Another theory on the “FBI” UDID leak
marco.org
marco.org
It's well known that APNS tokens are not unique on a per-app basis, even though the documentation says they might be. [0]
The theory that the leak didn't originate with the FBI is totally plausible, but I don't understand the connection with Glitter Draw Free, and I suspect the email's author doesn't realize that APNS tokens are not unique.
0: http://stackoverflow.com/questions/2338267/is-the-apn-device...
The only way to blame one particular app would be if that app were the only app ever installed on a device whose identifier appears in the leak.
Not that I see anything wrong with this post. It's progress towards finding the cause. But it gave me a chuckle.
Gruber, not so much.
This doesn't factor in his income from The Deck, the Build & Analyze podcast, or Instapaper, of course.
He clearly has a vested interest in the Apple eco-system and by proxy, the success of Apple and making them look good.
Except he was doing it long before anyone knew who he was and was willing to sponsor him for it. It's not like he suddenly became an Apple shill because he saw money in it, he was already an Apple fan and judged their decisions in that light even before his posts made the rounds on places like HN.
Citation required of both wilful intent and of calling out without solid evidence, from both Arment and Gruber.
I haven't witnessed the behavior you described. Examples?
Supposedly the guy whose laptop the data was hacked from was a DefCon attendee, so I guess it is possible that he cracked some database and got the data himself, unrelated to any FBI operation. But, of course, that's precisely what the FBI might want us to think if this data was widely distributed and they probably shouldn't have had it in the first place. It also doesn't explain the connection to NCFTA.
And of course it's possible the AntiSec hackers obtained it completely on their own and tried to connect it to the FBI afterwards.
For instance, I can’t figure out how and why the FBI would
have collected APNS tokens. What are they going to
do, steal the SpankApps SSL certificates somehow
and send a fake push notification from Glitter Draw
Free to a terrorist’s phone?FTR, I'm not affirming this actually is a plot by FBI to send fake updates to everyone. Just saying the theory is not as far fetched as Marco implied, either targeting terrorists or everybody.
That doesn't follow. I don't like the FBI installing sniffers at ISPs either, but "Carnivore" is just a dumb name for a technique you had to have assumed the FBI already had (what, they can tap phones but we thought email was off limits?).
(By the way, the NSA is by law limited to foreign communications.)
So they hack into an FBI laptop and all the do is release 1 million apple UDID's?? Hmmmmmmmm, makes you wonder.
Out of all the theories out there, this seems to be the most plausible once you think the FBI has nothing to do with it.