Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

241–250 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#241
post #170

Earlier quoted context omitted.

> you should be using Secure UDID or something similar As an app developer, does this give me some benefit over just generating and saving a random UUID on first launch?

If you save the random number, what happens when they wipe the device and reinstall your app? No way to get that original number back. Secure UDID is deterministic, so you'd get the same ID, and can resume the original session.

One way around this is to store that number in iCloud. Then you can always get it back no matter the device.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#242
post #176
post #134

Earlier quoted context omitted.

I run Cydia, and have determined only 16.7% of the UDIDs in that file are from jailbroken devices: I thereby do not believe that whatever managed to get this data is anywhere in our ecosystem.

Do you have similar information stored about the Cydia users? How many users do you have?

The question "how many users do you have" is impossible to answer, as all I can ever demonstrate is "X users used Cydia in the last Y period". As for your second question, the information I have for your average Cydia user (one that is not actively paying me money, in which case I obviously have tons of information) is purposely highly limited: I certainly do not have, for example, the "names" of devices that was included in these dumps from AntiSec (which often discloses the name of the user), or any of the other personal details that are claimed to be in the original file.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#243
post #174
post #134

Earlier quoted context omitted.

I run Cydia, and have determined only 16.7% of the UDIDs in that file are from jailbroken devices: I thereby do not believe that whatever managed to get this data is anywhere in our ecosystem.

Doesn't 16% sounds above the average ? Could it be related to app warez on jailbroken devices, somehow ?

One would not expect it to be at the average, because this information is going to have come from some popular app, and there will be high correlation between "people who have never used even a single app: they just wanted a phone" and "people who have never considered jailbreaking: they just wanted a phone"; this is even more the case once you consider that it might not be an app that "virtually everyone has": it might be an app that is either correlated with skill (you are slightly more likely to have the app, even controlling for people who have apps at all, if you are the kind of person who really cares) or negatively correlated with age (you are more likely to have the app if you are younger, which correlates better with the demographic of people who jailbreak).

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#244
post #133

Earlier quoted context omitted.

I doubt that they are a single app's data. Look at the repeat of certain Device names (try "Abo Mossa") and check their UDIDs - those UDIDs show an incremental pattern in their first 3 digits. This tells me: (a) those devices were bought in bulk and (b) those devices were never sold to one person - since the Device names were unchanged [assumption is that a regular customer cannot own so many devices]. I just don't s…

The UDID is a SHA1 of a few fields (including a couple MAC addresses): we actually know the exact algorithm; if you are seeing patterns in them it is either a trick your brain is playing on you or a trick the user is playing on you (some people modify their UDID occasionally to keep themselves from being tracked by apps).

How do you modify the UDID? Does it depend on the model?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#246
post #208

Earlier quoted context omitted.

There's always one person in the comments section that leaves a comment that couldn't be any further disconnected from the discussion. As pointed out you're getting confused with the CIA, it even quite clearly says in the Wikipedia article you linked: "...a failed assassination attempt organized by the American CIA and British intelligence" Lets not make this situation out to sound worse than it is. The FBI having ac…

> you're getting confused with the CIA No I am not. I was talking about the executive branch of the our government. > Lets not make this situation out to sound worse than it is. I was commenting on the assertion that this is 'illegal' and thus how could FBI possibly do this. And my response was that it seems illegality isn't exactly stopping anyone, be it FBI, CIA or other agency.

No need to go that far back - we can talk about the warrent-less wiretaps, or the pre-trial assassinations of US citizens.

...of course, the current administration insists that those are legal, but because they refuse to release a legal argument defending the practice, the best explanation they've given is 'Just trust us, okay?'. Not sure how that would hand up in a court of law.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#247
post #166

Earlier quoted context omitted.

Apple has everything to do with this. They're the ones who decided to put UDIDs on all their devices to begin with. And they know they've royally screwed up too - that's why they've deprecated UDIDs in iOS 5 and have started rejecting applications that access it. But that hardly fixes the problem since everyone will just use the Bluetooth or wireless MAC addresses instead - its not guaranteed to be unique, but close…

So, essentially, you're saying whatever Apple does or doesn't do is a bad decision in the end since it would always fall back to the hardware identifiers, then. Right?

Not quite. Part of the point was that "hardware coded IDs for devices concept should be erradicated from any device on the market in the future." I'd place MAC addresses in that bucket as well. A company like Apple that's been changing the status quo for years should be striving to do the same when it comes to their user's privacy and anonymity

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#249
post #193

Earlier quoted context omitted.

>Is Apple willingly sharing personal information with the FBI through the NCFTA? Define "willingly."

It wouldn't be "willingly". But If Apple was presented with an order from a court, then yes, they'd have no choice. They could fight it; but they'd lose, depending on the reason. Frankly the only reason would be some terrorism angle. But those types of actions are rare.

I wish that Apple, if indeed presented with a court order, would've gone the Twitter route and publicized that fact.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#250

Earlier quoted context omitted.

Pretty sure that a smart burglar could figure out approximate addresses of people who own iPhones by looking at publicly available Instagram or Twitter or Facebook or Flickr locations. Not to mention people telling the world "I'm camping this weekend" which a burglar hears as "I'll be gone all weekend, steal my things!"

I think a smart burglar would just look at any commonly available database of home sales. Anybody who has moved in the last few years into a more-expensive-than-average house should correlate much better with valuables than iPhones. However, I'd hope any criminal with brains like that would find something to do that has higher yield and lower risk than housebreaking. I'd suggest working for a private equity company.

Yeah i'm not really worried that burglars are going to use this data-set for harm. If they know about this data-set they likely know about databases of home sales or car sales or just plain old census data listing the average income by county.
Post reply on HN