anyone has confirmed that the leak is from icloud and thats the way they did it?
He claims the hackers got them from iCloud hacks, and other more social engineering hacks.
61–70 of 83 posts
anyone has confirmed that the leak is from icloud and thats the way they did it?
He claims the hackers got them from iCloud hacks, and other more social engineering hacks.
He's dead Jim https://twitter.com/hackappcom/status/506383498333007872 Still, I expected better from Apple. Props for the fast patch.
Here is another flaw in iPhone. If a person is casting their screen to an Apple TV and must enter their PIN number, the screen will highlight each button press on the TV. No fingers in the way to even block it. Simple solution: don't broadcast this or don't provide screen feedback for entering the PIN.
Earlier quoted context omitted.
Not so fast. This can very well be the leak used to access the celebs nude pics. Script kiddie gets access to the script. Tests it again some easily guessable celeb. emails (or emails he already knows somehow). Gets lucky. Gets access to many other celebrities' emails, gets even luckier. The whole thing snowballs from there. What do you guys think? Addendum: the way it went down on 4chan points towards someone that i…
> Anyway, I hope the FBI gets this freak and put him in the can for as long as they're able to. If only people shared the same feelings about illegal mass surveillance and the lax security of the companies responsible for these breaches.
Dictionary attacks are incredibly effective. Humans have a hard time coming up with unique passwords.
Earlier quoted context omitted.
Safari on OSX & iOS does do random password suggestions, out of the box.
I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.
So how could people use this to, for example, access people's photo's? Doesn't the two-factor authentication kick in whenever someone logs in from an untrusted device?
Earlier quoted context omitted.
Simple: it is Apples problem if their servers aren't secure. You don't owe apple free work. Delayed disclosure is a nicety, not something you are obligated to do.
So there is no ethical responsibility to protect the users who will be left vulnerable to this exploit? Remember the danger here is screwing people who have iCloud accounts. It's not like Julie the housewife in Minnesota, had any say in the security of Apple's products.