5 ms·
Make sure to read the actual details from David Schuetz's – @DarthNull – blog post (the dude who did the digging): http://intrepidusgroup.com/insight/2012/09/t
by hrbrmstr 14y ago
Make sure to read the actual details from David Schuetz's – @DarthNull – blog post (the dude who did the digging):
http://intrepidusgroup.com/insight/2012/09/tracking-udid-src/ http://intrepidusgroup.com/insight/2012/09/tracking-udid-src...
- j_s 14y agoIncredible contrast to the following: Another theory on the “FBI” UDID leak http://news.ycombinator.com/item?id=4484547 http://news.ycombinator.com/item?id=4484547 http://www.marco.org/2012/09/06/udid-theory http://www.marco.org/2012/09/06/udid-theory
- brittohalloran 14y agoWow -- great read
- brittohalloran 14y ago... and the BlueToad blog post. Nothing of substance, mostly just a "sorry" and "we've fixed it". http://blog.bluetoad.com/2012/09/10/statement-from-bluetoad-regarding-the-cyber-attack-suffered-in-the-recent-case-of-stolen-apple-udids/ http://blog.bluetoad.com/2012/09/10/statement-from-bluetoad-...
- rhizome 14y agoGood to see they don't forget the obligatory, "we take information security very seriously," line.
- jeremyarussell 14y agoThey always seem to say that in retrospect, even though the evidence shows they obviously don't take their security very seriously. Otherwise, they wouldn't of had such a leak.
- mikehotel 14y agoI wish they also said they were not collecting "other personal data as, full names, cell numbers, addresses, zipcodes", which the pastebin posters claimed was in the original file. Unfortunately, BlueToad's statement leaves some wiggle room. "BlueToad does not collect, nor have we ever collected, highly sensitive personal information like credit cards, social security numbers or medical information. The illegally obtained information primarily consisted of Apple device names and UDIDs – information that was reported and stored pursuant to commercial industry development practices." Edit: The "98% correlation" leads me to believe the publicly posted info is the full extent of the leak.
- Dylan16807 14y agoWhy? If 98% of the posted UDIDs are in their database then I could see them say "98% correlation"
- incision 14y agoNice story. It's a reminder how powerful the combination of simple tools and a little reasoning can be. I once found myself by chance with a customer just as they got smacked with a DDoS attack that they were completely unprepared for. The security folks threw up their hands claiming that they couldn't do anything to stop the attack due to certain random elements. The executives panicked and everyone started pointing fingers while their site went offline. It was chaos. I asked to have a look at logs on a hunch that the "random" element wasn't entirely random. One line of awk, grep and uniq later it was revealed that roughly 85% of the attack could be mitigated with a trivial change at the edge.
- darkarmani 14y agoAh, exploratory data analysis to the rescue! Those "experts" can only use confirmatory tools.
- drivingmenuts 14y agoNice sneer, there. High horse much? I'm not an expert in all the areas I'm expected to cover by any means. Some days, it's all I can do to not say "act of God, maybe?" I try to learn new things when I am afforded the time, but since we don't live in a CSI world, it's just not possible to always have the right tools, the right knowledge or the right answer at all times, especially when it comes to computer security. Bruce Schneier ain't cheap and not everyone can afford the services of specialists when it isn't a common occurence.
- darkarmani 14y agoI'm sorry you were personally insulted. Were you one of the people involved in that incident?
- ltp 14y agoAfter reading through that blog post it seems that David himself still has some serious doubts as to whether Bluetoad was the source of the breach. Reading through his analysis, it almost seems that he may have fallen victim to log file pareidolia as he doesn't make it clear how a device named "Hutch" or one named "Paul’s gift to Brad" a anything more than coincidences in a very large data set. Doing some quick analysis of the file shows that there is a UDID that has the alternate names; "Hutch Hicken" (Bluetoad CTO), "Bluetoad Support" and "Customer Service iPad" among others, but could this also be representative of an older iPad that has been a pass-me down through the company? Somewhat more interesting and possibly more revealing are the UDIDs 'ffffffffffffffffffffffffffffffffffffffff' (occurring three times) and the small number of records not conforming to the field size and format of other records (UDIDs > 42 characters, no APNS, device/iOS version number as fourth field). For anyone interested the following ugly and slow one-liner will print out a summary of non-unique UDIDs along with their APNS and names. perl -F, -lane '$a{$F[0]}{$F[1]}=$F[2]; END { foreach $k (keys %a) {next unless ~~ keys %{$a{$k}} > 2; print "\nUDID : $k"; foreach $d (keys %{$a{$k}}){print "\t-> $d : $a{$k}{$d}"} } }' data
- maxerickson 14y agoMy reading is that a single device appeared four times in the logs, twice named "Hutch" and twice named "Paul's gift to Brad". If that is the case, it would be a pretty striking coincidence for it to be someone else.