Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

icloud_icon_blueEarlier today, Apple issued a press release stating that an iCloud/Find My iPhone breach had not been responsible for the leak of several private celebrity photos over the weekend, instead pointing towards a "very targeted attack on user names, passwords, and security questions" hackers used to gain access to celebrity accounts.

The company did not divulge specific details on how hackers accessed the iCloud accounts, leading Wired writer Andy Greenberg to investigate the methods that hackers might possibly have used to acquire the stolen media.

Greenberg visited Anon-IB, a popular anonymous image board where some of the celebrity photos first originated, and discovered that hackers openly discuss exploiting software designed for law enforcement and government officials. Called ElcomSoft Phone Password Breaker (EPPB), the software in question lets hackers enter a stolen username and password to obtain a victim's full iPhone/iPad backup.

"Use the script to hack her passwd...use eppb to download the backup," wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. "Post your wins here ;-)"

Acquiring just a user name and password allows hackers access to content on iCloud.com, but with the accompaniment of the ElcomSoft software, a complete backup can reportedly be downloaded into easy-to-access folders filled with the device's contents.

According to security researcher Jonathan Zdziarski, who spoke to Wired, metadata from some of the leaked photos is in line with the use of the ElcomSoft software and possibly the iBrute software, which exploited a vulnerability in Find My iPhone to allow hackers unlimited attempts to guess a password. Apple has, however, patched the exploit, and has suggested iBrute was not a factor in the attacks.

As noted by TechCrunch, using ElcomSoft's software to download an iPhone's backup successfully circumvents two-factor verification as the two-factor authentication system does not cover iCloud backups or Photo Stream.

Two-factor verification can make it much more difficult for hackers to acquire a user's login credentials in the first place, preventing many attacks, but an iCloud backup can be installed with just a user name and a password.

twostepverification
The ElcomSoft software does not require any credentials to buy and while it costs $399, it is also available on bittorrent sites. The vulnerability in iCloud backups has been known for some time, with ElcomSoft's own CEO pointing towards the lack of two-factor authentication for iCloud backups back in May of 2013.

Apple has explored expanding two-factor authentication to some iCloud services, but an official expansion of the security feature has not yet been introduced.

Top Rated Comments

(View all)
Avatar
80 months ago
The Fappening 2014. Never forget
Score: 25 Votes (Like | Disagree)
Avatar
80 months ago
It seems there are no end if tricks available to the scumbags out there willing to do hurtful things.

However, bottom line (pun intended) is, if you want nude snaps of yourself, fine, take some, but don't keep them on your phone or in the cloud where they are most vulnerable.

While I have some sympathy for the victims, I also believe ignorance is not really an excuse these days.

People have to accept more responsibility for their actions, even if the consequences are far beyond what they initially imagined. The sad fact is in our cottonwool society is far easier to blame everyone else for everything than accept some responsibility personally. If you don't agree then you're part of the problem.
Score: 17 Votes (Like | Disagree)
Avatar
80 months ago
The ripping process, which has been going on for months:




Lots of security holes here, including weak password reset verification questions.
Score: 17 Votes (Like | Disagree)
Avatar
80 months ago
I think you need to change the headline for this article, so you are not claiming that someones opinion is fact.

Hackers Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication

Should be changed to:

Hackers May Be Using Law Enforcement Tools to Access iCloud Backups Unprotected by Two-Factor Authentication
Score: 16 Votes (Like | Disagree)
Avatar
80 months ago
If, and that obviously is an IF, that is what happened then Apple should not claim that the images were not stolen due to weaknesses in their security. In fact, this is an even bigger potential hole in their security in my opinion. And to those who want to make it the victims fault that these photos were stolen: You are messed up in the head.
Score: 14 Votes (Like | Disagree)
Avatar
80 months ago
Interesting timing with Apple about to come out with a mobile payments system.
Score: 14 Votes (Like | Disagree)

Top Stories

First Impressions From New iPhone 12 and 12 Pro Owners

Thursday October 22, 2020 4:20 pm PDT by
It's already Friday, October 23, in Australia and New Zealand, which means some customers who purchased an iPhone 12 or 12 Pro already have their new devices in hand. We've seen dozens of reviews of the iPhone 12 and iPhone 12 Pro from media sites, but now first impressions from regular Apple customers are available. Image via MacRumors reader Boardiesboi New iPhone 12 and 12 Pro owners are...

New Photos Offer Better Look at iPhone 12 Color Options

Tuesday October 20, 2020 2:34 am PDT by
As we wait for the iPhone 12 review embargo to lift later today, more pictures are circulating of the devices in real-world lighting conditions, providing a better look at the different colors available. Leaker DuanRui has shared images on Twitter of the iPhone 12 in white, black, blue, green, and (PRODUCT)RED. The black and white colors are similar to the iPhone 11 colors, but the other...

Photographer Austin Mann Tests the iPhone 12 Pro's Camera

Wednesday October 21, 2020 4:14 am PDT by
Travel photographer Austin Mann usually performs an in-depth review of new iPhone models to test their camera performance in real-world scenarios. To test Apple's new iPhone 12 Pro, Mann traveled to Glacier National Park, Montana. Mann focused on some of the biggest camera upgrades with the iPhone 12 Pro, including the upgraded Wide lens, Ultra Wide Night mode, and LiDAR autofocus, across a...

iPhone 12 Pro Max Has Smaller 3,687 mAh Battery According to Regulatory Filing

Tuesday October 20, 2020 8:48 pm PDT by
Apple's new iPhone 12 Pro Max is equipped with a 3,687 mAh battery, which is around 7% less capacity than the 3,969 mAh battery in the iPhone 11 Pro Max, according to a regulatory filing published by TENAA, the Chinese equivalent of the FCC. The regulatory filing, spotted by MacRumors, also lists the iPhone 12 Pro Max with 6GB of RAM as seen in benchmark results last week. Apple has filed ...

5G Drains iPhone 12 Battery 20% Faster Than 4G in Benchmark

Wednesday October 21, 2020 3:17 am PDT by
After the first reviews for the iPhone 12 and iPhone 12 Pro emerged yesterday, a new report by Tom's Guide reveals the extent of battery life reductions when using 5G. The report outlines a test wherein the iPhone surfs the web continuously at 150 nits of screen brightness, launching a new site every 30 seconds until the battery drains. Interestingly, the test was run on an iPhone 12 and...

Teardown Video Confirms iPhone 12 and iPhone 12 Pro Use Same 2,815mAh Battery

Thursday October 22, 2020 9:47 am PDT by
With the iPhone 12 launching on Friday and in just a few hours to Australia and New Zealand, hands-on videos, teardowns, reviews, and other iPhone-related content has been coming out. A new teardown video delves into both the iPhone 12 and the 12 Pro, confirming battery life for both models and giving us a closer look at their internals. The video from Io Technology is in Chinese, but ...

French iPhone Boxes Come Packed in an Outer Box With Separate EarPods

Wednesday October 21, 2020 6:52 am PDT by
After the news that France would be the only territory to continue to include EarPods with the iPhone, it seems that Apple is not packing the earbuds within the iPhone's box (via iGeneration). Screenshot from TheiCollection's review video The French iPhone 12 and iPhone 12 Pro does not have a different retail box to accommodate EarPods, meaning that all iPhone boxes are consistent...

Some Defective Apple iPhone 12 Cases Shipping Without Speaker Holes

Wednesday October 21, 2020 12:54 pm PDT by
At least two customers who have purchased iPhone 12 cases have received defective cases that do not have speaker holes, which obscures the sound. Photo by Reddit user zarnold16 There have been two separate threads on Reddit from iPhone 12 customers who purchased a case and received one without speaker holes. One customer was told by an Apple advisor that the case wasn't meant to have...

Watch: New iPad Air Unboxing Videos and First Impressions

Wednesday October 21, 2020 6:00 am PDT by
Apple's embargo has lifted on reviews for the new iPad Air ahead of its launch on Friday. In addition to our more detailed review roundup, we've shared a handful of unboxing videos and first impressions of the device below. The new iPad Air via Karl Conrad The new iPad Air features a larger 10.9-inch edge-to-edge display, a faster A14 Bionic chip, and a USB-C port instead of Lightning. It is...

Apple's AirTags Revealed in Newly Published Patent Applications

Thursday October 22, 2020 9:13 am PDT by
Two patent applications filed by Apple appear to depict the company's widely expected AirTags item trackers (via Patently Apple). The filings, which include a large number of images, are titled "Mounting Base for a Wirelessly Locatable Tag" and "Fastener with a Constrained Retention Ring," and describe a wirelessly locatable tag that can be used to determine the absolute location of an...