HomeSecurityApple knew about the security flaw months before the naked iPhones were released...

Apple knew about the security flaw months before the naked photos were released!

ImageHandler.ashx

The problem was identified by Ibrahim Balik who informed the company's security that he found a way by which anyone can attack and hack iCloud accounts

Leaked emails show that Apple knew about the iCloud security flaws months before hundreds of naked celebrity photos stolen from their personal accounts were published on the Internet!

cloud1The e‑mails published by the Daily Dot newspaper show conversations between Ibrahim Balik, a security researcher based in London, and Apple employees, with Mr. Balik stating that he found a way that Apple’s iCloud service security breaks and thus if someone else discovers it it will be very easy to attack and hack accounts!

cloud2This method is based on the simple assumption that a large number of passwords used come from automated software. Although the exact method used in the theft of sensitive personal data of celebrities is unknown, security experts claim that this – among other things – was done by deceiving users who, to enter fake websites, had to give their passwords.

cloud4Mr. Balik sent the first e‑mail to Apple in March and talked with the company's security on May 6. Despite the fact that the full conversation has not been released to the public, Daily Dot reports that at this point «the security flaw apparently remained unresolved».

cloud3The e‑mail from Apple shows that the company was interested in learning more details about the issue: “Hello Ibrahim, using the information you shared, it appears that it will take an extremely long period of time to find a valid sample that an account’s identity was stolen. Do you think you have a method to gain access to an account in a reasonably short period of time?».

A similar security issue was also highlighted by the technology news website «The Next Web», after the publication of private photos of celebrities, including Jennifer Lawrence, Kate Upton and Ariana Grande. Initially Apple denied any involvement in the hack, but later acknowledged that its accounts had been put «at risk», claiming that the responsibility lies with user security practices rather than the company's encryption.

«In none of the cases that have been investigated has any breach been found in any of Apple's systems, including iCloud or Find My iPhone», the company said on September 1st. «We continue to cooperate with law enforcement agencies to help locate the criminals involved in the case», it emphasized.

The answer was criticized by technology experts who said that Apple had the duty to take care of its customers, and that technology companies in general should not assume that the average user is aware of security and knows how to achieve it.

 

Source: protothema.gr

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS