'Find my phone' blamed for celebrity photo leak

A piece of computer code that repeatedly guesses passwords may be responsible for gaining access to celebrity photos stored on cloud services.

Jennifer Lawrence

Jennifer Lawrence (Getty)

The online hack that led to the posting of hundreds of explicit photos of some of Hollywood's most famous female stars could have been the result of an attack on their passwords.

Stars including actress Jennifer Lawrence and model Kate Upton saw intimate photos posted on to 4chan website on Sunday evening, with some reports initially concluding that Apple's iCloud service had been compromised to access the images.

A piece of computer code that repeatedly guesses passwords has been found online. The script was posted to software site GitHub, but a message has since appeared saying that Apple has issued a "patch" or fix for the bug.

"The end of the fun, Apple has just patched," read an update on the post. The technology giant is yet to make any comment on the incident.

According to the post, the script uses the top 500 most common passwords approved by Apple in order to try and gain access to user accounts. If successful, it would give the hacker full access to the iCloud account, and therefore photos.

Owen Williams from technology site The Next Web, who discovered the bug, said: "The Python script found on GitHub appears to have allowed a malicious user to repeatedly guess passwords on Apple's 'Find my iPhone' service without alerting the user or locking out the attacker.

"Given enough patience and the apparent hole being open long enough, the attacker could use password dictionaries to guess common passwords rapidly. Many users use simple passwords that are the same across services so it's entirely possible to guess passwords using a tool like this.

"If the attacker was successful and gets a match by guessing passwords against Find my iPhone, they would be able to, in theory, use this to log into iCloud and sync the iCloud Photo Stream with another Mac or iPhone in a few minutes, again, without the attacked user's knowledge. We can't be sure that this is related to the leaked photos, but the timing suggests a possible correlation."

Experts have pointed to the weakness of many internet users' passwords, and basic security knowledge as being the cause for the widespread leak.

iCloud is Apple's own cloud service, a wireless storage facility that can be used to access files remotely.

Jennifer Lawrence is threatening legal action over the leaked photographs.


Share

3 min read

Published

Updated


Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world