13 ms·
> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords > He gained un
by codeecan 5y ago
> he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords
> He gained unauthorized access to photos and videos of at least 306 victims across the nation
> Investigators soon discovered that a log-in to the victim’s iCloud account had come from an internet address at Chi’s house
Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools.
- eli 5y agoThis is a failure of the software community, not the users. I don’t think it’s reasonable to ask users to detect a halfway decent phishing attempt.
- SevenSigs 5y ago> but we really need to teach basic internet security in schools. I think you need to do that for people that are no longer in school... because most young people probably know not to give out their passwords
- glitcher 5y agoI agree that better education around Internet security is needed, especially for basic phishing attacks like this. OTOH, I believe Apple could be doing more to deter and/or detect this type of broad access, especially with the lack of sophistication behind this scheme! I feel like even Netflix does a better job at alerting me to access from a new device, and they aren't storing any of my personal photos.
- arsome 5y agoYeah, Netflix is actually annoying with it - I was using my "ultra low security" password which is in... probably every public password dump around for years, got dozens of logins, just ignored them til someone finally tried to change it and I had to reset it.
- shuckles 5y agoIf you have two factor enabled, which is required for many iCloud features, every single Apple device you own will receive an alert with the location of login before you can reveal the 2FA code, even for iCloud logins. What more would you like to see?
- not2b 5y agoThey would just get an email saying that icloudbackupsupport@gmail.com (his phony address) accessed the account immediately after giving their info to icloudbackupsupport@gmail.com. He could even have told them to expect and ignore such an email.
- rootusrootus 5y agoThere should be a request for approving the login attempt, and if you say yes, you get a six digit code to enter on the device trying to connect. Then when that succeeds, you get another push notification about it succeeding.
- anaganisk 5y agoAnd thats what happens on any iOS with 2FA enabled.
- makecheck 5y agoIt’s better than nothing but still not great because the login area they present is too broad. For example, if you live in a large city and the phisher is somebody you know, seeing “New login from Your City” is not going to make you think twice.
- gowld 5y agoIf you refuse to think, even when prompted, that's on you. You should think about whether you logged in from the city and device/OS named in the alert.
- glitcher 5y ago
- ryandrake 5y agoNot just better education around security practices, but better understanding around control of your content, where it's stored, what happens to content when you press that button in an app. I don't want to victim blame here, and this guy is a total creep, but the victims uploaded their nudes to the Internet. At that point, the cat was out of the bag. Part safely using the Internet is having the knowledge and being aware of where (in your apps) the boundary is between your local device and the global network that everyone has access to. People need to understand: When you sync to a cloud service, you're sending your content to someone's computer unknown to you. Yes, in this case, it's Apple's computer, but that didn't stop this guy. Once you sync something online, it's out of your hands, and on the Internet now. I personally treat all cloud services as if they were accessible publicly and anonymously, and will inevitably be printed in my local newspaper, and only upload content to those services where I am comfortable with that level of exposure. EDIT: To clarify, I wish applications would stop blurring the line between "on my device" and "on the Internet". I've used applications where, to an unsophisticated user, the save dialog looks like it's saving to their computer but it's actually in the cloud. Add to it all these apps that try to be helpful by seamlessly (and invisibly) keeping local content in sync with the cloud versions and you have a recipe for disasters like this. Have an explicit "upload this thing to the Internet" button, please!
- Tabular-Iceberg 5y agoIt boggles my mind that people have nudes of themselves on any digital medium. I say if you want to dabble in that, get a film camera and develop the pictures in your own basement.
- LinuxBender 5y agoOr get a non-wifi digital camera and manage your photos on a non cloudy computer. Maybe even take it a step further and use tools to remove EXIF data that has your camera's serial number and other metadata in the images. Photos taken from cell phones often give away GPS coordinates.
- TheCraiggers 5y ago> Not very sophisticated, but very effective, glad they shut him down but we really need to teach basic internet security in schools. They could start by following basic security. My kid's school sets everyone's passwords to various forms of "temp123" (same password for every kid) and often talks about them in cleartext. It sets a very bad example, and it occasionally gives me hives just thinking about it.
- throenabout 5y agoA friend worked at a UK government site that one week complained about an increase in "Russian" attempted intrusions and literally the next week issued an instruction in an unsigned email to all staff to change their password to a new password given in plaintext in the email. The instruction, they thought, had to be a poor phishing attempt - but no, it was a genuine email from the IT department and the friend was punished (!!) for questioning the instruction and not immediately complying. It may not have been the same password across the organisation but their's was reportedly word based and quite short.
- pier25 5y agoI worked at an ed tech company that provided services for schools and this was very common in my experience. Schools wanted to store the students' passwords in clear text in an excel basically to get less complaints from parents. Students didn't store their password after logging in. If they needed to log in again they did not know (or did not care) how to reset their passwords. Then the problem would fall unto the parents which would then complain to the school.
- pbhjpbhj 5y agoI can't believe Facebook haven't stopped the "your mother's maiden name and your first pets name is your pornstar name, post yours below" posts on Facebook. These companies clearly don't care their platforms are used to enable scammers so long as they're getting their cut of the money.
- legohead 5y agoSo all he needed do to avoid being caught was use a VPN?
- pier25 5y agoSeems so naive that you'd do such a thing from your home without any type of security like a VPN. The guy probably was the only one in the group doing this and was led to believe by the others that it was completely safe.