Hacker News new | past | comments | ask | show | jobs | submit login

> For example, it is well known that an iCloud hack leaked the photos of many celebrity women and was dubbed "the fappening", only possible because they were stored in a viewable format without e2e.

I thought the 2014 iCloud hack was because attackers tricked users into revealing their passwords, not because Apple's iCloud service itself was compromised. If that's true, e2e would not have made a difference.

https://en.wikipedia.org/wiki/2014_celebrity_nude_photo_leak

(Of course it's definitely possible for a service itself to be hacked wholesale, in which case e2e would help.)




It was the lack of two-factor that was the vector of attack for the hack. It's why so many iCloud features these days are not available at all if your Apple ID doesn't have two-factor enabled; Apple justifiably got shamed into improving security.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: