Man Steals 620K Photos From iCloud Accounts Without Apple Noticing (latimes.com) 74
An anonymous reader quotes a report from The Los Angeles Times: A Los Angeles County man broke into thousands of Apple iCloud accounts and collected more than 620,000 private photos and videos in a plot to steal and share images of nude young women, federal authorities say. Hao Kuo Chi, 40, of La Puente, has agreed to plead guilty to four felonies, including conspiracy to gain unauthorized access to a computer, court records show. Chi, who goes by David, admitted that he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords, according to court records. He gained unauthorized access to photos and videos of at least 306 victims across the nation, most of them young women, he acknowledged in his plea agreement with federal prosecutors in Tampa, Fla.
Chi said he hacked into the accounts of about 200 of the victims at the request of people he met online. Using the moniker "icloudripper4you," Chi marketed himself as capable of breaking into iCloud accounts to steal photos and videos, he admitted in court papers. Chi acknowledged in court papers that he and his unnamed co-conspirators used a foreign encrypted email service to communicate with each other anonymously. When they came across nude photos and videos stored in victims' iCloud accounts, they called them "wins," which they collected and shared with one another. "I don't even know who was involved," Chi said Thursday in a brief phone conversation. He expressed fear that public exposure of his crimes would "ruin my whole life."
The scam started to unravel In March 2018. A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure in Tampa, Fla., that nude photos of the person had been posted on pornographic websites, according to [FBI agent Anthony Bossone]. The victim had stored the nude photos on an iPhone and backed them up to iCloud. Investigators soon discovered that a log-in to the victim's iCloud account had come from an internet address at Chi's house in La Puente, Bossone said. The FBI got a search warrant and raided the house May 19. By then, agents had already gathered a clear picture of Chi's online life from a vast trove of records that they obtained from Dropbox, Google, Apple, Facebook and Charter Communications. On Aug. 5, Chi agreed to plead guilty to one count of conspiracy and three counts of gaining unauthorized access to a protected computer. He faces up to five years in prison for each of the four crimes.
Chi said he hacked into the accounts of about 200 of the victims at the request of people he met online. Using the moniker "icloudripper4you," Chi marketed himself as capable of breaking into iCloud accounts to steal photos and videos, he admitted in court papers. Chi acknowledged in court papers that he and his unnamed co-conspirators used a foreign encrypted email service to communicate with each other anonymously. When they came across nude photos and videos stored in victims' iCloud accounts, they called them "wins," which they collected and shared with one another. "I don't even know who was involved," Chi said Thursday in a brief phone conversation. He expressed fear that public exposure of his crimes would "ruin my whole life."
The scam started to unravel In March 2018. A California company that specializes in removing celebrity photos from the internet notified an unnamed public figure in Tampa, Fla., that nude photos of the person had been posted on pornographic websites, according to [FBI agent Anthony Bossone]. The victim had stored the nude photos on an iPhone and backed them up to iCloud. Investigators soon discovered that a log-in to the victim's iCloud account had come from an internet address at Chi's house in La Puente, Bossone said. The FBI got a search warrant and raided the house May 19. By then, agents had already gathered a clear picture of Chi's online life from a vast trove of records that they obtained from Dropbox, Google, Apple, Facebook and Charter Communications. On Aug. 5, Chi agreed to plead guilty to one count of conspiracy and three counts of gaining unauthorized access to a protected computer. He faces up to five years in prison for each of the four crimes.
Sort of makes sense (Score:2)
Re: (Score:2)
Re: Sort of makes sense (Score:2)
hope you get the book throw at you (Score:5, Insightful)
He expressed fear that public exposure of his crimes would "ruin my whole life."
You mean like how you happily ruin others lives for profit by exposing nude photos. No matter big a moron they are for keeping that on a phone account you are filthy piece of shit that deserves to have their life ruined for the damage you do all in the name of personal profit.
Re: (Score:2)
You mean like how you happily ruin others lives
I have no sympathy for this scumbag, but it is not true that he ruined the lives of others. The young women were blissfully unaware that their photos had been exposed until investigators informed them. Their lives were unaffected, not "ruined".
Re: (Score:3, Insightful)
Juat a giggle until rejected for a job (Score:2, Interesting)
Indeed. The problem is corporate reactions. And that person in HR used AI search to find the nudes.
Indeed, it may not even be a person in HR. The initial CV scan just automatically searched for nudes of applicants. And not even that. Corporate HR employs a background checking service that simply reports "bad character" with no further details, and the application is rejected.
While women would certainly be annoyed at having nudes they took published, it is most unlikely to directly ruin any lives. Even
Re: (Score:3, Insightful)
Re:Juat a giggle until rejected for a job (Score:4, Insightful)
Most people would find it quite distressing to know that intimate photos of them were shared with strangers, and people they know and work with.
Re: Juat a giggle until rejected for a job (Score:2)
Most people also shouldn't take nude photos of themselves and then sync it to iCloud.
Re: (Score:1)
While women would certainly be annoyed at having nudes they took published, it is most unlikely to directly ruin any lives. Even if work colleagues found out about them, they would have a giggle at the woman's expense, but hardly ruinous.
Not necessarily. It depends on the person. Some people could shrug this sort of thing off and move on, other people could end up with PTSD over this and potentially end up committing suicide because of it. So yes, it could potentially be quite ruinous.
Re:hope you get the book throw at you (Score:5, Insightful)
The young women were blissfully unaware that their photos had been exposed until investigators informed them. Their lives were unaffected, not "ruined".
Some were unaffected. The keyword here is "some".
Out of 306 victims, 200 of which were targeted because someone paid to have those accounts accessed. I'll bet some of those women were affected. After all, who would pay to access their account? Stalkers? Ex-boyfriends? Peeping toms? Celebrity stalkers? We don't know.
And then, there are women who may have shared some of those images with their significant other (or shared their PIN with them). That means that if they saw those images appear online, they might have suspected their partner, or ex-partner.
You really underestimate the impact to women (Score:5, Insightful)
The young women were blissfully unaware that their photos had been exposed until investigators informed them. Their lives were unaffected, not "ruined".
As someone else already pointed out, what if the photos are shared with their kids' classmates? What if they were posted publicly and word go out around their office? Ask your wife or last girlfriend how she'd feel if photos were shared in her office of her blowing you?
It doesn't matter what you or I think. Their privacy was violated. I will bet the impact to them is much greater than you or I realize. I personally love my dick and think it looks nice. I wish I had more opportunity to show it off...maybe you feel the same way...but few women think like I do. No matter how harmless or hot you may think these photos are, these women are probably deeply embarrassed and feel vulnerability you and I will never understand.
There are also many famous news stories about women who were fired after nudes were leaked, often by exes without their consent. I remember stories about court cases involving this going back to the 90s and even a very recent one about a mechanic who was fired because a coworker discovered she had an OnlyFans page and the dealership thought she was "too distracting" and fired her...for what she does in her personal time and never mentioned once in the office, nor was linked to her employer in anyway...because her male coworkers couldn't stop sexually harassing her once they saw her tits online.
But even if your workplace is supportive, will this still be online in 5 years? What if she's a teacher? She has to wonder if every creepy smile from a student or even a dad is related to them seeing her naked. Same thing with any public-facing job: real estate, sales, just being a clerk at the store. I assure you that if your kid's teacher had nude pics online, a large percentage of the moms would get really angry. I am not sure why, but they're unusually threatened by that.
This happened to a friend of mine. She has a distinctive face and tattoos. Her boyfriend uploaded pics of her to a porn site blowing and fucking him and apparently she was pretty popular. She was only 18 when the pics were taken and they were uploaded without her consent, like a year after she broke up with him. She got harassed constantly, once even in front of me, like 3 years after they were taken down. It made her life miserable and the guy never faced any consequences...this was long before "revenge porn" was in the lexicon. I still see her pics sometimes in random searches, now 15 years later. The original site shut down long ago, but the pics live on in file sharing services or just various scam sites that redistribute porn without permission under sketchy URLs.
It's slut shaming, not cancel culture. (Score:3)
Violating the unwritten moral code of your employer has been well established as a cause for firing by the SJW left. It's just because she's a woman and one of the chosen victim groups that you're even defending her.
You're complaining about capitalism, comrade. Cancel culture isn't really a thing in the real world. The famous firings all involved actual written rules, in a contract. Lookup morality clause. However, the only question asked and that matters is "is he/she good for business?"
Most famous cases of "cancel culture" involve money. Kevin Spacey molesting underage boys...hurts ticket sales for your movies. Gina Carano thinking she's like a holocaust victim on Twitter, risks the future of a billion doll
and... (Score:4, Interesting)
Meanwhile, 17 Apple employees that did the same exact thing were not found and did not get prosecuted.
And in other news, Apple tricks over one billion people to upload their private photos without encryption to Apple.
Re: (Score:3)
Also, awesome signature.
Re: (Score:3)
That 306 probably refers to the people with compromizing shots.
Re: (Score:2)
Re: (Score:3, Funny)
Yeah, really. And I guess I'm a dinosaur or something but 306 victims and 620k photos? Jeez, do people you photograph and save every single event in your life? Also, awesome signature.
Well to be fair 310K of those were accidental screen shots.
Re: (Score:2)
Sadly, when you double-accidental screenshot, the second one doesn't include the pop-up on the first one.
I hope these words suffice for what I'm describing because I literally can't show you. lol
Re: (Score:3)
Re: (Score:2, Insightful)
It tricks you by giving you a default "yes" button which it uses dark patterns to you trick you into pressing. And that button is iCloud and it uploads all your photos from past present and future for Apple to have in unencrypted format.
Yes, Apple tricks you into having an insecure password and not two-factor auth. It does this by A) requiring you to type in your password every time you buy something, rather than using autosave like every other app (unless using biometrics); B) by making two-factor auth ann
Re: (Score:1)
you are so fucking stupid and nothing you wrote is correct or true.
Re: (Score:2)
So in your world:
- Constant nags to set up iCloud is not a dark pattern
- Apple encrypts your photos with end-to-end encryption (i.e. the Fappening didn't happen)
- Apple accounts are only secured with strong passkeys like your FileVault 2 key or your Bitcoin wallet
- Everybody poops without taking off their pants
- When people buy a phone they think "this is an 1984 device, I should never do anything private near it"
Re: and... (Score:2)
Re: and... (Score:2)
Re: (Score:2)
17 is an approximate figure.
My source is common sense and related facts.
NSA employees have access to most everybody's emails and phone records on Earth. And they admitted to several cases of employees snooping on lovers https://www.cnet.com/news/nsa-... [cnet.com]
Apple has much more private information available, unencrypted, in its iCloud system. So naturally there at least that many people at Apple tempted to spy on at least their lovers.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Re: (Score:1)
It is completely, absolutely correct that theft requires that the victim be deprived of something.
You can "steal" trade secrets, because after having done so, they no longer have their "secrets." The secrets are gone.
Here, it isn't theft, it is a bunch of other crimes with the main one being, "conspiracy to gain unauthorized access to a computer."
Re: (Score:2)
Re: (Score:2)
The term "identity theft" is hyperbole, though.
And you can think through each example to find out if deprived the victim of something. Only credit theft fits the definition of theft, because I will no longer have my credit score if you impersonate me to use that.
Usually, "identity theft" is actually fraud. Not theft. And theft of the items the person ends up with, because the store no longer has those items, and the payments are likely to be reversed.
Re: (Score:2)
Re: (Score:2)
Re: Technically he did not steal the photos (Score:2)
Re: (Score:2)
...since they gave him their passwords.
When can we get beyond passwords for logging in so this ends? I know why we started with passwords but we can move beyond them now. Fingerprints, facial recognition, pseudorandom number generators, and so many other means to secure accounts are available now that stealing passwords should be history.
I've had people ask me why a high tech person like myself won't do online banking. I won't do it because I've seen how lax they are on security. When the banks start giving out pseudorandom number keychains
Start getting rid of passwords with WebAuthn (Score:2)
> When can we get beyond passwords for logging in so this ends? I know why we started with passwords but we can move beyond them now.
You can begin the transition away from passwords right now.
Well, hopefully you've already switched to passphrases, but that's almost the same. There are two ways to start going password-free.
WebAuthn is the new suite of protocols to get rid of passwords. It allows you to choose your authenticator, so you can use biometric + a hardware key or whatever you choose.
Currently, W
I feel like (Score:2, Insightful)
A solution exists: ICDL (Score:2)
International Certification of Digital Literacy (ICDL) [icdleurope.org]
Should be a basic requirement for non-trivial use of digital devices and services.
oh noez (Score:2)
Why should anyone care about his life getting ruined when he tried to or succeeded in ruining other people's lives? He has no empathy for others, yet expects a bunch when he's in a predicament.
It's the 'Murikan way! (Score:2)
Sigh! Hackers these days . . . (Score:3)
Investigators soon discovered that a log-in to the victim's iCloud account had come from an internet address at Chi's house in La Puente, Bossone said.
Smart enough to rip people off, not smart enough to use a VPN or Tor.
620K (Score:2)
should be enough for anyone.
I guess Apple really only cares what you upload. (Score:2)
Downloads, not so much.
Downloads probably aren't "scanned" for "inappropriate" content either.
So it goes.
"Without Apple Noticing"? (Score:5, Insightful)
He didn't break in. He phished his way in on such a small scale I wouldn't expect Apple to notice. If they had, and had initiated any response, the false positives would be incredibly annoying for the innocent.
Re: (Score:2, Insightful)
Apple seems to make very little effort to secure customer accounts. If you don't have 2FA set up on Google they bug you about it until you relent, and you get multiple notifications (every Android device and email and SMS if you registered your number) when a new machine logs in for the first time.
Apple seems happy with just an email address and password, and doesn't even seem to enforce minimum standards for password complexity.
Re: (Score:2)
Minimum password complexity is the responsibility of the user.
Re: (Score:1)
I'm sure Apple would agree, which is the problem. They built a service that contains all your private data, heavily marketed it, and then made only the most superficial attempt to secure it.
Re: (Score:2)
You hypothesize a sub-scenario based on an assumption, and then ask me to defeat it ("He probably"), as if that would defeat the whole argument.
https://en.wikipedia.org/wiki/... [wikipedia.org]
fear exposure of crimes would ruin his whole life (Score:3)
Re: (Score:2)
Wasn't the wide availability of porn suppose to reduce stuff like this from happening?
Re: (Score:3)
Re: (Score:1)
They're not getting rid of nudity.
Re: (Score:2)
Re: (Score:2)
620K? (Score:2)
nude young women? yeah, right. (Score:2)
"... in a plot to steal and share images of nude young women,
That was what he told the police.
What he really wanted was to find images of nude old men.
Can we get a drill sgt in here? (Score:3)
Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords
People are told, repeatedly, "We will not ask for your password", everyone is told "Do not give out your password". It says on the fucking site "Never provide your password, security questions, verification codes, recovery key, or any other account security details to anyone else. Apple will never ask you for this information." [apple.com]
People who give out their passwords should be treated to a recreation of the footlocker scene from Full Metal Jacket and the subsequent ass-beating.
Nothing to see here... (Score:4, Insightful)
>he impersonated Apple customer support staff in emails that tricked unsuspecting victims into providing him with their Apple IDs and passwords
All the security in the world won't help if you hand your keys to the first moron who comes along claiming he's a locksmith.
Re: (Score:2)
Repeat offender (Score:1)