Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

31–40 of 90 posts

Re: Update to Celebrity Photo Investigation

#31

I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone. Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates. I guess the thing I'm really trying to figure is that if it was IBrute (whi…

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone: > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Not necessarily. They could make an argument that the services themselves were not "breached", however the users weak passwords allowed them to be compromised.

Re: Update to Celebrity Photo Investigation

#32
post #27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

2FA needs more traction.

Also, email/text alerts about new logins, login attempts, and changes to account settings.

Re: Update to Celebrity Photo Investigation

#33
post #27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Whenever these types of questions are required for account recovery, I use a false set of answers as an additional security measure. Probably a good practice for a celebrity.

Re: Update to Celebrity Photo Investigation

#34
post #27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Don't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.

Re: Update to Celebrity Photo Investigation

#35
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

Answer: "Hack" was due to weak passwords and no 2-factor, not because of any weakness in Apple's systems.

> Apple's systems

Systems aren't just technical (software), they involve human beings, feedback loops, interactions, etc. Apple's security systems are in fact weak, just not weaker than the norm.

Actually I think the Apple press release was poorly worded. This in particular:

>None of the cases we have investigated has resulted from any breach in any of Apple’s systems

There was indeed a breach in Apple's system, there just wasn't a system wide breach that compromised all accounts, just a select few.

Re: Update to Celebrity Photo Investigation

#36

I'm confused. The description of the problem doesn't rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn't an issue with ICloud or FindMyPhone. Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates. I guess the thing I'm really trying to figure is that if it was IBrute (whi…

They seem to have specifically ruled it out later in the statement, as iBrute was targeted at Find my iPhone: > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

That's certainly what they want you to take away from it, but is it what they actually said?

Failing to rate limit login attempts is a fuzzy sort of failure. I would probably call it a "vulnerability", but I wouldn't call it a "breach" to take advantage of it to figure out someone's password.

To me, this reads as a carefully crafted non-denial that looks like a denial if you don't really pay close attention.

Re: Update to Celebrity Photo Investigation

#39
At what point do tech companies start making two factor authentication mandatory?

It's one thing to say "We tell our users to use two factor authentication - it's their fault if they don't use it" but it's another to say "all user accounts use two factor authentication to ensure security of their data"

Re: Update to Celebrity Photo Investigation

#40
post #27

Earlier quoted context omitted.

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Don't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.

Just because a lot of companies are using the system does not make it secure.

Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.

Post reply on HN