Update to Celebrity Photo Investigation
apple.com
apple.com
To all of you idiots blaming the victims out there right now "should have used 2fa, should have used stronger passwords":
1. You don't know if 2FA was in place, you don't know what strength the passwords were.
2. Again: those women were highly targeted. Can you defend yourself if someone takes a week/month long project to break into your phone? (Also this was during heartbleed and other big vulnerabilites)
Come off your bullshit high horse. Don't blame the victims here.
That being said, I think the culpability is on Apple here as much as it is on the individuals responsible for obtaining the links. Security questions were never good security and companies need to start moving away from failed models.
Pretty worthless statement by APPL. "happpens all the time", "not our fault", etc.. They should be called out for security questions in the 1st place if that's what they use at all. Even after Sarah Palin which was greatly publicized. These companies learn nothing.
Exactly the same way that Sarah Palin's email was hacked - https://en.wikipedia.org/wiki/Sarah_Palin_email_hack
It's a pain setting up two step authentication across a lot of services, but I guess iCloud is probably one that's worth the effort. Still I'd rather brute force was not an option.
link to one explanation: http://i.imgur.com/vnd0H9J.jpg
Headlines around the world are "iCloud hacked", "Apple hacking scandal", "Are your photos safe on iCloud?" etc.
Meanwhile celebrities like Kirsten Dunst have described iCloud as a "piece of shit" (a tweet with emoticons).
Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days.
Question is, would Apple have responded so quickly if celebrities weren't involved?
Additionally, making "security questions" passwords in and of themselves is going to tremendously increase the volume of your support tickets. At some point, you need to make a cost/benefit analysis and make a decision including that, not just looking at "what's more secure if we assume our users are stupid".
If you really want a niche market, though, "social media security consultant" for celebrities would probably make you a pretty penny nowadays...
I think as long as you can choose your own level of security, this is actually the best solution, even though some people will not have a firm grasp on how much security they are choosing to have. Right now the default is a fairly low level of security (answer the security questions correct, plus possibly an e-mail loop), but you can just answer the security questions with another password if you want to, assuming that they don't have any kind of thing that detects weird answers. Unfortunately, almost no one lets you selectively disable things like security questions or password resets.
Also, email/text alerts about new logins, login attempts, and changes to account settings.
Many security conscience people don't answer security questions truthfully because the application of security questions is inherently insecure.
Once something like this happens it's impressive how much cognitive dissonance there is behind the excuses those very same people make or their claims that not enough was done to protect them. Don't get me wrong, these individuals were horribly victimized and it's not ok, but we can't allow ourselves to be satisfied by just blaming the company, especially if they otherwise provided the tools that would have kept the account secure. We can only realistically expect the companies we entrust our data to be responsible for making it possible for us to secure our data and not leaking it through other systemic failures. If we choose to shortcut it then it's our responsibility to learn from that and do better next time. We can't blame anyone involved here for doing what they should otherwise be motivated/expected to do. Apple provided the tools to protect the accounts, and as far as we know didn't allow them to be otherwise compromised. The victims set up their accounts in a way that they could easily access/recover them in the future (honestly, it's now required to remember around 20+ account passwords to manage our lives and it's only getting worse) regardless if they knew the risks or not. Security education is out there and it's as loud as we could hope to get it, people just won't internalize it until the risk is tangible. We can demand that companies like Apple, but it won't actually improve anything if people can't be bothered to use them or more importantly find it WAY more inconvenient and seek ways to bypass them in whatever way possible just to get them out of the way.
It's a shame that this is blowing up for Apple as if it's all Apple's fault, but maybe some good can come from it.
The average user probably trusts their bank, and assumes that their bank is doing everything to protect them, and unknowingly compromise themselves by putting in correct answers to trivial questions.
they don't use facebook or photo sharing sites or ... oh wait I guess they do. That might be a problem.
I don't think this is rocket science here. Find my FB account, find my mom, what is her brother/uncle/fathers last name, or just look at her "friends" list and try the most common last names. Or heck just try them all, there won't be more than a couple hundred to try and thats easier than bruteforcing the entire phone book. Heck just use my friends list, I know enough men on my moms side of the family. Done. Next.
Find my FB account and get a general idea where I grew up (just to make sure, although my name is weird enough for this not to matter). Go to genealogy website, search old phone books for my mom's name or just my last name, street name was Greenfield. Maybe you'll find my house and my aunts house, so two names to try. Done. Next.
Find my FB account, look thru old pix, here's me and my girlfriend in front of this 80s subcompact POS that being my first car which was a falling apart POS when I got it, but whatever. Ask an "old" guy to id the car. Its either a Dodge Omni or a Plymouth Horizon. And its red, if thats the question. Done. Next.
Its very unusual to have a "personal security question" that isn't answered by facebook, twitter, linkedin, any of the photo sites, classmates.com, etc.
Those are the same hand-wavey thought processes used by people who are paid to know better that get them hacked.
If I knew your name and where you live, I could find out your mother's maiden name and the street you grew up on in not much more time than it took me to type this comment - especially if it were something I did all the time. Fact-based additional confirmation questions are stupid, and non-fact based ones are impossible to remember.
seriously: http://www.peekyou.com/ or any of these services will work, and many of them allow you to buy prepaid packages.
Not saying that's right, I definitely think that's the wrong take-away from all this, but I suspect that's what's happening, at least in these early days...
I think it's a good idea, but falls short in reality. Celebrities arguably don't want it, you'd be a babysitter between them and their devices/APIs. Something they'd likely hate and continuously undermine, especially when a large part of their "job" is connectedness.
If Entourage has anything to do with the real world, you could as well be talking about their agents. And as far as I know, there is no celebrity without agent.
> When you set up two-step verification, you register one or more trusted devices. A trusted device is a device you control that can receive 4-digit verification codes using either SMS or Find My iPhone. You're required to provide at least one SMS capable phone number.
> Then, any time you sign in to manage your Apple ID at My Apple ID or make an iTunes, App Store, or iBooks Store purchase from a new device, you'll need to verify your identity by entering both your password and a 4-digit verification code, as shown below.
>None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.
Um... doesn't "a very targeted attack on user names, passwords and security questions" count as a "breach in... Apple's systems"? A social engineering hack is still a hack.
And what should Apple do, in this situation? If your names show up in tabloids, don't allow you to answer certain security questions? Require 2FA if your name is mentioned on Google more than a certain number of times?
I don't feel this is an Apple problem any more than it would be if someone created their iCloud password and then posted it on their Twitter.
The proposed solutions you outline all assume that "password + security question" is only an insecure system for celebrities. But we have enough experience by now to know it's an insecure system for everyone.
How do you require 2FA for the Find My iPhone application when the only context for using that application is one in which your phone is lost?
It's one thing to say "We tell our users to use two factor authentication - it's their fault if they don't use it" but it's another to say "all user accounts use two factor authentication to ensure security of their data"
So, the brute force attack with reasonable guesses at email addresses?
Information like that isn't even secret, the whole practice of using password recovery questions needs to go away.
Which are even more trivially discoverable for celebrities, since their lives are frequently so well-documented!
That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't hard to do anymore.
(I suppose the good news is that you can actually protect yourself from this. However, how to protect themselves won’t reach most people, so in the big picture this is cold comfort. I do think it’s the job of the platform owner to make sure that users cannot easily leave themselves open to attacks. Most people don’t know about security, the platform owner does.)
> "None of the cases we have investigated has resulted from any breach in any of Apple’s systems"
Don't these lines contradict each other?
I think the issue is that the previously posted Find My Iphone code didn't rate limit invalid logins and this was used to bruteforce creds. This is probably the real underlying issue and not any type of buffer overflow / exploit etc.
Systems aren't just technical (software), they involve human beings, feedback loops, interactions, etc. Apple's security systems are in fact weak, just not weaker than the norm.
Actually I think the Apple press release was poorly worded. This in particular:
>None of the cases we have investigated has resulted from any breach in any of Apple’s systems
There was indeed a breach in Apple's system, there just wasn't a system wide breach that compromised all accounts, just a select few.
For the average consumer two-factor-authentication means nothing, but they will start distrusting Apple more and will be more careful with data. This does not mean they will use more and better security. The average consumer will just stop using some of these services.
> 2 a : an authorized representative or messenger
> b : an unofficial representative <traveling abroad as ambassadors of goodwill>
Why doesn't Apple at least offer a bug bounty reward? Is it irresponsible that they don't?
All they offer now, as far as I have found, is a mention on this web page:
http://support.apple.com/kb/HT1318
And, does the fact that this bug made it into production suggest a lack of internal security audits at Apple?
Is this to suggest that its social engineering or just a password reset job? I don't otherwise see how an attack on usernames and passwords translates.
I guess the thing I'm really trying to figure is that if it was IBrute (which personally I would find an embarrassing failure) would they actually admit it?
> None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.
>> > None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.
Have they ruled it out? When you factor that the statement's intended audience is the entire world, not just cyber security experts, the wording becomes muddy, as it depends on you how you interpret the word "breach".
If someone successfully uses a password attack, is it actually a 'breach' of Apple's systems? After all, the systems successfully prevented entry until a valid password was entered, which is exactly what the systems were designed to do.
Failing to rate limit login attempts is a fuzzy sort of failure. I would probably call it a "vulnerability", but I wouldn't call it a "breach" to take advantage of it to figure out someone's password.
To me, this reads as a carefully crafted non-denial that looks like a denial if you don't really pay close attention.
The media over hypes these things and really the celebs involved should of used stronger passwords and/or 2 factor authentication. They should of known better.
People get "hacked" this way tons of times by using weak passwords and/or security questions. You'll never see that appear in the media.
The inequality here is the importance the media places on Kate Upton, Jennifer Lawrence, etc. It a waste of tax payer money to get the "FBI" invoked. I see it also has a waste for the government to chummy up with these "celebs". Some of them are great entertainers no doubt, but what have they done to really deserve the popularity they have.
Have they build something that tremendously improves people lives. Are they key decision makers on items that effect people? Yes Jennifer Lawrence is a great actress but c'mon.
Stop giving importance to celebs by not reading news about them. Radaronline, Tmz, etc.
Is society enriched by the eloquence of humanity of ballet? Does humanity prove itself to the universe when our best singers hold a pure note for a brief moment in time? What impact does a movie exploring some aspect of the human experience have upon the world?
Popular performing artists are popular because their performances bring some amount of joy to people's lives.