Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

141–150 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#141
post #62

interestingly enough, top ten ios devices names: 42797 'iPhone' 5191 'iPod touch' 3136 '“Administrator”的 iPad' 2202 '“Administrator”的 iPhone' 1534 'Owner’s iPad' 1453 ' iPhone' 1309 'Administrator’s iPad' 1196 'Administrator’s iPhone' 1141 'PdaTX.Net' 1058 'John’s iPad'

If you look at the UDID's for the '“Administrator”的 iPad's or '“Administrator”的 iPhone's, there seems to be an incremental pattern in their first 2-3 digits. Does that mean these devices were purchased/ordered in bulk and hence belong to some reseller? In which case, these must not have been sold to people and thus we don't see change in the Device names maybe? And thus the claim that this came from one or two apps s…

The UDID is a SHA1 of a few fields (including a couple MAC addresses): we actually know the exact algorithm; if you are seeing patterns in them it is either a trick your brain is playing on you or a trick the user is playing on you (some people modify their UDID occasionally to keep themselves from being tracked by apps).

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#142
post #26

Putting a file of user data on a laptop is a fireable offense at at any reputable organization. Sad that the FBI is less careful about user data protection than consumer Internet companies.

The laptop was compromised while running. We do not know whether the disc was encrypted or not.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#143
post #123

Earlier quoted context omitted.

"Austrian, eh? Let's put some shrimp on the barbie!"

Paul Hogan hammed up his Australian accent. One of the best examples of a real Australian accent I've heard on American television is Dr. Chase [Jesse Spencer] from House, who is a real Australian and did not ham it up for an American audience. (Oddly though, the man who played his father in one episode had possibly the most embarrassingly bad fake Australian accent ever. Surprised Spencer didn't kick his arse during…

You do not get real foreign accents on prime time American television, the viewers would be bemused and look for subtitles.

You get what Americans think are foreign accents, i.e. lightly accented. The one exception is that Brits playing bad guys are allowed to use camp, pantomime villain accents. Alan Rickman has made his fame and fortune from this, a shame as he is rather a good actor.

Hugh Grant sounds nothing like he does/did before that series started.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#144

Earlier quoted context omitted.

I couldn't even guess the episode, but Marco has stated on is 5by5 podcast that he doesn't collect user information and only dips into user information grudgingly. I'd be surprised if this came from him as according to his statements he finds holding any user information that could be described as private unpleasant. This is all based on recollection however.

Still cant find the podcast, but here is what Marco says the FBI tool, quoted from the Instapaper blog about a year ago: >>The server was used as a MySQL replication slave, handling read-only queries to speed up the site. Instapaper suffered no downtime as a result of its theft and no data has been lost. Further down: >>Possibly most importantly, though, the FBI is now presumably in possession of a complete copy of t…

So "FBI theft" should be a new failure mode to defend against in web applications, right after SQLi and XSS? I'm handling this by not having any servers in the USA, hopefully GB is safe.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#145
post #73
post #27

Earlier quoted context omitted.

Doesn't a popular iOS developer have the same information? UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though. edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard…

iOS developers don't have the Apple IDs nor ZIP codes nor addresses (unless they separately ask for them but at least the apple ID is very uncommon)

I imagine it wouldn't be that difficult to extrapolate this information from your address book: I keep my own name, phone number, address, etc. all in there, and you can probably figure out which record is mine.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#146

I can't believe with nearly 100 comments I appear to be the only one to call the whole story of how these were acquired into doubt. I'm not saying that the FBI story isn't true, but so many comments here just assume it to be 100% factual - there's no evidence that it was taken from the FBI vs found on a USB Stick in the garbage. It's a big story, yes, but I think maybe a deep breath is in order before we all accuse t…

i think it's mainly because we'll never know, and it's not really the point that bothers most.

What bothers most is that this data exists at all, and what it's used for.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#147
post #100

Earlier quoted context omitted.

Seriously? Personal info about the President was leaked? Not that this particular instance looks like a big deal. Doesn't the NSA secure the President's communication? That must be carrer-impacting-embarrassing for someone .

Personal information about someone who had their device name set to "Obama". Let's not get all crazy now.

$ cat iphonelist.txt | grep c63e008e6271c3ac128eb6a242a9817528b6baef 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','“Administrator”的 iPad','iPad' 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','Obama','iPad'

Looks legit...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#148
post #116

Earlier quoted context omitted.

What apps do you have installed? This is interesting to know since the data might be from a popular app instead of Apple.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

Honestly, I'm pretty sure it's Facebook. They are the ones tracking everyone, including non-FB users, via a tracking cookie the moment you visit their site after all... And you know the feds just love that data that FB can acquire.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#149

I doubt very much that Apple had anything to do with this. That's not the kind of company they are.

Apple has everything to do with this. They're the ones who decided to put UDIDs on all their devices to begin with. And they know they've royally screwed up too - that's why they've deprecated UDIDs in iOS 5 and have started rejecting applications that access it. But that hardly fixes the problem since everyone will just use the Bluetooth or wireless MAC addresses instead - its not guaranteed to be unique, but close enough
Post reply on HN