Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Privacy Security Apple Your Rights Online

FBI Investigating iPad E-Mail Leaks 209

CWmike writes "The Federal Bureau of Investigation has opened an investigation into the leak of an estimated 114,000 Apple iPad user e-mail addresses. Hackers belonging to a group called Goatse obtained the e-mail addresses after uncovering a web application on AT&T's website that returned an iPad user's e-mail address when it was sent specially written queries. After writing an automated script to repeatedly query the site, they downloaded the addresses, and then handed them over to Gawker.com. Now the FBI is trying to figure out whether this was a crime. US law prohibits the unauthorized accessing of computers, but it is unclear whether the script that the Goatse group used violated the law, said Jennifer Granick, civil liberties director with the Electronic Frontier Foundation. 'The question is, when you do an automated test like this, [are you] getting any type of unauthorized access or not,' she said. If it turns out the data in question was not misused, it is unlikely that federal prosecutors will press charges, she added."
This discussion has been archived. No new comments can be posted.

FBI Investigating iPad E-Mail Leaks

Comments Filter:
  • by arkenian ( 1560563 ) on Thursday June 10, 2010 @11:12PM (#32531422)

    These guys aren't hackers. They are security advisors. They are the good guys. I suppose the editors didn't bother, you know, clicking a few links? Here, I've done your homework. Was it that hard?

    I'm sorry, but googling 'goatse' was not on the list of activities I had planned for the night. I mean, seriously? This said, you have my admiration for your fortitude and thanks for the sacrifices for the cause.

    Also, really, with a name like 'goatse' most people aren't going to automatically leap to the idea of it being a white-hat group.

  • assholes (Score:5, Insightful)

    by xaoslaad ( 590527 ) on Thursday June 10, 2010 @11:14PM (#32531426)
    This country is so egregiously fucked up it isn't funny. AT&T puts 114,000+ users info on the internet and that's OK. No investigation. Someone pulls it from their site and they get hunted down like a witch.

    FUCKED! UP!
  • by DJRumpy ( 1345787 ) on Thursday June 10, 2010 @11:18PM (#32531442)

    I don't know if I would call them journalists:
    Title: Apple's Worst Security Breach
    "Apple has suffered another embarrassment. A security breach has exposed iPad owners including dozens of CEOs, military officials, and top politicians. They—and every other buyer of the cellular-enabled tablet—could be vulnerable to spam marketing and malicious hacking."

    This is squarely AT&T's fault, yet the first paragraph implies it was "Apple Worst Security Breach". I also like how they imply that a spammer getting your e-mail address is the be-all-end-all of hacking. Really? These folks have never seen spam before? How will they venture out onto the internet without feeling exposed and dirty? Oh wait. They get a new e-mail address. *sigh*

  • by rolfwind ( 528248 ) on Thursday June 10, 2010 @11:22PM (#32531456)

    Hacker is not a term that means you are the bad guy although it conjures the fear in the ignorant (i.e. the general public). It just meant someone who hacks.

    This was a hack.

    http://en.wikipedia.org/wiki/Hack_(technology) [wikipedia.org]

  • by Wuhao ( 471511 ) on Thursday June 10, 2010 @11:25PM (#32531462)

    I have to admit, I had to ignore years of experience with Internet forums to follow a link to "goatse.fr."

  • by Fartypants ( 120104 ) on Thursday June 10, 2010 @11:32PM (#32531504)

    These guys aren't hackers. They are security advisors. They are the good guys.

    So, if you were one of the people who had their personal email leaked, would you be thanking the good guys right now for doing it? It's sort of like if a security consultant pushed somebody through a broken railing to "demonstrate" the flaw in security. Couldn't they have just called AT&T and pointed it out? Or would that not have been rad enough?

  • "Not misused"? (Score:1, Insightful)

    by Anonymous Coward on Thursday June 10, 2010 @11:37PM (#32531534)

    How is handing email addresses over to Gawker (i.e. a third party) anything other than misusing them?

  • by manicbutt ( 162342 ) on Friday June 11, 2010 @12:09AM (#32531692)

    It's not a hack, it's only indirectly related to Apple (despite Gawker's attempts to paint it otherwise), and the government email addresses that were "exposed" are public anyway. It's not difficult for me to send email to Rahm Emanuel. Goatse's brute force script isn't that interesting (see http://praetorianprefect.com/archives/2010/06/114000-ipad-owners-the-script-that-harvested-their-e-mail-addresses/ [praetorianprefect.com]) so why are we wasting so much time on this non-story?

  • by Anonymous Coward on Friday June 11, 2010 @12:13AM (#32531720)

    A white hat would see the hole, download a few to verify, write a script as a proof of concept and verify that the script worked, and then report the hole to AT&T. Downloading over 100,000 email addresses and sending them to the press is NOT what responsible security researchers do.

  • Re:assholes (Score:2, Insightful)

    by Simmeh ( 1320813 ) on Friday June 11, 2010 @12:17AM (#32531746)
    Agreed, if this happened in Europe there could have been an investigation into the failure to protect the users data. Instead, a group who made the flaw public is being investigated. Fact is, they might not of been the first to harvest this data, not that AT&T will ever admit otherwise.
  • by aliquis ( 678370 ) on Friday June 11, 2010 @01:26AM (#32532052)

    I like how they seem to think it's amazing to get some of those e-mail addresses, I mean, come on, just look at it:
    http://cache.gawkerassets.com/assets/images/7/2010/06/500x_ileakinside3.jpg [gawkerassets.com]
    Do you think Les Hintons e-mail address may be les.hinton@dowjones.com ?!

    Top secret!

  • by SoupIsGoodFood_42 ( 521389 ) on Friday June 11, 2010 @01:31AM (#32532074)

    You think if Vodafone got a bunch of iPads and was selling them at $1 on a 5 year plan that apple wouldn't shit itself?

    As long as Vodafone paid Apple what they agreed upon, I doubt Apple would care. Why would they?

    The security breach was with AT&T, because it was on their servers and only affected their customers.

  • Sensible l (Score:2, Insightful)

    by Anonymous Coward on Friday June 11, 2010 @05:27AM (#32533062)
    THIS is a serious breach of privacy, and yet releasing the IPs of people accused of downloading a torrent is cool with the authorities, media, and seemingly everyone else? Do we really want to be turning to 4Chan for insight into how fucked our system is? http://i.imgur.com/LgjPH.jpg [imgur.com]
  • Re:No relation (Score:3, Insightful)

    by Goaway ( 82658 ) on Friday June 11, 2010 @09:56AM (#32534778) Homepage

    There were plenty of much more responsible ways to get that vulnerability fixed. That was clearly not the intent of the people involved, since they chose this course of action rather than a responsible one.

  • by mcgrew ( 92797 ) * on Friday June 11, 2010 @10:26AM (#32535182) Homepage Journal

    Language evolves, whether we like it or not. I used to be a gay hacker untill they changed the meaning of "gay" and "hacker", now I'm just a happy nerd.

    Changing the meaning of "hacker" only affects us, but when they changed "gay" it affected hundreds of years of song and poetry -- "Deck the Halls" for example. I have an MP3 I ripped from an old 78 with lyrics "gay as a New Year's party"; it has a completely different meaning today than it did in my dad's youth, because the meaning of the word has changed.

    We just have to live with it. I blame Hollywood for the change in "hacker". Blame gays for the change of "gay".

Scientists will study your brain to learn more about your distant cousin, Man.

Working...