Started By
Message

re: Apple denies iCloud breach for The Fappening

Posted on 9/2/14 at 2:04 pm to
Posted by gmrkr5
NC
Member since Jul 2009
14904 posts
Posted on 9/2/14 at 2:04 pm to
quote:

It's still unclear whether the lockout bug had anything to do with it.


you cant brute force an account that does not suffer from a "lockout bug" unless you are a REALLY good guesser

quote:

a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.


i mean they are basically describing the components of a brute force attack right here^^^

you social engineer your way into finding the correct answers to the security questions then you have the ID. once you have the ID you brute force the account effected by the "lockout bug"
This post was edited on 9/2/14 at 2:06 pm
Posted by Spock's Eyebrow
Member since May 2012
12300 posts
Posted on 9/2/14 at 2:31 pm to
quote:

you cant brute force an account that does not suffer from a "lockout bug" unless you are a REALLY good guesser


True, and that gets down to what the meaning of "breach" is. Getting in due to the lockout vulnerability is a breach in my book, and I would hope Apple thinks the same way and isn't drawing such a fine technical distinction between "breach" and "targetted attack". I think it's going to come out if it's the lockout vulnerability, and they'll look like real weasels for not owning up in this statement. If the lockout vulnerability wasn't responsible, they should've explicitly said so, explain they log login attempts and saw no such activity, etc.

JLaw and the rest should reveal their passwords. Random ones probably could not have been brute-forced given Internet latency and the minimum requirements, which I read yesterday are 8 characters, upper and lower case, and digits.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram