While Apple has denied that its iCloud for the leak of nude celebrity photos last week, Wired reports that the attackers used a commercially available tool to take backups of iCloud accounts.
The author of the article, Andy Greenberg, has spent a lot of time researching a forum (Anon-IB) about the techniques hackers use to gain access to personal photos. One such tool is the Elcomsoft Phone Password Breaker (EPPB) app. Elcomsoft describes its software as “ideal for law enforcement and intelligence agencies,” but it seems to be very popular among hackers trying to steal other people’s data. While attackers would still have to obtain account credentials through other methods, the EPPB app advertises a password-bypassing access feature using an authentication token from a synced PC or Mac.
The technique is not new.
There are several hypotheses about the technique used by the hackers. Of course, the technique is known only to the person who used it and perhaps the investigation that will be carried out by Apple technicians and the authorities who have undertaken to clarify the case will reveal it. We may never know, as Apple avoids such announcements. Usually we learn about the vulnerabilities that allowed a breach from the attackers themselves and not from the company.
In this attack, however, the hacker or hackers have preferred to keep their mouths shut.
