<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Report: iTunes targeted in mystery&#160;hack</title>
	<atom:link href="http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Tue, 18 Jun 2013 04:51:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: teapot</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208699</link>
		<dc:creator>teapot</dc:creator>
		<pubDate>Fri, 09 Sep 2011 03:55:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208699</guid>
		<description>If you can&#039;t keep up it&#039;s not my problem.

1) Apple enforces the walled garden, so without a jailbreak you have no option but to use their appstore.
2) People use the appstore and load up credit under the assumption that everything is safer under that system, because apple ensured everyone so.
3) People&#039;s credit gets jacked and then the onus falls on them to:
a) notice their credit has been used without their authorisation
b) comprehensively prove to apple they didn&#039;t download whatever content they have been charged for
4) When people return to the appstore to check their credit hasn&#039;t been stolen they will possibly make an impulse purchase that they wouldn&#039;t have otherwise made if they didn&#039;t log on to check their credit.</description>
		<content:encoded><![CDATA[<p>If you can&#8217;t keep up it&#8217;s not my problem.</p>
<p>1) Apple enforces the walled garden, so without a jailbreak you have no option but to use their appstore.<br />
2) People use the appstore and load up credit under the assumption that everything is safer under that system, because apple ensured everyone so.<br />
3) People&#8217;s credit gets jacked and then the onus falls on them to:<br />
a) notice their credit has been used without their authorisation<br />
b) comprehensively prove to apple they didn&#8217;t download whatever content they have been charged for<br />
4) When people return to the appstore to check their credit hasn&#8217;t been stolen they will possibly make an impulse purchase that they wouldn&#8217;t have otherwise made if they didn&#8217;t log on to check their credit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: libelle</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208552</link>
		<dc:creator>libelle</dc:creator>
		<pubDate>Thu, 08 Sep 2011 23:38:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208552</guid>
		<description>There could have been a breach. Or there could be an internal problem. I had a series of charges against a Bank of America credit card that I had never used (activated it and then locked it in a drawer upon receipt). BofA denied any responsibility, but reversed the charges after I argued with several call-center people. They sent me a replacement card, and six months later, they sent me a new one because the new replacement&#039;s details had been &quot;accidentally published by a trusted third party.&quot; I can only assume there&#039;s some combination of data leaks and incompetence inside their organization that they refuse to acknowledge.</description>
		<content:encoded><![CDATA[<p>There could have been a breach. Or there could be an internal problem. I had a series of charges against a Bank of America credit card that I had never used (activated it and then locked it in a drawer upon receipt). BofA denied any responsibility, but reversed the charges after I argued with several call-center people. They sent me a replacement card, and six months later, they sent me a new one because the new replacement&#8217;s details had been &#8220;accidentally published by a trusted third party.&#8221; I can only assume there&#8217;s some combination of data leaks and incompetence inside their organization that they refuse to acknowledge.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Melissa Dow</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208473</link>
		<dc:creator>Melissa Dow</dc:creator>
		<pubDate>Thu, 08 Sep 2011 22:20:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208473</guid>
		<description>Huh! Didn&#039;t know this was widespread - it happened to me about 6mos ago. I found out when a purchase receipt showed up in my inbox for a bunch of games I had never downloaded. I contacted Apple right away, and they were very helpful. Full refund issued, no insinuations that I was trying to game them, etc.  </description>
		<content:encoded><![CDATA[<p>Huh! Didn&#8217;t know this was widespread &#8211; it happened to me about 6mos ago. I found out when a purchase receipt showed up in my inbox for a bunch of games I had never downloaded. I contacted Apple right away, and they were very helpful. Full refund issued, no insinuations that I was trying to game them, etc.  </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: That_Anonymous_Coward</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208460</link>
		<dc:creator>That_Anonymous_Coward</dc:creator>
		<pubDate>Thu, 08 Sep 2011 22:02:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208460</guid>
		<description>Heh, so I fired up iTunes last night, and got the new new new super version....  I rarely use iTunes, most of my iThingys are other peoples cast offs that needed a little work.
And I discovered something magical and wonderful, I have no CC number on file with iTunes.
I&#039;ve heard other people complaining that they had to fill one in, but my account is so very old and I only ever got songs from a promotion where you bought a pop and there was a code inside the cap.
I think I might be safe :)</description>
		<content:encoded><![CDATA[<p>Heh, so I fired up iTunes last night, and got the new new new super version&#8230;.  I rarely use iTunes, most of my iThingys are other peoples cast offs that needed a little work.<br />
And I discovered something magical and wonderful, I have no CC number on file with iTunes.<br />
I&#8217;ve heard other people complaining that they had to fill one in, but my account is so very old and I only ever got songs from a promotion where you bought a pop and there was a code inside the cap.<br />
I think I might be safe :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mikey</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208361</link>
		<dc:creator>Mikey</dc:creator>
		<pubDate>Thu, 08 Sep 2011 20:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208361</guid>
		<description>This exact thing happened to me several months ago.  I got an iTunes gift card for free from buying a printer at Office Max.  After I redeemed the card, a couple of days later all of the credit was gone and in it&#039;s place were horrible games that looked like they were designed and programmed by a third grader.  Apple refunded my money but it looks like this is an on-going problem with no easy solution.

This happened to me before the Gawker hack.</description>
		<content:encoded><![CDATA[<p>This exact thing happened to me several months ago.  I got an iTunes gift card for free from buying a printer at Office Max.  After I redeemed the card, a couple of days later all of the credit was gone and in it&#8217;s place were horrible games that looked like they were designed and programmed by a third grader.  Apple refunded my money but it looks like this is an on-going problem with no easy solution.</p>
<p>This happened to me before the Gawker hack.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208288</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 08 Sep 2011 19:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208288</guid>
		<description>Also: how many people seeing unauthorized purchases are using jailbroken devices?

This isn&#039;t an uninformed rant against jailbreaking. Do it if you want, but remember when you jailbreak, you are giving someone else&#039;s code (Cydia and all the apps on it...) root privileges. That code can access anything on your device, including your Apple ID and any cookies associated with it. App Store apps definitely do not have that kind of access. Everything they do goes through iOS&#039;s APIs, which allow things like in-app purchases without revealing account details.

Your iTunes password is never stored, and is never sent to Apple in the clear. When you log into your account at least two cookies get set on the device. One permits read-only access to your account for an indefinite period of time, allowing you to browse the store, download content, etc... The other permits purchases and changing account details for a small window (I think an hour, maybe?). That&#039;s why you have to enter your password the first time you buy something, but then you don&#039;t have to for a while. 

It would be trivial for a rogue app installed thru Cydia, etc... to snatch those cookies and send them somewhere, at which point they could be used on any device to purchase from your account.</description>
		<content:encoded><![CDATA[<p>Also: how many people seeing unauthorized purchases are using jailbroken devices?</p>
<p>This isn&#8217;t an uninformed rant against jailbreaking. Do it if you want, but remember when you jailbreak, you are giving someone else&#8217;s code (Cydia and all the apps on it&#8230;) root privileges. That code can access anything on your device, including your Apple ID and any cookies associated with it. App Store apps definitely do not have that kind of access. Everything they do goes through iOS&#8217;s APIs, which allow things like in-app purchases without revealing account details.</p>
<p>Your iTunes password is never stored, and is never sent to Apple in the clear. When you log into your account at least two cookies get set on the device. One permits read-only access to your account for an indefinite period of time, allowing you to browse the store, download content, etc&#8230; The other permits purchases and changing account details for a small window (I think an hour, maybe?). That&#8217;s why you have to enter your password the first time you buy something, but then you don&#8217;t have to for a while. </p>
<p>It would be trivial for a rogue app installed thru Cydia, etc&#8230; to snatch those cookies and send them somewhere, at which point they could be used on any device to purchase from your account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208249</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 08 Sep 2011 18:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208249</guid>
		<description>I wonder why the billing zipcode (but not the street address) is changed. The only reason I can think of is because CC processors verify the billing zipcode against what they have for the card, which is why you sometimes have to enter it at gas pumps. 

So you break into someone&#039;s iTunes account, change their billing zip and add a stolen card. Then you buy a bunch of crap you put on the App Store, and Apple pays your cut. You&#039;ve just used iTunes to launder money. But that isn&#039;t what&#039;s happening here... On the other hand, if you had credit on iTunes, wouldn&#039;t that get used before any card gets charged? Maybe the credit being drained is just a side effect. </description>
		<content:encoded><![CDATA[<p>I wonder why the billing zipcode (but not the street address) is changed. The only reason I can think of is because CC processors verify the billing zipcode against what they have for the card, which is why you sometimes have to enter it at gas pumps. </p>
<p>So you break into someone&#8217;s iTunes account, change their billing zip and add a stolen card. Then you buy a bunch of crap you put on the App Store, and Apple pays your cut. You&#8217;ve just used iTunes to launder money. But that isn&#8217;t what&#8217;s happening here&#8230; On the other hand, if you had credit on iTunes, wouldn&#8217;t that get used before any card gets charged? Maybe the credit being drained is just a side effect. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1208226</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 08 Sep 2011 18:27:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1208226</guid>
		<description>are you an idiot? iTunes hasn&#039;t had DRM on music for years now.</description>
		<content:encoded><![CDATA[<p>are you an idiot? iTunes hasn&#8217;t had DRM on music for years now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: librtee_dot_com</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207932</link>
		<dc:creator>librtee_dot_com</dc:creator>
		<pubDate>Thu, 08 Sep 2011 15:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207932</guid>
		<description>Wait...hackers broke in..and stole a bunch of crappy DRMed songs? That&#039;s like breaking into the sewage treatment plant to steal halfway treated shit...</description>
		<content:encoded><![CDATA[<p>Wait&#8230;hackers broke in..and stole a bunch of crappy DRMed songs? That&#8217;s like breaking into the sewage treatment plant to steal halfway treated shit&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dennis Smith</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207891</link>
		<dc:creator>Dennis Smith</dc:creator>
		<pubDate>Thu, 08 Sep 2011 15:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207891</guid>
		<description>This is a simple problem that has happened before where gangs people go to stores, look at the gift cards on display and note the numbers on the cards if they are in sequential order (A good store has several displays of cards and jumble them all up). If they are all in order, then they monitor them nearly daily, when one is sold, they know the number of the card and they just use it to there own account.

Simple fraud. Monitor a dozen stores in one small town and you have a few thousand quid, monitor a all the stores in all the towns on one motorway stretch and you have a shed load of cash over a few months. This also works with gift cards for other e-retailers/B+M stores too. Nearly every supermarket and card shop has at least one display with gift cards and apple/ebay/paypal/amazon gift cards openly available.</description>
		<content:encoded><![CDATA[<p>This is a simple problem that has happened before where gangs people go to stores, look at the gift cards on display and note the numbers on the cards if they are in sequential order (A good store has several displays of cards and jumble them all up). If they are all in order, then they monitor them nearly daily, when one is sold, they know the number of the card and they just use it to there own account.</p>
<p>Simple fraud. Monitor a dozen stores in one small town and you have a few thousand quid, monitor a all the stores in all the towns on one motorway stretch and you have a shed load of cash over a few months. This also works with gift cards for other e-retailers/B+M stores too. Nearly every supermarket and card shop has at least one display with gift cards and apple/ebay/paypal/amazon gift cards openly available.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan Griffin</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207868</link>
		<dc:creator>Ryan Griffin</dc:creator>
		<pubDate>Thu, 08 Sep 2011 14:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207868</guid>
		<description>by &#039;radio&#039; you obviously mean &quot;Clearchannel&quot;.  My dial never moves from my local NPR based station.</description>
		<content:encoded><![CDATA[<p>by &#8216;radio&#8217; you obviously mean &#8220;Clearchannel&#8221;.  My dial never moves from my local NPR based station.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207851</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Thu, 08 Sep 2011 14:17:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207851</guid>
		<description>Mr. BelBruno might listen to the radio.</description>
		<content:encoded><![CDATA[<p>Mr. BelBruno might listen to the radio.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ludopathy</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207847</link>
		<dc:creator>Ludopathy</dc:creator>
		<pubDate>Thu, 08 Sep 2011 14:00:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207847</guid>
		<description>He is actually spot on. It wouldn&#039;t be hard at all to develop an algorithm that routinely checks if people have logged onto their accounts, then steals something small, then the stealFactor variable that controls the amount stolen increases a little bit more.

And if people complain too much, the stealFactor variable scales back.
It could be possible, after all, it&#039;s a closed source platform.</description>
		<content:encoded><![CDATA[<p>He is actually spot on. It wouldn&#8217;t be hard at all to develop an algorithm that routinely checks if people have logged onto their accounts, then steals something small, then the stealFactor variable that controls the amount stolen increases a little bit more.</p>
<p>And if people complain too much, the stealFactor variable scales back.<br />
It could be possible, after all, it&#8217;s a closed source platform.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ludopathy</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207845</link>
		<dc:creator>Ludopathy</dc:creator>
		<pubDate>Thu, 08 Sep 2011 13:54:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207845</guid>
		<description>Creative Commons, Jammendo, Go to Concerts</description>
		<content:encoded><![CDATA[<p>Creative Commons, Jammendo, Go to Concerts</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ludopathy</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207843</link>
		<dc:creator>Ludopathy</dc:creator>
		<pubDate>Thu, 08 Sep 2011 13:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207843</guid>
		<description>The kind of flash content you can&#039;t display on most Apple toys?</description>
		<content:encoded><![CDATA[<p>The kind of flash content you can&#8217;t display on most Apple toys?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Hoskins</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207842</link>
		<dc:creator>David Hoskins</dc:creator>
		<pubDate>Thu, 08 Sep 2011 13:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207842</guid>
		<description>Are you advocating theft?</description>
		<content:encoded><![CDATA[<p>Are you advocating theft?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: RyanMcFitz</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207839</link>
		<dc:creator>RyanMcFitz</dc:creator>
		<pubDate>Thu, 08 Sep 2011 13:46:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207839</guid>
		<description>That&#039;s the party-line response from any credit card theft as well.  Credit card companies explain that the restaurant/hotel/store is the actual victim and disseminating details of how the theft occurred only weakens consumer confidence in going back to that restaurant/hotel/store.  So in that regard, Apple is only telling people the same thing a credit card company would.

Regardless, that particular argument that the credit card holder is merely inconvenienced whereas the store is the *real* victim really irks my chickens.</description>
		<content:encoded><![CDATA[<p>That&#8217;s the party-line response from any credit card theft as well.  Credit card companies explain that the restaurant/hotel/store is the actual victim and disseminating details of how the theft occurred only weakens consumer confidence in going back to that restaurant/hotel/store.  So in that regard, Apple is only telling people the same thing a credit card company would.</p>
<p>Regardless, that particular argument that the credit card holder is merely inconvenienced whereas the store is the *real* victim really irks my chickens.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justanothercynic</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207836</link>
		<dc:creator>justanothercynic</dc:creator>
		<pubDate>Thu, 08 Sep 2011 13:42:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207836</guid>
		<description>And in the end it is again the consumer who suffers at the feet of Apple&#039;s mistakes. </description>
		<content:encoded><![CDATA[<p>And in the end it is again the consumer who suffers at the feet of Apple&#8217;s mistakes. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tommy Timefishblue</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207813</link>
		<dc:creator>Tommy Timefishblue</dc:creator>
		<pubDate>Thu, 08 Sep 2011 12:50:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207813</guid>
		<description>I can&#039;t blame Apple for refusing to give some people refunds. Think of the cost to them! Copies of MP3s don&#039;t grow on trees, you know.</description>
		<content:encoded><![CDATA[<p>I can&#8217;t blame Apple for refusing to give some people refunds. Think of the cost to them! Copies of MP3s don&#8217;t grow on trees, you know.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stooge</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207800</link>
		<dc:creator>Stooge</dc:creator>
		<pubDate>Thu, 08 Sep 2011 11:48:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207800</guid>
		<description>There&#039;s also no proof that you understand what a non sequitur is...</description>
		<content:encoded><![CDATA[<p>There&#8217;s also no proof that you understand what a non sequitur is&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: teapot</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207788</link>
		<dc:creator>teapot</dc:creator>
		<pubDate>Thu, 08 Sep 2011 10:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207788</guid>
		<description>Where are all the proponents of the walled garden now? That walled garden just ate your credit.. there&#039;s also no proof that Apple didn&#039;t just sneakily delete it themselves. Customers (esp those who haven&#039;t logged on in a while) then return to their store en masse to check they haven&#039;t been screwed. Clever.

Oh, and F YOU AGAIN APPLE. Now I have to login to your crapstore to make sure you didn&#039;t steal/lose my money.</description>
		<content:encoded><![CDATA[<p>Where are all the proponents of the walled garden now? That walled garden just ate your credit.. there&#8217;s also no proof that Apple didn&#8217;t just sneakily delete it themselves. Customers (esp those who haven&#8217;t logged on in a while) then return to their store en masse to check they haven&#8217;t been screwed. Clever.</p>
<p>Oh, and F YOU AGAIN APPLE. Now I have to login to your crapstore to make sure you didn&#8217;t steal/lose my money.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: justanothercynic</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207785</link>
		<dc:creator>justanothercynic</dc:creator>
		<pubDate>Thu, 08 Sep 2011 10:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207785</guid>
		<description>The longer Apple ignore those affected and don&#039;t release statements about the breaches the longer that they can market their products to those who aren&#039;t aware of their poor practices as secure.</description>
		<content:encoded><![CDATA[<p>The longer Apple ignore those affected and don&#8217;t release statements about the breaches the longer that they can market their products to those who aren&#8217;t aware of their poor practices as secure.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nathan Hornby</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207786</link>
		<dc:creator>Nathan Hornby</dc:creator>
		<pubDate>Thu, 08 Sep 2011 10:41:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207786</guid>
		<description>Happened to me a little while back (maybe 4 months?).

It&#039;s worse than it sounds.The game in question was something to do with poker - a game I&#039;d never downloaded - not even by accident.  The credit was being drained via in-app purchases of this game, a game that not only have I not bought or downloaded but has also never been installed on any of my devices.

I use a unique password for iTunes and I&#039;m not the kind of chap to fall for Phishing scams.  I am convinced that someone gained access to my account either via accessing my password directly from Apple (unlikely) or managed to download this app without knowing my password, or managed to brute-force mine and several other peoples accounts.

So 2 things here.  A game was able to make in-app purchases on my account via a game I hadn&#039;t purchased and had never been installed.  And a totally secure, unique password wasn&#039;t enough to prevent it.  In short, if you don&#039;t want this to happen, never buy iTunes Credit (for some reason it wasn&#039;t able to use my stored card details).</description>
		<content:encoded><![CDATA[<p>Happened to me a little while back (maybe 4 months?).</p>
<p>It&#8217;s worse than it sounds.The game in question was something to do with poker &#8211; a game I&#8217;d never downloaded &#8211; not even by accident.  The credit was being drained via in-app purchases of this game, a game that not only have I not bought or downloaded but has also never been installed on any of my devices.</p>
<p>I use a unique password for iTunes and I&#8217;m not the kind of chap to fall for Phishing scams.  I am convinced that someone gained access to my account either via accessing my password directly from Apple (unlikely) or managed to download this app without knowing my password, or managed to brute-force mine and several other peoples accounts.</p>
<p>So 2 things here.  A game was able to make in-app purchases on my account via a game I hadn&#8217;t purchased and had never been installed.  And a totally secure, unique password wasn&#8217;t enough to prevent it.  In short, if you don&#8217;t want this to happen, never buy iTunes Credit (for some reason it wasn&#8217;t able to use my stored card details).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: That_Anonymous_Coward</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207759</link>
		<dc:creator>That_Anonymous_Coward</dc:creator>
		<pubDate>Thu, 08 Sep 2011 08:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207759</guid>
		<description>The problem is these reports are popping up from time to time, and Apple keeps saying NOTHING... they offer little to no help to the people affected.  
If it was just as password hack issue, Apple doesn&#039;t have the resources to run the gawker list and tell people to change their compromised info?
Instead you seem to have a continuous breech into the Apple system, that Apple seems to be pretending has never happened as more and more peoples accounts get hit.</description>
		<content:encoded><![CDATA[<p>The problem is these reports are popping up from time to time, and Apple keeps saying NOTHING&#8230; they offer little to no help to the people affected. <br />
If it was just as password hack issue, Apple doesn&#8217;t have the resources to run the gawker list and tell people to change their compromised info?<br />
Instead you seem to have a continuous breech into the Apple system, that Apple seems to be pretending has never happened as more and more peoples accounts get hit.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: vonbobo</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207747</link>
		<dc:creator>vonbobo</dc:creator>
		<pubDate>Thu, 08 Sep 2011 06:16:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207747</guid>
		<description>It&#039;s probably due to Flash related content.</description>
		<content:encoded><![CDATA[<p>It&#8217;s probably due to Flash related content.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Berk</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207745</link>
		<dc:creator>Berk</dc:creator>
		<pubDate>Thu, 08 Sep 2011 06:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207745</guid>
		<description>The headline is kinda misleading, I doubt Itunes has been hacked (not impossible, but unlikely)

I&#039;d guess it&#039;s more likely that it&#039;s just people being slack with passwords, the gawker hack etc, even without getting an Itunes password, an email account password will likely grant you access to enough that you can get into Itunes.</description>
		<content:encoded><![CDATA[<p>The headline is kinda misleading, I doubt Itunes has been hacked (not impossible, but unlikely)</p>
<p>I&#8217;d guess it&#8217;s more likely that it&#8217;s just people being slack with passwords, the gawker hack etc, even without getting an Itunes password, an email account password will likely grant you access to enough that you can get into Itunes.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ogvor</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207704</link>
		<dc:creator>ogvor</dc:creator>
		<pubDate>Thu, 08 Sep 2011 03:22:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207704</guid>
		<description>Interesting, this is exactly what happened to me about half a year ago.  I didn&#039;t have a credit card on file so I&#039;d just assumed someone had gotten my password (maybe the Gawker hack?) but couldn&#039;t do anything more than use up my gift card balance.  I think they bought the Sims for iPhone.  Anyway, Apple refunded the gift card balance and I changed my password so I&#039;d assumed that was the end of it.</description>
		<content:encoded><![CDATA[<p>Interesting, this is exactly what happened to me about half a year ago.  I didn&#8217;t have a credit card on file so I&#8217;d just assumed someone had gotten my password (maybe the Gawker hack?) but couldn&#8217;t do anything more than use up my gift card balance.  I think they bought the Sims for iPhone.  Anyway, Apple refunded the gift card balance and I changed my password so I&#8217;d assumed that was the end of it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: grimc</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207693</link>
		<dc:creator>grimc</dc:creator>
		<pubDate>Thu, 08 Sep 2011 03:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207693</guid>
		<description>Clearly, Apple needs moar SF cops.</description>
		<content:encoded><![CDATA[<p>Clearly, Apple needs moar SF cops.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Guest</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207688</link>
		<dc:creator>Guest</dc:creator>
		<pubDate>Thu, 08 Sep 2011 02:59:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207688</guid>
		<description>I think Apple needs to re-examine their policies regarding their iTunes store and the App Store.  Both offer more problems than solutions and are not easy to use for those of us who live in a foreign country.

I do know that Apple has a BIG problem if they can not solve this security issue and I wonder what other security issues will pop up in the future as their gear becomes more popular.</description>
		<content:encoded><![CDATA[<p>I think Apple needs to re-examine their policies regarding their iTunes store and the App Store.  Both offer more problems than solutions and are not easy to use for those of us who live in a foreign country.</p>
<p>I do know that Apple has a BIG problem if they can not solve this security issue and I wonder what other security issues will pop up in the future as their gear becomes more popular.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph BelBruno</title>
		<link>http://boingboing.net/2011/09/07/mystery-hack-targets-itunes-say-victims.html#comment-1207674</link>
		<dc:creator>Joseph BelBruno</dc:creator>
		<pubDate>Thu, 08 Sep 2011 02:33:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=116737#comment-1207674</guid>
		<description>Don&#039;t pay for music, problem solved.</description>
		<content:encoded><![CDATA[<p>Don&#8217;t pay for music, problem solved.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
