Why all the buzz? I thought that the people who buy Apple products or use centralized social networks knowingly sacrifice their privacy and already expect things like this to happen.
AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
191–200 of 279 posts
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#192Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…
This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#193Earlier quoted context omitted.
This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…
>Is Apple willingly sharing personal information with the FBI through the NCFTA? Define "willingly."
But those types of actions are rare.
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#194Apple could probably figure out if this data came from an app developer because I'd bet there's only exactly one app which every single one of those 1,000,001 devices downloaded. Even if they threw in a few fake rows to mess up the data, they could find the app that has the highest percentage of downloads from that entire data set.
And if the data came from Apple? I can't think of any apps that take a full address. Perhaps there are some, I just don't know them. Apple could have been compelled to release this data to the FBI. Unfortunately, we're unlikely to ever know this and Apple are equally unlikely to want to shed light on it. If the claim is true, that the source data included full postal address, then I find it hard to identify a better…
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#195Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#196We've recently discovered that even though the Apple docs suggest the APNS tokens may be unique to each app and may change over time they are NOT unique to an app and they also do not change (at least not over the last 18 months). So if you have two apps on the same device they both share the same UDID and the same APNS token. Whilst on the surface this may seem like a huge security issue it is not as bad as it seems…
> you should be using Secure UDID or something similar As an app developer, does this give me some benefit over just generating and saving a random UUID on first launch?
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#197Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…
This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#198Earlier quoted context omitted.
Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)
What about Pokerstars? Their US operations were shut down the FBI recently on bank fraud and money laundering charges. http://www.tightpoker.com/news/pokerstars-shuts-down-2347/
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#199Earlier quoted context omitted.
I run Cydia, and have determined only 16.7% of the UDIDs in that file are from jailbroken devices: I thereby do not believe that whatever managed to get this data is anywhere in our ecosystem.
Do you have similar information stored about the Cydia users? How many users do you have?
Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types
#200Earlier quoted context omitted.
Personal information about someone who had their device name set to "Obama". Let's not get all crazy now.
$ cat iphonelist.txt | grep c63e008e6271c3ac128eb6a242a9817528b6baef 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','“Administrator”的 iPad','iPad' 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','Obama','iPad' Looks legit...
I know for a fact, the NSA protects all communications from the president (and most of the top level folk in his administration). If this turns out to really be the president (which I doubt) it would be a MAJOR breech.