Live data from Hacker News

Update to Celebrity Photo Investigation

apple.com

71–80 of 90 posts

Re: Update to Celebrity Photo Investigation

#71
post #44

If I was in Hollywood right now I'd be offering high-price security consultation services to teach celeb's how to use 2FA.

I've spent some time thinking about and talking about ti with friends in the security world before.

I think it's a good idea, but falls short in reality. Celebrities arguably don't want it, you'd be a babysitter between them and their devices/APIs. Something they'd likely hate and continuously undermine, especially when a large part of their "job" is connectedness.

Re: Update to Celebrity Photo Investigation

#72
post #27

Earlier quoted context omitted.

I'm sorry, but Apple was hacked. There are multiple layers to security. Even the physical security of the building counts. If you have a terrible, easy to crack security system like "What is your first pet's name?" and your customers lose their data because of it, your system was hacked. Plain and simple. Security isn't just blocking a port or an ip range, it's the entire, the entire , system. Those "security questio…

While I wouldn't disagree with the stupidity of "security questions" answered straight, I don't know if this is something to lay on Apple's doorstep, because anyone with a modicum of knowledge either lies or supplies "custom" security questions-- it's basically a "if you forget password A, remember password B" system. But explaining that to users who have issues with a password is a lot more far-reaching and widespre…

>Additionally, making "security questions" passwords in and of themselves is going to tremendously increase the volume of your support tickets. At some point, you need to make a cost/benefit analysis and make a decision including that, not just looking at "what's more secure if we assume our users are stupid".

I think as long as you can choose your own level of security, this is actually the best solution, even though some people will not have a firm grasp on how much security they are choosing to have. Right now the default is a fairly low level of security (answer the security questions correct, plus possibly an e-mail loop), but you can just answer the security questions with another password if you want to, assuming that they don't have any kind of thing that detects weird answers. Unfortunately, almost no one lets you selectively disable things like security questions or password resets.

Re: Update to Celebrity Photo Investigation

#73
post #70

I'm still wondering if the Find My iPhone brute force bug was exploited. Why doesn't Apple at least offer a bug bounty reward? Is it irresponsible that they don't? All they offer now, as far as I have found, is a mention on this web page: http://support.apple.com/kb/HT1318 And, does the fact that this bug made it into production suggest a lack of internal security audits at Apple?

They specifically mention "Find My iPhone" as NOT the source. I'm not sure if you missed that bit, or you are you saying you don't believe them?

Re: Update to Celebrity Photo Investigation

#74
post #71
post #44

If I was in Hollywood right now I'd be offering high-price security consultation services to teach celeb's how to use 2FA.

I've spent some time thinking about and talking about ti with friends in the security world before. I think it's a good idea, but falls short in reality. Celebrities arguably don't want it, you'd be a babysitter between them and their devices/APIs. Something they'd likely hate and continuously undermine, especially when a large part of their "job" is connectedness.

>I think it's a good idea, but falls short in reality. Celebrities arguably don't want it, you'd be a babysitter between them and their devices/APIs. Something they'd likely hate and continuously undermine, especially when a large part of their "job" is connectedness.

If Entourage has anything to do with the real world, you could as well be talking about their agents. And as far as I know, there is no celebrity without agent.

Re: Update to Celebrity Photo Investigation

#75

Earlier quoted context omitted.

"Require 2FA for everybody, full stop" would do the trick. The proposed solutions you outline all assume that "password + security question" is only an insecure system for celebrities. But we have enough experience by now to know it's an insecure system for everyone.

>>"Require 2FA for everybody, full stop" would do the trick. How do you require 2FA for the Find My iPhone application when the only context for using that application is one in which your phone is lost?

Most 2FA schemes give you some backup codes. I'm sure people use Find My iPhone differently, but it's not unreasonable to suspect them to be used rarely. Once your device is back in-hand you could generate a few new backup codes.

Re: Update to Celebrity Photo Investigation

#76
So i'd wager there'd be quite a few celebrity dick picks available too if hackers wanted them. We know men like to send them unsolicited, and I'm sure those celebrities had received more than a few. But there are none. And why? Because those women were specifically targeted by people with a lot of resources and patience. (it's important that they were targeted specifically for being women).

To all of you idiots blaming the victims out there right now "should have used 2fa, should have used stronger passwords":

1. You don't know if 2FA was in place, you don't know what strength the passwords were.

2. Again: those women were highly targeted. Can you defend yourself if someone takes a week/month long project to break into your phone? (Also this was during heartbleed and other big vulnerabilites)

Come off your bullshit high horse. Don't blame the victims here.

Re: Update to Celebrity Photo Investigation

#77

The damage has been done, surely? Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc. Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons). Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days. Question is, would Apple hav…

AAPL stock is up today, despite iCloud being implicated. I'm not sure what exactly that means, but my personal guess would be that cognitive dissonance and a general "slut shame"-y attitude means people blame these celebrities for taking the photos / getting "hacked" and not Apple.

Not saying that's right, I definitely think that's the wrong take-away from all this, but I suspect that's what's happening, at least in these early days...

Re: Update to Celebrity Photo Investigation

#78
post #59

People have become so close with their smartphones that they entrust it with more information than their friends know. In addition no brand is more loved than Apple, with many celebrities being ambassadors to the brand. The brand is planning to introduce new payment and health services next week. For the average consumer two-factor-authentication means nothing, but they will start distrusting Apple more and will be m…

Nitpick: Ambassadors work in an Embassy.

http://www.merriam-webster.com/dictionary/ambassador

> 2 a : an authorized representative or messenger

> b : an unofficial representative

Re: Update to Celebrity Photo Investigation

#79
post #70

I'm still wondering if the Find My iPhone brute force bug was exploited. Why doesn't Apple at least offer a bug bounty reward? Is it irresponsible that they don't? All they offer now, as far as I have found, is a mention on this web page: http://support.apple.com/kb/HT1318 And, does the fact that this bug made it into production suggest a lack of internal security audits at Apple?

They specifically mention "Find My iPhone" as NOT the source. I'm not sure if you missed that bit, or you are you saying you don't believe them?

The way they worded it can be interpreted to mean that it is still a possibility that the Find My iPhone bug was involved. And anyway, I'm still wondering if it was exploited in this celeb pic scandal or other breaches we haven't heard about yet, so I still have those questions.
Post reply on HN