Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

251–260 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#251
post #249
post #193

Earlier quoted context omitted.

It wouldn't be "willingly". But If Apple was presented with an order from a court, then yes, they'd have no choice. They could fight it; but they'd lose, depending on the reason. Frankly the only reason would be some terrorism angle. But those types of actions are rare.

I wish that Apple, if indeed presented with a court order, would've gone the Twitter route and publicized that fact.

It's a no win situation for them. Hand the info over and you're on msnbc for giving it up, don't hand it over and you're on fox news for helping the terrorists...

Plus for certain kinds of investigations, it would go against the court order to go public. I don't want to defend apple here but this is an American law enforcement problem, I'm certain ms, google and others have provided info to the government that would anger many and there are probably a lot of companies that do it without a court order... Trying to be good citizens.

Why the hell was that info on a laptop?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#252
post #200

Earlier quoted context omitted.

You do know that there are other people in world with the name Obama, right? I know for a fact, the NSA protects all communications from the president (and most of the top level folk in his administration). If this turns out to really be the president (which I doubt) it would be a MAJOR breech.

For a fact? How so?

I'd have to kill ya if I told you. :)

No I'm kidding of course. Obviously, I did work in that area, ages ago.

And it's been like this for a long time, by the way. Even back in ancient times when we all used dials.

The president lives in the ultimate bubble. Nothing gets in or out without being vetted.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#253
post #249
post #193

Earlier quoted context omitted.

It wouldn't be "willingly". But If Apple was presented with an order from a court, then yes, they'd have no choice. They could fight it; but they'd lose, depending on the reason. Frankly the only reason would be some terrorism angle. But those types of actions are rare.

I wish that Apple, if indeed presented with a court order, would've gone the Twitter route and publicized that fact.

That would depend on which court the order came from. If it was from the FISA court, for example, then publicizing it would send people to jail.

But again, if that were the case then it would be related to anti-terrorism efforts. Well I hope it would be. The FISA court exists for that reason (mostly).

I guess my paranoia depends on how much I trust the government :)

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#254
post #242
post #176

Earlier quoted context omitted.

Do you have similar information stored about the Cydia users? How many users do you have?

The question "how many users do you have" is impossible to answer, as all I can ever demonstrate is "X users used Cydia in the last Y period". As for your second question, the information I have for your average Cydia user (one that is not actively paying me money, in which case I obviously have tons of information) is purposely highly limited: I certainly do not have, for example, the "names" of devices that was inc…

Thanks!

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#255
post #5

Money quote for the people that don't want to wade through ten pages of rant: During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder…

I have information this morning from source thats "in the know" that this is definitely a false-flag attack against the FBI.

Non-gov researchers I know also attribute this to a possible hacking of an iphone/ipad application backend DB before Apple put in the UUID storing restrictions to the IOS api.

I'm only bringing this to light because it is easy to fall for things you read on the Internet and get excited/theorize.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#256

Earlier quoted context omitted.

Still cant find the podcast, but here is what Marco says the FBI tool, quoted from the Instapaper blog about a year ago: >>The server was used as a MySQL replication slave, handling read-only queries to speed up the site. Instapaper suffered no downtime as a result of its theft and no data has been lost. Further down: >>Possibly most importantly, though, the FBI is now presumably in possession of a complete copy of t…

So "FBI theft" should be a new failure mode to defend against in web applications, right after SQLi and XSS? I'm handling this by not having any servers in the USA, hopefully GB is safe.

Other countries aren't that safe. https://www.eff.org/cases/indymedia-server-takedown

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#257
post #133

Earlier quoted context omitted.

The UDID is a SHA1 of a few fields (including a couple MAC addresses): we actually know the exact algorithm; if you are seeing patterns in them it is either a trick your brain is playing on you or a trick the user is playing on you (some people modify their UDID occasionally to keep themselves from being tracked by apps).

How do you modify the UDID? Does it depend on the model?

At some point, the UDID is being processed by code, so you don't really need to permanently modify anything: you just edit the code that generates it and make that return something different. These kinds of changes are very simple using Substrate, the library we all use (that I developed) for changing code at runtime. For the UDID, the obvious candidates are "edit every app so [UIDrvice uniqueIdentifier] returns fake" and "edit lockdownd so it calculates the wrong value every time it is generated".

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#258
post #243
post #174

Earlier quoted context omitted.

Doesn't 16% sounds above the average ? Could it be related to app warez on jailbroken devices, somehow ?

One would not expect it to be at the average, because this information is going to have come from some popular app, and there will be high correlation between "people who have never used even a single app: they just wanted a phone" and "people who have never considered jailbreaking: they just wanted a phone"; this is even more the case once you consider that it might not be an app that "virtually everyone has": it mi…

Very interesting analysis. The question now is : which app/network exhibits such properties? Considering the data is recent, I suppose it eliminates big guys like Facebook/Apple. Thanks for sharing your numbers with the community.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#259
post #245

Marco Arment thinks that the All Clear ID app is responsible for this leak: http://www.marco.org/2012/09/04/fbi-udid-leak Can anyone who can confirm they're on the list confirm that was one of their apps?

This guy says he's in the dump and didn't use AllClear ID. https://twitter.com/BFormations/status/243044444595687424

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#260
post #180
post #129

Earlier quoted context omitted.

Couldn't an American request a FOIA for this to see what's the level of information gathering on iPhone users? Could EFF sue them for it or something to unveil more?

If there is indeed an ongoing investigation, FOIA would not apply (reasonably enough).

An ongoing investigation of 12 million people?
Post reply on HN