> After more than 40 hours of investigation, we have discovered that certain celebrity accounts were compromised by a very targeted attack on user names, passwords and security questions, a practice that has become all too common on the Internet.
So, the brute force attack with reasonable guesses at email addresses?
Or just password recovery with trivially discoverable personal details. To a determined attacker, your mother's maiden name, the street you grew up on, and the name of your first pet are not hard to figure out.
Information like that isn't even secret, the whole practice of using password recovery questions needs to go away.
My guess would be that they found someone an address of someone with ties to a celebrity, compromised their account through security questions, and then found more personal information and iCloud accounts by going the contacts of each person they compromised.
That was my suspicion from the start, security questions tend to be the easiest way to compromise accounts since finding someone's mother's maiden name isn't hard to do anymore.
I think it‘s quite easy to argue that when accounts are compromised because of security questions whoever implemented those questions is at fault. They are a convenient, if crap way to secure accounts. Apple and everyone else have to do better.
(I suppose the good news is that you can actually protect yourself from this. However, how to protect themselves won’t reach most people, so in the big picture this is cold comfort. I do think it’s the job of the platform owner to make sure that users cannot easily leave themselves open to attacks. Most people don’t know about security, the platform owner does.)
I always put in made-up or nonsense information for the answers to the security questions, and store it all in the same encrypted file with my passwords. Seems more secure than using correct information that would not be hard for an attacker to discover. ("Then how will you get password recovery?" "I will never need that.")
So, the brute force attack with reasonable guesses at email addresses?