Hacker News new | past | comments | ask | show | jobs | submit login

Wasn't the Fappening because of a iCloud hole?



No, it was because celebrities are normal people and tended to use the same password for multiple services. One service was compromised, which compromised every other one because the passwords were the same.


Source?

My understanding was that some iCloud account login endpoints (associated with Find My iPhone) didn't have any rate limiting for password failures, and this allowed brute force to work for targetted accounts.


It's also much easier to find the answers to account recovery questions when the target is a celeb.


Source? Most of my google has netted the blame on Apple and a conspiracy throy of this beng a PR scandal.


Really? It seems to me that most articles conclude that it wasn’t iCloud that was hacked but the celebrities.

Apple also released a press release[1] saying that they “have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet. None of the cases we have investigated has resulted from any breach in any of Apple’s systems including iCloud® or Find my iPhone.”

[1]: http://www.apple.com/pr/library/2014/09/02Apple-Media-Adviso...


What most articles? You are giving me Apple's press release...

The news on it has died down over the past year, with a recent items search bringing up only links to pron sites hosting the content. This is the best summary I could find: https://www.nikcub.com/posts/notes-on-the-celebrity-data-the...

It clearly shows that iCloud was very susceptible to basic social engineered attacks. Their statement on the subject is vague and misleading. There was no breach of iCloud passwords database, but if somebody just "guessed" the answers to the security questions, that counts as a breach for everybody else.

FBI has made one arrest and the investigation is still on going. We probably would not know until it's over, but at least one celebrity, Kirsten Dunst suggested her images were taken from the iCloud: https://twitter.com/kirstendunst/status/506553772114317312

Again, what most articles you have besides Apple's hand waving?


The images in The Fappening came from a variety of cloud services, including iCloud. I think the hackers were getting access primarily via social engineering.

There was an iCloud hole that was discovered around the same time as The Fappening, but no evidence that it was used by them before it was patched by apple.


that was speculated, but denied by apple




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: