Live data from Hacker News

AppleID password brute force proof-of-concept

github.com

41–50 of 83 posts

Re: AppleID password brute force proof-of-concept

#42
post #22

He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

@nikcub seems to think it wasn't this.

https://twitter.com/nikcub/status/506421890517200896

Re: AppleID password brute force proof-of-concept

#43

I guess some female celebrities are going to reconsider Android next time they buy a smartphone.

Your typical Android phone has 2-3 built in backup options (e.g. Google+ photo backup, Google Cloud Backup, [manufacturer] backup).

So unless those are all well secured (and they may be, no clue) then moving to Android is no magical fix.

A better way of doing things is making it more clear to people what they are and aren't backing up. I'm sure for the majority of people backing up nudes is unintentional.

Re: AppleID password brute force proof-of-concept

#44

How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?

Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work.

Delayed disclosure is a nicety, not something you are obligated to do.

Re: AppleID password brute force proof-of-concept

#45
post #11

I don't know if this was the attack used in the hack, but it is really, really bad news for Apple. The public is not going to trust iCloud any more. I'm pretty sure Apple will drop iWallet from the keynote, or it'll end up like their maps.

"End up like their maps," meaning frequently used by the vast majority of iDevice owners?

I'm no fan of Apple Maps. I pretty much only use it when I have to (e.g. because Find My Friends uses it) or to make fun of it. But there are a ton of people who don't care and just use the default. Even among my tech-savvy programmer friends it's common.

Re: AppleID password brute force proof-of-concept

#46
post #42

Earlier quoted context omitted.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896

he's assuming from when the tool was released. The exploit was in the wild for much longer.

Re: AppleID password brute force proof-of-concept

#47

How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?

Not very. We don't know if they contacted Apple. However from my knowledge Apple doesn't offer bug bounty or often respond to security notifications.

Re: AppleID password brute force proof-of-concept

#48
post #44

How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?

Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.

So there is no ethical responsibility to protect the users who will be left vulnerable to this exploit? Remember the danger here is screwing people who have iCloud accounts. It's not like Julie the housewife in Minnesota, had any say in the security of Apple's products.

Re: AppleID password brute force proof-of-concept

#49
post #44

How is it ethical to distribute this without first disclosing to apple and waiting for a fix at least a few days?

Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.

Ethics are a nicety, not an obligation.

Re: AppleID password brute force proof-of-concept

#50
post #42

Earlier quoted context omitted.

@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896

he's assuming from when the tool was released. The exploit was in the wild for much longer.

The leaker got doxxed by 4chan and doesn't seem capable of discovering the exploit on his own.

Though he's commented to Buzzfeed denying it was him (but anyone would).

http://www.buzzfeed.com/charliewarzel/bryan-hamade-blamed-by...

@nikcub still thinks it's him

https://twitter.com/nikcub/status/506465151562694656

Post reply on HN