Live data from Hacker News

Ibrahim Balic breaks silence on hacking Apple developer site

news.com.au

31–40 of 56 posts

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#31

The article states that the website is back up but as of now 24/07 11:08GMT that is not the case. This is terrible timing for me since I came back from travelling on Thursday and haven't been able to get on with working in iOS 7. I really wish Apple were able to provide us with more information on time-scales.

Especially terrible timing for me. I hadn't gotten around to updating my phone off the original iOS 7 beta. Guess what expired yesterday? The original iOS 7 beta. My phone is essentially a brick now until I can update to a non-expired version of iOS.

If you've got a model a1429 I actually have a copy sat on my machine, I can put it on Dropbox and give you a link.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#32

The article states that the website is back up but as of now 24/07 11:08GMT that is not the case. This is terrible timing for me since I came back from travelling on Thursday and haven't been able to get on with working in iOS 7. I really wish Apple were able to provide us with more information on time-scales.

Especially terrible timing for me. I hadn't gotten around to updating my phone off the original iOS 7 beta. Guess what expired yesterday? The original iOS 7 beta. My phone is essentially a brick now until I can update to a non-expired version of iOS.

You still can roll back to 6.1.1. And this is exactly why you don't install a beta OS on your main phone.

Btw, you can download beta 3 using a certain p2p protocol.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#33

> I have taken 73 users details (all apple inc workers only) and prove them as an example ... > I have over 100,000+ users details ... > I do not want my name to be in blacklist One would think that 73 compromised Apple employee accounts should be enough to make a point. Why would he take another 100k user accounts hostage?

That probably wouldn't have shut down the site, which in turn would not have gotten the attention. He wasn't making a point to Apple, who already knew the bugs existed, he was making Apple do something about it. He did.

> That probably wouldn't have shut down the site

So the guy is a hero. Thanks for disturbing real life businesses for several days, I guess?

> he was making Apple do something about it.

This behavior is endemic for the self-righteous security "researcher" scene. "I found a bug - you must do what I say, NOW, or else ..."

It's not like Apple would have ignored his bug reports if he wouldn't have scraped 100k developer accounts.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#34
post #23

> I have taken 73 users details (all apple inc workers only) and prove them as an example ... > I have over 100,000+ users details ... > I do not want my name to be in blacklist One would think that 73 compromised Apple employee accounts should be enough to make a point. Why would he take another 100k user accounts hostage?

He probably downloaded 100k accounts (perhaps a range of IDs) and then grepped them for @apple.com accounts.

Maybe, but he writes that he still has those 100k data sets. So why didn't he delete them after grep ran through?

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#35
post #20

Earlier quoted context omitted.

disgrace |disˈgrās| noun loss of reputation or respect, esp. as the result of a dishonorable action [ in sing. ] a person or thing regarded as shameful and unacceptable How is it a disgrace? You're making it sound like Apple meant for this to happen, this could've happen to any companies. Apple should not be portrayed to be perfect at everything, they're lead by humans who can make mistakes, just like everybody else.…

> How is it a disgrace? You're making it sound like Apple meant for this to happen, this could've happen to any companies. Well if Ibrahim is to be believed, Apple failed to reasonably handle his disclosure of the security flaws. Apple is not entirely at fault, but they surely failed to protect their users' data. Users trusted Apple to prevent this from happening, but they have failed. That is a disgrace.

He created a bug in a portal of hundreds of thousands of bugs. That was not even two weeks ago.

I'd be surprised if someone had even looked at the bug until a few days ago. Then they did some investigating, determined it to be true and ran up the manager ladder till someone said shut it down.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#36

Earlier quoted context omitted.

That probably wouldn't have shut down the site, which in turn would not have gotten the attention. He wasn't making a point to Apple, who already knew the bugs existed, he was making Apple do something about it. He did.

> That probably wouldn't have shut down the site So the guy is a hero. Thanks for disturbing real life businesses for several days, I guess? > he was making Apple do something about it. This behavior is endemic for the self-righteous security "researcher" scene. "I found a bug - you must do what I say, NOW, or else ..." It's not like Apple would have ignored his bug reports if he wouldn't have scraped 100k developer…

He says he reported the bug previously and got no response...

So, it's very much "like Apple would have ignored his bug reports..."

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#38

> I have taken 73 users details (all apple inc workers only) and prove them as an example ... > I have over 100,000+ users details ... > I do not want my name to be in blacklist One would think that 73 compromised Apple employee accounts should be enough to make a point. Why would he take another 100k user accounts hostage?

That probably wouldn't have shut down the site, which in turn would not have gotten the attention. He wasn't making a point to Apple, who already knew the bugs existed, he was making Apple do something about it. He did.

His video shows that he filed radars on July 19th - the same day downloaded the 100,000 developer names and email addresses.

This is not responsible reporting, and he's clearly broken the UK computer misuse laws, since he signed an agreement with Apple governing the use of these systems.

I hope he's arrested soon. This behavior does nothing to help legitimate business or the security community.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#39
post #36

Earlier quoted context omitted.

> That probably wouldn't have shut down the site So the guy is a hero. Thanks for disturbing real life businesses for several days, I guess? > he was making Apple do something about it. This behavior is endemic for the self-righteous security "researcher" scene. "I found a bug - you must do what I say, NOW, or else ..." It's not like Apple would have ignored his bug reports if he wouldn't have scraped 100k developer…

He says he reported the bug previously and got no response... So, it's very much "like Apple would have ignored his bug reports..."

What he leaves out is that he waited less than a day for a response. (You can see this from the radar shown in his video)

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#40
post #23

Earlier quoted context omitted.

He probably downloaded 100k accounts (perhaps a range of IDs) and then grepped them for @apple.com accounts.

Maybe, but he writes that he still has those 100k data sets. So why didn't he delete them after grep ran through?

Because he's clearly not very experienced in this. Apparently his video (when it was up) had confidential information shown in it: https://twitter.com/ibrahimbalic/status/359347248473190402. Who the hell flouts confidential information in a public fashion? There's a interview with him with English subtitles here: http://video.ntvmsnbc.com/applei-sarsan-turk-yazilimci-ntvms..., where he says some interesting things near the end. It looks like he used a struts2 vulnerability, HN had a discussion about this 2 days ago: https://news.ycombinator.com/item?id=6080620, https://news.ycombinator.com/item?id=6082599. He basically did what Weeve did, except Weeve is in confinement now.
Post reply on HN