Commentary

Ed Hansberry
 

114,000+ 3G iPad User Emails Exposed

Adding to AT&T's troubled reputation is the recent security breach with iPad 3G users accounts. It has been labeled the worst security breach in Apple's history and it is a breach that was beyond Apple's control as it all happened on AT&T's servers. The list of who was exposed is a veritable who's who list of politicians, corporate executives and celebrities, along with the average Joe here and there.

Adding to AT&T's troubled reputation is the recent security breach with iPad 3G users accounts. It has been labeled the worst security breach in Apple's history and it is a breach that was beyond Apple's control as it all happened on AT&T's servers. The list of who was exposed is a veritable who's who list of politicians, corporate executives and celebrities, along with the average Joe here and there.Gawker was given data by a security firm called Goatse Security (yes, that Goatse). It is a list of about 114,000 user accounts with the email address associated with it. Gawker suggests though that it is possible all 3G iPad owner's email addresses may have been obtained.

It is an interesting list of people. White House Chief of Staff Rahm Emanuel's email was listed, as was Diane Sawyer's, Mayor Michael Bloomberg's, and the CEO's and executives of companies like The New York Times, Time Inc. and Dow Jones. More than a few high ranking military personnel were also listed, like Colonel William Eldridge, commander of the largest B-1 bomber squadron currently operational in the US. I hope these guys were using the devices for innocuous things like web browsing and reading ebooks, not using it for communicating or storing sensitive information.


More Mobility Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

The hack looks pretty straight forward. As Gawker explains it, each iPad has an integrated circuit card identifier, or ICC-ID. When that was fed into a specific URL, AT&T's web server would return the email address associated with the ICC-ID. Once you have once ICC-ID, you just need to write a script to start incrementing the numbers and feed them to the server waiting for the results to spew out like oil from a broken well.

AT&T has since closed the security hole, but the damage has been done. Assuming only email addresses were harvested, the worst case scenario is an increase in spam, spam which can be targeted to people with iPads and likely iPhones, Mac's and other high end tech gear. When you can craft emails so specifically, social engineering more likely to be successful.

That doesn't begin to cover the damage caused to AT&T's already embattled reputation, and it certainly puts a black spot on Apple's reputation, which as far as security goes, has been pretty stellar.

If you only have a WiFi iPad, you needn't worry as AT&T doesn't have your account information. iPhone accounts too appear to be unaffected. However, if you are an iPad 3G user in the US on AT&T's network check your email. There is a good chance you'll see two things. First an apology from AT&T alerting you to the breach. Secondly, you will probably see an increase in spam.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links