Slog

News & Arts

The Stranger Suggests

Critics' Best Bets
Music Arts & Food


Line Out

Music & the City
at Night

Wednesday, June 9, 2010

Did Apple or AT&T Unintentionally Leak iPad 3G Owner Information?

Posted by on Wed, Jun 9, 2010 at 2:31 PM

Gawker has the story:

Apple has suffered another embarrassment. A security breach has exposed iPad owners including dozens of CEOs, military officials, and top politicians. They—and every other buyer of the wireless-enabled tablet—could be vulnerable to spam marketing and malicious hacking.

...

It doesn't stop there. According to the data we were given by the web security group that exploited vulnerabilities on the AT&T network, we believe 114,000 user accounts have been compromised, although it's possible that confidential information about every iPad 3G owner in the U.S. has been exposed. We contacted Apple for comment but have yet to hear back. We also reached out to AT&T for comment. A call to Rahm Emanuel's office at the White House has not be returned.

This could get interesting.

 

Comments (13) RSS

Oldest First Unregistered On Registered On Add a comment
1
If you read the whole "article", it doesn't really have anything to do with Apple. This is just blatant link-baiting from a gossip website with a grudge.
Posted by Gaydolf Titler on June 9, 2010 at 2:40 PM
2
Indeed. Gawker owns Gizmodo, which likes to be receive stolen property, expose trade secrets, etc. And then gets punished by Apple with not getting access to its events any more. They've got an ax to grind. Very transparent how they try to tie Apple into what looks like a failing on the part of AT&T. The iPhone can't move to Verizon fast enough...
Posted by Kirk on June 9, 2010 at 3:03 PM
laterite 3
At the very least, AT&T should send new microSIMs out to every iPad owner. SIM spoofing is not uncommon at all and this is basically a list of free SIMs.
Posted by laterite on June 9, 2010 at 3:12 PM
Joe Szilagyi 4
@3 at the least? They have to period.
Posted by Joe Szilagyi http://www.joeszilagyi.com on June 9, 2010 at 3:23 PM
laterite 5
That's why I said "at the very least". If it were me I'd also throw in free service for a year for whoever ended up on this list.
Posted by laterite on June 9, 2010 at 3:27 PM
w7ngman 6
Oh nice, a presumably whitehat "web security group" sold their exploit to journalists instead of helping the victim patch the vulnerability. Fucking scum.
Posted by w7ngman http://userscripts.org/users/89370 on June 9, 2010 at 3:32 PM
7
Yeah, 1. Its from Gawker, who is almost certainly not an unbiased observer to these events. 2. This "breach" is clearly AT&Ts issue. 3. Its just email addresses and ICCs, which, in the scheme of things, really isn't that big of a deal. Most of these email addresses were easily guessable, and if your corporate network or personal security requires having a secret email address, you are doing it wrong.
Posted by Grawr Gawker Grawr on June 9, 2010 at 3:42 PM
8
@1:
no, the more typical link-baiting--if this were amazon or microsoft--would not have any such qualifier as 'unintentionally' or even pose the headline as a question.

if it were a local tech company, or at least not-Apple, it would have been more like "bullying apple's failure to protect you personal information could cost you your identity!"
Posted by not-apple! on June 9, 2010 at 3:42 PM
Will in Seattle 9
Time to trust bust AT&T ...

oh

wait

we did that already
Posted by Will in Seattle http://www.facebook.com/WillSeattle on June 9, 2010 at 3:47 PM
10
@8 Wasn't talking about Slog there. I was referring to Gawker- you know, the company that owns Gizmodo, who leaked iPhone 4 a couple months back?
Posted by Gaydolf Titler on June 9, 2010 at 3:55 PM
laterite 11
Oh, and while AT&T is at fault for the openly accessible site, Apple isn't entirely off the hook here since it's ultimately their product and application requirements that allows pass-through authentication in the first place. I wonder how many carriers internationally have this potential problem.
Posted by laterite on June 9, 2010 at 3:56 PM
12
Did they leave this information on a bar stool?
Posted by ratcityreprobate on June 9, 2010 at 5:03 PM
Karlheinz Arschbomber 13
@11 it is -trivial- to do secure passthru authentication. If you don't have nitwits in charge.
Posted by Karlheinz Arschbomber http://de.wikipedia.org/wiki/Arschbombe on June 9, 2010 at 5:18 PM

Add a comment

Advertisement
 

All contents © Index Newspapers, LLC
1535 11th Ave (Third Floor), Seattle, WA 98122
Contact Info | Privacy Policy | Terms of Use | Takedown Policy