"Journalism" at its bestAssociated Press has picked up the story...
Gawker's Headline: Apple's Worst Security Breach: 114,000 iPad Owners Exposed
AP's Headline: AT&T security hole exposes iPad users' e-mails
You tell me if there is any axe-grinding going on over at Gawker.
BTW, the AP story also said: "An Apple representative deferred requests for comment to AT&T."
I do agree that this could happen with any network provider, so when the iPhone finally is available on Verizon or whoever, the problems won't just go away.
It is a security breach alright — would you please care to explain how it is Apple's and not AT&T's?
Talking Points Memo said:Goatse Security obtained its data through a script on AT&T's website, accessible to anyone on the internet. When provided with an ICC-ID as part of an HTTP request, the script would return the associated email address, in what was apparently intended to be an AJAX-style response within a Web application. The security researchers were able to guess a large swath of ICC IDs by looking at known iPad 3G ICC IDs, some of which are shown in pictures posted by gadget enthusiasts to Flickr and other internet sites, and which can also be obtained through friendly associates who own iPads and are willing to share their information, available within the iPad "Settings" application.
To make AT&T's servers respond, the security group merely had to send an iPad-style "User agent" header in their Web request. Such header identify users' browser types to websites.
The group wrote a PHP script to automate the harvesting of data. Since a member of the group tells us the script was shared with third-parties prior to AT&T closing the security hole, it's not known exactly whose hands the exploit fell into and what those people did with the names they obtained. A member tells us it's likely many accounts beyond the 114,000 have been compromised.
Goatse Security notified AT&T of the breach and the security hole was closed.
And how did they guess that exactly 114 000 imei's were compromised and not all as you suggest? It's valid point that only activated ipad's were included in this number, but why would you buy a 3g Ipad and not activate it? So that number is probably very small.
Sadly, this will be the only time in my life when I can say that I am in pretty elite company.![]()
I'm going to wait myself or at least pay in full so I can switch as soon as Apple pulls the trigger.
Best comment of this thread so far.
Why pay in full? Unsubsidized 32GB iPhone 4 = $699. Subsidized 32GB iPhone 4 @ $299 + $325 early termination fee = $624.
Mark
By the way since a security group did this and reported it, is there any evidence anyone else actually got the email addresses?
Are you aware what could have happened to Apple's stock price and market cap if the iPhone had not been introduced on AT&T exclusively?
Fixed that for you.
Why is most here at mac rumors suggesting to get a new sim card? do any of you know something that at&t isn't telling about the sim card?
No wonder why I deleted Gizmodo from my Bookmarks, Bitter Bitches are Bitter.
Associated Press has picked up the story...
Gawker's Headline: Apple's Worst Security Breach: 114,000 iPad Owners Exposed
AP's Headline: AT&T security hole exposes iPad users' e-mails
You tell me if there is any axe-grinding going on over at Gawker.
BTW, the AP story also said: "An Apple representative deferred requests for comment to AT&T."