Skip to main content [aditude-amp id="stickyleaderboard" targeting='{"env":"staging","page_type":"article","post_id":1560789,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"security,","session":"B"}']

Apple may have known of huge iCloud security hole 6 months ago

iCloud

Apple received an alert that it had a glaring hole in the security of its iCloud service six months before myriad celebrities like Rihanna and Jennifer Lawrence had private nude photographs boosted from their accounts and posted online.

While it’s not clear if that vulnerability led to the nude leaks, Apple apparently brushed off the concerns of software programmer Ibrahim Balic, who approached the company with a formula he used to breach the iCloud firewall in March. Balic posted the email exchange with the Daily Dot.

[aditude-amp id="flyingcarpet" targeting='{"env":"staging","page_type":"article","post_id":1560789,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"security,","session":"B"}']

The London-based Balic made clear, at least in his multiple emails to Apple, that he’d devised a method of successfully breaching the iCloud firewall, using brute force attacks that throw a fast and continual stream of number-and-letter combinations at user accounts. Brute force attacks ultimately led to the nude celebrity scandal that is still reverberating. Balic told Apple that by using brute force attacks, he was able to hurl 20,000 password combination tries at iCloud accounts.

What’s clear is Balic is a white hatter who threw Apple a bone. In the Daily Dot piece, Balic shared his exasperation of being ignored by Apple when he broached the issue with them. Ultimately, Balic is using the case to illustrate how Apple and others white hatters seriously when they reach out and tell them they have a problem.

AI Weekly

The must-read newsletter for AI and Big Data industry written by Khari Johnson, Kyle Wiggers, and Seth Colaner.

Included with VentureBeat Insider and VentureBeat VIP memberships.

I reached out to Balic and will have more soon.

VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Learn More