Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

191–200 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#191
post #171

Why all the buzz? I thought that the people who buy Apple products or use centralized social networks knowingly sacrifice their privacy and already expect things like this to happen.

Do we really need to go into tired cliches of what kind of people own which device? We don't even know how this information was acquired.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#192
post #24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

A more likely source is neustar (a spinoff of Lockheed), who also has all that information and is actually in the intel business.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#193
post #24

Earlier quoted context omitted.

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

>Is Apple willingly sharing personal information with the FBI through the NCFTA? Define "willingly."

It wouldn't be "willingly". But If Apple was presented with an order from a court, then yes, they'd have no choice. They could fight it; but they'd lose, depending on the reason. Frankly the only reason would be some terrorism angle.

But those types of actions are rare.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#194
post #86

Apple could probably figure out if this data came from an app developer because I'd bet there's only exactly one app which every single one of those 1,000,001 devices downloaded. Even if they threw in a few fake rows to mess up the data, they could find the app that has the highest percentage of downloads from that entire data set.

And if the data came from Apple? I can't think of any apps that take a full address. Perhaps there are some, I just don't know them. Apple could have been compelled to release this data to the FBI. Unfortunately, we're unlikely to ever know this and Apple are equally unlikely to want to shed light on it. If the claim is true, that the source data included full postal address, then I find it hard to identify a better…

A reasonable assumption, besides Apple, is Facebook. With all the information these services have the easiest part may be to acquire your home address.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#196
post #170

We've recently discovered that even though the Apple docs suggest the APNS tokens may be unique to each app and may change over time they are NOT unique to an app and they also do not change (at least not over the last 18 months). So if you have two apps on the same device they both share the same UDID and the same APNS token. Whilst on the surface this may seem like a huge security issue it is not as bad as it seems…

> you should be using Secure UDID or something similar As an app developer, does this give me some benefit over just generating and saving a random UUID on first launch?

If you save the random number, what happens when they wipe the device and reinstall your app? No way to get that original number back. Secure UDID is deterministic, so you'd get the same ID, and can resume the original session.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#197
post #24
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

The National Cyber Forensics and Training Alliance in Pittsburgh is the office where the FBI Agent who posed as a member of the carding community worked when he helped take down Max Ray Vision, née Butler.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#198

Earlier quoted context omitted.

Whatsapp, ebuddy pro, ebuddy XMS, Angry Birds, Angry Birds Space, FML, XKCD, Facebook, Spotify, BBC News, Dropbox, Steam and PokerStars are the more popular ones official I have installed. I also have Cydia, a few tweaks and finally Installous (didn't want to admit that - I don't use it often - but thought it may spread some light here)

What about Pokerstars? Their US operations were shut down the FBI recently on bank fraud and money laundering charges. http://www.tightpoker.com/news/pokerstars-shuts-down-2347/

There are far too many accounts leaked for them to be the source.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#199
post #176
post #134

Earlier quoted context omitted.

I run Cydia, and have determined only 16.7% of the UDIDs in that file are from jailbroken devices: I thereby do not believe that whatever managed to get this data is anywhere in our ecosystem.

Do you have similar information stored about the Cydia users? How many users do you have?

That's a good question, I was wondering the same thing?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#200

Earlier quoted context omitted.

Personal information about someone who had their device name set to "Obama". Let's not get all crazy now.

$ cat iphonelist.txt | grep c63e008e6271c3ac128eb6a242a9817528b6baef 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','“Administrator”的 iPad','iPad' 'c63e008e6271c3ac128eb6a242a9817528b6baef','b996a080e11265a0c93436ba0b13b7c07ee4e8eef6faeb8516917b015d7355fb','Obama','iPad' Looks legit...

You do know that there are other people in world with the name Obama, right?

I know for a fact, the NSA protects all communications from the president (and most of the top level folk in his administration). If this turns out to really be the president (which I doubt) it would be a MAJOR breech.

Post reply on HN