Find My iPhone exploit may be linked to massive celebrity photo hack

Shawn Knight

Posts: 15,284   +192
Staff member

find iphone leak bug find my iphone exploit vulnerability leaked photos apple id celebrities hack hacker

A smattering of leaked images of various celebrities in the nude hit the web over the weekend. Initial reports claim the hackers involved managed to infiltrate the iCloud accounts of several high-profile targets, perhaps using the method detailed below.

As Engadget points out, the potential exploit is centered around a project on Github called ibrute. Just one day before the images hit the web, ibrute developers said they’d found a bug in the Find My iPhone service in which the service doesn’t use brute force protection (meaning someone can continue to try different passwords until they get guess the correct one).

Once a hacker has control of the Apple ID of a celebrity, it probably wouldn’t be too difficult to search their inbox or address book for other famous faces (celebs like to mingle with other celebs). Breaking into the first account would have likely required the e-mail address of the initial target, but after that, it’s open season on other celebs.

The good news is that the same developer that spoke of the bug now claims it has been patched.

As always, keep in mind that this is mostly speculation at this time and should be taken with a grain of salt. Apple has yet to comment on the matter but all we know for certain is that we are dealing with a widespread hack involving dozens of celebrities’ private photos.

Update: Apple has confirmed they are currently looking into the potential security breach connected to the celebrity photo hack. “We take user privacy very seriously and are actively investigating this report,” said Apple spokeswoman Natalie Kerris.

Update #2: Apple issues statement on celeb photo hack, says iCloud / Find my iPhone not to blame.

Permalink to story.

 
Surely they must mean the Google or MS cloud because the iCloud is impervious to hack attacks or so I've been told, not to mention blasphemous to iFans .
 
How many times do we need to say it

NEVER TRUST THE CLOUD

you have stuff that's private and cant be seen? encrypt THE **** out of it and store it yourself
 
IOsis the most insecure OS out there. Security issues always show up every two three months.

The SSL goto fail was bad. The Amazon crack was another. Find my iPhone, the list is endless.

It's amazing that IOs even has a market share, considering all these holes showing up consistently every few months for the past three years.
 
Another reason not to trust Apple. You may think Microsoft were slow to the phone revolution but really they just wanted to see Apple's mistakes and how not to make them.
 
Im sure the FBI would get just as involved if it was pictures of common folk that were leaked. right?
 
That's why they should use my stolen android phone finder app, altho it's not for apple. It's not hacked.
 
So basically, Hollywood is run by pimps and pedophiles who make prospective actresses into their *****s if they want to get into a movie. Most of those photos look like someone took it to blackmail them in case they refused to be a ***** for the Hollywood power players anymore.
 
Think about the implications if the kill switch garbage that California just past was online....

You could lock all the ios devices which you had the iaccount passwords to.
 
May I just say, after looking at Jlaw's photos, that I'm not impressed with them? For a such glorified and expensive device, iPhone makes mediocre low light photos. Those celebrities should buy themselves a middle range Nokia or something...
 
Just in case you were off planet when the Edward Snowden Scandal came to light, there is really no such thing as 100% secure file storage if its connected to the internet. (Especially if you use any third party storage...) I store EVERYTHING on a portable hard drive... and disconnect it when I am not using it.. You can get a terabyte portable hard drive for around $150.00, I never have to worry about losing anything or anyone stealing my files...and I don't pay a monthly fee..

Hell, I don’t even really use my “smart phone”. My old dumb-one is good enough for me and its cheaper. It’s a waste of money just like so many other things in America like student loans (get a cheap education!), expensive car insurance (my $25/month policy from Insurance Panda is good enough for me), and fast food (who wants to pay $10 for a Chipotle burrito?!?).

Also - One way to completely ensure there are no bad photos of yourself that could wind up in an embarrassing situations is to NOT take them. Seems pretty logical to me...
 
@alinazhibek - for all your apparent price savvyness you are getting screwed on HD prices. Western Digital 1TB portable USB 3 for $65 at newegg right now. A bunch of others aren't much above that. Several 2TB ones for $99.
 
Back