Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

21–30 of 90 posts

Re: Update to Celebrity Photo Investigation

#21
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

Or just password recovery with trivially discoverable personal details. To a determined attacker, your mother's maiden name, the street you grew up on, and the name of your first pet are not hard to figure out. Information like that isn't even secret, the whole practice of using password recovery questions needs to go away.

> trivially discoverable personal details

Which are even more trivially discoverable for celebrities, since their lives are frequently so well-documented!

Re: Update to Celebrity Photo Investigation

#22
post #9
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found more personal information and iCloud accounts by going the contacts of each person they compromised. That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't ha…

I always put in made-up or nonsense information for the answers to the security questions, and store it all in the same encrypted file with my passwords. Seems more secure than using correct information that would not be hard for an attacker to discover. ("Then how will you get password recovery?" "I will never need that.")

Re: Update to Celebrity Photo Investigation

#23
The damage has been done, surely?

Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc.

Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons).

Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days.

Question is, would Apple have responded so quickly if celebrities weren't involved?

Re: Update to Celebrity Photo Investigation

#25
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

Answer: "Hack" was due to weak passwords and no 2-factor, not because of any weakness in Apple's systems.

Ah, thanks for clearing that up.

Re: Update to Celebrity Photo Investigation

#26
post #9
post #2

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. So, the brute force attack with reasonable guesses at email addresses?

My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found more personal information and iCloud accounts by going the contacts of each person they compromised. That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't ha…

I think it‘s quite easy to argue that when accounts are compromised because of security questions whoever implemented those questions is at fault. They are a convenient, if crap way to secure accounts. Apple and everyone else have to do better.

(I suppose the good news is that you can actually protect yourself from this. However, how to protect themselves won’t reach most people, so in the big picture this is cold comfort. I do think it’s the job of the platform owner to make sure that users cannot easily leave themselves open to attacks. Most people don’t know about security, the platform owner does.)

Re: Update to Celebrity Photo Investigation

#27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire, system. Those "security questions" are very easy to find out, therefor the system is insecure.

Re: Update to Celebrity Photo Investigation

#29

I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone. Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates. I guess the thing I'm really trying to figure is that if it was IBrute (whi…

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone: > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

>> They seem to have specifically ruled it out later in the statement

>> > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Have they ruled it out? When you factor that the statement's intended audience is the entire world, not just cyber security experts, the wording becomes muddy, as it depends on you how you interpret the word "breach".

If someone successfully uses a password attack, is it actually a 'breach' of Apple's systems? After all, the systems successfully prevented entry until a valid password was entered, which is exactly what the systems were designed to do.

Re: Update to Celebrity Photo Investigation

#30
post #16

Earlier quoted context omitted.

Understood. My second question then is just asking whether Apple have a reputation for truthiness in this arena. I genuinely don't know, I'm asking.

I think that have a pretty good record on owning up to something. It would hurt them much much more to lie about it at this point.

I'm curious what you base that on... that they own up to problems. I know it's certainly not true with hardware issues. They may eventually fix it, but it's rare that they'll comment on it.
Post reply on HN