Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Hackers Target Chinese Users Accessing Apple’s iCloud

Apple advises users to watch for signs that their iCloud connection is being misdirected.

As Apple launched its iPhone 6 and iPhone 6 Plus in China, users have become the target of an attack aimed at stealing their user names and passwords and snooping on their activities.

A censorship watchdog, GreatFire.org, alleges that hackers staged a “man-in-the-middle” attack — essentially an electronic form of eavesdropping — to intercept a user’s login information when he or she attempted to access Apple’s iCloud online data storage service.

Apple said it was aware of the attacks, but said iCloud servers themselves have not been compromised.

Login information would give the hackers access to an individual’s private photos, contacts and messages stored on Apple’s iCloud servers. GreatFire points the finger at Chinese authorities, which have been accused in past attacks on Google and Yahoo. Beijing has issued statements in the past opposing cyber attacks.

“It would be a great tool for a nation state like China to track dissidents,” said Richard Stiennon, a security expert and chief research analyst at IT-Harvest.

A man-in-the-middle attack intercepts communications — in this case, between an iPhone and Apple’s secure iCloud servers, some of which have been moved to China to improve service. The hacker sits in the middle of this communication, Stiennon said, and redirects users to a third-party server used to pilfer user names and passwords.

Such an attack would be possible if the attacker controls the telecommunications networks, as is the case in China, Stiennon said.

An Apple spokesperson expressed concern about the attacks.

“We’re aware of intermittent organized network attacks using insecure certificates to obtain user information, and we take this very seriously,” said spokesperson Trudy Muller. “These attacks don’t compromise iCloud servers, and they don’t impact iCloud sign-in on iOS devices or Macs running OS X Yosemite using the Safari browser.”

In response, Apple created a support document to help consumers recognize when a hacker is attempting to execute this kind of misdirection play. The telltale sign is the absence of a certificate that verifies that the site is secure (a warning message will appear, stating “Safari can’t verify the identity of the website.”).

The Chinese censorship monitoring group speculated that the attacks may have come in response to Apple’s decision to bolster security on the new iPhones.

“This increased encryption would also prevent the Chinese authorities from snooping on Apple user data,” GreatFire wrote. “This [man-in-the-middle] attack may indicate that there is at least some conflict between the Chinese authorities and Apple over some of the features on the new phone.”

Apple’s enhanced encryption has also rankled U.S. law enforcement officials, who claim the tougher security and privacy measures make it harder to solve crimes or foil terrorists. FBI Director James Comey called on Apple and Google to reverse course.

This article originally appeared on Recode.net.

More in Technology

Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram
Technology
What happened when they installed ChatGPT on a nuclear supercomputerWhat happened when they installed ChatGPT on a nuclear supercomputer
Technology

How they’re using AI at the lab that created the atom bomb.

By Joshua Keating
Future Perfect
Humanity’s return to the moon is a deeply religious missionHumanity’s return to the moon is a deeply religious mission
Future Perfect

Space barons like Jeff Bezos and Elon Musk don’t seem religious. But their quest to colonize outer space is.

By Sigal Samuel