A “white hat” security researcher who says he found 13 bugs in Apple’s software claims to be the cause of Apple shutting down developer.apple.com. He also claims to have over 100,000 users’ private details.
Ibrahim Balic made the statement, along with a video allegedly detailing the breaches, in a comment on TechCrunch’s story about the hack.
VentureBeat is following up with both Balic and Apple and will update this story as we learn more.
Update: Apple responds to developer site hacker, sort of
It’s difficult to ascertain whether Balic’s statements are true. He has since made the YouTube video private, claiming on Twitter that he had to show it initially to prove that he had penetrated Apple’s security but that it showed “confidential information.”
Balic says he informed Apple of the issues, with screenshots and details, via Apple’s bug reporting page, but he said he’s received no answer. Four hours after his last post, Apple shut down the developer site. He has since e-mailed Apple but still received no response.
4 hours later from my final report Apple developer portal gas closed down and you know it still is. I have emailed and asked if I am putting them in any difficulty so that I can give a break to my research. I have not gotten any respond to this… I have been waiting since then for them to contact me, and today I’m reading news saying that they have been attacked and hacked. In some of the media news I watch/read that whether legal authorities were involved in its investigation of the hack. I’m not feeling very happy with what I read and a bit irritated, as I did not done this research to harm or damage. I didn’t attempt to publish or have not shared this situation with anybody else. My aim was to report bugs and collect the datas for the porpoise of seeing how deep I can go within this scope. I have over 100.000+ users details and Apple is informed about this. I didn’t attempt to get the datas first and report then, instead I have reported first.
Balic’s story seems a little strange, not least because English is obviously his second language. But he first says, “I have taken 73 users details, all apple inc workers only, and prove them as an example” and then later clearly states that “I have over 100,000+ users details and Apple is informed about this.”
Typically, white hat researchers do not actually access or copy user details. And there’s a major difference between accessing 73 to prove a breach and copying 100,000-plus. That’s much more serious and much more concerning for every Apple developer as well as Apple itself.
Balic hasn’t updated his blog since Jan. 31. Clearly, he’s had a lot of time to poke around Apple’s sites and find holes. Just as clearly, however, he’s aware of what a major hornet’s nest he’s kicked over, and is wishing that it could all just be over: