TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Update to Celebrity Photo Investigation

98 pointsby ssclafaniover 10 years ago

21 comments

karl_nerdover 10 years ago
So i&#x27;d wager there&#x27;d be quite a few celebrity dick picks available too if hackers wanted them. We know men like to send them unsolicited, and I&#x27;m sure those celebrities had received more than a few. But there are none. And why? Because those women were specifically targeted by people with a lot of resources and patience. (it&#x27;s important that they were targeted specifically for being women).<p>To all of you idiots blaming the victims out there right now &quot;should have used 2fa, should have used stronger passwords&quot;:<p>1. You don&#x27;t know if 2FA was in place, you don&#x27;t know what strength the passwords were.<p>2. Again: those women were highly targeted. Can you defend yourself if someone takes a week&#x2F;month long project to break into your phone? (Also this was during heartbleed and other big vulnerabilites)<p>Come off your bullshit high horse. Don&#x27;t blame the victims here.
评论 #8260887 未加载
edentover 10 years ago
So, basically find any celebrity interview where they state what school they went to, their first pet, etc.<p>Exactly the same way that Sarah Palin&#x27;s email was hacked - <a href="https://en.wikipedia.org/wiki/Sarah_Palin_email_hack" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Sarah_Palin_email_hack</a>
vitamenover 10 years ago
So &quot;This is a very common attack on the Internet that we didn&#x27;t do much to protect you against by default&quot;?<p>It&#x27;s a pain setting up two step authentication across a lot of services, but I guess iCloud is probably one that&#x27;s worth the effort. Still I&#x27;d rather brute force was not an option.
评论 #8259758 未加载
modfodderover 10 years ago
From what I&#x27;ve read on 4-chan, Ars, Slashdot (indiv. comments, not articles) and other sources that this wasn&#x27;t one person hacking a group of celebs acount, but a leak from an underground celeb nude trading ring that has existed for a while. So multiple hackers over a long period of time, from multiple sources.<p>link to one explanation: <a href="http://i.imgur.com/vnd0H9J.jpg" rel="nofollow">http:&#x2F;&#x2F;i.imgur.com&#x2F;vnd0H9J.jpg</a>
nokiamanover 10 years ago
The damage has been done, surely?<p>Headlines around the world are &quot;iCloud hacked&quot;, &quot;Apple hacking scandal&quot;, &quot;Are your photos safe on iCloud?&quot; etc.<p>Meanwhile celebrities like Kirsten Dunst have described iCloud as a &quot;piece of shit&quot; (a tweet with emoticons).<p>Timing is not great for Apple since they are supposed to be launching health and payment related features for iOS in the next few days.<p>Question is, would Apple have responded so quickly if celebrities weren&#x27;t involved?
评论 #8259636 未加载
评论 #8260044 未加载
flogover 10 years ago
If I was in Hollywood right now I&#x27;d be offering high-price security consultation services to teach celeb&#x27;s how to use 2FA.
评论 #8259985 未加载
评论 #8260128 未加载
smacktowardover 10 years ago
<i>&gt; After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.</i><p><i>&gt;None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.</i><p>Um... doesn&#x27;t &quot;a very targeted attack on user names, passwords and security questions&quot; count as a &quot;breach in... Apple&#x27;s systems&quot;? A social engineering hack is still a hack.
评论 #8259840 未加载
nedwinover 10 years ago
At what point do tech companies start making two factor authentication mandatory?<p>It&#x27;s one thing to say &quot;We tell our users to use two factor authentication - it&#x27;s their fault if they don&#x27;t use it&quot; but it&#x27;s another to say &quot;all user accounts use two factor authentication to ensure security of their data&quot;
tvonover 10 years ago
&gt; <i>After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.</i><p>So, the brute force attack with reasonable guesses at email addresses?
评论 #8259451 未加载
评论 #8259466 未加载
评论 #8259432 未加载
64mbover 10 years ago
&gt; &quot;we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions&quot;<p>&gt; &quot;None of the cases we have investigated has resulted from any breach in any of Apple’s systems&quot;<p>Don&#x27;t these lines contradict each other?
评论 #8259533 未加载
评论 #8259831 未加载
评论 #8259537 未加载
julianpyeover 10 years ago
People have become so close with their smartphones that they entrust it with more information than their friends know. In addition no brand is more loved than Apple, with many celebrities being ambassadors to the brand. The brand is planning to introduce new payment and health services next week.<p>For the average consumer two-factor-authentication means nothing, but they will start distrusting Apple more and will be more careful with data. This does not mean they will use more and better security. The average consumer will just stop using some of these services.
评论 #8259870 未加载
fjarlqover 10 years ago
I&#x27;m still wondering if the Find My iPhone brute force bug was exploited.<p>Why doesn&#x27;t Apple at least offer a bug bounty reward? Is it irresponsible that they don&#x27;t?<p>All they offer now, as far as I have found, is a mention on this web page:<p><a href="http://support.apple.com/kb/HT1318" rel="nofollow">http:&#x2F;&#x2F;support.apple.com&#x2F;kb&#x2F;HT1318</a><p>And, does the fact that this bug made it into production suggest a lack of internal security audits at Apple?
评论 #8260012 未加载
philip1209over 10 years ago
I had no idea that Apple supports two-step verification.
评论 #8259708 未加载
Torgoover 10 years ago
It seems like it would be a feat to gather all the user IDs of these famous people in the first place. I&#x27;m guessing there&#x27;s a black market just for that? I used to work on a service used by quite a few famous people, if anybody on the project was unscrupulous, it would have been easy to pass those emails and other personal information on to a hacker.
评论 #8259508 未加载
elliottpayneover 10 years ago
2FA is no panacea. My yahoo account (only used for flickr) was compromised with 2FA &amp; 20+ character password.
评论 #8259820 未加载
评论 #8259786 未加载
omfgover 10 years ago
If anyone wants to setup 2FA for their Apple ID here&#x27;s their support page on it: <a href="http://support.apple.com/kb/ht5570" rel="nofollow">http:&#x2F;&#x2F;support.apple.com&#x2F;kb&#x2F;ht5570</a>
评论 #8259496 未加载
davisover 10 years ago
Just a friendly remind of the sites that support 2FA, Apple is on the list: <a href="https://twofactorauth.org/" rel="nofollow">https:&#x2F;&#x2F;twofactorauth.org&#x2F;</a>
评论 #8259766 未加载
Quarrelsomeover 10 years ago
I&#x27;m confused. The description of the problem doesn&#x27;t rule out an issue with IBrute (targetted attack on usernames, passwords) but then they state it wasn&#x27;t an issue with ICloud or FindMyPhone.<p>Is this to suggest that its social engineering or just a password reset job? I don&#x27;t otherwise see how an attack on usernames and passwords translates.<p>I guess the thing I&#x27;m really trying to figure is that if it was IBrute (which personally I would find an embarrassing failure) would they actually admit it?
评论 #8259465 未加载
ciiworldwideover 10 years ago
Full investigation means full...Apple will clear this issue and do the best...and do the full investigation.. Ciiworldwide
curiousDogover 10 years ago
Why not make 2FA mandatory?
评论 #8259754 未加载
pptr1over 10 years ago
I am kinda of sick of hearing about how celebs got hacked and how it is such a big deal.<p>The media over hypes these things and really the celebs involved should of used stronger passwords and&#x2F;or 2 factor authentication. They should of known better.<p>People get &quot;hacked&quot; this way tons of times by using weak passwords and&#x2F;or security questions. You&#x27;ll never see that appear in the media.<p>The inequality here is the importance the media places on Kate Upton, Jennifer Lawrence, etc. It a waste of tax payer money to get the &quot;FBI&quot; invoked. I see it also has a waste for the government to chummy up with these &quot;celebs&quot;. Some of them are great entertainers no doubt, but what have they done to really deserve the popularity they have.<p>Have they build something that tremendously improves people lives. Are they key decision makers on items that effect people? Yes Jennifer Lawrence is a great actress but c&#x27;mon.<p>Stop giving importance to celebs by not reading news about them. Radaronline, Tmz, etc.
评论 #8259906 未加载