Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

11–20 of 90 posts

Re: Update to Celebrity Photo Investigation

#11

I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone. Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates. I guess the thing I'm really trying to figure is that if it was IBrute (whi…

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone: > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Understood. My second question then is just asking whether Apple have a reputation for truthiness in this arena. I genuinely don't know, I'm asking.

Re: Update to Celebrity Photo Investigation

#12
It seems like it would be a feat to gather all the user IDs of these famous people in the first place. I'm guessing there's a black market just for that? I used to work on a service used by quite a few famous people, if anybody on the project was unscrupulous, it would have been easy to pass those emails and other personal information on to a hacker.

Re: Update to Celebrity Photo Investigation

#15
post #12

It seems like it would be a feat to gather all the user IDs of these famous people in the first place. I'm guessing there's a black market just for that? I used to work on a service used by quite a few famous people, if anybody on the project was unscrupulous, it would have been easy to pass those emails and other personal information on to a hacker.

If you can break into one person's account and get their contacts then you can recurse from there. It's likely that one celebrity knows another and so on.

Re: Update to Celebrity Photo Investigation

#16

Earlier quoted context omitted.

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone: > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Understood. My second question then is just asking whether Apple have a reputation for truthiness in this arena. I genuinely don't know, I'm asking.

I think that have a pretty good record on owning up to something. It would hurt them much much more to lie about it at this point.

Re: Update to Celebrity Photo Investigation

#17
> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions"

> "None of the cases we have investigated has resulted from any breach in any of Apple’s systems"

Don't these lines contradict each other?

Re: Update to Celebrity Photo Investigation

#18
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

No as I can try and guess your login credentials and that is a perfectly acceptable and valid workflow which isn't exploiting anything.

I think the issue is that the previously posted Find My Iphone code didn't rate limit invalid logins and this was used to bruteforce creds. This is probably the real underlying issue and not any type of buffer overflow / exploit etc.

Re: Update to Celebrity Photo Investigation

#19
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

Answer: "Hack" was due to weak passwords and no 2-factor, not because of any weakness in Apple's systems.

Re: Update to Celebrity Photo Investigation

#20
post #14
post #10

If anyone wants to setup 2FA for their Apple ID here's their support page on it: http://support.apple.com/kb/ht5570

enables 2FA Apple: "Please wait 3 days to continue." Ugh.

Why "ugh"? Introducing a delay makes it much more difficult for an attacker to use 2FA to lock a user out of a compromised account. It's actually a really smart idea.
Post reply on HN