4 ms·
Find out if your iphone UDID was compromised
- dfc 14y ago"The service checks to see if the hashed value exists and then lets you know if your udid is among the ones compromised. Only hashed values are stored in the service, not any of the raw udid values." So all the site owner has to do is hash the udids to know who you are?
- afitnerd 14y agoThe udids have already all been hashed. It is the hashed values only that are stored on the site. The only piece of information sent to the site is a hashed udid (the udid is hashed on the browser before any information is sent over the wire).
- dfc 14y agoI realize that. But all the site owner has to do is keep a list of the UDID->hash mapping and then he can lookup the original UDID...
- afitnerd 14y agoI think you may be missing the point. I already have all of the 1,000,001 original UDIDs posted by AntiSec. I don't need to go through all that hassle you describe. I wrote the script that generated the hashes from the original UDIDs. The point is that in order to stop people from passing their UDIDs around the net they way some other checking services have made them do, this service does not have any of the original UDID's on local storage. Even if my site is compromised, it will not further the spread of UDID information. Of course, you do have to trust that what I am saying is the truth. Anyone can choose NOT to submit their (hashed) UDID to my site.
- dfc 14y agoI may be missing the point. I am not trying to be difficult, I promise. What is the difference between me sending you my UDID and me sending you my hashed UDID?
- afitnerd 14y agoThe difference is that if my site is compromised or if someone is listening in on the network traffic, no one will be able to take the database of hashed UDIDs and get the original UDIDs.
- afitnerd 14y agoThe difference is that if my site is compromised or if someone is listening in on the network traffic, no one will be able to take the database of hashed UDIDs and get the original UDIDs.
- dfc 14y agoThe original UDIDs are already published. The cat is out of the bag. From what I can see the only difference is that you don't know the submitters UDID if they were not on the published list. FYI: you can get around the no reply box "feature" by clicking "link."
- afitnerd 14y agoprecisely. The cat is already out of the bag. But, my site will not be a vector of "infection" in spreading the existing information or any new information.
- retrogradeorbit 14y agoIf your UDID tests negative, you still could be compromised. The original FBI file had 12 million. AntiSec released 1 million. This linked testing site says 20 million, which is wrong, as far as I know.
- afitnerd 14y agoThanks for info. I've updated the information on the page.