Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

191–200 of 223 posts

Re: Apple Developer Website Update

#191
post #50

Earlier quoted context omitted.

Yes, but it doesn't take more than a day to know that an intruder had accessed the system in a way that may have compromised your personal information. Basically, once the problem was serious enough that they felt like they needed to take the site down, I'm pretty sure they knew which machines had been accessed (or at least may have been accessed). They knew that some of those machines had developer's personal inform…

"I'm pretty sure." No, they likely took the portal down as soon as they knew there was a breach. Highly unlikely they left it up while they investigated, and it takes time to figure out what happened and how much information was taken. What motivation would there be to wait anyways?

> No, they likely took the portal down as soon as they knew there was a breach. Highly unlikely they left it up while they investigated, and it takes time to figure out what happened and how much information was taken.

They still haven't said anything about how much had been taken.

My point is they knew how much could have been taken. They knew what machines were at risk; hence taking them down. If those machines that were at risk had sensitive personal information, they should have notified the people affected right away, not three days later.

Taking the site down, with no indication of why, and waiting three days to tell people that their personal information may be at risk (and remember, the possibly compromised information includes credit card numbers, as there are a number of things you need to pay for in your developer account) is just crazy.

You should be upfront and transparent when the breach first occurs. Of course you don't know exactly what has been compromised; but they are still being plenty vague even three days later. If they had posted three days ago what they posted today, it would be a lot more reassuring.

Re: Apple Developer Website Update

#192
post #180

Theres a security researcher commenting on techcrunch claiming he's responsible for the breach here http://fyre.it/tjlVmC.4 His proof uploaded to youtube: http://www.youtube.com/watch?v=q000_EOWy80

Taking 40k records is more than just penetration testing.

Re: Apple Developer Website Update

#193
post #102

Earlier quoted context omitted.

By "sensitive personal information" they probably just mean passwords and credit card information, not names, email addresses and mailing addresses.

I'm imagining bank account numbers over CC info/passwords was the sensitive part.

Bank account numbers are not secret. If you write a check to someone they have your account number.

Re: Apple Developer Website Update

#195

Earlier quoted context omitted.

Alternately, inside the reality distortion field developers’ names, mailing addresses, and/or email addresses is not sensitive personal information.

How are names, mailing addresses, and email addresses sensitive personal information? I would imagine that for most of the people signed up, it wouldn't be that hard to track down their name and email just from knowing the name of their app.

Name and e-mail, I'm kinda with you. Everyone who uses my app knowing my current mailing address I look at a little bit different.

Re: Apple Developer Website Update

#196

Here's my semi-educated guess for how the attack started: from casual observation (view source, URLs ending with .action, etc) a good chunk of the ADC is written in Java and uses WebWork/Struts2, a framework I helped create years ago. Late last week a security advisory came out that allows for executing malicious code[1]. Atlassian, which uses similar technology, also issued announcements around the same time[2]. My…

technology choices tend to stick around a lot longer than you ever imagine :)

It amazes me how true this is. I've learned that assertions such as "this is a mockup and should be replaced ASAP for reasons X Y Z" tend to get ignored by inheritors of proofs-of-concepts for as long as (or longer than) possible. My coworkers wonder why now I fight tooth-and-nail to (from their perspective) over-engineer things from the start; I know that short-sighted decisions will never be revisited until it's too late.

Re: Apple Developer Website Update

#197

Here's my semi-educated guess for how the attack started: from casual observation (view source, URLs ending with .action, etc) a good chunk of the ADC is written in Java and uses WebWork/Struts2, a framework I helped create years ago. Late last week a security advisory came out that allows for executing malicious code[1]. Atlassian, which uses similar technology, also issued announcements around the same time[2]. My…

The timing of this looks right: Struts 2.3.15.1 was released on 7/16/13, and developer.apple.com went down on 7/18/13 for "maintenance". Plenty of time for an enterprising black hat to notice and exploit the vulnerability.

Re: Apple Developer Website Update

#198
post #170

Earlier quoted context omitted.

That's because the portal is down and people can no longer log in to revoke their developer certificates.

That's what I thought -- but it was also down the 19th yet 2 were revoked. Probably means nothing however. I doubt that anybody with the ability to get into the system would want to get only developer certificates.

[deleted]

Re: Apple Developer Website Update

#199

Good to see some transparency on Apple's part here. I understand this must be a very challenging situation for them to deal with, and I appreciate the notification. As I'm sure many developers feel, I'd like to know more details, but I'm sure these will come in due course.

It's a strange world we live in when every time we're told by a big corp that our personal info was compromised, we're grateful for being told. This is the worlds most cashed-up corporation. They could buy entire countries, yet they made a conscious choice not to update their server software or hire more competent sys-admins. There shouldn't be a way for them to gain marketing wins out of this. There should be a law…

There is a law that requires them to notify people immediately. I suppose their excuse for waiting three days will be that they did not know for sure whether any personal data was acquired by the intruder. There's going to be a debate on what they needed to know to "reasonably believe" that data had be accessed. http://info.sen.ca.gov/pub/01-02/bill/sen/sb_1351-1400/sb_13...

(b) Any person or business that maintains computerized data that includes personal information that the person or business does not own shall notify the owner or licensee of the information of any breach of the security of the data immediately following discovery, if the personal information was, or is reasonably believed to have been, acquired by an unauthorized person.

(c) The notification required by this section may be delayed if a law enforcement agency determines that the notification will impede a criminal investigation. The notification required by this section shall be made after the law enforcement agency determines that it will not compromise the investigation.

Re: Apple Developer Website Update

#200
post #121

Earlier quoted context omitted.

By "sensitive personal information" they probably just mean passwords and credit card information, not names, email addresses and mailing addresses.

I think I would rather someone have my CC number than my home address (which would be the same as my mailing address).

Why?
Post reply on HN