Live data from Hacker News

AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

pastebin.com

261–270 of 279 posts

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#261
post #260
post #180

Earlier quoted context omitted.

If there is indeed an ongoing investigation, FOIA would not apply (reasonably enough).

An ongoing investigation of 12 million people?

I have no idea. There are a lot of assumptions implicit in that question.

I'm just saying that you are unlikely to be successful in requesting more information for this file. Information that "could reasonably interfere" with law enforcement is exempt. Also, the FBI does not make it easy to request documents form them and, further, the turnaround on a request can be months or years.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#263
post #166

Earlier quoted context omitted.

So, essentially, you're saying whatever Apple does or doesn't do is a bad decision in the end since it would always fall back to the hardware identifiers, then. Right?

Not quite. Part of the point was that "hardware coded IDs for devices concept should be erradicated from any device on the market in the future." I'd place MAC addresses in that bucket as well. A company like Apple that's been changing the status quo for years should be striving to do the same when it comes to their user's privacy and anonymity

MAC addresses too?

How do you propose to make networks work?

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#264
post #24

Earlier quoted context omitted.

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

Good thing the announcement didn't say "A large monster from Mars radioed these in" - Imagine how upset you'd have been at NASA!!!! A bit of a dick way of putting it, but there's no evidence the FBI is involved in this other than some words in an announcement that could be by anyone with an axe to grind.

I'm not sure why you're getting downvoted here, it's a valid point. There is nothing to prove this list came from the FBI, and I wouldn't put it above Antisec/Anonymous to get into a database of some popular iOS app, release the info, and then say it was from the FBI both to slag on the FBI and to stroke their e-peni^H^H^H^H^H^H^H ego.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#265
post #181

Earlier quoted context omitted.

Encrypting it, at least, makes sense: They can take their time distributing the file without anyone peeking at it before they're suppose to. Then, when they release the decryption key, the file is already copied all over the place and really hard to shut down. Guess all the verifying means they are afraid someone will distribute "altered" versions. Checking it twice is maybe a little drastic? Don't know how hard it i…

MD5 is not the best cryptographic hash... it's weird that they would be so paranoid as to include two hashes but not use something harder to collide with.

While I agree there's better options, MD5 has no known preimage attacks. So it's stretching it a bit to imply that someone could easily cause a collision on an existing archive.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#266

Earlier quoted context omitted.

Good thing the announcement didn't say "A large monster from Mars radioed these in" - Imagine how upset you'd have been at NASA!!!! A bit of a dick way of putting it, but there's no evidence the FBI is involved in this other than some words in an announcement that could be by anyone with an axe to grind.

I'm not sure why you're getting downvoted here, it's a valid point. There is nothing to prove this list came from the FBI, and I wouldn't put it above Antisec/Anonymous to get into a database of some popular iOS app, release the info, and then say it was from the FBI both to slag on the FBI and to stroke their e-peni^H^H^H^H^H^H^H ego.

Neither am I, but I suppose the humour was a little too barbed.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#269
post #27
post #24

Earlier quoted context omitted.

This is very disturbing. How did the FBI gain access to all this information? It should be locked up in Apple. From what I see, the NCFTA in "NCFTA_iOS_devices_intel.csv" looks like it stands for the National Cyber-Forensics & Training Alliance, which "functions as a conduit between private industry and law enforcement." ( http://www.ncfta.net/ ) Is Apple willingly sharing personal information with the FBI through th…

Doesn't a popular iOS developer have the same information? UDIDs, APNS tokens (for push notifications), basic demographic information is something a popular social app or game might have. 12 million is a pretty good number, though. edit: our iOS app has over 2 million of these type of device records (though we don't collect any demographic info, so just device ids, apns tokens, device names, device types -- standard…

Well, at least the FBI is not going to share your personal information with advertisers, or (opt-in) spam you to death trying to sell you something.

The FBI's mission is reasonably clear; it's a government-regulated organization; it's non-commercial. They have a certain amount of accountability. Alas, we can't say the same for "popular iOS developers". We've seen how sneaky some iOS app developers can be with respect to privacy, and with little remorse after they get caught.

Re: AntiSec leaks 1,000,001 Apple UDIDs, Device Names/Types

#270

Earlier quoted context omitted.

Is there any evidence that this data comes from the source they claim? And is there some way to validate these are real UDIDs?

Sure - me. Both my iOS devices are on this list - confirmed both by name and UDID match. However, I renamed my iPad around last November after I started using it more in public, yet its original name (easy to find if you search for my HN nick) is the name listed. EDIT: Oh, and fwiw, law-abiding natural born US citizen here. But who am I kidding - LEAs don't give a toss about that.

It would be interesting if you and others with their device on the list could come up with a list of apps that you've had installed.
Post reply on HN