The UDID leak is a privacy catastrophe
21–30 of 52 posts
Re: The UDID leak is a privacy catastrophe
#22> If your UDID is contained in the list, take a minute to help us identify the traitor that did give your information to the FBI without any your agreement and without warrant ! Wouldn't it also be useful to gather information about who WASN'T on the list and what Apps they have? Maybe device type as well.
Re: The UDID leak is a privacy catastrophe
#23If I don't play games, much less belong to any social gaming networks, does this affect me at all?
Re: The UDID leak is a privacy catastrophe
#24Re: The UDID leak is a privacy catastrophe
#25Re: The UDID leak is a privacy catastrophe
#26After reading this, I'm still a bit confused as to why this is a catastrophe? Should we change our paypal passwords? Or worry about getting more spam? etc Why should an end user (eg my mom) care? I'm not saying there aren't serious repercussions, just having a hard time seeing exactly what they are.
Have a quick read through the posts linked in the article this story points to. I show that using just a UDID, you could access the user's geolocation, games they played, private messages and friends lists on many of the affected social networks, and in some cases (which affected millions of users) completely take over Twitter and Facebook accounts. This is with _just_ a UDID. Some of the companies I notified a year…
Re: The UDID leak is a privacy catastrophe
#27If you disallow an app from sending you push notifications, will it still have your UDID/Device ID? Or if you never enable it, does the app & app server never get it?
Push notifications don't use the UDID. They use a different token. UDIDs can be requested without user consent by applications, although that functionality is supposedly deprecated from iOS 5 onwards.
Re: The UDID leak is a privacy catastrophe
#28Re: The UDID leak is a privacy catastrophe
#29Earlier quoted context omitted.
Thanks for that. Not super worried about people knowing my location or games I played :p However, this is of interest: >and in some cases (which affected millions of users) completely take over Twitter and Facebook accounts How is that possible? Are we going to see mass defacements/malware links or other bad stuff on Twitter and Facebook as a result? Also what is meant by 'take over'? Surely it doesn't mean from a UD…
I found vulnerabilities in two social gaming networks that let you take control of people's Facebook and Twitter accounts using _just_ the UDID. I never published the details of these vulnerabilities, but you can find an official acknowledgement from at least one of these companies (Chillingo of Angry Birds fame) in this WSJ piece: http://blogs.wsj.com/digits/2011/09/19/privacy-risk-found-on...
Re: The UDID leak is a privacy catastrophe
#30It's also worth noting that Apple has deprecated the UDID, and new and updated apps are no longer able to access it.