Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

icloud_icon_blueEarlier today, Apple issued a press release stating that an iCloud/Find My iPhone breach had not been responsible for the leak of several private celebrity photos over the weekend, instead pointing towards a “very targeted attack on user names, passwords, and security questions” hackers used to gain access to celebrity accounts.

The company did not divulge specific details on how hackers accessed the iCloud accounts, leading Wired writer Andy Greenberg to investigate the methods that hackers might possibly have used to acquire the stolen media.

Greenberg visited Anon-IB, a popular anonymous image board where some of the celebrity photos first originated, and discovered that hackers openly discuss exploiting software designed for law enforcement and government officials. Called ElcomSoft Phone Password Breaker (EPPB), the software in question lets hackers enter a stolen username and password to obtain a victim’s full iPhone/iPad backup.

“Use the script to hack her passwd…use eppb to download the backup,” wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. “Post your wins here ;-)”

Acquiring just a user name and password allows hackers access to content on iCloud.com, but with the accompaniment of the ElcomSoft software, a complete backup can reportedly be downloaded into easy-to-access folders filled with the device’s contents.

According to security researcher Jonathan Zdziarski, who spoke to Wired, metadata from some of the leaked photos is in line with the use of the ElcomSoft software and possibly the iBrute software, which exploited a vulnerability in Find My iPhone to allow hackers unlimited attempts to guess a password. Apple has, however, patched the exploit, and has suggested iBrute was not a factor in the attacks.

As noted by TechCrunch, using ElcomSoft’s software to download an iPhone’s backup successfully circumvents two-factor verification as the two-factor authentication system does not cover iCloud backups or Photo Stream.

Two-factor verification can make it much more difficult for hackers to acquire a user’s login credentials in the first place, preventing many attacks, but an iCloud backup can be installed with just a user name and a password.

twostepverification
The ElcomSoft software does not require any credentials to buy and while it costs $399, it is also available on bittorrent sites. The vulnerability in iCloud backups has been known for some time, with ElcomSoft’s own CEO pointing towards the lack of two-factor authentication for iCloud backups back in May of 2013.

Apple has explored expanding two-factor authentication to some iCloud services, but an official expansion of the security feature has not yet been introduced.



Apple Releases OS X Yosemite Developer Preview 7

Apple today released a new version of OS X Yosemite to developers, two weeks after releasing the sixth Developer Preview and three months after unveiling the new desktop operating system at its annual Worldwide Developers Conference.

The update, build 14A343f, can be downloaded from the Mac App Store and through the Mac Developer Center. There’s also a new version of Xcode 6, an OS X Server 4.0 Developer Preview, and an updated version of Apple Configurator 1.7.

yosemite_dp_7_dev
OS X Yosemite brings a flatter, more modern look to OS X, with an emphasis on translucency and redesigned dock, windows, and more. It also includes a multitude of new features, such as improved integration with iOS 8 through Continuity, a new “Today” view in Notification Center that offers integration with third-party apps, a retooled Spotlight search with new data sources, and several new features for apps like Mail, Safari, and Messages.

Over the course of the beta testing period, each Developer Preview has added new features and refined the look and performance of OS X Yosemite. DP 4, for example, added a revamped version of iTunes with a streamlined design and support for Family Sharing, while an earlier beta introduced a new Dark Mode. Developer Preview 6 added several new icons, a new look for the dashboard, and new Yosemite-themed wallpapers.

Today’s Developer Preview is limited to registered developers, but in late July, Apple made a version of OS X Yosemite available to the public as part of a wide-ranging beta test. The pre-release version of Yosemite available to those participating in the public beta program has not received as many updates as the developer version and is on its second iteration. Apple is expected to release Yosemite to the public in the fall.

Notable changes in Developer Preview 7:

Dark Mode: Dark Mode has been tweaked slightly, and there’s a new look for Spotlight when Dark Mode is enabled.

spotlightdarkmode
Icons: There are new icons for Migration Assistant, Dashboard, Disk Utility, ColorSync Utility, and Keychain Access.

newyosemiteicons
System Preferences: There are several new and modified icons in System Preferences, including a new look for Language & Region and Startup Disk.

systempreferencesicons
Software Update: The “Software Update” option has been removed from the main Apple menu, with App Store now displaying available software updates.

softwareupdateremoved



Microsoft Office Apps for iPad Gain Support for Monthly Subscription Purchases [iOS Blog]

Microsoft today updated its Word, Excel, and PowerPoint iPad apps to allow users to purchase a monthly subscription to Office 365 directly in the apps.

Previously, customers were able to purchase a yearly subscription for Office 365 Home within the apps for $99.99, but it’s now possible to buy a monthly subscription for Office 365 Personal and Office 365 Home via in-app purchase.

officesubscriptionipad

As we continue to bring Microsoft Office to all platforms and devices, it’s important for customers to manage their Office 365 subscription–easily and on the go. You asked for more flexibility in signing up for Office 365 subscriptions on iPad. So starting today, you can buy a monthly subscription to Office 365 from within Microsoft Word, Excel, and PowerPoint for iPad. You can choose between Office 365 Personal and Office 365 Home

Introduced in March, Office 365 Personal is aimed at individual users who want to use Microsoft’s apps on just one PC/Mac and one tablet, while the Office 365 Home subscription is designed for households with up to five computers and five tablets.

Office 365 Personal is priced at $6.99 per month, while Office 365 Home is available for $9.99 per month. All of Microsoft’s apps can be downloaded for free from the App Store.

Microsoft Word for iPad [Direct Link]
Microsoft Excel for iPad [Direct Link]
Microsoft PowerPoint for iPad [Direct Link]



August Smart Lock Finally Begins Shipping to Customers [iOS Blog]

After a long delay, the August Smart Lock is finally shipping out to preorder customers beginning today. First introduced in May of 2013, the August Smart Lock is a Bluetooth-based iPhone-compatible locking system designed by Jason Johnson and notable designer Yves Béhar.

At August, our mission is to make beautiful products that allow your physical environment to seamlessly respond to you. Today, we are one step closer to achieving that goal. We are excited to announce that the August Smart Lock has begun shipping in limited quantities.

The August Smart Lock, which allows users to unlock their doors with their iPhones, is crafted from anodized aluminum and looks similar to a standard home lock. It comes with several different faceplates and deadbolt adapters to fit the majority of locks on the market, functioning on four AA batteries.

Like competing products from Lockitron and Kevo, the lock can be programmed remotely to let in visitors through an accompanying iPhone app. It’s also designed to monitor when guests enter and it can be customized with specific timers.

Initial preorders of the August Smart Lock, which originally had an estimated shipping date of November or December 2013, were available for $199, but the retail price of the lock is now $249.99. The company plans to fulfill orders for the lock over the course of the next few months, with new orders displaying a prospective shipping date of “late October.”



PayPal Offers 25{813a954d5e225a1509f22204ece89c855080ce25555f20805f61bed63cbfde3b} Off iTunes Gift Cards in the UK [iOS Blog]

PayPal is currently offering 25 percent off digital iTunes cards in the United Kingdom, allowing users to purchase iTunes codes for the App Store, Mac App Store, iBooks Store, and iTunes Store at a discount.

itunesukdiscount
Under the terms of the deal, an £15 iTunes card drops to £11.25, while a £25 card drops to £18.75. Larger denomination iTunes cards of £50 and £100 are available for £37.50 and £75. Cards are only redeemable in the UK iTunes Store.

The offer lasts until Thursday, August 28 at 11:59 BST, but as with all PayPal iTunes discounts, there are a limited number of codes available and discounts will only be available while supplies last.



Apple to Launch 12.9-Inch iPad in Early 2015

Apple is planning to launch its much-rumored 12.9-inch iPad in early 2015, reports Bloomberg. Hints of the tablet, which has been dubbed the “iPad Pro” in rumors, first appeared in mid-2013, with a prospective 2014 launch date. Recent rumors, however, …