Live data from Hacker News

The UDID leak is a privacy catastrophe

corte.si

1–10 of 52 posts

Re: The UDID leak is a privacy catastrophe

#4
post #2

That ended ubruptly and without much in the way of resolution?

Yes, sorry - I'm on the road at the moment, and wrote that in a rush. Part of the problem is that there's not much users can do at this stage. The ecosystem of companies that use and abuse UDIDs is fragmented, and each service that relies on UDIDs for identification or authentication can have its own unique problems. I guess it would be possible to start aggressively releasing a list of services that users should close their accounts on, but that would also be a shopping list for bad guys out to take advantage of this situation.

Re: The UDID leak is a privacy catastrophe

#5

Forgive me if I am mistaken, but don't all you need is a UDID to send a push message to a device? I.E. via Urban Airship.

No, you need a push token, which is a combination of device id and app id, and is only generated when the user authorizes the app for remote notifications. Additionally, you need a certificate on the server that is authorized to send messages to that app id.

Re: The UDID leak is a privacy catastrophe

#6
post #5

Forgive me if I am mistaken, but don't all you need is a UDID to send a push message to a device? I.E. via Urban Airship.

No, you need a push token, which is a combination of device id and app id, and is only generated when the user authorizes the app for remote notifications. Additionally, you need a certificate on the server that is authorized to send messages to that app id.

Good to know, thanks for the explanation.

Re: The UDID leak is a privacy catastrophe

#7
post #5

Forgive me if I am mistaken, but don't all you need is a UDID to send a push message to a device? I.E. via Urban Airship.

No, you need a push token, which is a combination of device id and app id, and is only generated when the user authorizes the app for remote notifications. Additionally, you need a certificate on the server that is authorized to send messages to that app id.

The push token is static for the device installation: it is not in combination with the "app id".

http://stackoverflow.com/questions/2338267/is-the-apn-device...

Re: The UDID leak is a privacy catastrophe

#9
> If your UDID is contained in the list, take a minute to help us identify the traitor that did give your information to the FBI without any your agreement and without warrant !

Wouldn't it also be useful to gather information about who WASN'T on the list and what Apps they have? Maybe device type as well.

Re: The UDID leak is a privacy catastrophe

#10
post #9

> If your UDID is contained in the list, take a minute to help us identify the traitor that did give your information to the FBI without any your agreement and without warrant ! Wouldn't it also be useful to gather information about who WASN'T on the list and what Apps they have? Maybe device type as well.

The device type is given in the leak
Post reply on HN