http://intrepidusgroup.com/insight/2012/09/tracking-udid-src...
http://intrepidusgroup.com/insight/2012/09/tracking-udid-src...
It's a reminder how powerful the combination of simple tools and a little reasoning can be.
I once found myself by chance with a customer just as they got smacked with a DDoS attack that they were completely unprepared for.
The security folks threw up their hands claiming that they couldn't do anything to stop the attack due to certain random elements. The executives panicked and everyone started pointing fingers while their site went offline. It was chaos.
I asked to have a look at logs on a hunch that the "random" element wasn't entirely random. One line of awk, grep and uniq later it was revealed that roughly 85% of the attack could be mitigated with a trivial change at the edge.
I'm not an expert in all the areas I'm expected to cover by any means. Some days, it's all I can do to not say "act of God, maybe?" I try to learn new things when I am afforded the time, but since we don't live in a CSI world, it's just not possible to always have the right tools, the right knowledge or the right answer at all times, especially when it comes to computer security.
Bruce Schneier ain't cheap and not everyone can afford the services of specialists when it isn't a common occurence.
http://blog.bluetoad.com/2012/09/10/statement-from-bluetoad-...
Unfortunately, BlueToad's statement leaves some wiggle room.
"BlueToad does not collect, nor have we ever collected, highly sensitive personal information like credit cards, social security numbers or medical information. The illegally obtained information primarily consisted of Apple device names and UDIDs – information that was reported and stored pursuant to commercial industry development practices."
Edit: The "98% correlation" leads me to believe the publicly posted info is the full extent of the leak.
Another theory on the “FBI” UDID leak
Reading through his analysis, it almost seems that he may have fallen victim to log file pareidolia as he doesn't make it clear how a device named "Hutch" or one named "Paul’s gift to Brad" a anything more than coincidences in a very large data set.
Doing some quick analysis of the file shows that there is a UDID that has the alternate names; "Hutch Hicken" (Bluetoad CTO), "Bluetoad Support" and "Customer Service iPad" among others, but could this also be representative of an older iPad that has been a pass-me down through the company?
Somewhat more interesting and possibly more revealing are the UDIDs 'ffffffffffffffffffffffffffffffffffffffff' (occurring three times) and the small number of records not conforming to the field size and format of other records (UDIDs > 42 characters, no APNS, device/iOS version number as fourth field).
For anyone interested the following ugly and slow one-liner will print out a summary of non-unique UDIDs along with their APNS and names.
perl -F, -lane '$a{$F[0]}{$F[1]}=$F[2]; END { foreach $k (keys %a) {next unless ~~ keys %{$a{$k}} > 2; print "\nUDID : $k"; foreach $d (keys %{$a{$k}}){print "\t-> $d : $a{$k}{$d}"} } }' dataIf that is the case, it would be a pretty striking coincidence for it to be someone else.