Man steals 620k photos from iCloud accounts from home without Apple noticing
latimes.com
latimes.com
This creep didn't need advanced tooling, exploits or deep knowledge of the backing system. All he needed was a basic phishing scam to work well enough, and the official iCloud software (either from his browser or his computer).
All the supposedly advanced algorithms that often arbitrarily ban accounts by mistake managed to miss some random dude behind his laptop, shamelessly leaking private pictures.
My heart goes out to this man's victims.
EDIT: DO NOT TRY WHAT FOLLOWS IT IS AN EXAMPLE OF A SCAM.
Wow! XYZ is smart enough to block your password so others can't see it! ╍⡵ⱇ⪞‾╴⧊↧Ⓗ⥔⋾⁅
I can see it, but you can't. Try it!!!!
An unbelievable number of people fell for this on Myspace and Facebook in the early days.
"quit smoking in console" for source games
Probably others I've forgotten falling for over the years
EDIT : it chould be a OS graphics layer service capable of drawing alerts on your active window. But I don't see why display manufacturers couldn't make this useful : the number of screens and applications anyone is logged into at any one time is increasing, and the primary screens we're using commonly have Windows Hello and Face ID type of biometric capabilities, which would be very useful for establishing the likelihood of unlawful access elsewhere.
EDIT 2: So Apple has a good position from which to offer this kind of "where are you working from?" heuristic check available to other security system software.
EDIT 3: Biometric presence data as a service to increase security for administration changes and logins hasn't come to my attention as being explored yet. I'm semi retired and extremely interested in this area if anyone is interested in a wider discussion in London - not burdened with any expectations or intentions and able to arrange professional legal cover if desired / necessary - I am interested in derivative applications for services that don't yet exist
Like Jim Browning, the Youtuber famous for scamming scammers, who recently fell for a phishing scam himself and ended up deleting his Youtube account. (https://news.slashdot.org/story/21/07/28/2023241/youtube-cha...)
I am very careful when it comes to phishing scams, but I guess one cannot be 100% vigilant all the time. One slip and you can fall prey.
And this is why having multiple layers of security is important. Even if you get phished, it can prevent further damage.
Nor do free apps downloaded via the App Store, as I just tried. Although this may be a setting somewhere.
But does it matter? You know what doesn't need a password? Accessing your photos. There's really very little you can do after authentication that you can't do otherwise. Maybe, after exfiltrating all the user data, you can also update macOS.
Sandboxing is really far more important than protecting sudo privileges, and I believe Apple is doing a fairly good job in that regard.
Is that "phishing"? Those actions should be secure to perform in a browser. The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something.
Of course, that security model sometimes has holes, but if for example clicking the link enables an XSS attack, I'd call it (primarily) an XSS attack. Same story if downloading an attachment did much more than just creating a file on disk.
You don't understand how hacking and planting of malware works. Hackers abuse zero day vulnerabilities in order to drive by download malware onto user's PC. They use exploit kits in order to manage and plant malware by abusing browser's or computer's zero day exploits. So when you visit a malicious website with vulnerable browser malware silently gets downloaded(drive by download) onto your PC.
On the other hand one of the most common email attachments is Microsoft Word document and again just like with browsers Microsoft Office and Microsoft Word have many zero day exploits or simply existing vulnerabilities(exploits) which user didn't patch so attacker abuses these kinds of exploits in order to drop malware when user opens Microsoft Word document and interacts with it.
Summa summarum: Hackers use zeroday or existing exploits to plant malware or they make lookalike websites or documents to trick you into giving your login credentials and/or payment information(credit card, bank account information etc.)
>The security model of browsers/computers is such that I don't need to establish authenticity/trust in order to click the link or even download something.
You do; websites use SSL certificates and computer files get digitally signed as well.
(IMHO human was always the weakest part in the security chain and this will not change looking at social engineering)
> He gained unauthorized access to photos and videos of at least 306 victims across the nation
> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house
Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools.
OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.
If the attacker was really not covering his tracks, perhaps Apple may have flagged hundreds of different iCloud account logins originating from the same location as something to look into?
If so, it’s incredibly unlikely that all 20k were online simultaneously. If they were, each person could only open ~3 TCP sockets to the internet (even if via a proxy if dealing with individual login sessions) at a time before you’ve run out of ports.
Adding detailed prompts won’t solve the problem.
Part safely using the Internet is having the knowledge and being aware of where (in your apps) the boundary is between your local device and the global network that everyone has access to. People need to understand: When you sync to a cloud service, you're sending your content to someone's computer unknown to you. Yes, in this case, it's Apple's computer, but that didn't stop this guy. Once you sync something online, it's out of your hands, and on the Internet now.
I personally treat all cloud services as if they were accessible publicly and anonymously, and will inevitably be printed in my local newspaper, and only upload content to those services where I am comfortable with that level of exposure.
EDIT: To clarify, I wish applications would stop blurring the line between "on my device" and "on the Internet". I've used applications where, to an unsophisticated user, the save dialog looks like it's saving to their computer but it's actually in the cloud. Add to it all these apps that try to be helpful by seamlessly (and invisibly) keeping local content in sync with the cloud versions and you have a recipe for disasters like this. Have an explicit "upload this thing to the Internet" button, please!
They could start by following basic security. My kid's school sets everyone's passwords to various forms of "temp123" (same password for every kid) and often talks about them in cleartext. It sets a very bad example, and it occasionally gives me hives just thinking about it.
The instruction, they thought, had to be a poor phishing attempt - but no, it was a genuine email from the IT department and the friend was punished (!!) for questioning the instruction and not immediately complying.
It may not have been the same password across the organisation but their's was reportedly word based and quite short.
Schools wanted to store the students' passwords in clear text in an excel basically to get less complaints from parents.
Students didn't store their password after logging in. If they needed to log in again they did not know (or did not care) how to reset their passwords. Then the problem would fall unto the parents which would then complain to the school.
The guy probably was the only one in the group doing this and was led to believe by the others that it was completely safe.
Apple didn't catch on to this, despite him not using VPN or Tor... it wasn't until the FBI investigated a public figure's hacked and posted photos that this came to light.
[EDIT]: Not the FBI, but a private company noticed this (h/t codeecan)
> A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure ...
He was caught by random chance of this company.
The fact that those hacks quickly were flushed from the news cycle without a bunch of public lawsuits etc. makes me suspect Apple very proactively went out and made settlements with the more high profile victims of those hacks. Of course, I have no proof of this at all, so it's purely speculation, but it was odd to see almost nothing come out of those hacks.
Apple is not at fault here though.
These people have clicked on a phishing email no different to a banking or retail one.
I assume each upload is tagged with device ID which first uploaded it etc. but maybe that can be spoofed as well?
If you are worried about the security of iCloud, then that can be read as more reason to prefer client side scanning. Of course the tweets are ambiguous about logical implications so you can’t engage with them directly.
However, stating my opinion as fact in an attempt to invalidate someone else's perspective on the matter would be debasing discourse so I wouldn't do that. None of us should.
Since you went ahead and stated opinion as fact (while cleverly pretending that you didn’t), can you provide an example where I dismissed a valid concern with a non sequitur? How do you reconcile the accusation that I assert “nobody should be concerned” with comments like this where I clearly outlined why the announcement should be concerning:
[1] https://news.ycombinator.com/item?id=28279776
[2] https://news.ycombinator.com/item?id=28165116
I’ll go further and say that I have sincere concerns with what was announced, but seeing how that Twitter account seeds legions of incorrect commenters who proliferate (and post intentionally clickbait material on HN, as the poster of this article themselves admitted on this very thread!) led me to the conclusion that Matt is doing plenty of harm, especially since he should know better.
Edit: No if they use the same algorithm, but they could use other algorithm which are less abusable and no one would know the hashes in the database, so Yes I guess?
Apple knows the sync dates of all of the photos that are uploaded. So unless someone has hacked your account and has been directly trickle feeding CSAM for years (without you noticing) then it's going to look suspicious. A big dump of lots of CSAM at one particular timestamp is a pretty easy thing to spot.
And then in this case they aren't hacking the phone but the account which means Apple is going to notice a set of photos coming from an IP address they haven't seen used from that account before.
Seems like there could be some legal ramifications from the choice to bypass law enforcement under certain circumstances
Of course metadata could exonerate someone who is a victim in a case like this. The question is will it ever see the light of day?
Also known as a 20 line script which checks the last modified date for a bunch of recently uploaded files and validates the IP address against the recently known list.
Only if that system / heuristic has been built. The same could have been said about Apple’s systems for identifying bulk account hijacks, but Apple didn’t, which I suppose is the value of this story.
And companies aren’t allowed to Just inspect content once they identify CSAM. It is kryptonite for criminal liability. Companies are required to turn it over to the feds quickly and to try not to disturb metadata.
I suspect your line of thought would work given full ability to inspect (and some assumptions about what an IP change actually proves), but in practice Apple still hasn’t gotten the basics around account hijacks/fraud sorted out, so I’m hesitant to cheer them on as they try to quickly jump into the deep screaming “think of the children!”.
From the site guidelines:
> Otherwise please use the original title, unless it is misleading or linkbait; don't editorialize.
Just a reminder because if a mod ends up viewing this they will probably change the title back to the original.
Google, Microsoft etc we know for a fact do server side scanning of photos for CSAM. Apple should be assumed to do the same.
So what exactly is the difference if this is done client or server side. The person being hacked would still be investigated by the FBI.
I don’t know how often unintentional possessors are prosecuted, but the US system of prosecution makes it easy for an innocent to get railroaded by threats of massive charges and comparatively leanient plea deals, combined with punitive sentencing for those who reject the plea bargain. Think Aaron Schwartz, but without any intent to violate the law.
> The person being hacked would still be investigated by the FBI
As someone with family in the FBI (one on a relevant team) and a local LEO that was deputized to do this work for the US Marshals, that doesn’t reassure me. The best forensics employees in the FBI with enough resources can identify that there was a hack and that the account owner is innocent. We live in a world of scarcity where that much effort is not always invested.
I think the client-side versus server side is more about relative trade offs of who owns the client device (and what “ownership” means) and whether the equivalent server side search is technologically feasible (might not be if the client encrypts with a key only the client owns, as some have speculated about Apple’s future plans).
IANAL so I am very likely wrong.
US Code 18 Sec 2252 seems to state that possessing or looking at CSAM material requires that the action is done “knowingly”.
In any case flagging multiple accounts logging in from a single public IP is not as useful a signal as you might think.
For a brief time there was a kind of explosion of said nudes. I could be on Yahoo Chat and women would just send them, unsolicited, and I think that was the era of people not realizing that nudes can get around, like any other secret, once you let go of them. My guess is that probably came to an end roughly ten years ago or so, and people now hold onto them tightly, which is probably much more reasonable.
People still take nudes, and pass them on, but I think there is a level of discretion that has increased, although I know some women who mention being pestered for such by men they know. Still, these images are on cameras and cloud storage and such, and for the life of me I do not get the hunger that drives such a risky behavior as getting into hacked iCloud accounts versus, I don't know, average sources of free nudes? Poor judgment of course abounds in so many reported crimes but ... how does one even trawl more than half a million photos for nudes? Was he planning on going through them individually? Was he going to make a neural net to scan for skin?
I just find the whole thing a little baffling in this day and this age.
I presume the hunger is more about having access to something you are not supposed to have access to, or were not given access to.
"Everything in human life is really about sex, except sex. Sex is about power.”
He mentioned this when a bunch of stories were coming out about GeekSquad and other IT help as a service companies stealing data or acting as data harvesters for the FBI/DEA etc.
No warning in the world will help because the attacker will just say "Ok thats ok, that warning is just for untrusted people. Since I am an Apple employee, it is perfectly safe". These victims already trust the attacker so they will just do anything asked.
I think the only solution here is to just block all logins outside of the users own country and to have local law enforcement crack down hard on any in country criminals. Apple can use the find my location to work out if any of the users devices are at or have been at a certain location. I can't imagine many situations where you leave all of your devices at home, leave the country and then try to log in.
How does this amount to only four felonies?! Our system is so abysmally bad at understanding crimes of scale, especially when they happen over the internet. If he burgled 4,700 houses, it would be a lot more than four felonies.
(With the latter, strictly speaking, being a subset of the former anyway)
> but he managed to get victims to give him the iCloud passwords he needed to download their data.
Then he might have been able to get victims to allow his access.
He goes through the trouble of phishing so many accounts and photos, only to access them directly from his own residence?
This reminds me of this thread https://news.ycombinator.com/item?id=28279326
Where the attacker was able to trick Tmobile / Sprint customer service into providing a PUK number.
In the end, in our case, USAA gave us a detailed rundown of how they failed, and then turned up to 11 the security questions my wife had to answer. Every single call she had to give a password, pin code, and then answer the questions that are sourced from Experian(or some other credit bureau) intended to prove identity through knowledge. Every time. They punished us for a mistake they fully admitted was their employee's fault.
Nah, I'm not bitter at all. Ultimately, though, it will be one of the reasons I move my account away from USAA.
Btw a lot of words in English have multiple meanings, and transform meaning over time, which can be confusing sometimes. For example, in baseball you steal a base, which was being protected by the other team, but you don’t remove the base from the field and run off with it.
I think steal works better than copy here, more accurately conveying meaning and intention, and unjust access.
The phrase "not stealing" is almost exclusively used in this context on HN: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...