The security and privacy ramifications of AT&T's iLeak

Summary: A French group of security researchers has obtained the email addresses of 114,000 iPad users, who signed up for AT&T's 3G wireless service, relying on a flaw in AT&T's site which allowed them to automate the process. What are the security and privacy ramifications of this leak, if any?

A French group of security researchers, has obtained the emails of 114,000 iPad users who signed up for AT&T's 3G wireless service, including their associated ICC-IDs, relying on a flaw in the company's site which allowed them to automate the process.

Does this leak pose any security, privacy, or perhaps even national security risks due to the leaked U.S Department of Defense, U.S Army and DARPA emails? Update: FBI launches probe over AT&T's iPad breach

UPDATED: Tuesday, June 15, 2010: Due to the anticipated "What If" scenarios, and many direct questions that I'm receiving, the following update including comments from Goatse Security and Gawker, aims to clarify the situation.

Chris Paget comments on the incident:

"I'm somewhat of an authority on GSM security, having given presentations on it at Shmoocon (M4V) and CCC (I'm also scheduled to talk about GSM at this year's Defcon). This is my take on the iPad ICCID disclosure — the short version is that (thanks to a bad decision by the US cell companies, not just AT&T) ICCIDs can be trivially converted to IMSIs, and the disclosure of IMSIs leads to some very severe consequences, such as name and phone number disclosure, global tower-level tracking, and making live interception a whole lot easier. My recommendation? AT&T has 114,000 SIM cards to replace and some nasty architectural problems to fix."

  • According to the statement issued by the group, they have not just erased the emails+ICCIDs, but haven't shared them with anyone else but Gawker. Moreover, given the fact that there's no known public copy of the emails+ICCDs (as of June 15th, 2010), for researchers to experiment with, you can always request a new SIM card from AT&T, if you're uncomfortable with the incident that took place.

Asked to comment on the case, both, Goatse Security (Escher Auernheimer) and Gawker (Remy Stern) had the following to say.

Q: Once the harvested emails were obtained, were they shared with anyone else, but Gawker's reporter, or posted online in any form?

Goatse Security: No, they were only shared with Gawker who agreed to responsibly redact them to not reveal any personally identifying information. We did not post them online nor publish them as many have alleged. We destroyed the data after we gave it to Gawker, to prevent loss and security risks.

Q: Are you aware of whether Gawker's reporter did the same, namely erase the content, and not share the data with anyone else?

Goatse Security: I do not know if Ryan Tate destroyed his copy of the data. I believe he has been ordered by the FBI to retain it, so any potential breach of the data's security there would be the responsibility of the federal government.

Q: Did you share a copy of the PHP script with anyone? And if yes, was a copy of the script shared BEFORE the flaw was fixed, or AFTER it was fixed making the script virtually useless?

Goatse Security: A version of the script was potentially stored in an insecure fashion when the original author first made it. At this point in time we were lacking an additional bit of data that did not allow us to understand the full ramifications of the vulnerability. We have no evidence that it was retrieved or used by anyone else and made a best effort to lock it down and publicly disclose the vulnerability as soon as we had an understanding of the scale of AT&T's data exposure. As everyone at GS had other priorities when the script was first written it was not until later until it was tested and made a high priority on our groupware. Unfortunately for the consumer, our commercial priorities have to take precedence over our charitable public interest ones.

Q: Since Goatse claims to have erased the data, and have never shared it with anyone else but with Gawker, did you do the same, namely, not share it with anyone else, and delete it?

Gawker: No, we did not share the data with anyone else nor do we have any plans to do so. The printed copy of the data, which was depicted in our original story, was shredded immediately after the photograph was taken.

We do continue to possess a digital copy of the file. Per the preservation notice we received from last week from federal authorities, we have retained all our files related to the story, as was requested of us.

The security risks posed by this email leak, are pretty similar to the security risks from related compromises, with the potential malicious attackers now sitting on hundreds of thousands of email accounts. Here are two of the most common abuse scenarios that could take place:

  • Targeted malware/phishing attacks impersonating Apple Inc.Spear phishing attacks are emails specifically crafted for a particular targeted group, attempting to capitalize on a particular event. In this case, potential attackers could easily execute such an attack impersonating Apple's response to the situation/mitigation practices, knowing that the owners of these emails are now particularly susceptible to interacting with such emails.
  • Targeted malware/phishing attacks impersonating AT&T - This scenario is identical to first one, however, this time it's AT&T's response/mitigation practices that could be used as social engineering lure. And although I don't really think there's going to be a significant outbreak of such campaigns, due to the fact that the rest of their campaigns are producing the results they desire, the possibility for abuse remains.

The following is brief FAQ summarizing the most important aspects of AT&T's iLeak incident:

  1. How did Goatse Security manage to obtain the emails and associated ICC-IDs? - The group (listen to a podcast with one of the researchers) appears to have automated the brute forcing process using a script with which they fed the AT&T's site with spoofed user-agents (iPad) and random ICC-IDs numbers, in between recording all the valid emails that were returned for a correct ICC-ID. The last time, a similar attempt abusing weak security practices was seen in the wild, resulted in thousands of leaked confidential/nude photos of the photo sharing iPhone app Quip.
  2. What are the privacy ramifications of the leak, if any? - Despite the leaked emails of top executives at the New York Times Company, Dow Jones, Condé Nast, Viacom, Time Warner, News Corporation, HBO, Goldman Sachs, JP Morgan, Citigroup, Morgan Stanley etc. the only case where the incident would pose a privacy risk to these executives, is when these email accounts weren't published on the Web in the first place. Moreover, despite claims that average users can obtain the physical location of an iPad's user through the leaked ICC-ID, that's not really the case. The physical location is already known to the mobile carrier using plain simple triangulation and related techniques used by law enforcement agencies, with or without the possession of the ICC-ID.
  3. Does the leak pose any national security risks due to the sensitive nature of the emails involved? - Depends on the perspective and degree of paranoia, although the U.S Intelligence Community is definitely not happy with the fact that a particular U.S Department of Defense, U.S Army or DARPA email can now be associated with a ICC-ID that leaked on the Web. Meanwhile, the NYTimes has already responded by asking iPad users to turn off access to the 3G network - "As our security team and network engineers investigate the full extent of the breach via Apple and AT&T, we suggest that you turn off your access to the 3G network on your iPad until further notice."
  4. Did AT&T issue a response to the incident? - The following is the company's official response to the situation: AT&T was informed by a business customer on Monday of the potential exposure of their iPad ICC IDs [used to authenticate the subscriber on AT&T's network]. The only information that can be derived from the ICC IDs is the e-mail address attached to that device. This issue was escalated to the highest levels of the company and was corrected by Tuesday; and we have essentially turned off the feature that provided the e-mail addresses. The person or group who discovered this gap did not contact AT&T. We are continuing to investigate and will inform all customers whose e-mail addresses and ICC IDs may have been obtained. At this point, there is no evidence that any other customer information was shared. We take customer privacy very seriously and while we have fixed this problem, we apologize to our customers who were impacted.

Although the iLeak is an embarrassing moment for both, AT&T and Apple, the incident only adds a small additional risk to the ones users are currently facing, such as malware, phishing, blackhat SEO, and client-side exploitation through unpatched 3rd party applications.

What it proves through, is what independent data breach reports have been saying for years - in the majority of cases a third-party business partner was usually responsible for the breach.

Are you affected by this incident, and somehow concerned about your privacy. What's your main concern? Do you believe that the leak of unpublished emails belonging to company executives, would somehow affect them? How about the ones belonging to the DOD, DOJ and DARPA? Who's to blame for this incident, Apple for trusting AT&T's ability to securely operate with the data, or AT&T for allowing this to happen?

TalkBack.

Topics: AT&T, Collaboration, Hardware, Mobility, Security, Wi-Fi

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

46 comments
Log in or register to join the discussion
  • Sorry, but the last question is insane:

    "Whos to blame for this incident, Apple for trusting AT&Ts ability to securely operate with the data, or AT&T for allowing this to happen?"<br><br>1. <b>At NO POINT</b> Apple has anything to do with this.<br><br>2. And there <b>was NO WAY</b> for Apple (or whichever company that could be in Apple's place) to foresee or prevent this problem.<br><br>So no FUD please.
    DDERSSS
    • RE: The security and privacy ramifications of AT&T's iLeak

      @denisrs

      But if the same thing happens Microsoft, feel free to run a double standard and blame them.

      Right. whatever.
      CobraA1
      • I never ran to blame MS in similar situation

        @CobraA1: why you inventing things?
        DDERSSS
      • &lt;a href=&quot;http://www.tran33m.com/vb/&quot;&gt;forums&lt;/a&gt;

        @CobraA1 You wrote that the group obtained the "e-mails" of users. Ooh - scary - the group read user e-mails. But no, that's not what happened. The group obtained e-mail addresses, but didn't obtain anybody's e-mails. But why bother using language correctly if you just want to be more sensational about a problem?
        omaia7
      • why you inventing orjin krem

        You wrote that the group obtained the "e-mails" of users. Ooh - scary - the group read user e-mails. But no, that's not what happened. The group obtained e-mail addresses, but didn't obtain anybody's e-mails. But why bother using language correctly if you just want to be more sensational about a problem? <font color="LightGrey"></font></a><a href="http://www.revivalymaske.com/"><font color="LightGrey">pembe maske</font></a> <font color="LightGrey"></font></a><a href="http://www.energybalancebileklik.com/"><font color="LightGrey">energy balance</font></a> <font color="LightGrey"></font></a><a href="http://www.oynaoyunu.com/"><font color="LightGrey">oyna oyunu</font></a> <font color="LightGrey"></font></a><a href="http://www.moliva.web.tr/"><font color="LightGrey">moliva</font></a>
        ekoaldiva
      • RE: The security and privacy ramifications of AT&T's iLeak

        @CobraA1 Microsoft also makes patches to fix bugs in their OS and some of their applications like Internet Explorer but Windows faces more severe vulnerabilities and threats than either Mac OS 9 or OS X have ever had. With OS X Apple improved security in their operating system which was a bigger problem in OS 9. OS X is more secure than OS 9 because OS X integrates some good security features. Even if you don't have Snow Leopard with the anti-virus features it includes Mac OS X Tiger and Leopard have a firewall. Besides one can always ins<a href="http://www.tran33m.com/vb/">t</a>all a third party anti-virus program for Mac on a system running an older version of OS X than Snow Leopard.
        jku1
      • RE: The security and privacy ramifications of AT&T's iLeak

        Group is Goatse security, so maybe you should google Goatse. Just a<a href="http://ipadbagblog.com/"><font color="light&height"> ipad bag blog</font></a><a href="http://www.sutudeg.org/"><font color="light&height"> sutudeg </font></a> <a href="http://wposfv.com/"><font color="light&amp;height">education news</font></a> and suggestion.<a href="http://ipadbagblog.com/"><font color="LightGrey"> k</font></a><a href="http://www.sutudeg.org/"><font color="LightGrey"> l</font></a>
        edward polling
      • RE: The security and privacy ramifications of AT&T's iLeak

        You wrote that the group obtained the "e-mails" of users. Ooh - scary - the group read user e-mails. But no, that's not what happened. The group obtained e-mail addresses, but didn't obtain anybody's e-mails. But why bother using language correctly if you just want to be more sensational about a<a href="http://www.titsuganda.org/"><font color="light&amp;height"> about it</font></a> is bank that <a href="http://www.filthy-lucre.net/"><font color="light&amp;height">website</font></a> attacked from the <a href="http://www.conpacoop.com/"><font color="light&amp;height">site support</font></a> from any soldier <a href="http://www.poetryetcetc.com/"><font color="light&amp;height">site</font></a> to the light <a href="http://www.blackspotnews.com/"><font color="light&amp;height">home page</font></a> is great problem?
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        Care to explain how a breach in AT&Ts security proves that the iPad is just a laptop
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        The IPAD is finally revealing what many of us though it was in the beginning. It is just a substandard laptop. What happened to great Apple products
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        Did you mean "steal your password" or "steal your email address"? I believe this incident was about stolen email addresses of AT&T 3G iPad customers.
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        Would this same method uncover email addresses of ATT 3G users that do not use iPad?
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        and provided att's system probably runs on windows , it was a windows security breach that put ipads user's data on risk. ouch. you are right, windows is just to dangerous.
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        I think everyone should panic. We are talking personal info here and it could get very bad.

        Agreed! Time to stockpile Guns, ammo and gold.
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        Apple is taking collateral damage from AT&T.

        Doing a Bing, Google and, Yahoo search I came across hits about Windows e-mail and, address book malware that steal users data, take over e-mail accounts, steal address book information. Are you not afraid?
        Linux Love
      • RE: The security and privacy ramifications of AT&T's iLeak

        @CobraA1 I see the pricing has been release, bot can't find anyplace that mentioned how much storage is included. While the licensing costs are very reasonable, I wonder if there are any surprise costs. i.e. how much storage is included in the 25 user plan and how much does it cost for extra storage?
        Arabalar
      • RE: The security and privacy ramifications of AT&T's iLeak

        You have got some great posts in your blog. I will be visiting again.
        <a rel="follow" href="http://www.philadelphiaaccidentlawyer.com/">Philadelphia accident lawyer</a>
        <a rel="follow" href="http://www.mystopblushingcure.com/">blushing cure</a>
        sabir12
    • RE: The security and privacy ramifications of AT&T's iLeak

      @denisrs

      1) Of course Apple has everything to do with this. AT&T is their partner.

      2) They could have run a security audit.

      You're either a simpleton or too much of a fan.
      nicholas22
      • Ridiculous and lame

        @nicholas22:

        1) it is like saying John Lennon was killed by daytime because he was kill during day (not night). So your attempt to refute the point is superridiculous.

        2) noone would ever let them (or any other company) do such audit. And none of your beloved nokias, rims, googlephone makers ever did such audit on Verison, T-Mobile, Sprint -- because this is impossible. So your attempt to refute the point is superlame.
        DDERSSS
      • RE: The security and privacy ramifications of AT&T's iLeak

        @nicholas22 1) it is like saying John Lennon was killed by daytime because he was kill during day (not night). So your attempt to refute the point is superridiculous.<br><br>2) noone would ever let them (or any other company) do such audit. <a href="http://www.altincilekmix.com">altin cilek</a>And none of your beloved nokias, rims, googlephone<a href="http://www.orjinkrem.net">orjin krem</a> makers ever did such audit on Verison, T-Mobile, Sprint -- because this is impossible. So your attempt to refute the point is superlame.
        osoz