Live data from Hacker News

Ibrahim Balic breaks silence on hacking Apple developer site

news.com.au

51–56 of 56 posts

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#51

Earlier quoted context omitted.

That probably wouldn't have shut down the site, which in turn would not have gotten the attention. He wasn't making a point to Apple, who already knew the bugs existed, he was making Apple do something about it. He did.

> That probably wouldn't have shut down the site So the guy is a hero. Thanks for disturbing real life businesses for several days, I guess? > he was making Apple do something about it. This behavior is endemic for the self-righteous security "researcher" scene. "I found a bug - you must do what I say, NOW, or else ..." It's not like Apple would have ignored his bug reports if he wouldn't have scraped 100k developer…

"This behavior is endemic for the self-righteous security 'researcher' scene"

Yes, and that behavior is moving us to a world where corporations have to be careful what they put out, not just rush the newest shiny feature out faster. Besides, who do you want exploiting the bug, a self-righteous guy who 'may' be in it for his own glory, or an out-and-out criminal?

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#52
post #40

Earlier quoted context omitted.

Maybe, but he writes that he still has those 100k data sets. So why didn't he delete them after grep ran through?

Because he's clearly not very experienced in this. Apparently his video (when it was up) had confidential information shown in it: https://twitter.com/ibrahimbalic/status/359347248473190402 . Who the hell flouts confidential information in a public fashion? There's a interview with him with English subtitles here: http://video.ntvmsnbc.com/applei-sarsan-turk-yazilimci-ntvms... , where he says some interesting things…

>He basically did what Weeve did, except Weeve is in confinement now.

Hopefully not for long... https://news.ycombinator.com/item?id=6093468

Don't get me wrong, I don't agree with what he did, but the whole case is baffling to me.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#53
post #50
post #17

This kind of pen-testing, without previous authorization, is a very risky enterprise if you live in the UK. The Computer Misuse Act 1990 expressly forbids "unauthorised access". Sections 1-3 of the Act introduced three criminal offences: - unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000); - unauthorised access with…

Those laws are retarded and it's sad to see them defended in HN. Always try to do a parallel without computers to see if a computer law pass the retarded test. In this case "it's illegal to enter a door left wide open for months, pick up a wallet full of money from a desk visible inside thru said open door, and return it to the home owner with all the money and a note about closing the door because it's not a safe ne…

It's sad to see another stupid comment on HN. He never defended the laws. He was just stating the facts.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#54
post #50
post #17

This kind of pen-testing, without previous authorization, is a very risky enterprise if you live in the UK. The Computer Misuse Act 1990 expressly forbids "unauthorised access". Sections 1-3 of the Act introduced three criminal offences: - unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000); - unauthorised access with…

Those laws are retarded and it's sad to see them defended in HN. Always try to do a parallel without computers to see if a computer law pass the retarded test. In this case "it's illegal to enter a door left wide open for months, pick up a wallet full of money from a desk visible inside thru said open door, and return it to the home owner with all the money and a note about closing the door because it's not a safe ne…

He cannot return the data per se, so there is a difference. Once it leaves Apple's servers it could be less secure and he's not registered as a data controller I'm sure.

In your example above, why could the person not just point out that the money was not safe? It's no loss to them if the person does not act on the information.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#55
post #48

Earlier quoted context omitted.

I do wish they had converted WebObjects back to Objective-C and released EOF with it. It would have been nice to write the app and the server code in the same language and environment.

EOF, sure, but WebObjects in general? You don't actually want that. You just think you do. Look: WebObjects was amazing at the time. But have you used it recently (meaning in the last several years) to write something? Because it's almost literally impossible to write something that looks modern and acts modern. WebObject was designed to hide web development as much as possible from the developer . I.e., to make writ…

> You don't actually want that. You just think you do.

No, I pretty sure I want an updated version of it. We don't have any clue where it would have evolved, but I wouldn't be surprised if Apple would have kept at it, there would have been a "Final Cut Pro X" moment.

> All those pointer errors you make in your iOS app that generally just result in a crash suddenly result in your server being rooted.

I really don't seem to run into those as much as others, maybe I'm lucky. Between Ruby or Objective-C, I'll take my chances with Objective-C.

Re: Ibrahim Balic breaks silence on hacking Apple developer site

#56
post #50
post #17

This kind of pen-testing, without previous authorization, is a very risky enterprise if you live in the UK. The Computer Misuse Act 1990 expressly forbids "unauthorised access". Sections 1-3 of the Act introduced three criminal offences: - unauthorised access to computer material, punishable by 6 months' imprisonment or a fine "not exceeding level 5 on the standard scale" (currently £5000); - unauthorised access with…

Those laws are retarded and it's sad to see them defended in HN. Always try to do a parallel without computers to see if a computer law pass the retarded test. In this case "it's illegal to enter a door left wide open for months, pick up a wallet full of money from a desk visible inside thru said open door, and return it to the home owner with all the money and a note about closing the door because it's not a safe ne…

I don't believe I defended those laws, nor critised them. I merely stated the facts.
Post reply on HN