Live data from Hacker News

AppleID password brute force proof-of-concept

github.com

51–60 of 83 posts

Re: AppleID password brute force proof-of-concept

#51
post #24

Earlier quoted context omitted.

It'd be nice if Windows/OSX/iOS/Android came with 1Password out of the box. It's both easier to use and more secure than manual passwords, which is a rare combination.

Safari on OSX & iOS does do random password suggestions, out of the box.

I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.

Re: AppleID password brute force proof-of-concept

#52
post #11

I don't know if this was the attack used in the hack, but it is really, really bad news for Apple. The public is not going to trust iCloud any more. I'm pretty sure Apple will drop iWallet from the keynote, or it'll end up like their maps.

Yeah, no one plays Playstation since the Sony hack. And I bet no one shops at Target any more. TKMaxx ceased trading right after their hack. Linked In is a thing of the past.

Don't forget eBay, they went out of business. Adobe has also shut down.

Re: AppleID password brute force proof-of-concept

#53
post #22

He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

Address books are backed up on icloud aren't they? So you get into one celeb account and it's easy from there. Use their address book to find agent/manager/publicists's info, then an endless chain of celebs from there.

Re: AppleID password brute force proof-of-concept

#54
post #22

He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

> Anyway, I hope the FBI gets this freak and put him in the can for as long as they're able to.

If only people shared the same feelings about illegal mass surveillance and the lax security of the companies responsible for these breaches.

Re: AppleID password brute force proof-of-concept

#55

Earlier quoted context omitted.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

Address books are backed up on icloud aren't they? So you get into one celeb account and it's easy from there. Use their address book to find agent/manager/publicists's info, then an endless chain of celebs from there.

You can find agents from IMDB Pro too. It's not that hard if you're determined (or obsessed for that matter).

Re: AppleID password brute force proof-of-concept

#56
post #11

I don't know if this was the attack used in the hack, but it is really, really bad news for Apple. The public is not going to trust iCloud any more. I'm pretty sure Apple will drop iWallet from the keynote, or it'll end up like their maps.

Yeah, no one plays Playstation since the Sony hack. And I bet no one shops at Target any more. TKMaxx ceased trading right after their hack. Linked In is a thing of the past.

Target's quarterly revenue did fall after the hack.

Re: AppleID password brute force proof-of-concept

#57
post #42

Earlier quoted context omitted.

@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896

he's assuming from when the tool was released. The exploit was in the wild for much longer.

The password list for this particular implementation is pretty limited. I doubt all the celebs hacked had a password on that list. The concept may well have been used with different code / pw dictionary.
Post reply on HN