Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

1–10 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#2
I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices.

Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light.

[EDIT]: Not the FBI, but a private company noticed this (h/t codeecan)

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#3
> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords

> He gained unauthorized access to photos and videos of at least 306 victims across the nation

> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house

Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#4

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

Scary indeed, slight correction, not the FBI [initially];

> A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure ...

He was caught by random chance of this company.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#5

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

https://twitter.com/matthew_d_green/status/14299631415684014...

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#6

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#7
It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this.

This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iCloud software (either from his browser or his computer).

All the supposedly advanced algorithms that often arbitrarily ban accounts by mistake managed to miss some random dude behind his laptop, shamelessly leaking private pictures.

My heart goes out to this man's victims.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#9
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

I agree that better education around Internet security is needed, especially for basic phishing attacks like this.

OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#10
post #9
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

I agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.

If you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?
Post reply on HN