Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

1–10 of 90 posts

Re: Update to Celebrity Photo Investigation

#2
> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.

So, the brute force attack with reasonable guesses at email addresses?

Re: Update to Celebrity Photo Investigation

#3
So "This is a very common attack on the Internet that we didn't do much to protect you against by default"?

It's a pain setting up two step authentication across a lot of services, but I guess iCloud is probably one that's worth the effort. Still I'd rather brute force was not an option.

Re: Update to Celebrity Photo Investigation

#4
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

or phishing

Re: Update to Celebrity Photo Investigation

#6
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

Or just password recovery with trivially discoverable personal details. To a determined attacker, your mother's maiden name, the street you grew up on, and the name of your first pet are not hard to figure out.

Information like that isn't even secret, the whole practice of using password recovery questions needs to go away.

Re: Update to Celebrity Photo Investigation

#7
I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone.

Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates.

I guess the thing I'm really trying to figure is that if it was IBrute (which personally I would find an embarrassing failure) would they actually admit it?

Re: Update to Celebrity Photo Investigation

#8

I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone. Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates. I guess the thing I'm really trying to figure is that if it was IBrute (whi…

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone:

> None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Re: Update to Celebrity Photo Investigation

#9
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found more personal information and iCloud accounts by going the contacts of each person they compromised.

That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't hard to do anymore.

Post reply on HN