iPhoneDevSDK Details What Led to Apple, Facebook Hacking

In January, a number of Apple employees had their Macs compromised following visits to the popular iPhoneDevSDK forum. Employees from Facebook and likely dozens of other companies were compromised as well. In a blog post today, site owner Ian Sefferman shared some limited details* about what happened and what the site is doing about it.

Most notably, the attack was reportedly ended by the hacker on January 30, 2013, meaning the site believes that there is no ongoing threat.

Iphonedevsdk

What we've learned is that it appears a single administrator account was compromised. The hackers used this account to modify our theme and inject JavaScript into our site. That JavaScript appears to have used a sophisticated, previously unknown exploit to hack into certain user's computers.

We're still trying to determine the exploit's exact timeline and details, but it appears as though it was ended (by the hacker) on January 30, 2013.

As with Facebook, it's important to stress that we have no reason to believe user data was compromised.

Eric Romang has done some additional detective work on the the attack, laying much of the blame on Java itself. Last month, Apple twice blocked Java 7 from working on users' Macs, perhaps after the company discovered that its own machines had been compromised.

* URL to blog post: http://iphonedevsdk.com/forum/site-news-announcements/111889-iphonedevsdk-compromised-what-happened-and-how-we-are-dealing-with-it.html -- We've avoiding linking it due to the recent hack at that site.

Popular Stories

AirPods Pro Firmware Feature

Apple Releases New Firmware for AirPods Pro 2, AirPods Pro 3, and AirPods 4

Thursday November 13, 2025 11:35 am PST by
Apple today released new firmware designed for the AirPods Pro 3, the AirPods 4, and the prior-generation AirPods Pro 2. The AirPods Pro 3 firmware is 8B25, while the AirPods Pro 2 and AirPods 4 firmware is 8B21, all up from the prior 8A358 firmware released in October. There's no word on what's include in the updated firmware, but the AirPods Pro 2, AirPods 4 with ANC, and AirPods Pro 3...
CarPlay Pinned Messages

iOS 26.2 Adds New CarPlay Setting

Thursday November 13, 2025 6:48 am PST by
iOS 26 extended pinned conversations in the Messages app to CarPlay, for quick access to your most frequent chats. However, some drivers may prefer the classic view with a list of individual conversations only, and Apple now lets users choose. Apple released the second beta of iOS 26.2 this week, and it introduces a new CarPlay setting for turning off pinned conversations in the Messages...
Tesla Charging

Tesla Working to Add Apple CarPlay Support to Vehicles

Thursday November 13, 2025 8:31 am PST by
Tesla is working to add support for Apple CarPlay in its vehicles, Bloomberg's Mark Gurman reports. Tesla vehicles rely on its own infotainment software system, which integrates vehicle functions, navigation, music, web browsing, and more. The automaker has been an outlier in foregoing support for Apple CarPlay, which has otherwise become an industry standard feature, allowing users to...
iPhone Pocket Short

iPhone Pocket Now Available to Order, But Already Selling Out

Friday November 14, 2025 6:20 am PST by
Apple recently teamed up with Japanese fashion brand ISSEY MIYAKE to create the iPhone Pocket, a limited-edition knitted accessory designed to carry an iPhone. iPhone Pocket is available to order on Apple's online store starting today, in the United States, France, China, Italy, Japan, Singapore, South Korea, and the United Kingdom. However, it is already completely sold out in the United...
tvOS 26 Profiles

tvOS 26.2 Adds a Useful New Feature to Your Apple TV

Friday November 14, 2025 10:02 am PST by
Starting with the upcoming tvOS 26.2 update, currently in beta, additional profiles created on the Apple TV no longer require their own Apple Account. In the Settings app on the Apple TV, under Profiles and Accounts, anyone can create a new profile by simply entering a name and indicating whether the profile is for a kid. The profile will be associated with the primary user's Apple Account,...
homepod mini thumb feature

New HomePod Mini, Apple TV, and AirTag Were Expected This Year — Where Are They?

Wednesday November 12, 2025 11:42 am PST by
While it was rumored that Apple planned to release new versions of the HomePod mini, Apple TV, and AirTag this year, it is no longer clear if that will still happen. Back in January, Bloomberg's Mark Gurman said Apple planned to release new HomePod mini and Apple TV models "toward the end of the year," while he at one point expected a new AirTag to launch "around the middle of 2025." Yet,...
iOS 26

iOS 26.2 Available Next Month With These 8 New Features

Tuesday November 11, 2025 9:48 am PST by
Apple released the first iOS 26.2 beta last week. The upcoming update includes a handful of new features and changes on the iPhone, including a new Liquid Glass slider for the Lock Screen's clock, offline lyrics in Apple Music, and more. In a recent press release, Apple confirmed that iOS 26.2 will be released to all users in December, but it did not provide a specific release date....
m1 chip slide

Five Years of Apple Silicon: M1 to M5 Performance Comparison

Monday November 10, 2025 1:08 pm PST by
Today marks the fifth anniversary of the Apple silicon chip that replaced Intel chips in Apple's Mac lineup. The first Apple silicon chip, the M1, was unveiled on November 10, 2020. The M1 debuted in the MacBook Air, Mac mini, and 13-inch MacBook Pro. The M1 chip was impressive when it launched, featuring the "world's fastest CPU core" and industry-leading performance per watt, and it's only ...
walmart new ornametns

Walmart Black Friday Deals Begin Today With Low Prices on Headphones, TVs, and More

Friday November 14, 2025 7:55 am PST by
Walmart's Black Friday sale has officially kicked off today, with an online shopping event that's also seeing some matching deals in retail locations. There are quite a few major discounts in this sale, including savings on headphones, TVs, and more. Note: MacRumors is an affiliate partner with Walmart. When you click a link and make a purchase, we may receive a small payment, which helps us...
iOS 26

Everything New in iOS 26.2 Beta 2

Wednesday November 12, 2025 3:29 pm PST by
Apple today provided developers with the second beta of iOS 26.2, which adds a few new features worth knowing about. Measure App Apple's Measure app now features a Liquid Glass design for the level, with two Liquid Glass bubbles instead of white circles. Games App There's now an option to sort games in the Games app Library by size, in addition to Name and Recent. CarPlay The...

Top Rated Comments

newagemac Avatar
166 months ago
Is it Java or Javascript? Those are two entirely different things. Java is a plugin with security holes and can be disabled. Javascript is not Java in any way, shape, or form and is not a plugin. It is now as basic to the web as HTML and CSS. You shouldn't disable Javascript unless you want to break pretty much any modern website.

One of the dumbest things ever done on the web was giving it the name of "Javascript". Why the heck there hasn't been a movement to change the name puzzles me.
Score: 12 Votes (Like | Disagree)
iGrip Avatar
166 months ago
Insecure?

So lots and lots of big giant companies were hacked. It was the fault of some third party.


But all we hear about is that Apple was hacked! Apple has lousy security! Anybody who owns any Apple anything is in SERIOUS DANGER! Run for the hills, but only after destroying all Apple products!

Typical. Apple is just the whipping boy of the mainstream media.

They go into a frenzy and let everybody else have a pass. But not Apple. They act like it is all Apple's fault. They pick on Apple. It is not FAIR! Apple is a scapegoat. Everybody who owns any Apple anything is seen as a lesser person because of this stuff. A complete and total idiot.

I for one am sick of it.

/s

----------

Well, I use Safari with Java disabled, AdBlock, and Click to Flash. I had been thinking of adding one of the NoScript extensions, but haven't gotten around to it yet. Unfortunately, I got suckered in by a Phishing attempt a few days ago (it's no longer safe to check your email before you're fully awake...) and am wondering what to do about it.

Change all of the affected passwords. Close any credit card accounts that were compromised. If you gave your SS number, there is nothing that can be done about that.
Score: 4 Votes (Like | Disagree)
Sean4000 Avatar
166 months ago
and THIS is why "noscript" is mandatory on all of my company's computers.
Score: 4 Votes (Like | Disagree)
jlgolson Avatar
166 months ago
Is it Java or Javascript? Those are two entirely different things.
Apparently they used a JavaScript exploit to inject Java code. It's all a little unclear at the moment. Hopefully Facebook or (less likely) Apple will post a play-by-play going into exactly what happened at some point.
Score: 3 Votes (Like | Disagree)
SeattleMoose Avatar
166 months ago
After all this java stuff, I went into Safari and disabled Java (not JavaScript) and guess what? Safari is INDEED snappier!!! (no joke...it really is).

And I agree with a previous poster, Apple is the media's favorite whipping boy right now. Wallstreet's lapdog, the media, is being used to manipulate AAPL stock prices via fear and gloom. When they have driven it down low enough...the sharks will buy-up AAPL yet again...run a bunch of positive articles (PUMP)...followed by yet another DUMP when it gets to their target "high" value. Then they'll place puts on AAPL, run more gloom and doom stories, and make money on the way down too. And then you have Einhorn, the hedge fund "humanitarian" who simply wants to raid the APPL cash pile for his elite clients. It has already been proven that AAPL stock volatility was tied directly to hedge fund manipulation. Expect more...unfortunately. Wallstreet is just a steaming pile.
Score: 2 Votes (Like | Disagree)
PinoyAko Avatar
166 months ago
The Java update yesterday was magical and revolutionary. :apple:
Score: 2 Votes (Like | Disagree)