Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

iCloud is trivial to hack. Recall the massive leak of celebrity nudes a few years back. As long as iCloud is forced on users (you cannot apply security updates to an apple device without an Apple ID and an attached iCloud account) these attacks will be simple to do in mass, with very little risk to the perpetrators. Terrible security model, with a long history of spectacular and avoidable breaches which go totally unsolved.


Let’s ignore the fact that you just shifted the goalposts from “emailing a 1 pixel image SWATs them” to an extremely wide scope for a minute -

Even assuming that is true that iCloud is trivially “hackable” - and as I understand it, that was never clear how those leaks happened - how does uploading to iCloud help when it specifically needs to be uploaded from the users phone along with the scanning metadata.

In fact, isn’t apples proposed implementation here the _only_ cloud service that protects against your proposed attack - while other clouds scan stored data and can be triggered by your attack, Apple’s requires you to upload specifically from a registered phone on their account; data stored on-cloud is never scanned.


You can choose to use an iPhone. Most people will never be targeted. Hell you could use a phone with no security at all and odds are you’ll be safe. But if you have enemies or are a high profile target, apple has made you easy to destroy. iPhones themselves can be hacked with no click attacks and we know this because macron’s phone was one of many that was listed in the recent fiasco. Icloud can be hacked because legions of celebrities had their nudes published. If the device is not secure, even for the president of France, and iCloud is not secure for legions if celebrities, then people can and will be hit with this attack and have their lives permanently destroyed. Worse than having you sex photos leaked, worse than having all you calls and communications intercepted, you’ll become known as a pedo. You can’t undo that. To be sure, that probably won’t happen to most people, but political figures, those with enemies working in infosec, etc…. I want a secure phone, and iPhone no longer meets that need for me and many others. You can do you.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: