Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Hackers Target Chinese Users Accessing Apple’s iCloud

Apple advises users to watch for signs that their iCloud connection is being misdirected.

As Apple launched its iPhone 6 and iPhone 6 Plus in China, users have become the target of an attack aimed at stealing their user names and passwords and snooping on their activities.

A censorship watchdog, GreatFire.org, alleges that hackers staged a “man-in-the-middle” attack — essentially an electronic form of eavesdropping — to intercept a user’s login information when he or she attempted to access Apple’s iCloud online data storage service.

Apple said it was aware of the attacks, but said iCloud servers themselves have not been compromised.

Login information would give the hackers access to an individual’s private photos, contacts and messages stored on Apple’s iCloud servers. GreatFire points the finger at Chinese authorities, which have been accused in past attacks on Google and Yahoo. Beijing has issued statements in the past opposing cyber attacks.

“It would be a great tool for a nation state like China to track dissidents,” said Richard Stiennon, a security expert and chief research analyst at IT-Harvest.

A man-in-the-middle attack intercepts communications — in this case, between an iPhone and Apple’s secure iCloud servers, some of which have been moved to China to improve service. The hacker sits in the middle of this communication, Stiennon said, and redirects users to a third-party server used to pilfer user names and passwords.

Such an attack would be possible if the attacker controls the telecommunications networks, as is the case in China, Stiennon said.

An Apple spokesperson expressed concern about the attacks.

“We’re aware of intermittent organized network attacks using insecure certificates to obtain user information, and we take this very seriously,” said spokesperson Trudy Muller. “These attacks don’t compromise iCloud servers, and they don’t impact iCloud sign-in on iOS devices or Macs running OS X Yosemite using the Safari browser.”

In response, Apple created a support document to help consumers recognize when a hacker is attempting to execute this kind of misdirection play. The telltale sign is the absence of a certificate that verifies that the site is secure (a warning message will appear, stating “Safari can’t verify the identity of the website.”).

The Chinese censorship monitoring group speculated that the attacks may have come in response to Apple’s decision to bolster security on the new iPhones.

“This increased encryption would also prevent the Chinese authorities from snooping on Apple user data,” GreatFire wrote. “This [man-in-the-middle] attack may indicate that there is at least some conflict between the Chinese authorities and Apple over some of the features on the new phone.”

Apple’s enhanced encryption has also rankled U.S. law enforcement officials, who claim the tougher security and privacy measures make it harder to solve crimes or foil terrorists. FBI Director James Comey called on Apple and Google to reverse course.

This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh