Australian iPhone and iPad Users Waylaid By Ransomware
DavidGilbert99 (2607235) writes "Multiple iPhone/iPad/Mac users in Australia are reporting their devices being remotely locked and a ransom demand being made to get them unlocked again. However, unlike PC ransomware, the vector of attack here seems to be Apple's iCloud service with the attacker getting to a database of username/password credentials associated with the accounts. It is unclear if the database was one of Apple's or the hacker is simply using the fact that people reuse the same password for multiple accounts and is using data stolen from another source. Apple is yet to respond, but there has already been one report of the issue affecting a user in the UK."
Is anybody else getting this, or is it discussed elsewhere? When I try to login via Chrome I get a screen with "The site's security certificate has expired!", and a similar message w/ Mozilla (26.0). This is on Windows 7 (hey, my work machine). IIRC I've been getting this since the end of last week, and nothing in my setup has changed.
Oh, the humanity!
seems like they might have been a target of MITM attack
personally I would advocate support for DANE in apple products :
http://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities
http://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities
not a total solution but it would help
regards
John Jones
The article font in the IBTimes website is really pleasing to read, because it has enough weight. Thin characters on many websites make my eyes bleed.
Wouldn't the FBI/other put a trace on the account and prevent the criminals from withdrawing without revealing themselves, within a day or two?
It is not like the message is: "Leave 10,000 dollars under the bridge, and come alone or your data gets it."
Troll is not a replacement for I disagree.
Where do you get such misinformation? Apple deprecated the use of OpenSSL when it deprecated CDSA back in 2011 for OS X in favor of Common Crypto. At the time there was some mumblings about how Apple didn't like standards. And Apple has never used OpenSSL in iOS.
. . . although OS X provides OpenSSL libraries, the OpenSSL libraries in OS X are deprecated, and OpenSSL has never been provided as part of iOS.
Password Reuse
Over the years I've turned on more and more iCloud features on my iOS devices but I've yet to turn on Backups and never will.
I backup to my mac at home. So if someone ever gets my password they can remote wipe my phone if they want but then I'll just restore from my manual backup and change my password.
This is also why I won't turn on Find My Mac. The same people that might gain access to my account could easily wipe my phone and my Mac at the same time and then I'm screwed (although not really since I also have 2 by weekly on side backups and constant off site backups but you get my point).
Apple is built on older versions of OpenSSL - this looks like it might be because they weren't quick enough to adapt, and someone snuck in under the radar. Lets hope they get it sorted quickly!
Apple deprecated the use of OpenSSL in 2011, and the version shipped with OS X was never updated to the versions which introduced Heartbleed. Strike 1!
OpenSSL has never been used in iOS. Strike 2!
Apple also was not using affected versions in any of its online/cloud services. Strike 3!
You're out! Your post was ridiculously bad even by /. standards!
If you happen to tap your Apple ID / password in a subway, in a crowded place or under a surveillance camera, and someone can see it, your account is not blocked, it's hijacked... and you know nothing about it! Thanks to iCloud, where is my i* and the like, that someone may see your personal data, where you are at this very moment, and where you go usually etc... As long as he doesn't alter your data, you don't know. It's been a recurring problem with Apple IDs. Google gmail shows a list of recent activity with IP adresses, and warns immediately about suspicious activity, like a connection from a far/different IP. http://www.forbes.com/sites/adriankingsleyhughes/2012/08/04/the-dangerous-side-of-apples-icloud/.
Slashdot, fix the reply notifications... You won't get away with it...
"...FIND HIM AND KILL HIM!"
[Start Trek: DS9, "Take Me Out To The Holosuite"]
If the phone is locked, on wonders how they contact the owner to tell them their locked phone is being held for ransom.
And iOS Users in Australia are so much better off for it!
Oh wait,,,.
The cert was showing expired, and now it seems to be redirecting https to http
When you cant win, ad hominem.
Looks like slashdot just replaced their certificate, maybe they only replaced it after expiry.
The cert I see was issued on May 27 2014 0:00:00 AM GMT.
SHA1 fingerprint 74:41:40:02:D6:79:4B:C2:9D:5C:B4:1A:7F:1A:B9:C6:8C:4B:79:C5
MD5 fingerprint 1E:D3:F7:70:37:CB:BE:D3:8E:66:92:59:50:A3:37:F1
How does this have to do with Apple using or not using OpenSSL? Right now the source of the attack is unknown but speculation is that people reuse their username (email) and passwords from other sites that have been compromised. So if someone has a list of yahoo credentials from heartbleed they might be able to take over someone's Apple account regardless if Apple used or did not use OpenSSL.
Well, there's spam egg sausage and spam, that's not got much spam in it.
Thanks. At least I know that I'm not going crazy (or at least this issue isn't evidence of it). I'm glad you mentioned when it was renewed. I feel a little sheepish but both browsers had been open since yesterday. Close and re-open of the browser fixed it, but I know that wasn't the case the last few days.
Need more coffee. Since I fixed it, why did I post the PP as AC?
I hope someone hangs that asshole by his tiny balls.
Looks fine from here. X11 and web browsers have had ugly fonts forever. Even today the default fonts still look like something CDE vomited up.
Only the State obtains its revenue by coercion. - Murray Rothbard
I’ll be you my iCloud password, it’s a re-wrap of this:
http://soylentnews.org/article...
If you can MitM a “consenting” user to unbrick a stolen phone, I can’t see any reason it doesn’t work the other way around.
Isn't Apple's "walled garden" itself a form of ransomware?
Oleg Pliss Stahp!
I think the most important thing here is to not reuse your passwords. Otherwise breaches at one site can spill over into breaches at more important sites (like for your iphone, or your bank). the best thing to do is to have an easy approach to remember, so you end up with passwords like slashdotsucks666 and yahoosucks666.
Hell, it could very well be a phishing attack - a couple of months ago I've been getting a ton of "Apple ID confirmation" and other crap email asking you to "verify" your Apple ID with Apple.
It's slowed down or gone now, but that could also very well be the problem. (Yes, those phishes were pretty obvious, but some were quite good).
Heck, I've gotten them in FRENCH, too. That one was interesting. (In Canada, the typical standard is one email in both English and French, but this was French only).
I wouldn't be surprised if this wasn't the result of said phishing attack.
NOT.
If they were stupid enough to entrust somebody else with the power to lock them out of their devices then they deserve it.
I fairly recently got a message on some Safari page (probably from an ad) that an app I didn't have needed to update. Maybe that's what happened?