Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

jakeXT

(10,575 posts)
Sat Sep 27, 2014, 06:21 AM Sep 2014

Apple knew of iCloud security hole 6 months before Celebgate

..

The emails, obtained earlier this month by the Daily Dot and reviewed by multiple security experts, show Ibrahim Balic, a London-based software developer, informing Apple of a method he’d discovered for infiltrating iCloud accounts.

The strength of Apple’s security came under fire earlier this month after hundreds of celebrity nude photos, allegedly stolen from iCloud servers, flooded the Internet. While the exploit Balic says he reported to Apple shares a stark resemblance to the exploit allegedly used in the so-called "Celebgate" hack, it is currently unclear if they are the same vulnerability.

In a March 26 email, Balic tells an Apple official that he’s successfully bypassed a security feature designed to prevent “brute-force” attacks—a method used by hackers to crack passwords by exhaustively trying thousands of key combinations. Typically, this kind of attack is defeated by limiting the number of times users can try to log in.

Balic goes on to explain to Apple that he was able to try over 20,000 passwords combinations on any account. “I would like to inform you for it to be fix,” he wrote. (Editor’s note: Balic’s emails were written in English, which is not his first language.)


http://www.dailydot.com/technology/apple-icloud-brute-force-attack-march/
..

3 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Apple knew of iCloud security hole 6 months before Celebgate (Original Post) jakeXT Sep 2014 OP
Well, Sherman A1 Sep 2014 #1
Try updating to iOS 8 without getting tangled up in Apple's spiCloud whether you want it or not. corkhead Sep 2014 #2
I really hope what comes out of this is yeoman6987 Sep 2014 #3

Sherman A1

(38,958 posts)
1. Well,
Sat Sep 27, 2014, 06:31 AM
Sep 2014

this will not go well for Apple, if proven to be true.

I see a large number of lawyers in their future.

corkhead

(6,119 posts)
2. Try updating to iOS 8 without getting tangled up in Apple's spiCloud whether you want it or not.
Sat Sep 27, 2014, 06:34 AM
Sep 2014

It requires more effort to disable it than most people probably care to put into it.

 

yeoman6987

(14,449 posts)
3. I really hope what comes out of this is
Sat Sep 27, 2014, 09:51 AM
Sep 2014

A better security for the cloud. Overall, I like the idea of the cloud to keep items on that are accessible at anytime regardless of switching to a new computer and not having a portable hard drive that may not be access able to future computers. However, I would never put personal information and especially financial items on a cloud. And for nude pics of me....the last thing I would want to do is scare the poor little hacker.

Latest Discussions»Issue Forums»Editorials & Other Articles»Apple knew of iCloud secu...