Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

221–223 of 223 posts

Re: Apple Developer Website Update

#221
post #88
post #7

Uh, how does this "encryption" work? For the website to show these details (and it does, in part, use these details in the interface) it must be able to decrypt these on the web applications side. Ergo the keys for decryption must also be on the server or derived from the users passwords, both of which make the use of encryption a fairly worthless venture. ED: As another commenter mentioned in an earlier thread, lots…

Maybe they phoned for a ransom after breaking in? Your post is pure speculation and depends heavily on what Apple means by 'sensitive'. I'm guessing that Apple means your CC numbers, certs, shared keys, etc. Possibly also your support tickets, your bank numbers, etc. As for how encryption works, I'd suggest Applied Cryptography by Scheiner. I think there's a problem in that book about Bob keeping speculative posts to…

AFAIK, it was a white (or grey) hat hacker. See the comment on the techcrunch article. He nabbed Apple employee details, as proof. But they are probably worried that someone else has also done it.

Re: Apple Developer Website Update

#222

Earlier quoted context omitted.

I think the human being, as imperfect, is finally to blame.

Are you people out of your mind? The person responsible for this is the unethical human being(or organization) that decided to abuse that security hole and use it to steal our information. Not the engineers, not Apple. When you see an old lady walking alone in the dark, do you steal her purse because she did not protect herself well enough? I'm sure you don't... So please, don't over complicate things.

So when you entrust your belongings to a storage company, and they leave the doors unlocked and your stuff gets stolen, do you get mad at the thief? Or do you demand better security from your storage company?

Re: Apple Developer Website Update

#223
post #201

Earlier quoted context omitted.

No, I made no mention whatsoever about how long it took them to tell us. Did you even read my comment? > That doesn't mean that Apple is some evil company trying to hide the fact that there was a breach. I never said that they were trying to hide anything. Again, did you even read my comment? > Obviously this means they would have kept it secret if it were at all possible. Well yes, that is logical. A corporation wou…

> if they had a guarantee that there was no other way people could find out Do you believe this is unique to corporations? Would "real people" always do the right thing even if they had a guarantee nobody would e able to tell?

Yes, many people would. I for one.
Post reply on HN