x PhoneArena is looking for new authors! To view all available positions, click here.
  • Home
  • News
  • Apple’s iCloud allegedly breached in celebrity photo theft

Apple’s iCloud allegedly breached in celebrity photo theft

Posted: , by Maxwell R.

Tags:

Apple’s iCloud allegedly breached in celebrity photo theft
During what is a long holiday weekend in the United States, an anonymous hacker claims to have successfully hacked Apple iCloud and its Photo Stream feature of nearly 100 celebrity accounts and place several photos on 4chan.

Celebrity photos are nothing new, and risqué photos of attractive female actresses is also not new, but was probably a large part of what made this a big story. What added to the headlines was the possibility that iCloud was breached.

As of the time of this writing, it is not known if iCloud was actually circumvented, but it probably played a role somehow. We looked through a Pastebin page with several thousand lines of EXIF data.  It does not conclusively point to one direction or the other because EXIF data is not necessarily indicative of anything. That said, a lot of binary information there appears to trend consistently.

Some security folks started picking at what data they had on hand about the pictures, and everything is a theory at the moment. On one hand, a particular tweet from Mary Winstead, star of Scott Pilgrim vs. The World points strongly to the idea that at least some photos resided on a server, not a device. She stated that the pictures of her were removed from her device “long ago.” With Photo Stream, the pictures remain on iCloud and on device back-ups even after they are deleted off the device.

On the other hand, it seems unlikely (albeit not inconceivable) that unauthorized access could get into Apple’s iCloud and pick through over 100 accounts. A few of the celebrities have confirmed (or denied then later confirmed) the authenticity of the pictures. A spokesman for Jennifer Lawrence, of Hunger Games fame, said they contacted the authorities and would prosecute anyone who posts the stolen images. Other celebrities affected by this wave of pictures include Vanessa Hudgens, Rihana, Kate Upton, and Hillary Duff

Photo Stream retains pictures in the cloud, even after they are deleted off a device

Photo Stream retains pictures in the cloud, even after they are deleted off a device

This could be a case of “social engineering” too, where someone grabs publicly available data about an individual and deducts password or security question insights through a bit of trial and error. Given the number of people involved however, that strikes us as unlikely. Finding the accounts not adequately protected is far more feasible (a lot of people use terrible passwords). Another plausible theory is that someone’s private “prized” collection of photos, kept on a single machine, was compromised.

As we watch the story unfold, there is the simple issue of what many are phrasing as an invasion of privacy. That is true, but the difference here is that “celebrity” exposure is treated differently than if these were pictures of one’s next door neighbor. Back in 2012, a man was sentenced to 10 years in prison for posting nude photos hacked from Scarlett Johansson's phone.

This will certainly be an evolving story as people try to establish a digital crumb trail and see where these images were found. Since Monday is the Labor Day holiday in the United States, it is possible we may not see any official statements from Apple until Tuesday at the earliest.

In the meantime, be good stewards of your digital self. Use strong passwords, secondary authentication, and simply do not put anything on the internet that you would be uncomfortable with the whole world knowing tomorrow.

sources: The Telegraph, Jonathan Zdziarski, @SwiftOnSecurity, Pastebin data

41 Comments
  • Options
    Close




posted on 01 Sep 2014, 02:57 3

1. vandroid (Posts: 301; Member since: 04 Sep 2012)


Were Jennifer Lawrence and Victoria part of the victim list?

posted on 01 Sep 2014, 03:04 4

3. LeBrownJames (Posts: 157; Member since: 17 Mar 2014)


Yes they are.

posted on 01 Sep 2014, 03:36 7

9. AnTuTu (Posts: 981; Member since: 14 Oct 2012)


hmmmmm and I thought iOS is safe ;)

posted on 01 Sep 2014, 09:54 1

24. Vexify (banned) (Posts: 570; Member since: 16 Jun 2014)


Most cloud services are not safe. People who know this before putting their tatas in the cloud lol. Especially when the hacker is ex-NSA.

posted on 01 Sep 2014, 17:44 1

28. JakeLee (banned) (Posts: 1021; Member since: 02 Nov 2013)


And why do they have movie clips? iCloud doesn't upload movies.

Maybe they hacked Google drive.

posted on 01 Sep 2014, 17:51 2

29. Sniggly (Posts: 7183; Member since: 05 Dec 2009)


They definitely hacked iCloud, at least. Some of the celeb shots show them using iPhones to take the selfies in mirrors and such. Google Drive may have been hacked *too,* but the primary target was iCloud.

posted on 01 Sep 2014, 06:51 1

19. vincelongman (Posts: 1718; Member since: 10 Feb 2013)


Funny thing is Victoria said that hers were fake, but people were able to match items from her leaks to her instagram

posted on 01 Sep 2014, 10:53 1

26. InspectorGadget80 (Posts: 6741; Member since: 26 Mar 2011)


Who cares if a celebrity got their pics stolen. They are all TRASH.

posted on 01 Sep 2014, 19:38

31. Ninetysix (Posts: 1681; Member since: 08 Oct 2012)


When did you come out?

posted on 01 Sep 2014, 02:57 9

2. 0xFFFF (Posts: 3775; Member since: 16 Apr 2014)


Not surprising at all. As it has been recently exposed, there basically is no security for iPhones due to all the backdoor APIs Apple put in. Now we see that iCloud is probably the same way.

Feel sorry for the people who put their trust in Apple's security theater.

Hopefully more people will learn that the NSA deemed iPhone security to be a complete farce and called iPhone users "iZombies", in part due to their blind trust in Apple. They didn't say these things because they were talking smack. They said these things because it is the truth.

posted on 01 Sep 2014, 03:09 4

4. Liveitup (Posts: 1591; Member since: 07 Jan 2014)


I wonder if you will stick to your comment if and when the full details come out and Android devices or Google drive are also at fault.

Its tech its not good when things like this takes place but #hit happens.

posted on 01 Sep 2014, 03:14 5

7. 0xFFFF (Posts: 3775; Member since: 16 Apr 2014)


Because so many Android devices use iCloud? I think you've gotten confused again, FakeItUp.

Seems like you got assigned to the same team as FakeLee. Are you now working with Fake on the "anti-Android/anti-Google" reputation management team? Remember, Uber is hiring people of your ilk. And you will get to change your title to "Brand Ambassador". It will be good for your CV.

posted on 01 Sep 2014, 03:21 2

8. Liveitup (Posts: 1591; Member since: 07 Jan 2014)


It is alleged that it is iCloud however as time goes by more photos gets leaked and the picture becomes clearer, there could very well Googledrive, Onedrive etc whose security got undermined. I stated what i said earlier cause you are an ardent Android fan who is quick to bash others.

As who Fakelee is i don't even know, if any thing i truthitup.

If i was interested in bashing Google i would be someone on Android articles bashing them, that's is juvenile and reserved for haters like yourself to bash other platforms.

posted on 01 Sep 2014, 05:02 4

15. Sniggly (Posts: 7183; Member since: 05 Dec 2009)


Liveitup, when the hacker was boasting about doing what he did, he only mentioned hacking users' iCloud accounts to get these photos. If Microsoft or Google's cloud services were involved as well, he'd probably have mentioned them too.

posted on 01 Sep 2014, 09:56 1

25. Vexify (banned) (Posts: 570; Member since: 16 Jun 2014)


He did. He mentioned Google Drive and MEGA. Do some research. Go visit 4chan.

posted on 01 Sep 2014, 18:50

30. JC557 (Posts: 1164; Member since: 07 Dec 2011)


And these people probably have the same user name and password for all those accounts making it trivial to get into.

posted on 01 Sep 2014, 12:29 1

27. nithyakr (Posts: 80; Member since: 20 Jun 2014)


The photos were leaked on Google Drive as well. Go do your research.
And in some of the photos, celebrities were taking selfies with Samsung Phones.
So it's not only Apple's fault or Google's.
But yes, Most of the photos were leaked on iCloud because obviously a lot of celebrities use iPhones than Android phones.
So a lot of photos were on iCloud.

posted on 01 Sep 2014, 08:16 1

20. BobbyDigital (Posts: 622; Member since: 29 May 2014)


You know, I've noticed something about you. You blast others who troll WP articles and yet in almost every post, you manage to say something disparaging about Android and Google. Pot calling the kettle black, I see.

posted on 02 Sep 2014, 07:41 1

36. Scott93274 (Posts: 1363; Member since: 06 Aug 2013)


That's just how we roll here on Phone arena. :P

posted on 01 Sep 2014, 04:13

10. microsoftnokiawin (Posts: 1044; Member since: 30 Mar 2012)


I don't remember the NSA speaking about any of this I mean share your opinion sure but don't start making crap up long the way you don't need crap to make your argument valid !

posted on 01 Sep 2014, 08:20 3

22. BobbyDigital (Posts: 622; Member since: 29 May 2014)


Here's the link about the NSA calling iPhone users zombies. -http://m.huffpost.com/us/entry/3895375

posted on 02 Sep 2014, 00:55 1

34. microsoftnokiawin (Posts: 1044; Member since: 30 Mar 2012)


thanks you :) !

posted on 01 Sep 2014, 04:25

13. power_x (Posts: 244; Member since: 28 Aug 2013)


Or simply don't take nudes of yourself ? Much easier solution than all this hate on iCloud right ?

posted on 01 Sep 2014, 06:42 2

18. Zeeya (Posts: 222; Member since: 17 Mar 2013)


Haha.... stupidest comment ever!

posted on 02 Sep 2014, 07:47

37. Scott93274 (Posts: 1363; Member since: 06 Aug 2013)


I think it's common sense not to take nudes of yourself especially if you're a high profile celebrity, but that doesn't change the fact that iCloud is marketed as a quality cloud storage service and then this happens. What if you were storing family photos with no backup and then the hacker deleted them all? What if you has personal financial information saved in there? Your personal data needs to be safeguarded properly regardless if you've taken nudes or not.

posted on 01 Sep 2014, 03:09 5

5. Tritinum (Posts: 281; Member since: 06 May 2014)


Solution - stop taking naked pictures of yourself.

posted on 01 Sep 2014, 04:25

14. CannabisHighway (Posts: 18; Member since: 07 Oct 2013)


True. People should go back to the Polaroid Instant-non digital photos if they want to do nudes or any freaky stuff.

posted on 01 Sep 2014, 03:13 2

6. xperiaDROID (banned) (Posts: 5629; Member since: 08 Mar 2013)


Don't worry, BlackBerry welcomes you to join their adventurous secured journey, with just a few swipes.

BlackBerry keeps you moving.

posted on 01 Sep 2014, 04:14 2

11. microsoftnokiawin (Posts: 1044; Member since: 30 Mar 2012)


keeps you clothed :p

posted on 01 Sep 2014, 04:18

12. esperanza (Posts: 46; Member since: 23 Mar 2013)


I'm a little bit shocked when I saw Jennifer Lawrence's bj photo but She looks pretty in even these kind of photos.

posted on 02 Sep 2014, 00:35

33. clarkjeferson (Posts: 53; Member since: 22 Dec 2013)


The photo was a lie, I've been to the forums and I can say that it's a lie.

posted on 01 Sep 2014, 05:04 2

16. Sniggly (Posts: 7183; Member since: 05 Dec 2009)


First I'm going to say that anyone who blames the celebs themselves for having sex lives and nude photos of themselves is a blithering di.ckwaffle who clearly doesn't respect privacy rights nor do they respect the concept of consent to release photos like these.

Second I'm going to say that with a leak this big, Apple is potentially in huge trouble. It could well be the class action lawsuit of the century if it's shown that multiple iCloud accounts were hacked in order to get these pictures.

posted on 01 Sep 2014, 08:16 2

21. remixfa (Posts: 14188; Member since: 19 Dec 2008)


If this is found to be strickly an iCloud hack, its going to be a massive shyeet storm for Apple... and right before their next big unveil. The timing couldn't be worse for them.
If it is an iCloud hack and they are not forced to redirect their yearly show to have a focus on new security, I'd be amazed.

That said, remember folks, none of your data on ANY of your devices is ever 100% secure.

posted on 01 Sep 2014, 06:40 3

17. meanestgenius (Posts: 2274; Member since: 28 May 2014)


Time for those celebs and others to get a BlackBerry, IMO. ;)

Perhaps Apple should look to hire John Chen and Co. as security experts, to help Apple shore up all of these breaches and hacks that have been happening to them, especially as of late.

And I agree with Sniggly, anyone who is blaming these celebs for having a sex life in their private lives is a complete iD*ot.

posted on 02 Sep 2014, 07:53 1

38. Scott93274 (Posts: 1363; Member since: 06 Aug 2013)


Well, you know I'm not big on Blackberry, but I do have to give credit when credit's due. The Apple flock is always bragging about how secure iOS is compared to Android. Reality really knows how to smack ignorant people in the face really hard in times like these. If Blackberry plays its cards right, it can maybe reclaim some market from Apple after this fiasco.

posted on 02 Sep 2014, 14:21

41. meanestgenius (Posts: 2274; Member since: 28 May 2014)


You're not big on anything except Android...and that's your choice and I respect it. I'm not big on Android or iOS....and I hope others respect my choice in that as I never troll other OS's.

posted on 01 Sep 2014, 08:25 2

23. VHMP01 (banned) (Posts: 93; Member since: 27 Aug 2014)


iCloud should be renamed iPorn !

posted on 02 Sep 2014, 00:35

32. clarkjeferson (Posts: 53; Member since: 22 Dec 2013)


Anyway, let this be a lesson to celebrities everywhere, get a blackberry, not even a hacker would touch that.

posted on 02 Sep 2014, 04:01 1

35. meanestgenius (Posts: 2274; Member since: 28 May 2014)


More like a hacker CAN'T touch a BlackBerry.

posted on 02 Sep 2014, 07:54

39. Scott93274 (Posts: 1363; Member since: 06 Aug 2013)


Famous last words. Nothing is unhackable. iCloud on the other had just left the back door wide open and got screwed as a result.

posted on 02 Sep 2014, 14:18 1

40. meanestgenius (Posts: 2274; Member since: 28 May 2014)


BlackBerry 10 has yet to be hacked. BlackBerry always uses the most stringent security measures and is constantly updating them and adding more measures of security. It is indeed the most secure mobile OS in the industry.

Want to comment? Please login or register.

Latest stories