How icloud was hacked

Galdorf

Well-Known Member
Reaction score
502
Location
Ontario, Canada
According to Alexei Troshichev a Russian internet security analyst:

"I started to research different login interfaces. iCloud and iTunes were protected. FindMyiPhone was not ... all together it took about two hours to find the bug. It was a trivial task,"

The glitch identified by Mr Troshichev makes iCloud vulnerable to iBrute, a form of hacker attack that exploits the possibility of an unlimited number of login attempts to eventually give access to accounts with predictable passwords.

Apple fixed the problem with the FindMyiPhone app, which allows remote tracking of Apple devices, on Monday shortly after the nude celebrity photos began spreading online.
 
Apple says it was social engineering tricks that got people access to the accounts:

http://money.cnn.com/2014/09/01/technology/celebrity-nude-photos/index.html

What's talked about in the article is not a social engineering trick. it's just plain old taking advantage of software designers refusal to learn from their mistakes.

These articles always end with the same statements, use two-factor authentication.

Or my favorite;

Passphrases are especially strong passwords, particularly ones that are easy to remember but are long and hard to guess (example: "1 Day I ate 364 bananas & 13 cherry Pies!!!").

Does anyone know of any site that always that many characters is a password or one that even allow spaces to be used?

User names are limited to x number of characters or even worse, your email address and passwords are required to have 1 capital letter, 1 lower case, 1 special and 1 number at a minimum and to be between 6 and x numbers of characters.

What's the worst is ATM's pin number can only now be a maximum of 4 digits. In the old days I could have up to 12 digits .
 
Last edited:
Back
Top