Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

61–70 of 90 posts

Re: Update to Celebrity Photo Investigation

#61

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. >None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone. Um... doesn't "a very targeted attack on…

Is it still a social engineering hack if a well-known celebrity with their personal info broadcasted all over the internet decides to use that personal info to secure their account? Or rather, is that a social engineering hack on Apple, or the celebrity themselves? And what should Apple do, in this situation? If your names show up in tabloids, don't allow you to answer certain security questions? Require 2FA if your…

"Require 2FA for everybody, full stop" would do the trick.

The proposed solutions you outline all assume that "password + security question" is only an insecure system for celebrities. But we have enough experience by now to know it's an insecure system for everyone.

Re: Update to Celebrity Photo Investigation

#62
post #27

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Personally I don't believe using preset security questions should ever be allowed. People should be allowed to type their own security question and answer.

Re: Update to Celebrity Photo Investigation

#63
post #41

I am kinda of sick of hearing about how celebs got hacked and how it is such a big deal. The media over hypes these things and really the celebs involved should of used stronger passwords and/or 2 factor authentication. They should of known better. People get "hacked" this way tons of times by using weak passwords and/or security questions. You'll never see that appear in the media. The inequality here is the importa…

They are performing artist, how you feel about their contribution to society is based upon how you feel about performing artists in general.

Is society enriched by the eloquence of humanity of ballet? Does humanity prove itself to the universe when our best singers hold a pure note for a brief moment in time? What impact does a movie exploring some aspect of the human experience have upon the world?

Popular performing artists are popular because their performances bring some amount of joy to people's lives.

Re: Update to Celebrity Photo Investigation

#65
post #33
post #27

Earlier quoted context omitted.

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Whenever these types of questions are required for account recovery, I use a false set of answers as an additional security measure. Probably a good practice for a celebrity.

If the only way to safely use the system is to deliberately ignore its instructions ("provide answers to these questions"), then the system is broken.

Re: Update to Celebrity Photo Investigation

#66

> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. >None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone. Um... doesn't "a very targeted attack on…

Is it still a social engineering hack if a well-known celebrity with their personal info broadcasted all over the internet decides to use that personal info to secure their account? Or rather, is that a social engineering hack on Apple, or the celebrity themselves? And what should Apple do, in this situation? If your names show up in tabloids, don't allow you to answer certain security questions? Require 2FA if your…

Allowing people to create their own security question/answer pair would be an excellent start.

Re: Update to Celebrity Photo Investigation

#67

Earlier quoted context omitted.

Is it still a social engineering hack if a well-known celebrity with their personal info broadcasted all over the internet decides to use that personal info to secure their account? Or rather, is that a social engineering hack on Apple, or the celebrity themselves? And what should Apple do, in this situation? If your names show up in tabloids, don't allow you to answer certain security questions? Require 2FA if your…

"Require 2FA for everybody, full stop" would do the trick. The proposed solutions you outline all assume that "password + security question" is only an insecure system for celebrities. But we have enough experience by now to know it's an insecure system for everyone.

>>"Require 2FA for everybody, full stop" would do the trick.

How do you require 2FA for the Find My iPhone application when the only context for using that application is one in which your phone is lost?

Re: Update to Celebrity Photo Investigation

#68
post #27

Earlier quoted context omitted.

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

Don't most companies use this very same "insecure" system? 99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name. If you are going to use this information as part of your personal security, don't go telling people. Because, duh, you might as well tell them your password.

>99% of the population won't have this problem because not even some of your closest friends know what street you grew up on or your mother's maiden name.

Those are the same hand-wavey thought processes used by people who are paid to know better that get them hacked.

If I knew your name and where you live, I could find out your mother's maiden name and the street you grew up on in not much more time than it took me to type this comment - especially if it were something I did all the time. Fact-based additional confirmation questions are stupid, and non-fact based ones are impossible to remember.

seriously: http://www.peekyou.com/ or any of these services will work, and many of them allow you to buy prepaid packages.

Re: Update to Celebrity Photo Investigation

#69
post #17

> "we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions" > "None of the cases we have investigated has resulted from any breach in any of Apple’s systems" Don't these lines contradict each other?

Answer: "Hack" was due to weak passwords and no 2-factor, not because of any weakness in Apple's systems.

It seems significantly more likely that the "hack" was in the account recovery system which allows -- via a couple of often easily discovered personal details -- a complete, immediate account takeover.

Re: Update to Celebrity Photo Investigation

#70
I'm still wondering if the Find My iPhone brute force bug was exploited.

Why doesn't Apple at least offer a bug bounty reward? Is it irresponsible that they don't?

All they offer now, as far as I have found, is a mention on this web page:

http://support.apple.com/kb/HT1318

And, does the fact that this bug made it into production suggest a lack of internal security audits at Apple?

Post reply on HN