24 Jun 2011
A California man has pleaded guilty to writing code that used a security flaw in AT&T's iPad interface to exposed thousands of high-profile user's personal information.
Daniel Spitler, 26, of San Francisco pleaded guilty to one count of conspiracy to gain unauthorised access to computers connected to the internet and one count of identity theft. He admitted helping to write the code that enabled the theft of data from AT&T, and then helping publish it online.
Spitler and his accused accomplice Andrew 'Escher' Auernheimer, AKA weev, are charged with writing a script which exploited a weakness in AT&T's handling of iPad user identification. Each 3G iPad received a unique Integrated Circuit Card Identifier (ICC-ID) number that could be matched to an email address and the code Spitler admits writing harvested this data.
The team, named after an unsavoury internet meme, than passed the data to internet gossip site Gawker.com, and revealed the email addresses of White House chief of staff Rahm Emanuel, the head of the US B1 strategic bomber group and numerous executives at Apple, Google, Microsoft and Amazon. They were arrested shortly afterwards.
"The magnitude of this crime affected everyone from high ranking members of the White House staff to the average American citizen," said Michael Ward, special agent of the FBI's Newark division.
"It's important to note that it wasn't just the hacking itself that was criminal, but what could potentially occur utilising the pilfered information. Because of the popularity and widespread use of the new and emerging technology of the iPad and devices like it, it was absolutely critical that emerging threats to it were addressed promptly and aggressively."
Spitler's alleged accomplice Auernheimer is still defending his innocence, and broke a gagging order to insist that the team were being persecuted by Apple, although the flaw used came from AT&T's software.
Spitler faces a maximum of five years in prison and a $250,000 (£156,000) fine and is due to be sentenced on 28 September.
"Computer hackers are exacting an increasing toll on our society, damaging individuals and organisations to gain notoriety for themselves," said US attorney Paul Fishman.
"Hacks have serious implications – from the personal devastation of a stolen identity to danger to our national security. In the wake of other recent hacking attacks by loose-knit organisations like Anonymous and LulzSec, Daniel Spitler's guilty plea is a timely reminder of the consequences of treating criminal activity as a competitive sport."
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
V3 examines the key strengths and weaknesses of Samsung's latest iPhone killer
Connect with V3.co.uk
Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them
The importance of understanding your infrastructure
Ihre Aufgaben Sie sind zuständig für die Beratung...
***MS Visual Basic Programmierer mit Oracle DB-Erfahrung...
IT Business Analyst Location: London, but...
Senior Software Developer Company overview...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
ipad technology is not new
the part: "It's important to note that it wasn't just the hacking itself that was criminal, but what could potentially occur utilising the pilfered information. Because of the popularity and widespread use of the new and emerging technology of the iPad and devices like it, it was absolutely critical that emerging threats to it were addressed promptly and aggressively." since ipad doesn't actually incorporate any emerging technologies technically, computers have been around decades, that part makes no sense except for talking smack and gives the wrong impression on what is really his job, to protect the public, he should have noted that certain people shouldn't even have admitted their information into that database in the first place. especially when the hack was just on a poorly designed web interface, it wasn't an emerging technology hack that would be needed to be protected "aggressively",if anything they acted passively only after the data leak had happened, and if they had been protecting it aggressively the whole hack(data mining) wouldn't have happened in the first place. but it's sure for fishman that it gives him a job as long as companies continue to make poor decisions about what user data they even need to have, from functional perspective the data was unnecessary for apple or at&t to even keep and keeping it accessible like that should have been criminal in itself, which the state attorney should have known - instead of making a veiled demand for more cash for his department to go after something else than traditional crime(after all, that is messy, coercing nerds to make plea deals they shouldn't go with however IS easy).
Posted by: las 25 Jun 2011