Can we talk about the apparent iCloud break-in?

Status
Not open for further replies.
I think most security people has ruled it as very unlikely due to the short time it was online and the sheer amount of work that had to be done.

Just because it was published online recently does not mean some other hacker didn't know of the exploit for a while. Just saying.

Also, it would definitely take some social engineering to be able to get the celebrities' emails (I presume). So it's not as simple as knowing about the exploit. Maybe the hacker(s) were sitting on account info for a while until they found a way to breach in.
 
Just because it was published online recently does not mean some other hacker didn't know of the exploit for a while. Just saying.

Also, it would definitely take some social engineering to be able to get the celebrities' emails (I presume). So it's not as simple as knowing about the exploit. Maybe the hacker(s) were sitting on account info for a while until they found a way to breach in.

Yup.

And the exploit being closed last night would explain why the materials were suddenly passed around.
 
This is not really a cost. This is like the heartbleed bug.

The heartbleed bug really came down to a financial cost, the OpenSSL team had no money to finance developers that could have (easily) caught that bug.

Being a PR must be the easiest job in the world if celebs are allowed to upload - willingly or not - naked pics to the cloud. But it's really hard to feel any sympathy when this has happened several times already. If it's stored outside of your control unencrypted, tough luck.

Methinks celebs are putting on an angry face but they don't really mind the extra publicity.
 
This is why you shouldn't click on the naked photos of Jennifer Lawrence



Great article, brings up 3 points that I feel definitely needs to be addressed in lieu of some of the responses and reactions I'm seeing.
jennifer-lawrence-10.gif
 
Blackberry didn't store photos in the cloud. You know who did? Sidekick, and that shit leaked. There were absolutely nude leaks from celebs with bad passwords back then.

I still remember Paris Hilton's entire phonebook and photo album leaking because her security question was her dog's name.
 
The heartbleed bug really came down to a financial cost, the OpenSSL team had no money to finance developers that could have (easily) caught that bug.

Open-source code also has the advantage of massive amounts of peer review because everyone can see exactly what the code is doing. It can be a huge advantage for security-related code.

I read an article a few months talking about terrorist groups beginning to come up with their own cryptographic service due to all the concerns about NSA backdoors in some of the main ones. In reality, it will probably make intelligence agencies' jobs even easier since it's very hard to develop crytography without weaknesses.
 
The heartbleed bug really came down to a financial cost, the OpenSSL team had no money to finance developers that could have (easily) caught that bug.
The companies that used the code, like Google, could've checked, but they instead faced doomsday because they were negligent and trying to save costs on the back of customers/employees/environment.
 
This is why you shouldn't click on the naked photos of Jennifer Lawrence



Great article, brings up 3 points that I feel definitely needs to be addressed in lieu of some of the responses and reactions I'm seeing.
The second point is weak I think. It's not because they're women that they shouldn't be taking nude photos of themselves, it's because they're celebrities, something they chose to be, unlike being women.

If Brad Pitt had a nude selfie leaked, it would be plastered throughout the internet too, because he's a super famous, desirable man. In theory of course they should be able to take nudes for their own private use, and they should be able to go to Starbucks without being asked to sign some crap, but they decided to pursue a career that was always going to impact their personal freedoms in various practical ways.

JLaw is probably the most important actress in the world right now, she should be very cautious about how she carries on her personal life, because she knows she lives in a world where people will go to extremes to abuse any opportunity like this.
 
Has it already been posted that it likely wasn't iCloud? Some of the celebs used Android and still had their pics leaked.

Already posted, discussed and largely discredited - actually, the legit photos all seem to come from iPhones, and even if they didn't, if they were sent to people with iPhones then they would still get uploaded to iCloud.

It's possible that there's a Dropbox vuln as well, but it's likely that quite a lot of these were sourced from iCloud at this point.

Hearing from some infosec people I know that there are some worrying noises about iCloud security in general.
 
She said they're fake, they're composites, they're not of a real person.

Sure, they're someone's nipples, but that person can't be identified by the images, if they are even against their distribution.
Victoria Justice's tweet saying they're fake was just for the first leak of a couple images, which turned out to be fake. The hacker then released a boatload of new ones and it's 100% confirmed to be her.
 
After thoroughly examining these pics you do start to wonder why people care about this bullshit. Celebrities are fucking sexy and have lots of sex. It's a shame that people have to hide this side of them.
 
Someone citing Android as a means of security and ruling out a possible leak.

Is this how the world ends?

I say this as a staunch Android user that has seen many discussions trashing the security of the platform!
 
Victoria Justice's tweet saying they're fake was just for the first leak of a couple images, which turned out to be fake. The hacker then released a boatload of new ones and it's 100% confirmed to be her.
I don't know who confirmed them, but of the ones I've seen, there are very few that actually have her nude while showing her face. One she specifically said is fake, and retweeted 'proof', and one is outside in the dark, grainy, and blurry as all hell. Maybe they're real, but I doubt it. Grande denied her's a real, and I think she's right, now this Trisha woman is providing very strong proof.

Obviously whoever is releasing these does have some real things, the JLaw ones are very clear, and there's no way they're fake, but I think a great deal of them are just bullshit.
 
The second point is weak I think. It's not because they're women that they shouldn't be taking nude photos of themselves, it's because they're celebrities, something they chose to be, unlike being women.

If Brad Pitt had a nude selfie leaked, it would be plastered throughout the internet too, because he's a super famous, desirable man. In theory of course they should be able to take nudes for their own private use, and they should be able to go to Starbucks without being asked to sign some crap, but they decided to pursue a career that was always going to impact their personal freedoms in various practical ways.

JLaw is probably the most important actress in the world right now, she should be very cautious about how she carries on her personal life, because she knows she lives in a world where people will go to extremes to abuse any opportunity like this.

I've seen at least two nude pics of him back when he was with Paltrow.
 
Is he very famous if you have to tell someone he is very famous?

That doesn't mean he isn't famous. The guy has millions of subscribers and his own company. He has shows in various parts of the world that sell out within hours. Not everyone knows every single person who is famous and what they do, that doesn't mean the person in question isn't famous.
 
The second point is weak I think. It's not because they're women that they shouldn't be taking nude photos of themselves, it's because they're celebrities, something they chose to be, unlike being women.

If Brad Pitt had a nude selfie leaked, it would be plastered throughout the internet too, because he's a super famous, desirable man. In theory of course they should be able to take nudes for their own private use, and they should be able to go to Starbucks without being asked to sign some crap, but they decided to pursue a career that was always going to impact their personal freedoms in various practical ways.

JLaw is probably the most important actress in the world right now, she should be very cautious about how she carries on her personal life, because she knows she lives in a world where people will go to extremes to abuse any opportunity like this.

Do you seriously not see hot women are more in danger of this than men? Even if men are also under this risk, it's much rarer for a reason. I don't think you can compare the situation of female celebrities and male celebrities.

This is no to mention that even if she should be more cautious, it doesn't negate the fact that no one under ANY circumstances has any right to invade her, or anyone's, privacy like that. It's indefensible.
 
Because it's a violation of their privacy?

I'm talking about caring about celeb pics in general, not the crime. Maybe I've just gotten old, but it's not like there is a shortage of gorgeous people out there willing to show off themselves in even sexier ways than this .
 
Status
Not open for further replies.
Top Bottom