App publisher not FBI leaked Apple UDIDs

Powered by SC Magazine
 

Researcher tips off victim.

Last week's disclosure of Apple Unique Device Identifiers (UDIDs) was caused by a breach of a US application publisher.

Florida-based publishing company Blue Toad said the million-record database of UDIDs was stolen from its servers two weeks ago, contradicting hacker claims that they were stolen from an FBI agent's laptop in March.

The FBI denied it was linked to the incident.

Blue Toad CEO Paul DeHart told NBC News staff downloaded the data released by Anonymous and compared it to the company's own database. They found a 98 per cent correlation between the two datasets.

 "pretty apologetic to the people who relied on us to keep this information secure" 

But DeHart said the compromised data may have been shared and ended up on a FBI computer. 

The company was tipped off by external researcher David Schuetz who compared apps against multiple devices to narrow down the source.

“I had decided to look more closely at the most frequently repeated device IDs, on the theory that perhaps that would belong to a developer. They'd naturally test multiple apps for their company, each of which should have a different device token,” he said.

“By the time I went to bed, I had identified 19 different devices, each tied to Blue Toad in some way.

"I found iPhones and iPads belonging to their CEO, CIO, CCO, a customer service rep, the director of digital services, the lead system admin, and a senior developer."

Apple publicly denied giving the information to the FBI and said that it began rejecting apps that access UDIDs earlier this year after phasing them out with the introduction of iOS 5.

This article originally appeared at scmagazineuk.com

Copyright © SC Magazine, UK edition


App publisher not FBI leaked Apple UDIDs
 
 
 
Top Stories
NBN Co names first 140 FTTN sites
National trial extended.
 
Cloud, big data propel bank CISOs into the boardroom
And this time, they are welcome.
 
Photos: A tour of CommBank's new innovation lab
Oculus Rift, Kinect and more.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  25%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  23%
 
End user computing (desktops, mobiles, apps)
  12%
 
Software development
  27%
TOTAL VOTES: 225

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  63%
 
No
  37%
TOTAL VOTES: 67

Vote