Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

11–20 of 223 posts

Re: Apple Developer Website Update

#11
post #7

Uh, how does this "encryption" work? For the website to show these details (and it does, in part, use these details in the interface) it must be able to decrypt these on the web applications side. Ergo the keys for decryption must also be on the server or derived from the users passwords, both of which make the use of encryption a fairly worthless venture. ED: As another commenter mentioned in an earlier thread, lots…

I think the 'sensitive personal information' is passwords, so the names, addresses etc which are displayed on the site were not encrypted.

Re: Apple Developer Website Update

#15
post #5

"In the spirit of transparency". Right, Apple.

In the spirit of transparency, we're giving you vague warning that some information might have been accessed _4 days ago_

That's not a long time to receive a letter like this. That's as fast as Apple instantly responds to anything, esp. considering the weekend.

And the site was down, so it was clear something was going on.

It is also extremely transparent in the sense that people were wondering this exact thing even earlier today, and now received a response detailing that this is an extremely severe breach, as opposed to something else. What more do you want on a Sunday?

Re: Apple Developer Website Update

#16
Hmm so it only takes a few days to "completely overhaul" their developer systems? Not sure I believe this is what they're actually doing. And why haven't they updated their server software before? I know mistakes can never be completely avoided, but this seems slightly amateurish for a company with so much cash.

Re: Apple Developer Website Update

#17
Is the encryption not good enough (and I mean in general when sites get bcrypt'd passwords stolen, etc) when owners are worried the encrypted data is in the hands of intruders?

As a developer I'd still be concerned if I lost such data when encrypted - so I understand - but what measures can be put in place so that as a developer/site owner you're without uncertainty that the encrypted data will never be encrypted by the attacker (eg, would take trillions of years).

Re: Apple Developer Website Update

#19
post #6

These details are befuddling. "Personal information was encrypted and cannot be accessed". It can't be accessed because it's somehow stored elsewhere, or it can't be accessed because of the encryption? That is, does the intruder currently own my encrypted data? I'm also disappointed that it took them 72 hours to tell us anything, and that the update doesn't even have a timeline for when the site may be back. "Soon" i…

Yeah I'm confused why companies tells us DAYS after something serious happened as opposed to right away. I can understand waiting a day but 3 whole days?! I just don't understand the delay.

It's our data, we should have the right to know what happened to it.

Post reply on HN