransom note.

It's elite (or 1337 if you will). It's supposed to sound cool. All the underground computer groups have talked like that since the early warez/cracking/phreaking scene.

Are you sure they're not just really bad at writing?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#114
post #62

interestingly enough, top ten ios devices names: 42797 'iPhone' 5191 'iPod touch' 3136 '“Administrator”的 iPad' 2202 '“Administrator”的 iPhone' 1534 'Owner’s iPad' 1453 ' iPhone' 1309 'Administrator’s iPad' 1196 'Administrator’s iPhone' 1141 'PdaTX.Net' 1058 'John’s iPad'

If you look at the UDID's for the '“Administrator”的 iPad's or '“Administrator”的 iPhone's, there seems to be an incremental pattern in their first 2-3 digits. Does that mean these devices were purchased/ordered in bulk and hence belong to some reseller? In which case, these must not have been sold to people and thus we don't see change in the Device names maybe? And thus the claim that this came from one or two apps s…

The Chinese character "的" is being used here as a possessive; it just means that the iPad belongs to the "Administrator", which is the default account name for many Windows XP computers [1]. Because iTunes activates iPods, iPhones, and iPads under the current user account name, and because the default user account names in many XP installations is "Administrator", there are a plethora of devices with the same name: '“Administrator”的 iPad'.

So, the only significance of this name is that there are quite a few Chinese Apple devices in this sample. Perhaps they are over-represented in the whole dataset; it's hard to say without having the breakdown of Apple devices sold by country, as well as the entire dataset.

1. http://www.mydigitallife.info/unhide-the-administrator-accou...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#115
post #52

Earlier quoted context omitted.

The FBI stole an Instapaper server in an unrelated raid http://blog.instapaper.com/post/6830514157

I couldn't even guess the episode, but Marco has stated on is 5by5 podcast that he doesn't collect user information and only dips into user information grudgingly. I'd be surprised if this came from him as according to his statements he finds holding any user information that could be described as private unpleasant. This is all based on recollection however.

Still cant find the podcast, but here is what Marco says the FBI tool, quoted from the Instapaper blog about a year ago: >>The server was used as a MySQL replication slave, handling read-only queries to speed up the site. Instapaper suffered no downtime as a result of its theft and no data has been lost.Further down:

>>Possibly most importantly, though, the FBI is now presumably in possession of a complete copy of the Instapaper database as it stood on Tuesday morning, including the complete list of users and any non-deleted bookmarks. (“Archived” bookmarks are not deleted. “Deleted” bookmarks are hard-deleted out of the database immediately.)

Instapaper stores only salted SHA-1 hashes of passwords, so those are relatively safe. But email addresses are stored in the clear, as is the saved content of each bookmark saved by the bookmarklet.

The server also contained a complete copy of the Instapaper website codebase, but not the codebase of the iOS app.

Linked Facebook, Twitter, or Tumblr accounts only store their respective OAuth keys. Linked Evernote accounts only store the Evernote email-in address. Linked Pinboard accounts, however, store plaintext usernames and encrypted passwords, and the encryption keys are present in the website source code on the server. <<

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#116

I have found my own UDID - I can confirm these are real UDID's - and now I want to know why an FBI agent had my (a brit) UDID on their laptop.

What apps do you have installed? This is interesting to know since the data might be from a popular app instead of Apple.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#117
post #73
post #27

Earlier quoted context omitted.

Doesn't a popular iOS developer have the same information? UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though. edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard…

iOS developers don't have the Apple IDs nor ZIP codes nor addresses (unless they separately ask for them but at least the apple ID is very uncommon)

Could this data have been taken from the AT&T "breach" a while back where all the data for iPhone customers wasn't protected and crawled?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#118
I like the card AntiSec is playing:

  well we have learnt it seems quite clear nobody pays attention if you just come
  and say 'hey, FBI is using your device details and info and who the fuck knows what
  the hell are they experimenting with that', well sorry, but nobody will care.
Arms race for attention, while the government races towards quieter actions and laws...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#119
post #24

Earlier quoted context omitted.

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

>Is Apple willingly sharing personal information with the FBI through the NCFTA? Define "willingly."

FBI: "Can we have this data? we can pay something" Apple: "Sure! In which format do you prefer to have it?"

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#120

This is troubling on so many levels. Why did an FBI agent have a document of user and device info on his desktop and the real question is why are the FBI tracking this information in the first place? Surely this is illegal. By the way, I think AntiSec needs to hire someone to write their releases for them. I struggled at times to make sense of the almost gibberish in their rant-filled sentences and at times some of t…

I thought it was quite well written, also noticed the "Life as a Service" part. Maybe it only works on me because I thought about those things before, but it wouldn't be an effective propaganda piece.
Post reply on HN