Nude Celebs (The Fappening) !!! and Password Recovery

Nude Jennifer Lawrence… Sorta.

Apple says that the mass theft of nude celebrity photos (Dubbed, the Fappening) that were released over the weekend did not occur because of a breach in any Apple systems, including iCloud. Apple also says that Find my iPhone was not involved in the photo thefts.

Based on an analysis of the metadata from leaked photos of Kate Upton, it is determined that the photos came from a downloaded backup that would be consistent with the use of iBrute and Elcomsoft Phone Password Breaker (EPPB).

Another way that many accounts are compromised are by using a password recovery website that prompts for out of wallet questions.
Here are some examples of out of wallet questions:

  • What is your favorite sport?
  • What is your favorite vacation spot?
  • What was the make of the first car you owned?
  • What is your favorite hobby?
  • What do you like to do to relax?
  • What is your primary frequent flyer number?
  • What is your library card number?
  • What was your first phone number?
  • What was your first teacher’s name?
  • What is your father’s middle name?
  • What is the name of your favorite celebrity?
  • What is your favorite food?
  • What is the name of your favorite city?
  • What is your favorite animal?
  • What is your mother’s maiden name?
  • What is your favorite 5-digit number?
  • What are the last 5 digits of your favorite credit card?
  • What are the last 5 digits of your driver’s license number?
  • What are the last 5 digits of your vehicle identification number?
  • What are the last 5 digits of your employee ID number?
  • What are the last 5 digits of your Social Security number?
  • What City were you born in?
  • What is your shoe size?
  • How many bedrooms does your house have?
  • Where does your nearest sibling live?
  • What’s your drink of choice?
  • What color are the towels in your personal bathroom?
  • What is your ideal weight, in your view?
  • What is the last name of the author of the best book you ever read?
  • What is your favorite musical performer?
  • What is your brother’s/sister’s middle name?
  • What is your favorite game?
  • What was your nickname in high school/college?
  • How many miles do you live from work?
  • What is your favorite song?
  • What are the first five letters of your favorite song title? (Could also be a movie.)
  • What is your cell phone number? (No directories for this and you get another contact means. With number portability this should improve.)
  • What is your favorite feature about yourself? (A little invasive perhaps, but people like talking about themselves. The answer would need to be concise.)
  • How many siblings do you have?
  • What is your favorite word?
  • What is your Grandmother’s maiden name?
  • What was the town/City of grandfather’s birth?
  • What is the name of your favorite non-chain restaurant?
  • What is the pet name you gave your first car?
  • What is your favorite color?

The big thing to remember when setting up your answers, is that there is no fact checking attached to these, thus, it is possible to answer untrue answers to every one of these questions and would be attackers would go ahead and research all your publicly available information to find and use the real answers to try to get your password reset and have access to your account.

This entry was posted in Security Blog and tagged , , , , , , . Bookmark the permalink.