icloud hero

Twitter, Reddit and several other social networks are blowing up this evening with talk of a major nude celebrity photo leak. The trove first appeared on 4chan’s /b/ thread earlier today, and it includes Academy Award winner Jennifer Lawrence and several others.

The pictures were allegedly retrieved through a vulnerability in Apple’s iCloud service, which allowed the celebrities’ phones to be hacked. Thus far, no one has confirmed that iCloud was actually breached, and few details are known about the attack, or the attacker.

Many of the celebrities named in the leak have taken to Twitter to comment on the matter. Some of them, such as Victoria Justice, are disputing the authenticity of the photos, while others, including Jennifer Lawrence (well, her PR agent), have confirmed their legitimacy.

Again, it hasn’t been established that this was the result of an iCloud hack. In a comment, actress Mary Elizabeth said “knowing those photos were deleted long ago, I can only imagine the creepy effort that went into this,” suggesting this may have not been the case.

That being said, Apple has been criticized for iCloud’s security multiple times in the past, and an attack did take down its developer center for several weeks last summer. If the reports are true, what a terrible time for bad PR, just ahead of next month’s iPhone event.

[Mashable, BuzzFeed]

    Apple encrypts photos being sent and stored on the server with AES-128. The only way this would be possible is if someone from Apple internally leaked these photos by gaining access to the master server certificate but I would guess that’s pretty hard to do

    I also see a galaxy note in some of the photos. With the stuff Samsung has done in the past I wouldn’t be surprised, especially when we are so close to the iPhone 6 keynote.

    Basically no one has proof that iCloud is the cause of this

        Please stop being such an Apple fanboy and acknowledge the fact: Apple WAS hacked. NOTHING is actually very, very, secure, and Apple is not an exception.
        For their prices, at least, they could take responsabilities for their screw-up and admit it.

    • iCloud isn’t even the problem. Many blogs and news websites are suggesting the problem is a flaw with FindMyiPhone that allowed the bruteforcing of password. A proof of concept known as iBrute exists on GitHub. Even with this tool though two-step-authentication and strong passwords would easily prevent any security breaches.

      TLDR; Celebrities need to improve their security online and use more secure passwords and perhaps encrypt ‘sensitive’ photographs. Of course none of them will likely do this so I don’t know why I’m even writing this…

  • toortoor

    “Again, it hasn’t been established that this was the result of an iCloud hack. In a comment, actress Mary Elizabeth said “knowing those photos were deleted long ago, I can only imagine the creepy effort that went into this,” suggesting this may have not been the case.”

    or, apple keeps your photos even after you delete them :), where else? “creepy efforts” is not an image recovery app 😉

    Well, almost all pictures are real, since they are geotagged to places related to the particular celebrity, even if they say they are fake, you can prove it yourself with the metadata. However some folders of the leak come with the getting started dropbox pdf, it could be another cloud service that has permission to the camera roll that got hacked, also that would explain all the android devices being involved.

  • Chris Longden

    It’s either Dropbox, Google Drive or OneDrive…. all 3 can auto-upload the images and work on iOS/android….

  • chris125

    And people wonder why users want more on board storage and not have to rely on the “cloud”

    Regarding data security:

    Nothing is “impossible” to get into.

    Some things can be made greatly difficult to get into.

    U.S. diplomats are advised not to use personal devices when going outside of the States and to use the attitude that their phones will be accessed by outside forces (camera, mic, etc).

    And although it’s beyond the discussion of private citizens gaining access to phones it goes without saying that there are those that can access practically anything (NSA).

  • Helen Ben

    Of course, they wouldn’t admit that there is a flaw in their software. However, as far as I am concerned, celebrities still stupid enough to fill their phones with nude pictures. I think it’s still safe to use Apple’s iPhone even if some keyloggers like iKeyMonitor exists. The simple trick is “DO NOT JAILBREAK”. Hackers crack into iPhones when they are jailbroken and didn’t change the root password. The default root password opens a door to hackers, when the device is not jailbroken, the door closed.

  • sdfs

