Showing posts with label Privacy. Show all posts
Showing posts with label Privacy. Show all posts

Wednesday, 19 January 2011

Hacker pair involved in 2010 iPad 3G AT&T data breach arrested by the FBI

On Tuesday morning, two members of the group Goatse Security, who hacked into AT&T's customer database last year and delivered close to 120,000 e-mail addresses of iPad 3G owners to Gawker, were arrested by the FBI. The pair, Daniel Spitler, 25, and Andrew Auernheimer, 26, used a "brute force" attack and an AT&T security hole to gather the email addresses.

The pair used the fact that iPad 3G's SIM has an ICC-ID, a 19-digit code that AT&T associated with a user's account and email address. AT&T used the ICC-ID to pre-populate a field containing the owner's email address when the user needed to login and check account status. By attempting ICC-IDs until they got a "hit," the pair was able to gather the email addresses.

AT&T was supremely embarrassed by the incident. Among the notables outed when the story first broke were luminaries such as New York City Mayor Michael Bloomberg, ABC News' Diane Sawyer, movie titan Harvey Weinstein and New York Times Co. CEO Janet Robinson.

In a statement, U.S. Attorney Paul Fishman in New Jersey said:
"Hacking is not a competitive sport, and security breaches are not a game. Companies that are hacked can suffer significant losses, and their customers made vulnerable to other crimes, privacy violations and unwanted contact."
Each of the two was each charged with one count of fraud and one count of conspiracy to access a computer without authorization. Each of those charges carries a maximum punishment of five years in prison plus a $250,000 fine.

Although Goatse Security notified AT&T of the breach after harvesting the data, the U.S. Attorney's statement noted that in chats, it was made clear that the group wasn't doing this to be altruistic. Instead, Fishman said,
"Those chats not only demonstrate that Spitler and Auernheimer were responsible for the data breach, but also that they conducted the breach to simultaneously damage AT&T and promote themselves and Goatse Security."
Last year, Auernheimer was arrested on drug charges. Authorities were actually searching his home for evidence related to the AT&T - iPad investigation.  Auernheimer is pictured above in a booking photo from that arrest.

Monday, 17 January 2011

Facebook profile info used to hack into women's email accounts

People who wonder if perhaps some people give out too much information via social networking sites such as Facebook can look to this story and see the answer is at least sometimes "yes." George Samuel Bronk, 23, used profile information from Facebook to hack into women's e-mail accounts, steal nude images of them, and even blackmail them.

Bronk used an obvious, but clever method to hack into the women's accounts: since Webmail accounts have password recovery schemes that could be bypassed using information from Facebook profiles, such as favorite foods, high-school mascots, favorite colors, and so on, once he obtained that information, he would try to hack into an account. If he did, he would then change the password, locking out the original user, and that was just the beginning.

Bronk would then scan each women's "Sent Message" folder, looking for any nude pictures or videos. If he found any, sometimes he'd pictures to the women's entire contact list, just for fun. On other times, he'd blackmail the woman directly, telling them he'd publish the pictures unless he received more nude pictures from them. One victim called it "virtual rape." He would sometimes even double-dip, emailing Facebook using the stolen account to get the password, then using that account for mischief.

Late last week, Bronk pleaded guilty in Sacramento Superior Court to seven felony charges, including computer intrusion, impersonation and possession of child pornography. He faces up to six years in prison, and will return in March for sentencing.

Reportedly, he hacked into hundreds of accounts, with the women spread across 17 states and even in England.

This is obviously a cautionary tale. While it's probably not going to stop women from sending nude photos to their beaus (which might be a good idea), many Webmail sites allow custom password recover questions. If a user created their own custom question, one which they don't post to their Facebook profile, they wouldn't see this problem happen.

It's also possible to use standard questions if you either don't post the answer to a social networking site, or muck with the answer with a faux response. At any rate, it's just another example of why you shouldn't share "everything" on the Internet.