Live data from Hacker News

Man steals 620k photos from iCloud accounts from home without Apple noticing

latimes.com

121–130 of 149 posts

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#121
post #3

> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained unauthorized access to photos and videos of at least 306 victims across the nation > Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house Not very sophisticated, but very effective, glad they…

> but we really need to teach basic internet security in schools.

I think you need to do that for people that are no longer in school... because most young people probably know not to give out their passwords

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#122
post #33
post #7

It's kind of funny. When you look into cyber security, the papers are all about controlled rate limiting, advanced anomaly detection, client fingerprinting, the likes, but in practice, very little companies will actually pick out abuse like this. This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iClo…

You mean like this? EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM. Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅ I can see it, but you can't. Try it!!!! An unbelievable number of people fell for this on Myspace and Facebook in the early days.

Uz)j>q5k*n</:bHh

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#123

I posted this link and I named it the way I did to draw attention to this in context of CSAM enforcement... this man could have easily uploaded any photos to these hacked iCloud accounts, which would've been synced down to end user devices. Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light. [EDIT]:…

Comments like are so bizarre to me. Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same. So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.

The problem with the US statute for CSAM is that possession is illegal, not just intentional creation/collection/distribution. The person being hacked has technically broken the law, even if they don’t get prosecuted.

I don’t know how often unintentional possessors are prosecuted, but the US system of prosecution makes it easy for an innocent to get railroaded by threats of massive charges and comparatively leanient plea deals, combined with punitive sentencing for those who reject the plea bargain. Think Aaron Schwartz, but without any intent to violate the law.

> The person being hacked would still be investigated by the FBI

As someone with family in the FBI (one on a relevant team) and a local LEO that was deputized to do this work for the US Marshals, that doesn’t reassure me. The best forensics employees in the FBI with enough resources can identify that there was a hack and that the account owner is innocent. We live in a world of scarcity where that much effort is not always invested.

I think the client-side versus server side is more about relative trade offs of who owns the client device (and what “ownership” means) and whether the equivalent server side search is technologically feasible (might not be if the client encrypts with a key only the client owns, as some have speculated about Apple’s future plans).

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#125
post #43
post #39

Earlier quoted context omitted.

It doesn't. DO NOT TRY. I was just giving an example of a classic scam, and I can't believe someone actually tried it.

I meant I won't try if I can log into their account with what their comment said at first.

holy shit i tried it it worked lol

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#126

Earlier quoted context omitted.

This was also a common technique used in Runescape back in the day. Takes me back. The much more innocent version was all chatting "Press alt q q for free gold" in Warcraft 3. Alt+q+q was the keyboard shortcut to abandon the match, which I learned the hard way.

In Brood War it was "press Alt-F4 to download faster" when someone wanted to boot the slow user on a dial-up modem.

"Hold F3+C for cheats" in Minecraft

"quit smoking in console" for source games

Probably others I've forgotten falling for over the years

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#128

Earlier quoted context omitted.

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

This comment assumes that Apple does a lot of heavy lifting to exonerate individuals who are found with CSAM beyond just reporting them to law enforcement. Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?

"A lot of heavy lifting"

Also known as a 20 line script which checks the last modified date for a bunch of recently uploaded files and validates the IP address against the recently known list.

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#129

Earlier quoted context omitted.

Comments like are so bizarre to me. Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same. So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.

The problem with the US statute for CSAM is that possession is illegal, not just intentional creation/collection/distribution. The person being hacked has technically broken the law, even if they don’t get prosecuted. I don’t know how often unintentional possessors are prosecuted, but the US system of prosecution makes it easy for an innocent to get railroaded by threats of massive charges and comparatively leanient…

What strict-liability statute are you referring to?

Re: Man steals 620k photos from iCloud accounts from home without Apple noticing

#130
post #6

Earlier quoted context omitted.

If Apple were to do what many recommend and do CSAM scanning in the cloud like other providers, would that change this attack vector?

It's only an attack vector in the minds of people who haven't given it more than 10 seconds of thought. Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot. And then…

> A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot.

Only if that system / heuristic has been built. The same could have been said about Apple’s systems for identifying bulk account hijacks, but Apple didn’t, which I suppose is the value of this story.

And companies aren’t allowed to Just inspect content once they identify CSAM. It is kryptonite for criminal liability. Companies are required to turn it over to the feds quickly and to try not to disturb metadata.

I suspect your line of thought would work given full ability to inspect (and some assumptions about what an IP change actually proves), but in practice Apple still hasn’t gotten the basics around account hijacks/fraud sorted out, so I’m hesitant to cheer them on as they try to quickly jump into the deep screaming “think of the children!”.

Post reply on HN