I guess some female celebrities are going to reconsider Android next time they buy a smartphone.
AppleID password brute force proof-of-concept
41–50 of 83 posts
Re: AppleID password brute force proof-of-concept
#42He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.
Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…
Re: AppleID password brute force proof-of-concept
#43I guess some female celebrities are going to reconsider Android next time they buy a smartphone.
So unless those are all well secured (and they may be, no clue) then moving to Android is no magical fix.
A better way of doing things is making it more clear to people what they are and aren't backing up. I'm sure for the majority of people backing up nudes is unintentional.
Re: AppleID password brute force proof-of-concept
#44How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?
Delayed disclosure is a nicety, not something you are obligated to do.
Re: AppleID password brute force proof-of-concept
#45I don't know if this was the attack used in the hack, but it is really, really bad news for Apple. The public is not going to trust iCloud any more. I'm pretty sure Apple will drop iWallet from the keynote, or it'll end up like their maps.
I'm no fan of Apple Maps. I pretty much only use it when I have to (e.g. because Find My Friends uses it) or to make fun of it. But there are a ton of people who don't care and just use the default. Even among my tech-savvy programmer friends it's common.
Re: AppleID password brute force proof-of-concept
#46Earlier quoted context omitted.
Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…
@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896
Re: AppleID password brute force proof-of-concept
#47How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?
Re: AppleID password brute force proof-of-concept
#48How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?
Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.
Re: AppleID password brute force proof-of-concept
#49How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?
Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.
Re: AppleID password brute force proof-of-concept
#50Earlier quoted context omitted.
@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896
he's assuming from when the tool was released. The exploit was in the wild for much longer.
Though he's commented to Buzzfeed denying it was him (but anyone would).
http://www.buzzfeed.com/charliewarzel/bryan-hamade-blamed-by...
@nikcub still thinks it's him