Share

How nude celeb pics could have leaked

Cape Town - As Apple prepares to launch its latest iPhone, some are asking how they can trust the iCloud platform that resulted in several celebrities' nude pictures being released to the public.

Stay with Fin24 for Live Updates on the Apple event.

But the problem may not only rest with Apple's security.

"E-mail addresses and passwords got harvested from a breach or leak on another website. They just happen to share the same credentials on iCloud, which led to the compromise. This is the most plausible hypothesis," Guillaume Lovet, senior manager, FortiGuard Labs Threat Response Team at Fortinet told Fin24.

Celebrities, including Jennifer Lawrence and Mary Elizabeth Winstead, have had images from their iCloud accounts leaked and Apple rejected accusations that its platform was flawed.

However, the company moved to restore trust in its cloud platform ahead of the launch of its latest iPhone, expected on Tuesday.

Social engineering

Apple will alert users through e-mail and push notifications when someone tries to change an account password, restore iCloud data to a new device, or when a device logs into an account for the first time, CEO Tim Cook told the Wall Street Journal in an interview.

Lovet said that Fortinet was unable to detect any specific flaw in Apple's iCloud service.

Most users do not make enough of an effort to create strong passwords and this may have contributed to the hack. According to the 2014 Trustwave Global Security Report, the most common password was "123456", followed by "123456789", "1234" and "password".

"Celebrities, like any other end-user, probably do not always use strong passwords to protect their accounts, however, they will usually keep their email addresses private, so as not to be spammed by fans," said Lovet.

Cyber criminals also use social engineering techniques to trick users into giving away sensitive information.

"Often the first kind of vulnerability exploited by attackers is the human one. They use social engineering techniques to trick individuals who work for an organisation into doing something that jeopardises corporate security," Ghareeb Saad, senior security researcher with the Global Research & Analysis Team, Middle East, Turkey and Africa at Kaspersky Lab told Fin24.

According to multiple reports, the US FBI is investigating the data breach though charging an individual may prove difficult as the images were posted anonymously.

Strong passwords

Lovet said that the two-factor authentication system should go some way to preventing the kind of breach.

"Again, should two-steps authentication been available for iCloud as well, this might have prevented at least part of the leak: ID/password combinations harvested from previous database breaches would have not been enough to log in iCloud and download the targets' photostream."

He advised that people use multiple strong passwords for different platforms. Strong passwords have a mix of numbers, symbols and letters in both upper and lower case.

Regarding iCloud specifically, you can prevent photos to be uploaded from your Apple device to the cloud by disabling Settings → iCloud → Photos → My Photo Stream.


- Follow Duncan on Twitter

We live in a world where facts and fiction get blurred
Who we choose to trust can have a profound impact on our lives. Join thousands of devoted South Africans who look to News24 to bring them news they can trust every day. As we celebrate 25 years, become a News24 subscriber as we strive to keep you informed, inspired and empowered.
Join News24 today
heading
description
username
Show Comments ()
Rand - Dollar
19.15
-0.7%
Rand - Pound
23.82
-0.6%
Rand - Euro
20.39
-0.5%
Rand - Aus dollar
12.30
-0.5%
Rand - Yen
0.12
-0.6%
Platinum
950.40
-0.3%
Palladium
1,028.50
-0.6%
Gold
2,378.37
+0.7%
Silver
28.25
+0.1%
Brent Crude
87.29
-3.1%
Top 40
67,190
+0.4%
All Share
73,271
+0.4%
Resource 10
63,297
-0.1%
Industrial 25
98,419
+0.6%
Financial 15
15,480
+0.6%
All JSE data delayed by at least 15 minutes Iress logo
Company Snapshot
Editorial feedback and complaints

Contact the public editor with feedback for our journalists, complaints, queries or suggestions about articles on News24.

LEARN MORE
Government tenders

Find public sector tender opportunities in South Africa here.

Government tenders
This portal provides access to information on all tenders made by all public sector organisations in all spheres of government.
Browse tenders