Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

131–140 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#131
post #116

I have found my own UDID - I can confirm these are real UDID's - and now I want to know why an FBI agent had my (a brit) UDID on their laptop.

What apps do you have installed? This is interesting to know since the data might be from a popular app instead of Apple.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#132
post #103
post #77

Earlier quoted context omitted.

there's a bunch of UDID apps (free) that you can download from the App Store.

Don't iOS apps have the permission to use the internet without any hassle? In that case, I would assume by using such app, chances are, you are contributing to another entity's UDID collection.

If in doubt, download and turn flight mode on before running, then uninstall?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#133

Refresh my memory - aren't the device tokens for the Apple Push Notification Service application-specific? That suggests this data comes from a single application, not Apple. The patchy personal information columns also suggests that this is a single (somewhat grabby) application's data store - presumably Apple would have more comprehensive records. My wild speculation, assuming what we're told is true - the applicat…

I doubt that they are a single app's data. Look at the repeat of certain Device names (try "Abo Mossa") and check their UDIDs - those UDIDs show an incremental pattern in their first 3 digits. This tells me: (a) those devices were bought in bulk and (b) those devices were never sold to one person - since the Device names were unchanged [assumption is that a regular customer cannot own so many devices]. I just don't s…

The UDID is a SHA1 of a few fields (including a couple MAC addresses): we actually know the exact algorithm; if you are seeing patterns in them it is either a trick your brain is playing on you or a trick the user is playing on you (some people modify their UDID occasionally to keep themselves from being tracked by apps).

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#134
post #116

Earlier quoted context omitted.

What apps do you have installed? This is interesting to know since the data might be from a popular app instead of Apple.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

I run Cydia, and have determined only 16.7% of the UDIDs in that file are from jailbroken devices: I thereby do not believe that whatever managed to get this data is anywhere in our ecosystem.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#135
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

Is there any evidence that this data comes from the source they claim? And is there some way to validate these are real UDIDs?

Sure - me. Both my iOS devices are on this list - confirmed both by name and UDID match.

However, I renamed my iPad around last November after I started using it more in public, yet its original name (easy to find if you search for my HN nick) is the name listed.

EDIT: Oh, and fwiw, law-abiding natural born US citizen here. But who am I kidding - LEAs don't give a toss about that.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#137
post #116

Earlier quoted context omitted.

What apps do you have installed? This is interesting to know since the data might be from a popular app instead of Apple.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

Jailbroken eh? Wonder if that is the common link?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#138
post #88

Earlier quoted context omitted.

APNS tokens are generally tied to a specific app so it may be possible to figure out what app leaked their database This isn't true, APNS device tokens are shared among apps on a device. The only time a device will have more than one device token is if it's being used for development. This isn't to say that Apple couldn't correlate the device tokens by looking for shared apps with active APNS entitlements.

I don't think so. The device token is even generated over the version of the app. Meaning: you get a new device token if the app version changes.

No: the APNS token is only changed if you get a new device (as it is tied to your device's certificate) or restore your phone (and not restore a backup: if you restore a backup it restores the token).

http://stackoverflow.com/questions/2338267/is-the-apn-device...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#139

Earlier quoted context omitted.

This is the stated reason for the release - to have people ask why an agent has 12m UDID numbers on his laptop. They released 1m out of the 12m UDIDs so that they can guarantee a statistical sample that can be verified, while preserving a bit of privacy. Along with the UDIDs were other columns with an assortment of personal data, although there were a lot of holes.

How large would a 12m line long .csv file be? Not sure how many bytes per entry, but it would be of the order of gigabytes.

It might be a gigabyte if there were about 90 characters per line 1 or 2 gigabytes tops? "on the order of gigabytes" is a rather pretentious way of saying that.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#140

If you look at line #'s 3741 through 3845, you will see they all (105) belong to one Abo Mossa. Is Abo Mossa some kind of an iPhone/iPad reseller or is there something else going on?

He probably is using a tool that spoofs his UDID... a lot. ;P
Post reply on HN