Page 1 of 1

Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Wed Jun 09, 2010 8:10 pm
by Sabre
Article
Apple's Worst Security Breach: 114,000 iPad Owners Exposed
Goatse Security obtained its data through a script on AT&T's website, accessible to anyone on the internet. When provided with an ICC-ID as part of an HTTP request, the script would return the associated email address, in what was apparently intended to be an AJAX-style response within a Web application. The security researchers were able to guess a large swath of ICC-IDs by looking at known iPad 3G ICC-IDs, some of which are shown in pictures posted by gadget enthusiasts to Flickr and other internet sites, and which can also be obtained through friendly associates who own iPads and are willing to share their information, available within the iPad "Settings" application.

To make AT&T's servers respond, the security group merely had to send an iPad-style "User agent" header in their Web request. Such header identify users' browser types to websites.
Ouch

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Wed Jun 09, 2010 8:43 pm
by scheherazade
Goatse

LOL

-scheherazade

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Wed Jun 09, 2010 9:02 pm
by Mr Kleen
Image

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Wed Jun 09, 2010 9:29 pm
by chicken n waffles
:rolllaugh:

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Wed Jun 09, 2010 11:29 pm
by Sabre
scheherazade wrote:Goatse
LOL
haha, I thought the same thing!

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Thu Jun 10, 2010 1:41 pm
by complacent
I'm trying to figure out why this is being called "Apple's" worst breach.

The entirety of the hack was on AT&T, correct?

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Thu Jun 10, 2010 3:42 pm
by chicken n waffles
^ that's what i gather from the info i've read. apple had no part in this snafu at all.

Re: Massive AT&T Breach Exposes A-Listers' iPad Data

Posted: Thu Jun 10, 2010 10:07 pm
by Mr Kleen
chicken n waffles wrote:^ that's what i gather from the info i've read. apple had no part in this snafu at all.
except for picking AT&T as their dance partner. :lol: