Live data from Hacker News

AppleID password brute force proof-of-concept

github.com

61–70 of 83 posts

Re: AppleID password brute force proof-of-concept

#61
post #4

anyone has confirmed that the leak is from icloud and thats the way they did it?

According to the person who is actually leaking this pictures to popular forums, he acquired many of the pictures either by trading or buying them from the -real- hackers on one of those shady online marketplaces.

He claims the hackers got them from iCloud hacks, and other more social engineering hacks.

Re: AppleID password brute force proof-of-concept

#62
post #41

I guess some female celebrities are going to reconsider Android next time they buy a smartphone.

CyanogenMod specifically...

Agree. I can totally see a celeb buying an Android then going on line and hunting CyanogenMod and then flashing their phone.

Re: AppleID password brute force proof-of-concept

#63
post #22

He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.

>Still, I expected better from Apple.

Here is another flaw in iPhone. If a person is casting their screen to an Apple TV and must enter their PIN number, the screen will highlight each button press on the TV. No fingers in the way to even block it. Simple solution: don't broadcast this or don't provide screen feedback for entering the PIN.

Re: AppleID password brute force proof-of-concept

#64
post #41

Earlier quoted context omitted.

CyanogenMod specifically...

Agree. I can totally see a celeb buying an Android then going on line and hunting CyanogenMod and then flashing their phone.

Good point. They're probably too poor to afford to hire someone to do it for them. /s

Re: AppleID password brute force proof-of-concept

#65

Earlier quoted context omitted.

Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…

> Anyway, I hope the FBI gets this freak and put him in the can for as long as they're able to. If only people shared the same feelings about illegal mass surveillance and the lax security of the companies responsible for these breaches.

I do, I think Snowden is a hero. That does not stop me from thinking that this kind of behavior should be punished exemplarily. This is no "new product" leak, nor a ethical hack performed to expose a hidden truth. It's just some private pictures stolen and uploaded to the internet for the public to see. Jennifer Lawrence has all the rights to take private nude pictures of herself in the privacy of her own house. Nobody has the right to steal them, even if her iCloud password was Katniss.

Re: AppleID password brute force proof-of-concept

#67
post #51

Earlier quoted context omitted.

Safari on OSX & iOS does do random password suggestions, out of the box.

I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.

Worse, many sites -- notably banking sites -- reject secure passwords (no weird characters, no long passwords)

Re: AppleID password brute force proof-of-concept

#68

So how could people use this to, for example, access people's photo's? Doesn't the two-factor authentication kick in whenever someone logs in from an untrusted device?

Two-factor authentication is optional and not enabled by default. Not sure if there is email confirmation required when logging in from an untrusted device the first time.

Re: AppleID password brute force proof-of-concept

#69
post #48
post #44

Earlier quoted context omitted.

Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.

So there is no ethical responsibility to protect the users who will be left vulnerable to this exploit? Remember the danger here is screwing people who have iCloud accounts. It's not like Julie the housewife in Minnesota, had any say in the security of Apple's products.

Maybe the harm caused to a few people is worth the publicity and increased awareness.
Post reply on HN