Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

51–60 of 90 posts

Re: Update to Celebrity Photo Investigation

#51

2FA is no panacea. My yahoo account (only used for flickr) was compromised with 2FA & 20+ character password.

Google and Yahoo both had 2FA holes in their mobile authentication entry points. No data to back this up other than my own experience and seeing the last logins coming from mobile devices in another country.

Re: Update to Celebrity Photo Investigation

#52

Earlier quoted context omitted.

Don't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.

Just because a lot of companies are using the system does not make it secure. Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.

You're right. I guess I have too much faith in the average user to not pick a question with a potentially obvious or easily discovered answer to it.

Re: Update to Celebrity Photo Investigation

#53
> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.

>None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.

Um... doesn't "a very targeted attack on user names, passwords and security questions" count as a "breach in... Apple's systems"? A social engineering hack is still a hack.

Re: Update to Celebrity Photo Investigation

#55
post #27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

While I wouldn't disagree with the stupidity of "security questions" answered straight, I don't know if this is something to lay on Apple's doorstep, because anyone with a modicum of knowledge either lies or supplies "custom" security questions-- it's basically a "if you forget password A, remember password B" system. But explaining that to users who have issues with a password is a lot more far-reaching and widespread than any one company.

Additionally, making "security questions" passwords in and of themselves is going to tremendously increase the volume of your support tickets. At some point, you need to make a cost/benefit analysis and make a decision including that, not just looking at "what's more secure if we assume our users are stupid".

If you really want a niche market, though, "social media security consultant" for celebrities would probably make you a pretty penny nowadays...

Re: Update to Celebrity Photo Investigation

#56
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

Not really. There's a perfectly valid distinction between accounts compromised by poor password recovery processes and more general ways of compromising the system, ie attacks that require targeted information about the account being compromised and attacks that compromise many accounts at once.

Re: Update to Celebrity Photo Investigation

#57

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. >None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone. Um... doesn't "a very targeted attack on…

Is it still a social engineering hack if a well-known celebrity with their personal info broadcasted all over the internet decides to use that personal info to secure their account? Or rather, is that a social engineering hack on Apple, or the celebrity themselves?

And what should Apple do, in this situation? If your names show up in tabloids, don't allow you to answer certain security questions? Require 2FA if your name is mentioned on Google more than a certain number of times?

I don't feel this is an Apple problem any more than it would be if someone created their iCloud password and then posted it on their Twitter.

Re: Update to Celebrity Photo Investigation

#58
From what I've read on 4-chan, Ars, Slashdot (indiv. comments, not articles) and other sources that this wasn't one person hacking a group of celebs acount, but a leak from an underground celeb nude trading ring that has existed for a while. So multiple hackers over a long period of time, from multiple sources.

link to one explanation: http://i.imgur.com/vnd0H9J.jpg

Re: Update to Celebrity Photo Investigation

#59

People have become so close with their smartphones that they entrust it with more information than their friends know. In addition no brand is more loved than Apple, with many celebrities being ambassadors to the brand. The brand is planning to introduce new payment and health services next week. For the average consumer two-factor-authentication means nothing, but they will start distrusting Apple more and will be m…

Nitpick: Ambassadors work in an Embassy.

Re: Update to Celebrity Photo Investigation

#60
post #27

Earlier quoted context omitted.

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Don't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.

"99% of the population won't have this problem because"

they don't use facebook or photo sharing sites or ... oh wait I guess they do. That might be a problem.

I don't think this is rocket science here. Find my FB account, find my mom, what is her brother/uncle/fathers last name, or just look at her "friends" list and try the most common last names. Or heck just try them all, there won't be more than a couple hundred to try and thats easier than bruteforcing the entire phone book. Heck just use my friends list, I know enough men on my moms side of the family. Done. Next.

Find my FB account and get a general idea where I grew up (just to make sure, although my name is weird enough for this not to matter). Go to genealogy website, search old phone books for my mom's name or just my last name, street name was Greenfield. Maybe you'll find my house and my aunts house, so two names to try. Done. Next.

Find my FB account, look thru old pix, here's me and my girlfriend in front of this 80s subcompact POS that being my first car which was a falling apart POS when I got it, but whatever. Ask an "old" guy to id the car. Its either a Dodge Omni or a Plymouth Horizon. And its red, if thats the question. Done. Next.

Its very unusual to have a "personal security question" that isn't answered by facebook, twitter, linkedin, any of the photo sites, classmates.com, etc.

Post reply on HN