Re: [iPad] Ouch a real iPad Virus / Ransomware

 

Spearhead an initiative using multi-factor authentication. Most of the best people are. There are always good ideas. Amazon and better sites are laden with multi-factor authentication at several layers.
http://redmondmag.com/articles/2014/05/01/lesson-from-target-breach.aspx

Many of the security we take for granted now or products we took for granted were considered impossible or infeasible till people though out of the box and solved the problems in new ways.

There may be ways to get the bigger better sites (Amazon, iTunes, NetFlix, etc.) in long term to  switch to certificates or biometrics instead of passwords or as a component with passwords, or even block cross site passwords - a salted-checksum of a password I attempted to create on one of those sites could hit a webservice and give me a "disallowed, used elsewhere" message.

All security is about hardening and better design, not invulnerability.


On Sat, May 31, 2014 at 9:36 AM, Jim Saklad jimdoc@icloud.com [iPad] <iPad@yahoogroups.com> wrote:
 

>> Hopefully Apple will patch quick and remind us why they are security superheroes while Windows still is vulnerable to Crypto and ICE and a few dozen ransom wares that have been out for over a year.
>
> Right in the article is the line:
> "seem to involve any malware or malicious activity on the device itself"
>
> I don't understand your heading -- what has happened is neither a virus nor is it Ransomware. Instead it is a person who has been able to take control of the iDevice from a remote location through using Apple's own anti-theft protocol.
>
> Yes it is asking for a ransom, but true ransomware is a piece of software which is loaded onto your device and then takes control until you pay the ransom.
>
> This is just a clever person outsmarting Apple's own "lock this device if it gets lost or stolen" protocol.
>
> How exactly do you expect Apple to patch things so that this can't happen?
>
> David H. Bailey

More relevantly, since it is apparently NOT a defect in iCloud security, how can Apple patch "users so stupid as to use the same password for iCloud as elsewhere" ?


__._,_.___

Posted by: Charles Carroll <911@learnasp.com>
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (10)

.

__,_._,___

[iPad] Re: Ouch a real iPad Virus / Ransomware

 

Hi Jim:
Should the Apple ID and the Cloud IDs be different?
Carol

Jim wrote:
Patch?

First you create a password for a site, banking perhaps, or Target, or some such, that gets hacked through *their* system vulnerabilities.

Then, against ALL advice to the contrary, you re-use that same password on iCloud.

The hacker tries the thousands of passwords he got from his hack, together with the attached name, on iCloud.

He finds a few that match, locks those people's devices, and demands ransom.

It isn't clear to me how Apple fixes the users stupidity.

Sent from my iPad Air

__._,_.___

Posted by: floridabouvs <floridabouvs@yahoo.com>
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (9)

.

__,_._,___

Re: [iPad] Ouch a real iPad Virus / Ransomware

 

>> Hopefully Apple will patch quick and remind us why they are security superheroes while Windows still is vulnerable to Crypto and ICE and a few dozen ransom wares that have been out for over a year.
>
> Right in the article is the line:
> "seem to involve any malware or malicious activity on the device itself"
>
> I don't understand your heading -- what has happened is neither a virus nor is it Ransomware. Instead it is a person who has been able to take control of the iDevice from a remote location through using Apple's own anti-theft protocol.
>
> Yes it is asking for a ransom, but true ransomware is a piece of software which is loaded onto your device and then takes control until you pay the ransom.
>
> This is just a clever person outsmarting Apple's own "lock this device if it gets lost or stolen" protocol.
>
> How exactly do you expect Apple to patch things so that this can't happen?
>
> David H. Bailey

More relevantly, since it is apparently NOT a defect in iCloud security, how can Apple patch "users so stupid as to use the same password for iCloud as elsewhere" ?

__._,_.___

Posted by: Jim Saklad <jimdoc@icloud.com>
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (8)

.

__,_._,___

Re: [iPad] Ouch a real iPad Virus / Ransomware

 

Apple tighten up the
"lock this device if it gets lost or stolen" protocol. They have smart people who have locked down much harder thing others have failed to.


On Sat, May 31, 2014 at 5:18 AM, 'David H. Bailey' dhbailey52@comcast.net [iPad] <iPad@yahoogroups.com> wrote:
 

On 5/30/2014 10:17 PM, Charles Carroll 911@learnasp.com [iPad] wrote:
> http://nakedsecurity.sophos.com/2014/05/29/apple-ios-ransomware-mystery-deepens-oleg-pliss-pops-up-in-la/
>
> Hopefully Apple will patch quick and remind us why they are security
> superheroes while Windows still is vulnerable to Crypto and ICE and a
> few dozen ransom wares that have been out for over a year.
>

Right in the article is the line:
"seem to involve any malware or malicious activity on the device itself"

I don't understand your heading -- what has happened is neither a virus
nor is it Ransomware. Instead it is a person who has been able to take
control of the iDevice from a remote location through using Apple's own
anti-theft protocol.

Yes it is asking for a ransom, but true ransomware is a piece of
software which is loaded onto your device and then takes control until
you pay the ransom.

This is just a clever person outsmarting Apple's own "lock this device
if it gets lost or stolen" protocol.

How exactly do you expect Apple to patch things so that this can't happen?

--
David H. Bailey
dhbailey@davidbaileymusicstudio.com
http://www.davidbaileymusicstudio.com


__._,_.___

Posted by: Charles Carroll <911@learnasp.com>
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (7)

.

__,_._,___

黃麥麥, 張媁如 and Adel Sayed are waiting for you to see their posts on your timeline

黃麥麥 , 張媁如 and Adel Sayed posted on your timeline. 黃麥麥 3,048 friends 張媁如 821 friends Adel Sayed 644 friends
facebook
黃麥麥, 張媁如 and Adel Sayed posted on your timeline.
黃麥麥黃麥麥
3,048 friends
張媁如張媁如
821 friends
Adel SayedAdel Sayed
644 friends
View Posts
Go to Facebook
This message was sent to fiiendgroupes@gmail.com. If you don't want to receive these emails from Facebook in the future, please unsubscribe.
Facebook, Inc., Attention: Department 415, PO Box 10005, Palo Alto, CA 94303

Re: [iPad] Ouch a real iPad Virus / Ransomware

 

On 5/30/2014 10:17 PM, Charles Carroll 911@learnasp.com [iPad] wrote:
> http://nakedsecurity.sophos.com/2014/05/29/apple-ios-ransomware-mystery-deepens-oleg-pliss-pops-up-in-la/
>
> Hopefully Apple will patch quick and remind us why they are security
> superheroes while Windows still is vulnerable to Crypto and ICE and a
> few dozen ransom wares that have been out for over a year.
>

Right in the article is the line:
"seem to involve any malware or malicious activity on the device itself"

I don't understand your heading -- what has happened is neither a virus
nor is it Ransomware. Instead it is a person who has been able to take
control of the iDevice from a remote location through using Apple's own
anti-theft protocol.

Yes it is asking for a ransom, but true ransomware is a piece of
software which is loaded onto your device and then takes control until
you pay the ransom.

This is just a clever person outsmarting Apple's own "lock this device
if it gets lost or stolen" protocol.

How exactly do you expect Apple to patch things so that this can't happen?

--
David H. Bailey
dhbailey@davidbaileymusicstudio.com
http://www.davidbaileymusicstudio.com

__._,_.___

Posted by: "David H. Bailey" <dhbailey52@comcast.net>
Reply via web post Reply to sender Reply to group Start a New Topic Messages in this topic (6)

.

__,_._,___