Tuesday, September 4, 2012

12 million iOS unique device identifiers (UDID) hacked from FBI laptop

Over 12 million unique device identifiers (UDID), and related, personally-identifiable information, for iPhones, iPod touches, and iPads have reportedly been hacked from an FBI laptop using a Java vulnerability. AntiSec has released 1 million of the UDIDs as proof of the hack. They've also released the following about the hack itself:

During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of "NCFTA_iOS_devices_intel.csv" turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose.

UDIDs are used by developers to register devices with Apple's iTunes Connect so they can run beta versions of iOS and test ad-hoc versions of their apps prior to release. While some developers also used to use them to identify users and their devices, Apple has now disallowed that practice.

Any single piece of identifying information, be it a UDID number or a cell phone number, when combined with a sufficiently large pool of data and the right kind of analytics, can be used to create profiles and assess patterns.

AntiSec says they released the information to draw attention to the FBI's collection of it.

Source: AntiSec



Source: http://feedproxy.google.com/~r/TheIphoneBlog/~3/yZpaTmeIiks/story01.htm

sweet home alabama etch a sketch the host hoodie hoosiers temperance world bank

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.