Apple iCloud cracked by Russian hacker Vladimir Katalov

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Read more at ZDNet: Apple's iCloud cracked: Lack of two-factor authentication allows remote data download

Katalov's findings appear to support his emphatic statement that Apple can access data it claims to not be able to access.

A malicious attacker only needs an Apple ID and password to perform remote iCloud backups — and do not need the user's linked devices.

He explained that there is no way for a user to encrypt their iCloud backups.

The data is encrypted, he explained, but the keys are stored with the data. Katalov added that Apple holds the encryption keys.

Katalov told ZDNet he was shocked to discover that in addition to all of these security chain issues, Apple's iCloud data is stored on Microsoft and Amazon servers.

[...]

When asked if he had presented his discoveries to Apple, he explained that his findings were the results of protocol analysis — and are not a vulnerability.

Put another way, the iCloud security hole falls into the "it's a feature, not a bug" category.
 

Ink

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Do you use the iCloud service?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top