Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

31–40 of 292 posts

Re: Notes on the Celebrity Data Theft

#31
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

Agreed! At first I figured that if I could save one piece of information for each dollar I had spent on the software, it would be worth my money.

By day two of using 1Password I had 70 entries, and was blown away at how much peace of mind I had. There were seventy things I never needed to _worry_ about forgetting. It was like my brain was holding onto each of those and now I felt more able to just focus on working, it's insane how since I didn't know any better I waited years to finally try it.

Second thing I did, buy a copy for my cousin for his birthday! Hope he has a great year with more brainspace for ideas and less spent trying not to forget things :)

Re: Notes on the Celebrity Data Theft

#32

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

Paparazzi have no problem selling exclusive photos.

Hut those are not stolen. It's much harder to get a good price for stolen goods because there is no demand from legitimate buyers, in this case large publishers.

Re: Notes on the Celebrity Data Theft

#33

While I am complete appalled by the data breach and hope that similar things never happens to anyone again I would like to propose a purely thought experiment: The hacker reported sold the nude photos of Jennifer lawrence for a mere sum of $130 using bitcoin. If we apply game theory here, these kind of data is very difficult to monetize. If you sell one copy of the data, it is then immediately distributed online for…

This would also facilitate committing to assurance contracts via bitcoin.

http://en.wikipedia.org/wiki/Assurance_contract

Re: Notes on the Celebrity Data Theft

#34
Isn't showing partially blacked out private photos still a violation of privacy? If the author of this post really wants to be white hat, he should modify the image (above 14) to obscure the non-blacked out part of the photo with a different color. I'm unfamiliar with that celebrity in the picture but if I was familiar with her work, it would feel creepy to look at it.

Re: Notes on the Celebrity Data Theft

#35
post #25
post #13

Icloud hacking was mentioned and everyone has jumped on it. Many cell transmissions are unencrypted. MITM attacks should not be thrown out as a possibility. Malware is also a vector, including apps.

One of the victims stated the pictures were from several years ago. Unless the hacker was extraordinarily patient and persistent, I have to think a MITM attack on a cell tower is unlikely. More likely a cloud service (email, social media, storage) of some sort was compromised.

Another possibility is purchasing an old phone from Ebay and extracting deleted files. Or a local mac/pc/phone repair shop pulling the data during a repair. Then theres the nsa/border sec vector too.

Photos uploaded to a mac or pc could also be malwared or malicious apps. Theres the ex/friends/family as possible weak points too.

Plus we have no idea how long these photos have been traded within that private group.

What i'm saying is there are lots of ways this could be done and we shouldn't get so hung up on the icloud idea.

Re: Notes on the Celebrity Data Theft

#36
post #7

Why is nobody talking about password reset questions?

It seems attackers used them somehow:

"After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone."

http://www.businesswire.com/news/home/20140902006384/en/Appl...

Re: Notes on the Celebrity Data Theft

#37
post #4
post #3

Earlier quoted context omitted.

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

>Dude. 1Password. Password managers only protect against certain kinds of attack. Many cloud services do not or can not properly encrypt their users' data, so having a strong password won't help in the event that your cloud provider's datacenter gets rooted.

I think the main point is that while no platform is 100% safe, you can help alleviate the issue by reducing risk (in the case of the original commentor, they were emailing passwords to themselves).

Of course there are limits to any measure of security, but 1password does a great job in helping people manage themselves.

Personally, it's helped me a lot in just keeping my various usernames/user accounts organized (I sign up for just about anything).

Re: Notes on the Celebrity Data Theft

#38
post #3
post #2

I wrote this in the other thread on the leak before it died: > Even if the leaks result from one at a time social engineering, it still really calls into question the practical security of the cloud. I doubt it's much harder to steal, e.g. confidential business documents from executives' cloud accounts than it is to steal pictures from celebrities' cloud accounts. > If I were a big organization with confidential info…

Dude. 1Password. Switching to using it for everything was one of the single smartest things I did this year. I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.

[deleted]
Post reply on HN