Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

81–90 of 223 posts

Re: Apple Developer Website Update

#81
post #69

Earlier quoted context omitted.

Access to an API to get certificates from a different server one at a time is different thing from having the actual private signing key.

Certainly, but an unrestricted code signing certificate would be quite useful too (until they are revoked)

Which wouldn't take very long. I'd be amazed if Apple wasn't using a hardware security module to store their intermediate signing keys and logging the keys generated from it.

I wonder where the CRL for the dev certificates is -- we might see an update to it soon.

Re: Apple Developer Website Update

#82
post #69

Earlier quoted context omitted.

Access to an API to get certificates from a different server one at a time is different thing from having the actual private signing key.

Certainly, but an unrestricted code signing certificate would be quite useful too (until they are revoked)

Mmmm... maybe. Okay, let's say you can sign code as anyone, even Apple itself, and create rogue apps.

Now, how do you use that information to compromise iOS devices? You probably won't be able to get it in the App Store, and the iOS devices won't install from anywhere else. You could make an Ad Hoc distribution package, but for that you need to know the UDID of each device and convince your victim to download the rogue app from somewhere other than the App Store.

Re: Apple Developer Website Update

#83
post #6

These details are befuddling. "Personal information was encrypted and cannot be accessed". It can't be accessed because it's somehow stored elsewhere, or it can't be accessed because of the encryption? That is, does the intruder currently own my encrypted data? I'm also disappointed that it took them 72 hours to tell us anything, and that the update doesn't even have a timeline for when the site may be back. "Soon" i…

As I interpreted it, yes, the intruder does have your encrypted data.

[deleted]

Re: Apple Developer Website Update

#86

Good to see some transparency on Apple's part here. I understand this must be a very challenging situation for them to deal with, and I appreciate the notification. As I'm sure many developers feel, I'd like to know more details, but I'm sure these will come in due course.

It's a strange world we live in when every time we're told by a big corp that our personal info was compromised, we're grateful for being told. This is the worlds most cashed-up corporation. They could buy entire countries, yet they made a conscious choice not to update their server software or hire more competent sys-admins. There shouldn't be a way for them to gain marketing wins out of this. There should be a law…

This isn't about marketing. It's about a security breach. And security breaches take time (> 2 days) to properly investigate and report.

It's entirely possible that this is a massive oversight by Apple and they've been extremely negligent in their security policies.

It's equally possible that there's some bug (that either you or I could easily have made the mistake of introducing) that's resulted in this being possible.

Let's calm things down, give it a few days, and then evaluate. Nobody can make an immediate judgement about the exact causes of problems like this. If you're making judgements at this point, you really have no idea whether you're being accurate or not.

And yes, if it turns out to be negligence on Apple's part, I'll be very angry. But let's wait and see.

Re: Apple Developer Website Update

#87

> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it. Apparently our intelligence, which cannot be insulted, has been in…

By "sensitive personal information" they probably just mean passwords and credit card information, not names, email addresses and mailing addresses.

What I find slightly unnerving is that Apple didn't make this clearer.

If they know that credit card information was not affected, they should say that. E.g. "Sensitive personal information (such as credit card data) was encrypted and cannot be accessed, ..."

It's reasonable to suppose that 'sensitive' includes credit card information, but as it stands it's something we have to interpret.

I'd suggest we all check our credit/debit card statements more often over the coming days, just to be sure. =)

Re: Apple Developer Website Update

#88
post #7

Uh, how does this "encryption" work? For the website to show these details (and it does, in part, use these details in the interface) it must be able to decrypt these on the web applications side. Ergo the keys for decryption must also be on the server or derived from the users passwords, both of which make the use of encryption a fairly worthless venture. ED: As another commenter mentioned in an earlier thread, lots…

Maybe they phoned for a ransom after breaking in?

Your post is pure speculation and depends heavily on what Apple means by 'sensitive'. I'm guessing that Apple means your CC numbers, certs, shared keys, etc.

Possibly also your support tickets, your bank numbers, etc.

As for how encryption works, I'd suggest Applied Cryptography by Scheiner. I think there's a problem in that book about Bob keeping speculative posts to Alice secret from Eve. After reading that book, I'd suggest applying for a job at Apple to give you first hand knowledge of what they're actually doing and then you could make an informed judgement about what may or may not have been exposed.

Re: Apple Developer Website Update

#89

Is there any other source that this actually happened besides from a guy posting some text on HN?

Plenty of Apple and tech-related news sites have posted the email:

http://9to5mac.com/2013/07/21/apple-explains-developer-cente...

http://techcrunch.com/2013/07/21/apple-confirms-that-the-dev...

http://allthingsd.com/20130721/apple-developer-center-was-ha...

Re: Apple Developer Website Update

#90

Good to see some transparency on Apple's part here. I understand this must be a very challenging situation for them to deal with, and I appreciate the notification. As I'm sure many developers feel, I'd like to know more details, but I'm sure these will come in due course.

Transparency? After 3 days? Transparency would be telling us right away (with an update as soon as they know more). They should also tell us what kind of info was taken and what does sensitive information mean to them since they don't seem to be sure about that.

> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed.

Edit: and seriously, what does this "updating our server software, and rebuilding our entire database" mean?

Post reply on HN