Slashdot Mirror


Has iTunes Been Hacked?

An anonymous reader writes "Betanews has a series of articles talking about an apparent hack in iTunes that has resulted in fraudulent charges for some users involving Sega's Kingdom Conquest game. The reports start with a personal account from reporter Ed Oswald, who was a victim of the hack itself. The next story adds reports from readers, and the most recent story adds additional reports, with Oswald saying the number of reports received are in the 'dozens.' Apple has yet to confirm the existence of a hack, although reports have appeared on Sega's own support forums, Apple discussion boards, and through other news outlets."

35 of 191 comments (clear)

  1. Reminds Me of Something the Sony CEO Said ... by eldavojohn · · Score: 3, Interesting
    I recall Stringer saying a lot of stupid crap but when criticized for the delay in his notification of a breach he said something quite memorable to me:

    "This was an unprecedented situation," he said. "Most of these breaches go unreported by companies."

    At first I thought this was just to spread generalized fear, take a cheap swipe at their competition or even shift attention to something else, but it appears we'll get to see how pervasive this becomes. Perhaps he wasn't completely full of lies ...

    --
    My work here is dung.
    1. Re:Reminds Me of Something the Sony CEO Said ... by obarthelemy · · Score: 5, Funny

      can't be: there are no viruses on Apple. Go ask your local Genius !

      --
      The Cloud - because you don't care if your apps and data are up in the air.
    2. Re:Reminds Me of Something the Sony CEO Said ... by Sprouticus · · Score: 4, Interesting

      Half a dozen years ago, I worked at a company that got hacked due to a web vulnerability. The hackers simply used our storage to store geman porn. But it was still a hack. And it went unreported. It was detemrined that there was no value in reporting the hack since it would affect stock value.

      I am betting that the VAST majority of hack never get reported for this exact reason.

    3. Re:Reminds Me of Something the Sony CEO Said ... by wvmarle · · Score: 4, Interesting

      So you closed the vulnerability and kept the stash?

    4. Re:Reminds Me of Something the Sony CEO Said ... by rAiNsT0rm · · Score: 4, Insightful

      I've worked in IT security for a long time and for banks... The sheer number of unreported hacks at banks and at retail stores would blow your mind. People mistakenly get angry at the hackers (which is how the media has trained most everyone to think) when in reality it is almost always gross negligence on the hack-ee side and they deserve the ire.

      --
      http://teasphere.wordpress.com - A little spot of tea
    5. Re:Reminds Me of Something the Sony CEO Said ... by DurendalMac · · Score: 2

      "Dozens" of reports doesn't mean that much. It could have easily been a phishing attack or someone getting ahold of a different online account from said user and they happened to use the same password.

      Someone getting access to your account is NOT necessarily a "breach".

    6. Re:Reminds Me of Something the Sony CEO Said ... by StikyPad · · Score: 3, Insightful

      Or, quite possibly, we're starting to see the impact of the Sony hacks themselves. I'd bet money that the affected people were using the same login information on each service, especially since both services use the same "username": the player's e-mail address. If you're not using unique passwords for each of your services (and especially the for the e-mail account that unifies them all), you're doing it wrong.

    7. Re:Reminds Me of Something the Sony CEO Said ... by Ixokai · · Score: 3, Interesting

      Seriously, "mistakenly", "trained"?

      Sorry, no.

      Sure, the companies deserve ire and disdain if they don't take care of our information securely. They even deserve some real civil liability -- a lot more then they're getting now.

      But asshat little fuckheads who go around breaking into said company deserve ire, irregardless of any other ire given.

      Cracking into networks and systems and grabbing data, damaging systems, anything of the sort-- even if they aren't properly secured-- is not noble.

      It its worthy of ire, scorn, and jail time.

      Now, its not worth as much jail time as is being handed out often these days, nor silly, inflammatory words like "terrorism" being thrown around to make it all worse -- and adolescents who are frankly incapable of understanding that being an idiot even though its a rush or fun is dangerous and has real consequences, should be treated like the kids they are, not adults.

      But, no. Its not a mistake to give them all kinds of ire.

      I pretty much hate Sony, for instance. But what the cracker-jackass groups are doing is pretty sociopathic.

      There's no Greater Good involved, thats self-delusion at best. There could have been a way to go about it that may have been ethical, in a vigilante, internet-patriot sort of way. But these data dumps of real, personal information (including usernames and password hashes) is not at all it.

    8. Re:Reminds Me of Something the Sony CEO Said ... by pipedwho · · Score: 5, Funny

      So you closed the vulnerability and kept the stash?

      Close the vulnerability? Don't be daft man! That sounds like the kind of automatic update that is best left enabled.

    9. Re:Reminds Me of Something the Sony CEO Said ... by MobileTatsu-NJG · · Score: 2

      No, he accepted more porn as payment for their services.

      --

      "I like to lick butts!" by MobileTatsu-NJG (#32700246) (Score:5, Informative)

    10. Re:Reminds Me of Something the Sony CEO Said ... by baldass_newbie · · Score: 4, Insightful

      irregardless of any other ire given

      Irregardless is not a word. You may have a point, but your use of a non-word makes me wonder.

      --
      The opposite of progress is congress
    11. Re:Reminds Me of Something the Sony CEO Said ... by gmhowell · · Score: 4, Funny

      However Apple's users are certainly prone to social engineering.

      Of course I'm prone to social engineering. Why else would I have an iMac. And a MacBook. Two iPods. One iPhone (and two iPods and an iPhone for my kid.)
       

      --
      Jesus was all right but his disciples were thick and ordinary. -John Lennon
    12. Re:Reminds Me of Something the Sony CEO Said ... by grouchomarxist · · Score: 2

      Apparently this word goes back to at least 1874 http://dictionary.reference.com/browse/Irregardless

    13. Re:Reminds Me of Something the Sony CEO Said ... by pandrijeczko · · Score: 4, Interesting

      Also about half a dozen years ago, a CEO in a software company was suffering one way transmission on VoIP calls and as the manufacturer of the VoIP hardware and software, we'd had technicians trying to fix the problem for months - countless hardware was changed, IP stations, etc. etc. because the customer was screaming at my company daily and it had been escalated to the highest levels.

      As a security & network guy, I got dragged in at the later stages, myself and another consultant went through some packet sniff captures when the problem was happening and we eventually worked out that someone from within the software company was trying to do a man-in-the-middle attack to snoop on the CEO's calls, he/she clearly hadn't got it working right and was interrupting one of the transmission paths, hence the problem.

      We emailed the analysis to the customer and showed it was someone in their company causing the problem. From that point on, it went completely quiet - no daily secreaming from the customer, not even an acknowledgement of our emailed analysis.

      I don't know if higher up in my company we billed the customer for all the work we did or if anything was said afterwards but this was definitely hushed very quickly within that software company.

      --
      Gentoo Linux - another day, another USE flag.
    14. Re:Reminds Me of Something the Sony CEO Said ... by pandrijeczko · · Score: 2

      I work in security on Linux-based VoIP telephony systems for the manufacturer of those systems.

      About two years ago, I was contacted by one of our global customers, a big name in the airline industry, because of their Eastern European call centres had suffered toll fraud and they needed an analysis of the cause and additional hardening put on the servers if it was necessary - that in itself was nothing unusual, I do this kind of the stuff all of the time.

      But the interesting part of it was that the request for my services came directly from management people in that call centre and as I started planning what I was going to do and how I was going to do it, it became clear it was a cover-up in that I was being asked to work very discreetly so as not to alert that airline company's head office - in other words, the call centre management were covering up the toll fraud, presumably because they themselves had left security holes on the system when administering them, even from their own head office.

      From my perspective, because the airline company is a global customer of ours, this was a definite conflict of interest - so I stopped planning it there and then and handed it off to our global account manager for the airline company to go and sort out.

      --
      Gentoo Linux - another day, another USE flag.
  2. Most likely not a "hack" by adversus · · Score: 3, Insightful

    More like identity theft.

    1. Re:Most likely not a "hack" by EastCoastSurfer · · Score: 4, Interesting

      Yep. My bank recently called and canceled my CC. The trigger? The number was attempted to be used for a small ITMS purchase. The fraud department at the bank said that buying a 99c song at ITMS is quick way to verify if they have the right info or not. In my case they used the incorrect pin digits from the back of the card and the bank denied the charge, but it must work some of the time.

    2. Re:Most likely not a "hack" by mikael_j · · Score: 4, Informative

      In my case they used the incorrect pin digits from the back of the card and the bank denied the charge, but it must work some of the time.

      Sorry for being pedantic but the card security code (also known as CSC, CVV, CVV2, etc.) is not a PIN code.

      The PIN for Mastercard or VISA cards is a code you as the user must remember, here in Europe it is used pretty much every time you use your card instead of a signature.

      --
      Greylisting is to SMTP as NAT is to IPv4
  3. Re:lol by Divebus · · Score: 2

    Nobody ever hacked my cassette deck.

    --

    Most of the stuff on /. won't survive first contact with facts.
  4. Billing glitch? by Bieeanda · · Score: 3

    People being overcharged because the accounting software fucked up happens all the time. What would a hacker get out of making someone pay a few extra bucks to Sega, via Apple, compared to both dodging an accusation of faulty billing software that could sour people on microtransactions?

  5. trash, no mention of phishing or trojans by blueworm · · Score: 3, Interesting

    No mention of keylogging trojans or phishing combined with ridiculous uneducated guessing makes these authors' ramblings pure trash. Apparently all the links are from Betanews, too; I'd like to see Betanews stick to talking about iThings and not security. Choice quotes interspersed with my reactions:

    "Apple's iTunes user logs themselves may have been compromised."

    All I can think of on this one is the time I had someone tell me that my router had "lost its ARP table".

    "... several of the victims that reported into Betanews on their experience are employed in IT -- obviously understanding the risks of improperly secured personal data."

    I'd hope these same IT employees someday understand the risks of improperly secured personal data by not browsing the web on their own PCs (no Windows implied).

  6. Re:Very unlikely that iTunes was hacked... by scdeimos · · Score: 2

    Also there would a variety of purchases, not just for one game.

    It's not just for one game...

    Since Betanews' original report last Wednesday, dozens of readers have e-mailed their own reports of account issues, most dealing with Sega's Kingdom Conquest.

    Additionally...

    Nearly every victim had a gift card balance on their account, and some have reported that their credit card and/or payment information had been removed from their account. This indicates that Apple likely is aware of the attacks, and is actively trying to protect its users.

    In all cases, whether they're admitting the hack is occurring or not, users are having little trouble getting their money refunded to them.

  7. Hacking? Easier answers... by Jason+Pollock · · Score: 3, Insightful

    Considering we've seen a story about how everyone is using the same password everywhere, and how Sony got hacked again , exposing even more passwords, is it any surprise that a number of people are having their iTunes and PayPal accounts attacked and drained to buy game gold?

    iTunes and PayPal are pretty huge targets, but who'd attack a single game if they had access to the back end?

  8. Re:Very unlikely that iTunes was hacked... by wvmarle · · Score: 4, Interesting

    This is what bugged me about general security advice: people are recommended not to re-use passwords over a variety of web sites (sensible). However the solutions proposed are to store these passwords in a local "password vault" protected with just a single password, or for all sites to use a centralised log-in system such as Google or OpenID or whatever.

    Now if really those web masters all follow suit and all switch to doing their logins using Google: is that any safer than re-using a password? If Google gets hacked, logins to all web sites are suddenly on the streets. Google's security may be better than Sony's, that's not said that it can not be breached.

    Or if a keylogger finds its way on your computer, then the complete password vault can be opened in one go.

  9. Happened to Me, in much the same way by raabetj · · Score: 5, Interesting

    I very recently had the same situation that is described in the articles happen to my iTtunes Account. I received 2 emails for gift cards purchased through the iTunes store. As I was on vacation with no PC and thus no iTunes access, and not buying gift cards, I knew something was up. At first, I was thinking they were actually spam/phishing emails, as they listed the last 4 digits of a Credit Card that didn't match any of my Credit cards. Without iTunes, all I could do was access my Apple ID account through the web on my phone, and when logged into my account, I saw that my billing information had been changed.

    Luckily I had moved about 3 weeks before, and updated my billing info with my credit card, and not in iTunes (or I suspect I would have had several more app/gift card purchases on my own card.) The strange part was that they didn't change my password at all, or any security related questions. It seems as all they did was change my billing info to some one else's and buy $100 worth of gift cards (Who knows what they were used for...).

    I changed my iTunes Password, and contacted Apple Technical support, and all I got was a standard form letter about how I could dispute the charges on my credit card (even though I had pointed out that it *wasn't* my credit card info). They locked my account and after a short investigation they enabled it with no indication of anything other than their form letter.

    I will freely admit that my password was vulnerable to a dictionary attack, as in the past, I wasn't too worried about someone buying me lots of music, but have since changed it. However, I had no indication that someone was attempting to access my account. If someone was indeed using a dictionary attack on my account, I would have hoped Apple would notice several thousand invalid logins on an account and do something about it.

    I suspect there is someone named Jason in Seattle, who is wondering why they have a $100 purchase from iTunes on their MasterCard...

  10. Data corruption? by Hachima · · Score: 5, Interesting

    This may be unrelated, but yesterday I noticed that my iTunes account had became corrupted with someone else's data. My first name, last name, address and registered CC number became someone else's info. Had I not noticed, I would have been making charges against this other persons account. Maybe someone wrote one messed up database query and screwed up a massive amount of people's payment association. Some users are starting to notice they have someone else's info and are going on a buying spree. Or people are just making their normal purchases and are unknowingly charging other people's accounts, like I almost did last night.

    1. Re:Data corruption? by CosmeticLobotamy · · Score: 2

      Obviously I have no idea what happened in your case, but it gave me an interesting thought. If you have thousands of stolen credit cards (or even just one) but are afraid of getting caught using them, making thousands of other people unknowingly use stolen credit cards by changing their stored data would make for some fantastic plausible deniability.

  11. Re:Meh. by jo_ham · · Score: 2

    That's great, but how does that stop someone else with your credentials logging in from a different computer and buying something?

    I'm going to assume you don;t have a CC on file with Apple (if your iTunes paranoia is anything to go by) but your setup would not help anyone who does.

    My suspicions are that this is due to usernames and passwords being the same across multiple services, so one big compromise (Sony), has led to ID theft on other services, like the iTunes store.

  12. Re:Too coincidental? by sconeu · · Score: 2

    I tried to get them to email the new TOS, but my wifes iPhone kept trying to spell-check/correct my email address. Why the F*** does it do that to *EMAIL ADDRESSES*??????

    --
    General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
  13. Disturbing. by w0mprat · · Score: 3, Insightful

    From reading up on the user reports of this. It seems this has been happening in this pattern since mid to late May. Apple has inexplicably not said a damn thing (yet), but has been removing credit card details from accounts, and locking some others out. Which indicates they are aware of this issue and dealing with it. Interestingly users report they are having no problems having their balances refunded. The silence is conspicuous, no? I guess this issue getting slashdotted means Apple is going to say something.

    What worries me is they appear to have known about it for a while and are trying to clean it up as quietly as possible. If this is was a glitch one presume they would admit it in a downplayed fashion. I'd wager it is a BIG hack.

    Leaving us with two possiblities:
    1) iTunes has been seriously fckued over for teh lulz and profit and is trying to keep it quiet.

    2) Or iTunes fraud may have been a constant (but contained) background noise for some while and this isn't much of an abberation. Apple may prefer to live with some level of fraud and patch it up the leaks quietly. Just because it's trending on /. != a actual real issue.

    Either way, talk about reality distortion.

    --
    After logging in slashdot still does not take you back to the page you were on. It's been that way for 20 years.
    1. Re:Disturbing. by Serious+Callers+Only · · Score: 2

      You missed out:

      3) Most iTunes passwords are insecure, and are also used for other accounts like Sony

      Though your option no.2 is a good description of Apple's reaction to the problem. They should probably offer another level of protection like a certificate per device for login.

  14. Re:Watching this closely. by PRMan · · Score: 2, Insightful

    because if this turns out to be another widespread hack like the others reccently it'd be the last time I ever buy an Apple product.

    What, Steve Jobs controlling every aspect of your life wasn't enough?

    --
    Peter predicted that you would "deliberately forget" creation 2000 years ago...
  15. Re:Watching this closely. by amicusNYCL · · Score: 4, Funny

    I'm watching how this develops, I purchased my wife

    Was she more than $.99?
    Would you buy another?
    Have you seen any fraudulent wife purchases on your bill?

    --
    "Our two-party system is like a bowl of shit looking at itself in a mirror." - Lewis Black
  16. Re:Watching this closely. by Serious+Callers+Only · · Score: 2

    It doesn't any more. Log in to your iTunes account and choose None as payment method, and no details will be kept on file. If you don't purchase regularly then it'll be no inconvenience to re-enter them.

  17. Re:Watching this closely. by jo_ham · · Score: 2

    It doesn't - you can open and run an iTunes account without ever using a credit card, only topping it up with iTunes gift cards. No CC ever needs to go near the account.