Free Republic
Browse · Search
News/Activism
Topics · Post Article

Full Title: "Apple Just Patched A Security Flaw In iCloud That Could've Been Used To Hack Celebrity Accounts"

Sadly, it's not known if this is what was used.

Apple is going to have a huge black eye for a long while from this. I wonder what the settlements will cost with all the actresses.

1 posted on 09/01/2014 8:12:52 AM PDT by ConservativeMind
[ Post Reply | Private Reply | View Replies ]


To: ConservativeMind

I’ll, of course, have to see the photos in question in order to determine the severity of the breech.


2 posted on 09/01/2014 8:14:50 AM PDT by Puppage (You may disagree with what I have to say, but I shall defend to your death my right to say it)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

I can’t believe they didn’t have some kind of lockout policy. Even a ten-try maximum would be effective against brute-force; you could also establish a modest lockout duration so legitimate users could try again after a set amount of time.


4 posted on 09/01/2014 8:16:32 AM PDT by Mr Ramsbotham (Laws against sodomy are honored in the breech.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

I got an iphone last week. Coincidentally they pushed me a message that I should back it up to iCloud on friday, just before this hit.


5 posted on 09/01/2014 8:19:10 AM PDT by DManA
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind
So, why do celebrities have nude photos of themselves posted to the cloud anyway?

Bob Barker and George Clooney can keep it to themselves.

6 posted on 09/01/2014 8:19:29 AM PDT by Izzy Dunne (Hello, I'm a TAGLINE virus. Please help me spread by copying me into YOUR tag line.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

bkm


10 posted on 09/01/2014 8:24:23 AM PDT by no-to-illegals (Scrutinize our government and Secure the Blessing of Freedom and Justice)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

My new ipad has icloud as my new email address but I don’t have any naked pictures on it. No pictures at all. What else could happen?


12 posted on 09/01/2014 8:28:18 AM PDT by Ditter
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

Must have been the “Click here to download dirty pictures of celebs” backdoor...oops I mean security flaw


23 posted on 09/01/2014 8:50:25 AM PDT by bigbob (The best way to get a bad law repealed is to enforce it strictly. Abraham Lincoln)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind
What is funny to me are all the comments, if this was MS they would be slammed left and right, but since it's Apple the little darling even the negative comments are extremely mild.I think we are going to see more and more hacks against Apple because for one thing it's the challenge they desire and for another all the beautiful, special people own Apple products and the treasure trove of information is just too hard to resist.
27 posted on 09/01/2014 9:05:16 AM PDT by Mastador1 (I'll take a bad dog over a good politician any day!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

Impossible. Swordmaker always said apple is perfect. Ha ha.


31 posted on 09/01/2014 9:18:30 AM PDT by for-q-clinton (If at first you don't succeed keep on sucking until you do succeed)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

They are going to have to pay settlements - plus - no one is going to trust this Cloud business anymore


36 posted on 09/01/2014 10:08:47 AM PDT by Scotswife
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; ...
Thanks for the additional Ping, Conservative. Yes, Apple did patch a flaw in The FindMyiPhone API. However, the creator of the Brute Force exploit, when contacted, had this to say about the overall issue:

"We discussed the tool with its creator, Hackapp, over Twitter, who said “This bug is common for all services which have many authentication interfaces” and that with “basic knowledge of sniffing and reversing techniques” it is “trivial” to uncover them. When asked if the method could have been used in the celebrity hack today, Hackapp said “I’ve not seen any evidence yet, but I admit that someone could use this tool.”
Reviews of the metadata from the nude celebrity photographs that have been released have found that while many were taken with Apple equipment, many were also taken with Android phones and webcams on Windows PCs, which would not be likely to be stored on Apple's iCloud.

The script does apparently implement a brute force serial attack through the FindMyiPhone API using a list of the 500 most commonly used passwords such as "password, password1, passw0rd, p@ssw0rd, p@ssword, princess, princess1, etc."

Strangely, all of Alexey Troshichev's direct articles and evidence of the script and claims have been removed from the web for some reason.

Apple has been recommending for some time that users employ a two-level authentication to avoid this exact kind of exploit.


Apple iCloud Security Ping!

If you want on or off the Mac Ping List, Freepmail me.

46 posted on 09/01/2014 4:02:38 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

49 posted on 09/01/2014 4:21:58 PM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind

More reports on analysis of the picture sources say that a lot have “Tumblr” watermarks on them, for whatever that’s worth. Others show Android phones in the selfies as well as Apple phones. Data that shows varied sourcing. Apple has announced they are “Actively investigating IF the data could have originated from breeches of Apple customer accounts.”


63 posted on 09/01/2014 9:18:23 PM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ConservativeMind
The Washington Post just put up this interesting theory by Dan Kaminsky of WhiteOps.com:

A theory offered on Twitter by security expert Dan Kaminsky, chief scientist at WhiteOps.com, is that someone who was collecting a cache of the celebrity nudes may have been hacked by the person or people who spread the images online over the weekend. If the photos were collected by a person from different sources over a long period of time, it could explain why some of the images appear to be genuine and others are allegedly fake.
That would explain the melange of photo types.
66 posted on 09/02/2014 2:44:10 AM PDT by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson