007Aston wrote:
It's not really the process the hackers used to unlock the devices that is interesting, but more the fact that icloud was compromised by the hackers, and apparently Apple didn't admit publicly that the system was compromised.
Now, Apple have said that the icloud was not compromised in this instance. Really?
It seems to me that icloud was compromised, how in the heck could they allow a bot to access many user accounts, in a short period of time, and put heaps of devices in lost mode, along with applying a screen message?
This attack didn't occur over a number of days, but in a relatively short period of time, when Apple could surely expect most of their customers were asleep - not madly realising they had 'lost' all their devices, and whilst the locked screen message has varied slightly, there are common words. Isn't this unsual activity? why was it not discovered by Apple until, possibly 6-8 hours later when we all woke up and started visiting Apple stores, and contacting support?
To your first point, since the unlocking uses a Man-in-the-middle attack, this does not mean that icloud was compromised. It means they successfully created a fake apple server, that can communicate with a device and potentially icloud (we do not know this for sure.) Basically unlocking a device, which should only be unlocked by the original Apple ID and password, which they do not possess. Either the hack can extract this in the exchange somehow, or the password is not needed, just say the Apple ID and some generated hash or not and some specific info that find my device is expecting.
Regarding the bot and putting heaps of users into safe mode. Once again goes along the lines of the unlock hack. If you could unlock a phone without knowing the credentials, you could surely lock a phone, establish a passcode, then send a ransom message without credentials. More likely they have hacked the find my device programs (if you turn it off, I believe the hack is stopped) and potentially icloud. The doulCi guys claimed 5700 unlocks in 5 minutes, thats 19 devices a second. Considering router times in the sub 100 ms, this seems plausible to me. If it really is this quick, I do not know that major decryption/encryption can be done in this short period of time, but since processors operate in Ghz maybe it is.
Too your last comment, If all these device were subject to a MITM attack or some sort of injection, it could/would be a one way communcation. Meaning the spoofed server sent the device their instructions, if the devices do send responses back to Apple, they would have been intercepted as well and could be dropped, thus Apple would never know anything happened at all.
The other weird thing are reports that people have reset their devices, only to be locked again moments later. Too me this implies that their reset potentially occurred through the spoofed sever and more data could have been mined from people. If turning off the find my device service prevents the attack, that is good, but authorities need to ascertain whether more data was compromised from many people changing/resetting their Apple ID and passwords. These could be compromised, but not used until a later time.
I would also be curious if the attack is against all device or the spoofed server only does a certain percentage of the devices. Meaning lets say it infects/locks only 10% of devices, by allowing 90% of normal apple traffic through and only truly redirecting or injecting a smaller percentage. This could represent why some device are reset with no further effects and others are immediately locked again.