Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

icloud_icon_blueEarlier today, Apple issued a press release stating that an iCloud/Find My iPhone breach had not been responsible for the leak of several private celebrity photos over the weekend, instead pointing towards a “very targeted attack on user names, passwords, and security questions” hackers used to gain access to celebrity accounts.

The company did not divulge specific details on how hackers accessed the iCloud accounts, leading Wired writer Andy Greenberg to investigate the methods that hackers might possibly have used to acquire the stolen media.

Greenberg visited Anon-IB, a popular anonymous image board where some of the celebrity photos first originated, and discovered that hackers openly discuss exploiting software designed for law enforcement and government officials. Called ElcomSoft Phone Password Breaker (EPPB), the software in question lets hackers enter a stolen username and password to obtain a victim’s full iPhone/iPad backup.

“Use the script to hack her passwd…use eppb to download the backup,” wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. “Post your wins here ;-)”

Acquiring just a user name and password allows hackers access to content on iCloud.com, but with the accompaniment of the ElcomSoft software, a complete backup can reportedly be downloaded into easy-to-access folders filled with the device’s contents.

According to security researcher Jonathan Zdziarski, who spoke to Wired, metadata from some of the leaked photos is in line with the use of the ElcomSoft software and possibly the iBrute software, which exploited a vulnerability in Find My iPhone to allow hackers unlimited attempts to guess a password. Apple has, however, patched the exploit, and has suggested iBrute was not a factor in the attacks.

As noted by TechCrunch, using ElcomSoft’s software to download an iPhone’s backup successfully circumvents two-factor verification as the two-factor authentication system does not cover iCloud backups or Photo Stream.

Two-factor verification can make it much more difficult for hackers to acquire a user’s login credentials in the first place, preventing many attacks, but an iCloud backup can be installed with just a user name and a password.

twostepverification
The ElcomSoft software does not require any credentials to buy and while it costs $399, it is also available on bittorrent sites. The vulnerability in iCloud backups has been known for some time, with ElcomSoft’s own CEO pointing towards the lack of two-factor authentication for iCloud backups back in May of 2013.

Apple has explored expanding two-factor authentication to some iCloud services, but an official expansion of the security feature has not yet been introduced.



AT&T complains about unfairness of municipal broadband to FCC

Given the opportunity to petition against the expansion of municipal broadband expansion in Chattanooga, TN and Wilson, NC, AT&T has taken the opportunity to remind the government of its role in the state of Internet connectivity in the US. In its filing with the US Federal Communcations Commission, the telecom giant lays out its case against why local broadband, or “Government Owned Networks” (GON), shouldn’t be allowed….



Cambridge Audio Go v2 Portable Bluetooth Speaker

Last year, we covered Cambridge Audio’s Minx series of speakers, which like other Apple AirPlay-standard wireless audio systems were saddled with unjustifiably high price tags and unimpressive wireless performance. Despite sharing its predecessors’ industrial design, Go V2 is a very different beast. Armed with Bluetooth rather than AirPlay and five total speakers — twin 0.75” tweeters, two 2” woofers, and one 5.4”-wide…

Review: Soundfreaq Double Spot SFQ-09 Wireless Speaker

Most of Soundfreaq’s speakers require no explanation: it’s clear from their designs that they are made to be stationary, portable, ultra-portable, clock radios, or highly budget-sensitive. Double Spot doesn’t fit neatly into any of those categories. It’s based upon the company’s stripped-down $70 Sound Spot, yet it’s more than twice as large, and roughly twice as expensive.   When asked to explain Double Spot’s…

Apple says iCloud flaw not at root of celebrity photo hack

Addressing a widespread hack of celebrities’ photos, Apple on Tuesday issued an update on its investigation into the incident and said that it was continuing to work with law enforcement on the matter.

According to the company, more than 40 hours of investigation from the company’s engineers has established that the accounts that were compromised were the subjects of a “very targeted attack on user names, passwords and security questions.” While previous reports suggested that a flaw in iCloud was responsible for the hack, Apple says that none of the cases it has looked into were tied to any vulnerability in the company’s systems.

To read this article in full or to leave a comment, please click here