UDID Leak : Identifying the Traitor
fredericjacobs.com
fredericjacobs.com
See this post for the source of these figures: http://corte.si/posts/security/apple-udid-survey/index.html
We know nothing. Other than that there are 1,000,001 leaked UDIDs. Everything else is just speculation and needs to be regarded as such until such time as proven otherwise.
Anonymous is not a group that can have a reputation. At best, it's a subculture. Anyone can call themselves anonymous. Whoever didn't lie in all the previous incidents may not be behind this one - this could be a totally different person or group of persons with totally different ideals.
But to assume everyone is lying until proved correct will not work. Reading news would be impossible, as would most other actives involving other people. The only working method then is to assume people are telling the truth until indication (not proof) is presented of the opposite. Blind trust would be only if we disregarded indication of falsehood when said indications exist.
A file filled with identifiers is not extraordinary evidence to link this to the claim of being a FBI laptop. It is only what it is (a file of identifiers) and says nothing about where it came from.
I hardly think it's Apple that leaked the information. Even if it's hard to believe for some people: Apple values their users' personal information pretty high.
I personally believe that this is from a internal FBI job, so they got this information in a non-legal way.
Dan Larkin (the FBI Agent who setup NCFTA in 1997) http://www.linkedin.com/pub/dan-larkin/25/90/910
Note that he used to be with CIRFU.
Now, check it out: https://www.allclearid.com/plans/mobile-app
I've Never Installed: ... Other [ ]
This is a joke, isn't it? How could I possibly answer this question correctly?(My deadpan-sarcasm filter isn't working very well right now.)
Which leads to an interesting question for me. Given that many web sites have more users than many countries, should there be a more proscribed relationship?
Huh? How? Most companies who have an iOS app with over 12 million users could have given it.
Similarly, what if the UDIDs are from people who installed a common app on their devices and agreed as part of the terms and conditions to allow information about their hardware (including device name, UDID, etc.) to be transmitted to the app vendor and to other parties including law enforcement?
EDIT: the question of whether they should have this information is completely separate from whether it's illegal for them to have this information. And, as noted by others, no proof has been presented that it was obtained from the FBI.
The paranoia on these UDID threads is ridiculous. Investigating crimes is what the FBI primarily does, so if they've got any information it's most likely for that - not some broad-spread domestic surveillance scheme.
Their US operations were shut down the FBI recently on bank fraud and money laundering charges.
http://www.tightpoker.com/news/pokerstars-shuts-down-2347/
Can anyone else confirm they have PokerStars installed? http://news.ycombinator.com/item?id=4473730
http://www.google.com/search?q=udid+site:developer.apple.com
Making an incorrect claim is spreading disinformation, plain and simple. Is it a big deal? No. But that's what it is.
As for the OP doing it too, that's no defense.
I claimed nothing, I merely offered an answer, which happened to be incorrect. Being human, I make mistakes. FTR, Unique Data Item Description is what the military use the acronym UDID for, I made an innocent assumption. So I was hardly making false statements, as you claim.
Seeings as the second point sailed over your head, I'll spell it out. I proffered and answer without being patronising and snarky, I could've said to the OP "Google it...", but I made an effort to be a decent member of the community. What's your excuse?
It's a number that uniquely identifies your device
However, use of UDID has been deprecated by Apple, and they are now rejecting some new apps that read it. You're meant to use a unique application-level ID instead.
Think about it this way: there are more than 250m iOS devices in the world[1]. I think 300m is a good, conservative estimate.
12m (~4%) of the world's UDIDs have leaked. 1m of those (~.33% of the total, 8% of the dump) have leaked.
A data point saying "my iOS device is in the dump" represents 1/1m of its group. Pretty significant, relative to 300m devices!
A data point saying "my iOS device isn't in the dump" has two possibilities; a 96% chance it isn't in the dump and a 3.66% chance it is but wasn't leaked.
As one of the 99.66% of iOS users, your data point represents just 1/299m of its group, and is thus ~300x less powerful than a positive data point.
[1]: http://www.engadget.com/2011/10/04/apple-250-million-ios-dev...
1) "Have you been to the US recently"? The way this Q is worded suggests that the audience is not people who live in the US. Either way, the non-specificity of the Q makes me worry with what info will be extrapolated from the responses.
2) "I haven't installed the following apps: Facebook, LinkedIn...OTHER".
...there are a lot of apps I haven't installed. I hope you don't want me to list them all...?
tl;dr - when putting together a survey like this, be careful to look at it from all sides and see where you could be introducing a bias of some sort. Drawing conclusions from flawed data = FTL.
Rabble all you want over this traitor business, even clamor for new laws to protect us (although that just makes things worse and poisons the waters). In my humble opinion, you breathless bloggers are all just wasting energy. Until we techies start designing networks and storage systems for anonymity and privacy, all your dirty laundry is money in the bank to these service providers and easily searchable by big brother.
$ grep 의 iphonelist.txt | wc 10682 23316 1469444 $ grep 的 iphonelist.txt | wc 32168 77171 4522336 $ grep の iphonelist.txt | wc 4838 15191 671159 $ grep 의 iphonelist.txt | grep 的 | grep の | wc 0 0 0
Please, why won't anybody think of the children?
The small number leads me to think that the UUIDs might belong to people the FBI are particularly interested in tracking. If your UUID is in there, fasten your tinfoil hat.
Just a thought.
What do you mean that it is "very dangerous"?
As I posted in another thread... I wonder if it is significant that so many of the UDIDs are known to OpenFeint. If you took a random sample of UDIDs, how many would OpenFeint have data on?
The formatting of this blog is just awful for iPad users zooming in on the text.
I have no real problem if the UDID:s of my iPad/iPhone/iPod are stored with my name by intelligence organisations in democracies.
But... I do have problems with them being so incompetent that private information about me is leaked!!
We have to accept that we are being spied upon because we have no control over that, but we should always resent and resist it when possible.
The number of stopped terror attacks in the West over the last decade is quite large, that would hardly have happened without spying on the citizens.
Is it worth the security? I don't really know. As long as it is in very stable democracies, it ought to be safe...
They can't even manage their own internal information, so their fishing through our personal information seems a bit reaching, eh?
How can a government not love "terrorism"? It's a catch-all phrase that allows it to act as it wishes with impunity.
Uh, hell no. We have already seen the kind of evil things the FBI are willing to do in the US: http://en.wikipedia.org/wiki/Cointelpro
But that was during the cold war, 40 years ago. The levels of paranoia increased after 9/11, but hardly to the pre-1989 levels.
No one has attempted to argue against my point about active terror threats imply high voter pressure for security.
But maybe the problem is that I'm Swedish.
Traditionally, Swedes trust the state uncritically to do the right thing (I've heard the explanation that the king historically was allied with the lower classes against the nobility).
I thought I was immune to those Swedish attitudes, after e.g. seeing oligopolies (food, building, etc) keeping prices high and hurting both individuals' economy and the country's, without getting any problems from either politicians or media.
But maybe I still have naive reflexes.
Edit: I wish I hadn't gone away for a while, so I could have added this comment while people still were reading and give feedback. :-)
Bull. Fucking. Crap.
For example, according to this[1] source, there have been not even 50 terror attacks against America in the last 90 years. And while the amount seems to have increased recently, this surely has absolutely nothing to do with the US playing world police and giving more and more people reasons to hate them (not that this excuses terror attacks, but you get the point).
This whole bullshit is a gigantic pile of FUD and propaganda. There is no terror threat. There never has been any. At least not more than randomly getting shot on the street or dying in a car crash caused by a drunk driver. I don't see people pushing for universal surveillance of the blood alcohol of all drivers or some other nonsense.
The whole thing is so fucktardedly ridiculous that the FBI regularly invents terror suspects[2], and arrests them "last minute" to then claim it has "once again eliminated a threat to national security". Everything's fair game to continue their bullshit pushes for more surveillance and less civil liberty. And what's even more enraging: people like you buy it.
Conclusion: No, we don't need surveillance. No, we don't need fed agencies spying on everyone and everything and no one to keep them in check (who watches the watchmen?). No, we don't need bullshit laws that further and further infringe on every human's civil liberties and human rights for no reason but "um... well... uh... BUT TERRORISM!!!1!1oneoneeleven".
[1]: http://www.infoplease.com/ipa/A0001454.html [2]: http://www.rollingstone.com/politics/blogs/national-affairs/...
Democracy != immutable state.