Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.sys.mac.system > #29056 > unrolled thread

iCloud Hacked Article

Started byFred Moore <fmoore@gcfn.org>
First post2012-08-06 17:46 -0400
Last post2012-08-08 04:31 +0000
Articles 20 on this page of 135 — 26 participants

Back to article view | Back to comp.sys.mac.system


Contents

  iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-06 17:46 -0400
    Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-06 21:54 +0000
      Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:33 -0400
        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-06 20:47 -0400
          Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:05 -0400
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:05 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:20 -0400
            Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 00:08 +0000
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 20:40 -0400
        Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-07 13:20 +1200
      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-07 10:48 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 12:34 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 12:58 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-08 14:30 -0400
              Re: iCloud Hacked Article MC <copespaz@mapca.inter.net> - 2012-08-08 17:18 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:19 +0000
    Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-06 23:21 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 01:15 -0400
          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:24 -0400
            Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:29 -0400
        Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 01:26 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 05:41 +0000
            Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:11 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 06:22 +0000
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 02:31 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 08:28 +0200
      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-07 09:19 -0400
        Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 09:30 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:15 +0000
        Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-08 08:11 -0400
      Re: iCloud Hacked Article David Lesher <wb8foz@panix.com> - 2012-08-07 18:26 +0000
    Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 00:26 -0400
      Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 00:31 -0400
        Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-07 20:16 -0400
          Re: iCloud Hacked Article dempson@actrix.gen.nz (David Empson) - 2012-08-08 12:28 +1200
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:13 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:16 +0200
              Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:56 -0400
                Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 09:46 -0400
                  Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 10:35 -0400
                    Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 12:41 -0400
                      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-09 14:15 -0400
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 14:57 -0400
                  Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-09 16:25 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:51 -0400
          Re: iCloud Hacked Article Larry Gusaas <larry.gusaas@gmail.com> - 2012-08-07 18:34 -0600
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 20:41 -0400
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-08 01:49 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:29 +0000
            Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-08 01:14 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:25 +0000
                Re: iCloud Hacked Article Justin <justin@nobecauseihatespam.edu> - 2012-08-09 02:57 -0400
      Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-07 04:49 +0000
    Re: iCloud Hacked Article Jeff N <jeff+no.spam@jnadeau.com> - 2012-08-07 00:01 -0700
      Re: iCloud Hacked Article Barry Margolin <barmar@alum.mit.edu> - 2012-08-07 03:48 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:49 +0200
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 21:52 +0200
            Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 17:33 -0400
              Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 16:44 -0500
              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 18:09 -0400
                Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 18:33 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-07 19:26 -0400
                    Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-07 19:19 -0500
                    Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-07 21:07 -0400
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 11:14 -0400
                        Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-08 13:11 -0400
                          Re: iCloud Hacked Article me@home.spamsucks.ca (Király) - 2012-08-09 04:56 +0000
                    Re: iCloud Hacked Article "John Varela" <newlamps@verizon.net> - 2012-08-08 21:48 +0000
                      Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:50 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:15 -0400
                          Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-08 20:16 -0500
                          Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:22 -0400
                      Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 07:03 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 10:57 -0400
                          Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 12:29 -0400
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:50 -0500
                              Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:53 -0400
                                Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-11 20:18 -0500
                                  Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-11 21:44 -0400
                                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-11 23:35 -0400
                          Re: iCloud Hacked Article J.J. O'Shea <try.not.to@but.see.sig> - 2012-08-09 19:00 -0400
                Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:19 +0200
            Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 23:06 -0400
              Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:26 +0200
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 10:59 +0000
                Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 16:27 -0400
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-08 17:29 -0400
                  Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-08 22:25 -0400
                    Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 13:30 -0400
                      Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 14:49 -0400
                        Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-09 15:05 -0400
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 15:55 -0400
                        Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-09 14:53 -0500
                          Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-09 20:30 -0400
                            Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-09 17:50 -0700
                              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-10 09:15 -0400
                                Re: iCloud Hacked Article Warren Oates <warren.oates@gmail.com> - 2012-08-10 10:18 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:49 -0700
                              Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 10:50 -0400
                                Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 08:48 -0700
                                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-10 12:21 -0400
                                    Re: iCloud Hacked Article Michelle Steiner <michelle@michelle.org> - 2012-08-10 10:00 -0700
                            Re: iCloud Hacked Article George Kerby <ghost_topper@hotmail.com> - 2012-08-10 13:23 -0500
                      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-10 22:54 -0400
                        Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-12 20:14 -0400
      Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 08:50 -0400
        Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-07 20:55 +0200
          Re: iCloud Hacked Article Tom Stiller <tom_stiller@yahoo.com> - 2012-08-07 15:17 -0400
          Re: iCloud Hacked Article nospam <nospam@nospam.invalid> - 2012-08-07 15:27 -0400
          Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:28 +0000
            Re: iCloud Hacked Article Paul Sture <paul@sture.ch> - 2012-08-08 11:39 +0200
              Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 10:44 -0400
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 14:59 +0000
                  Re: iCloud Hacked Article Richard Kettlewell <rjk@greenend.org.uk> - 2012-08-09 10:50 +0100
                Re: iCloud Hacked Article Michael Vilain <vilain@NOspamcop.net> - 2012-08-08 17:40 -0700
                  Re: iCloud Hacked Article Jim Janney <jjanney@shell.xmission.com> - 2012-08-09 07:55 -0600
                    Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:40 -0400
              Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:15 -0400
                Re: iCloud Hacked Article Fred Moore <fmoore@gcfn.org> - 2012-08-08 11:42 -0400
              Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 15:19 +0000
                Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-08 15:44 +0000
                  Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 18:36 -0400
                    Re: iCloud Hacked Article JF Mezei <jfmezei.spamnot@vaxination.ca> - 2012-08-08 19:21 -0400
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-08 21:09 -0400
                    Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 05:34 +0000
                      Re: iCloud Hacked Article Davoud <star@sky.net> - 2012-08-09 10:45 -0400
                        Re: iCloud Hacked Article "Geoffrey S. Mendelson" <gsm@mendelson.com> - 2012-08-09 17:39 +0000
                  Re: iCloud Hacked Article Alan Browne <alan.browne@FreelunchVideotron.ca> - 2012-08-09 11:12 -0400
                  Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-10 01:08 +0000
      Re: iCloud Hacked Article Wes Groleau <Groleau+news@FreeShell.org> - 2012-08-07 22:59 -0400
        Re: iCloud Hacked Article Lewis <g.kreme@gmail.com.dontsendmecopies> - 2012-08-08 04:31 +0000

Page 3 of 7 — ← Prev page 1 2 [3] 4 5 6 7  Next page →


#29237

Fromnospam <nospam@nospam.invalid>
Date2012-08-09 09:46 -0400
Message-ID<090820120946056274%nospam@nospam.invalid>
In reply to#29231
In article <jvvmuf$fn6$1@dont-email.me>, Justin
<justin@nobecauseihatespam.edu> wrote:

> >> Here is the victim's article describing the hack in detail, including
> >> having got details from one of the hackers. The hackers did not guess
> >> any of his passwords.
> >>
> >> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/
> >
> > On my first look at that article I didn't notice the page numbers at the
> > bottom so missed 3/4 of the story.  There's also an option to see the
> > whole report on one page.
> >
> 
> I read the whole thing, and iCloud itself was not hacked.

it was hacked, and very easily at that, simply by supplying trivially
acquired information.

so are you going to admit you were wrong about the password being
cracked?

> Now keep on failing.

that's what you keep doing, alright.

[toc] | [prev] | [next] | [standalone]


#29239

FromTom Stiller <tom_stiller@yahoo.com>
Date2012-08-09 10:35 -0400
Message-ID<tom_stiller-1FA0B4.10350009082012@news.individual.net>
In reply to#29237
In article <090820120946056274%nospam@nospam.invalid>,
 nospam <nospam@nospam.invalid> wrote:

> In article <jvvmuf$fn6$1@dont-email.me>, Justin
> <justin@nobecauseihatespam.edu> wrote:
> 
> > >> Here is the victim's article describing the hack in detail, including
> > >> having got details from one of the hackers. The hackers did not guess
> > >> any of his passwords.
> > >>
> > >> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/
> > >
> > > On my first look at that article I didn't notice the page numbers at the
> > > bottom so missed 3/4 of the story.  There's also an option to see the
> > > whole report on one page.
> > >
> > 
> > I read the whole thing, and iCloud itself was not hacked.
> 
> it was hacked, and very easily at that, simply by supplying trivially
> acquired information.
> 
> so are you going to admit you were wrong about the password being
> cracked?
> 
> > Now keep on failing.
> 
> that's what you keep doing, alright.

Geez! You really can't admit an error, can you?

-- 
PRAY, v.  To ask that the laws of the universe be annulled in behalf
of a single petitioner confessedly unworthy. -- Ambrose Bierce

[toc] | [prev] | [next] | [standalone]


#29246

Fromnospam <nospam@nospam.invalid>
Date2012-08-09 12:41 -0400
Message-ID<090820121241126678%nospam@nospam.invalid>
In reply to#29239
In article <tom_stiller-1FA0B4.10350009082012@news.individual.net>, Tom
Stiller <tom_stiller@yahoo.com> wrote:

> In article <090820120946056274%nospam@nospam.invalid>,
>  nospam <nospam@nospam.invalid> wrote:
> 
> > In article <jvvmuf$fn6$1@dont-email.me>, Justin
> > <justin@nobecauseihatespam.edu> wrote:
> > 
> > > >> Here is the victim's article describing the hack in detail, including
> > > >> having got details from one of the hackers. The hackers did not guess
> > > >> any of his passwords.
> > > >>
> > > >> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/
> > > >
> > > > On my first look at that article I didn't notice the page numbers at the
> > > > bottom so missed 3/4 of the story.  There's also an option to see the
> > > > whole report on one page.
> > > >
> > > 
> > > I read the whole thing, and iCloud itself was not hacked.
> > 
> > it was hacked, and very easily at that, simply by supplying trivially
> > acquired information.
> > 
> > so are you going to admit you were wrong about the password being
> > cracked?
> > 
> > > Now keep on failing.
> > 
> > that's what you keep doing, alright.
> 
> Geez! You really can't admit an error, can you?

i'm not the one who is wrong, justin is, and even after he claims
having read the very article that proves him wrong, he still won't
admit it.

[toc] | [prev] | [next] | [standalone]


#29252

FromTom Stiller <tom_stiller@yahoo.com>
Date2012-08-09 14:15 -0400
Message-ID<tom_stiller-EF4A28.14153409082012@news.individual.net>
In reply to#29246
In article <090820121241126678%nospam@nospam.invalid>,
 nospam <nospam@nospam.invalid> wrote:

> In article <tom_stiller-1FA0B4.10350009082012@news.individual.net>, Tom
> Stiller <tom_stiller@yahoo.com> wrote:
> 
> > In article <090820120946056274%nospam@nospam.invalid>,
> >  nospam <nospam@nospam.invalid> wrote:
> > 
> > > In article <jvvmuf$fn6$1@dont-email.me>, Justin
> > > <justin@nobecauseihatespam.edu> wrote:
> > > 
> > > > >> Here is the victim's article describing the hack in detail, 
> > > > >> including
> > > > >> having got details from one of the hackers. The hackers did not 
> > > > >> guess
> > > > >> any of his passwords.
> > > > >>
> > > > >> http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking
> > > > >> /
> > > > >
> > > > > On my first look at that article I didn't notice the page numbers at 
> > > > > the
> > > > > bottom so missed 3/4 of the story.  There's also an option to see the
> > > > > whole report on one page.
> > > > >
> > > > 
> > > > I read the whole thing, and iCloud itself was not hacked.
> > > 
> > > it was hacked, and very easily at that, simply by supplying trivially
> > > acquired information.
> > > 
> > > so are you going to admit you were wrong about the password being
> > > cracked?
> > > 
> > > > Now keep on failing.
> > > 
> > > that's what you keep doing, alright.
> > 
> > Geez! You really can't admit an error, can you?
> 
> i'm not the one who is wrong, justin is, and even after he claims
> having read the very article that proves him wrong, he still won't
> admit it.

I guess I can do without your brand of "correctness" in the future.

-- 
PRAY, v.  To ask that the laws of the universe be annulled in behalf
of a single petitioner confessedly unworthy. -- Ambrose Bierce

[toc] | [prev] | [next] | [standalone]


#29254

FromJF Mezei <jfmezei.spamnot@vaxination.ca>
Date2012-08-09 14:57 -0400
Message-ID<50240818$0$8568$c3e8da3$e408f015@news.astraweb.com>
In reply to#29231
Justin wrote:

> I read the whole thing, and iCloud itself was not hacked.

I'd say it was. Someone found a security gap in the service and
exploited it.

Whether the security gap is in the operating system, hardware,
applications or in the support staff, it is a still a security gap which
was exploited.


You could say that the iCloud infrastructure was not hacked and that it
was the iCloud service which was. But at the end of the day, iCloud was
hacked.

[toc] | [prev] | [next] | [standalone]


#29260

Fromnospam <nospam@nospam.invalid>
Date2012-08-09 16:25 -0400
Message-ID<090820121625434932%nospam@nospam.invalid>
In reply to#29254
In article <50240818$0$8568$c3e8da3$e408f015@news.astraweb.com>, JF
Mezei <jfmezei.spamnot@vaxination.ca> wrote:

> > I read the whole thing, and iCloud itself was not hacked.
> 
> I'd say it was. Someone found a security gap in the service and
> exploited it.
>
> Whether the security gap is in the operating system, hardware,
> applications or in the support staff, it is a still a security gap which
> was exploited.
> 
> You could say that the iCloud infrastructure was not hacked and that it
> was the iCloud service which was. But at the end of the day, iCloud was
> hacked.

exactly.

*which* exploit was used doesn't matter. the fact is that an
unauthorized person gained access and caused quite a bit of damage.

fortunately, the particular exploit used is no longer valid but there
may be others.

[toc] | [prev] | [next] | [standalone]


#29303

FromWes Groleau <Groleau+news@FreeShell.org>
Date2012-08-10 22:51 -0400
Message-ID<k04hbh$dqh$1@dont-email.me>
In reply to#29254
On 08-09-2012 14:57, JF Mezei wrote:
> Justin wrote:
>> I read the whole thing, and iCloud itself was not hacked.
>
> I'd say it was. Someone found a security gap in the service and
> exploited it.
>
> Whether the security gap is in the operating system, hardware,
> applications or in the support staff, it is a still a security gap which
> was exploited.
>
> You could say that the iCloud infrastructure was not hacked and that it
> was the iCloud service which was. But at the end of the day, iCloud was
> hacked.

Any bets on how long we'll be arguing over the definition of "hacked" ?


-- 
Wes Groleau

    You're all individuals!
           Yes, we're all individuals!
    You're all different!
           Yes, we are all different!
                                I'm not!
                      ("Life of Brian")

[toc] | [prev] | [next] | [standalone]


#29168

FromLarry Gusaas <larry.gusaas@gmail.com>
Date2012-08-07 18:34 -0600
Message-ID<jvsc71$vmt$1@dont-email.me>
In reply to#29164

On 2012-08-07 6:16 PM Justin wrote:
> On 8/7/12 12:31 AM, nospam wrote:
>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>> <justin@nobecauseihatespam.edu> wrote:
>>
>>>> Thought folks here would be interested in this article I saw on
>>>> Macintouch:
>>>>
>>>> Yes, I was hacked. Hard.
>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>
>>> Even Apple can't defend against lousy passwords.
>>
>> it wasn't a lousy password. in fact, his password made no difference
>> whatsoever.
>>
>> apple *gave* the hacker a new, temporary password.
>
> Wrong.

Nope.

> His original password was guessed, with that he (they?) gained enough information to go 
> through the password reset procedure pretending to be the victim.

No it wasn't. Here is what the original article said:

    Update Three: I know how it was done now. Confirmed with both the hacker and Apple. It
    wasn¹t password related. They got in via Apple tech support and some clever social
    engineering that let them bypass security questions.

> Didn't score very high on the reading comprehension part of the SAT, now did you?

You scored zero. Did you even attempt to read the article?

-- 
_________________________________

Larry I. Gusaas
Moose Jaw, Saskatchewan Canada
Website: http://larry-gusaas.com
"An artist is never ahead of his time but most people are far behind theirs." - Edgard Varese

[toc] | [prev] | [next] | [standalone]


#29170

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 20:41 -0400
Message-ID<070820122041548309%nospam@nospam.invalid>
In reply to#29164
In article <jvsb5c$q33$3@dont-email.me>, Justin
<justin@nobecauseihatespam.edu> wrote:

> >> Even Apple can't defend against lousy passwords.
> >
> > it wasn't a lousy password. in fact, his password made no difference
> > whatsoever.
> >
> > apple *gave* the hacker a new, temporary password.
> 
> Wrong.

nope.

> His original password was guessed, with that he (they?) gained enough 
> information to go through the password reset procedure pretending to be 
> the victim.

nope.

the hacker obtained his address via a google search and got the last 4
digits of his credit card from amazon. 

using both of those, the hacker was able to have the apple account
reset to a temporary password. 

at that point, game over.

> Didn't score very high on the reading comprehension part of the SAT, now 
> did you?

much better than you, apparently.

[toc] | [prev] | [next] | [standalone]


#29188

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-08 01:14 -0400
Message-ID<jvssj8$98u$2@dont-email.me>
In reply to#29170
On 8/7/12 8:41 PM, nospam wrote:
> In article <jvsb5c$q33$3@dont-email.me>, Justin
> <justin@nobecauseihatespam.edu> wrote:
>
>>>> Even Apple can't defend against lousy passwords.
>>>
>>> it wasn't a lousy password. in fact, his password made no difference
>>> whatsoever.
>>>
>>> apple *gave* the hacker a new, temporary password.
>>
>> Wrong.
>
> nope.
>
>> His original password was guessed, with that he (they?) gained enough
>> information to go through the password reset procedure pretending to be
>> the victim.
>
> nope.

Wrong.


>
>> Didn't score very high on the reading comprehension part of the SAT, now
>> did you?
>
> much better than you, apparently.
>

Wrong.

[toc] | [prev] | [next] | [standalone]


#29192

Fromnospam <nospam@nospam.invalid>
Date2012-08-08 01:49 -0400
Message-ID<080820120149261437%nospam@nospam.invalid>
In reply to#29188
In article <jvssj8$98u$2@dont-email.me>, Justin
<justin@nobecauseihatespam.edu> wrote:

> >>>> Even Apple can't defend against lousy passwords.
> >>>
> >>> it wasn't a lousy password. in fact, his password made no difference
> >>> whatsoever.
> >>>
> >>> apple *gave* the hacker a new, temporary password.
> >>
> >> Wrong.
> >
> > nope.
> >
> >> His original password was guessed, with that he (they?) gained enough
> >> information to go through the password reset procedure pretending to be
> >> the victim.
> >
> > nope.
> 
> Wrong.

yes, you are very, very  wrong. you forgot to put "i'm" in front. 

at no point was his password guessed or cracked. period.

apple reset the password and then gave the hacker a new, temporary
password, simply because the hacker provided the last 4 digits of mat
honan's credit card and his street address, which he obtained fairly
easily.

<http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/a
ll/1>
  At 4:33 p.m., according to Apple¹s tech support records, someone
  called AppleCare claiming to be me. Apple says the caller reported
  that he couldn¹t get into his .Me e-mail ‹ which, of course was my
  .Me e-mail.

  In response, Apple issued a temporary password. It did this despite
  the caller¹s inability to answer security questions I had set up. And
  it did this after the hacker supplied only two pieces of information
  that anyone with an internet connection and a phone can discover.

the hacker himself said,
  ³didnt guess ur password or use bruteforce. i have my own guide on
  how to secure emails.²

in response to this glaring security hole, both apple and amazon have
changed their policies and at least this particular hack can no longer
occur.

<http://www.wired.com/gadgetlab/2012/08/apple-icloud-password-freeze/all
/1>
  Apple on Tuesday ordered its support staff to immediately stop
  processing AppleID password changes requested over the phone,
  following the identity hacking of Wired reporter Mat Honan over the
  weekend, according to Apple employees.

[toc] | [prev] | [next] | [standalone]


#29183

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 04:29 +0000
Message-ID<slrnk23qpj.vfq.g.kreme@mbp55.local>
In reply to#29164
In message <jvsb5c$q33$3@dont-email.me> 
  Justin <justin@nobecauseihatespam.edu> wrote:
> On 8/7/12 12:31 AM, nospam wrote:
>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>> <justin@nobecauseihatespam.edu> wrote:
>>
>>>> Thought folks here would be interested in this article I saw on
>>>> Macintouch:
>>>>
>>>> Yes, I was hacked. Hard.
>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>
>>> Even Apple can't defend against lousy passwords.
>>
>> it wasn't a lousy password. in fact, his password made no difference
>> whatsoever.
>>
>> apple *gave* the hacker a new, temporary password.

> Wrong.

No.

> His original password was guessed,

No it wasn't.

> Didn't score very high on the reading comprehension part of the SAT, now 
> did you?

730. You?


-- 
'I really should talk to him, sir. He's had a near-death experience!'
'We all do. It's called living.'

[toc] | [prev] | [next] | [standalone]


#29189

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-08 01:14 -0400
Message-ID<jvsske$98u$3@dont-email.me>
In reply to#29183
On 8/8/12 12:29 AM, Lewis wrote:
> In message <jvsb5c$q33$3@dont-email.me>
>    Justin <justin@nobecauseihatespam.edu> wrote:
>> On 8/7/12 12:31 AM, nospam wrote:
>>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>>> <justin@nobecauseihatespam.edu> wrote:
>>>
>>>>> Thought folks here would be interested in this article I saw on
>>>>> Macintouch:
>>>>>
>>>>> Yes, I was hacked. Hard.
>>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>>
>>>> Even Apple can't defend against lousy passwords.
>>>
>>> it wasn't a lousy password. in fact, his password made no difference
>>> whatsoever.
>>>
>>> apple *gave* the hacker a new, temporary password.
>
>> Wrong.
>
> No.

Wrong.

>
>> His original password was guessed,
>
> No it wasn't.

Yes it was.

>
>> Didn't score very high on the reading comprehension part of the SAT, now
>> did you?
>
> 730. You?
>
>

799.

[toc] | [prev] | [next] | [standalone]


#29205

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-08 15:25 +0000
Message-ID<slrnk2517d.14pv.g.kreme@mbp55.local>
In reply to#29189
In message <jvsske$98u$3@dont-email.me> 
  Justin <justin@nobecauseihatespam.edu> wrote:
> On 8/8/12 12:29 AM, Lewis wrote:
>> In message <jvsb5c$q33$3@dont-email.me>
>>    Justin <justin@nobecauseihatespam.edu> wrote:
>>> On 8/7/12 12:31 AM, nospam wrote:
>>>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>>>> <justin@nobecauseihatespam.edu> wrote:
>>>>
>>>>>> Thought folks here would be interested in this article I saw on
>>>>>> Macintouch:
>>>>>>
>>>>>> Yes, I was hacked. Hard.
>>>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>>>
>>>>> Even Apple can't defend against lousy passwords.
>>>>
>>>> it wasn't a lousy password. in fact, his password made no difference
>>>> whatsoever.
>>>>
>>>> apple *gave* the hacker a new, temporary password.
>>
>>> Wrong.
>>
>> No.

> Wrong.

You've been told you are wrong by many people. Maybe you should go read
once again for comprehension this time. *NO* *PASSWORD* *WAS* *HACKED*.

Here is the URL again, since you seem to be too stupid to find it yourself.

<http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/>

>>> His original password was guessed,
>>
>> No it wasn't.

> Yes it was.

Sigh. No.

>>
>>> Didn't score very high on the reading comprehension part of the SAT, now
>>> did you?
>>
>> 730. You?

> 799.

HAHAHA. not only are you a liar, but you must have gotten a 200 on the math.

Fucking troll.

-- 
I collect blondes and bottles. ~Marlowe

[toc] | [prev] | [next] | [standalone]


#29232

FromJustin <justin@nobecauseihatespam.edu>
Date2012-08-09 02:57 -0400
Message-ID<jvvn0u$fn6$2@dont-email.me>
In reply to#29205
On 8/8/12 11:25 AM, Lewis wrote:
> In message <jvsske$98u$3@dont-email.me>
>    Justin <justin@nobecauseihatespam.edu> wrote:
>> On 8/8/12 12:29 AM, Lewis wrote:
>>> In message <jvsb5c$q33$3@dont-email.me>
>>>     Justin <justin@nobecauseihatespam.edu> wrote:
>>>> On 8/7/12 12:31 AM, nospam wrote:
>>>>> In article <jvq5co$6tm$4@dont-email.me>, Justin
>>>>> <justin@nobecauseihatespam.edu> wrote:
>>>>>
>>>>>>> Thought folks here would be interested in this article I saw on
>>>>>>> Macintouch:
>>>>>>>
>>>>>>> Yes, I was hacked. Hard.
>>>>>>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>
>>>>>>
>>>>>> Even Apple can't defend against lousy passwords.
>>>>>
>>>>> it wasn't a lousy password. in fact, his password made no difference
>>>>> whatsoever.
>>>>>
>>>>> apple *gave* the hacker a new, temporary password.
>>>
>>>> Wrong.
>>>
>>> No.
>
>> Wrong.
>
> You've been told you are wrong by many people. Maybe you should go read
> once again for comprehension this time. *NO* *PASSWORD* *WAS* *HACKED*.
>
> Here is the URL again, since you seem to be too stupid to find it yourself.
>
> <http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/>
>
>>>> His original password was guessed,
>>>
>>> No it wasn't.
>
>> Yes it was.
>
> Sigh. No.
>
>>>
>>>> Didn't score very high on the reading comprehension part of the SAT, now
>>>> did you?
>>>
>>> 730. You?
>
>> 799.
>
> HAHAHA. not only are you a liar, but you must have gotten a 200 on the math.
>
> Fucking troll.
>

Its not my fault you're wrong.

[toc] | [prev] | [next] | [standalone]


#29093

FromLewis <g.kreme@gmail.com.dontsendmecopies>
Date2012-08-07 04:49 +0000
Message-ID<slrnk217j8.17rs.g.kreme@mbp55.local>
In reply to#29084
In message <jvq5co$6tm$4@dont-email.me> 
  Justin <justin@nobecauseihatespam.edu> wrote:
> On 8/6/12 5:46 PM, Fred Moore wrote:
>> Thought folks here would be interested in this article I saw on
>> Macintouch:
>>
>> Yes, I was hacked. Hard.
>> <http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard>

> Even Apple can't defend against lousy passwords.

Please go read the link. His Apple password was not *hacked*, Apple reset it.


-- 
Suddenly the animals look shiny and new

[toc] | [prev] | [next] | [standalone]


#29117

FromJeff N <jeff+no.spam@jnadeau.com>
Date2012-08-07 00:01 -0700
Message-ID<2012080700010178635-jeffnospam@jnadeaucom>
In reply to#29056
Personally I find it prudent to not enable the otherwise-useful Remote 
Wipe feature unless I have a persistent backup of the machine. But 
that's just me.

(And yes, Remote Wipe is quite useful. Some companies require it on 
devices that carry sensitive data.)

I also think that "security questions" which consist of easily 
discoverable information (mother's maiden name, street you grew up on, 
city you were born in) are outstandingly stupid gatekeepers to a 
process for resetting my password. Never ever give honest answers to 
those.

-- 
Software Engineer
(My posts reflect my opinions, not my employer's)

[toc] | [prev] | [next] | [standalone]


#29121

FromBarry Margolin <barmar@alum.mit.edu>
Date2012-08-07 03:48 -0400
Message-ID<barmar-45B23A.03480107082012@news.eternal-september.org>
In reply to#29117
In article <2012080700010178635-jeffnospam@jnadeaucom>,
 Jeff N <jeff+no.spam@jnadeau.com> wrote:

> Personally I find it prudent to not enable the otherwise-useful Remote 
> Wipe feature unless I have a persistent backup of the machine. But 
> that's just me.
> 
> (And yes, Remote Wipe is quite useful. Some companies require it on 
> devices that carry sensitive data.)
> 
> I also think that "security questions" which consist of easily 
> discoverable information (mother's maiden name, street you grew up on, 
> city you were born in) are outstandingly stupid gatekeepers to a 
> process for resetting my password. Never ever give honest answers to 
> those.

That's common advice, but I think it's hard to expect most people to 
implement it. It's hard enough to remember the *honest* answers you give 
(e.g. name of first girlfrield -- did I put her full name or just her 
first name, and did I use the short kathy or the full kathleen?). And if 
you make up different answers to the same question on different sites, 
how are you supposed to remember which answer you gave where?

I know, put it in your Keychain.  But if you're going through a password 
recovery process, it often means you lost your keychain, or you're away 
from your computer. The point of questions like these is that they're an 
alternate method when the usual secret password system can't be used, so 
it doesn't make sense for them to be as hard to remember as the password 
itself.

-- 
Barry Margolin, barmar@alum.mit.edu
Arlington, MA
*** PLEASE post questions in newsgroups, not directly to me ***

[toc] | [prev] | [next] | [standalone]


#29147

FromPaul Sture <paul@sture.ch>
Date2012-08-07 20:49 +0200
Message-ID<7j48f9-7qh.ln1@news1.chingola.ch>
In reply to#29121
On Tue, 07 Aug 2012 03:48:01 -0400, Barry Margolin wrote:

> That's common advice, but I think it's hard to expect most people to
> implement it. It's hard enough to remember the *honest* answers you give
> (e.g. name of first girlfrield -- did I put her full name or just her
> first name, and did I use the short kathy or the full kathleen?). And if
> you make up different answers to the same question on different sites,
> how are you supposed to remember which answer you gave where?

Exactly.  I also came across one website which rejected answers as "too 
short" at 4 characters for pet name.  There goes Toby, Spot.

As the new outlook.com mail service has just proved, fields might be too 
short as well.  Folks are complaining that passwords are limited to 16 
characters.
 
> I know, put it in your Keychain.  But if you're going through a password
> recovery process, it often means you lost your keychain, or you're away
> from your computer. The point of questions like these is that they're an
> alternate method when the usual secret password system can't be used, so
> it doesn't make sense for them to be as hard to remember as the password
> itself.

Your computer could have died or be temporarily malfunctioning as well.

-- 
Paul Sture

[toc] | [prev] | [next] | [standalone]


#29151

Fromnospam <nospam@nospam.invalid>
Date2012-08-07 15:27 -0400
Message-ID<070820121527063876%nospam@nospam.invalid>
In reply to#29147
In article <7j48f9-7qh.ln1@news1.chingola.ch>, Paul Sture
<paul@sture.ch> wrote:

> > That's common advice, but I think it's hard to expect most people to
> > implement it. It's hard enough to remember the *honest* answers you give
> > (e.g. name of first girlfrield -- did I put her full name or just her
> > first name, and did I use the short kathy or the full kathleen?). And if
> > you make up different answers to the same question on different sites,
> > how are you supposed to remember which answer you gave where?
> 
> Exactly.  I also came across one website which rejected answers as "too 
> short" at 4 characters for pet name.  There goes Toby, Spot.

i had one that asked for what kind of car was your first car and like
your question, 4 characters was too short. so much for ford, bmw, mg
and quite a few other cars. 

however, it's a really good idea to use fake info. using real info is
how people get hacked. it happened to sarah palin and paris hilton.
there are people who know what your first car was. there are people who
know what your mother's maiden name is. some of it is public info and
not that hard to find out for someone sufficiently motivated.

[toc] | [prev] | [next] | [standalone]


Page 3 of 7 — ← Prev page 1 2 [3] 4 5 6 7  Next page →

Back to top | Article view | comp.sys.mac.system


csiph-web