Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

151–160 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#153
post #137

Earlier quoted context omitted.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

Jailbroken eh? Wonder if that is the common link?

No: http://news.ycombinator.com/item?id=4473747

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#154

Earlier quoted context omitted.

Still cant find the podcast, but here is what Marco says the FBI tool, quoted from the Instapaper blog about a year ago: >>The server was used as a MySQL replication slave, handling read-only queries to speed up the site. Instapaper suffered no downtime as a result of its theft and no data has been lost. Further down: >>Possibly most importantly, though, the FBI is now presumably in possession of a complete copy of t…

So "FBI theft" should be a new failure mode to defend against in web applications, right after SQLi and XSS? I'm handling this by not having any servers in the USA, hopefully GB is safe.

Yeah, this gives a whole new meaning to having live backups/redundancy. I guess this is an advantage of hosting on EC2 since there would be difficult for the FBI to seize the physical server.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#157
post #130

Is there some good reason for all those steps to actually get the file after downloading? I don't see the point of encrypting it, or of having a tarball with just one file. They also suggest checking the file integrity of the download, and then also checking the integrity of the final extracted file--this seems completely pointless as the final extracted file is derived deterministically from the download so you've a…

Theoretically, it is possible to create another file, which after encryption will give you the same checksum. I doubt that someone will be able to do it in a reasonable amount of time though.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#158
post #142
post #26

Putting a file of user data on a laptop is a fireable offense at at any reputable organization. Sad that the FBI is less careful about user data protection than consumer Internet companies.

The laptop was compromised while running. We do not know whether the disc was encrypted or not.

If it was exploited through the JRE, then it doesn't really matter...

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#159

Earlier quoted context omitted.

This is the stated reason for the release - to have people ask why an agent has 12m UDID numbers on his laptop. They released 1m out of the 12m UDIDs so that they can guarantee a statistical sample that can be verified, while preserving a bit of privacy. Along with the UDIDs were other columns with an assortment of personal data, although there were a lot of holes.

How large would a 12m line long .csv file be? Not sure how many bytes per entry, but it would be of the order of gigabytes.

The 1,000,001 line file is 136MBs uncompressed, so 12M should be around 1.6GB

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#160

Earlier quoted context omitted.

>Is Apple willingly sharing personal information with the FBI through the NCFTA? Define "willingly."

FBI: "Can we have this data? we can pay something" Apple: "Sure! In which format do you prefer to have it?"

FBI: "Just give it to us as CSV, kthxbai."
Post reply on HN