According to Great Fire, Chinese authorities are reportedly using a 'man-in-the-middle attack' to gather usernames and passwords from Chinese iCloud Users. Chinese officials have reportedly set up a firewall that blocks all connections to iCloud.com, and redirects users to dummy site that looks exactly like Apple's iCloud login page.
This is clearly a malicious attack on Apple in an effort to gain access to usernames and passwords and consequently all data stored on iCloud such as iMessages, photos, contacts, etc. Unlike the recent attack on Google, this attack is nationwide and coincides with the launch today in China of the newest iPhone. While the attacks on Google and Yahoo enabled the authorities to snoop on what information Chinese were accessing on those two platforms, the Apple attack is different. If users ignored the security warning and clicked through to the Apple site and entered their username and password, this information has now been compromised by the Chinese authorities. Many Apple customers use iCloud to store their personal information, including iMessages, photos and contacts. This may also somehow be related again to images and videos of the Hong Kong protests being shared on the mainland.
Since this phishing attempt is taking place at a high level, it is very likely that the Chinese authorities are indeed behind this attack to gather usernames and passwords. A similar attack is also being launched against Microsoft's login.live.com accounts.
Great Fire advises Chinese users to use a trusted web browser such as FireFox and Chrome, which will warn users of the phishing attempt. Unfortunately, Qihoo, the most popular browse in China, is not warning users of the attack.
The phishing attempt comes just as Apple has recently launched the iPhone 6 and iPhone 6 Plus in the country.
Would you like to be notified when someone replies or adds a new comment?
Yes (All Threads)
Yes (This Thread Only)
No
Notifications
Would you like to be notified when we post a new Apple news article or tutorial?
Yes
No
Comments (7)
Comments are closed for this article.
0
iProService - October 21, 2014 at 5:10pm
Makes me wonder how "safe" our computers and devices are after using pangu.
0
Chul - October 21, 2014 at 11:56am
Menurut Arif , Jokowi-JK perlu memastikan pengejawantahan program-program jangka pendek atau menunjukkan sinyal positif perubahan pada masa awal pemerintahan, karena hal itu merupakan cara efektif untuk menjemput harapan dan kepercayaan rakyat.
0
dave vangina - October 21, 2014 at 8:33am
One more reason to buy Samsung. Samsung clearly wins. They do not even need new phones, just wait for more bugs showing up on iPhonies.
0
tommyy - October 21, 2014 at 12:18am
Enable two-step verification will solve login leaked.
They can't use it easily. They have to get same mobile number simcard or steal user phone.
0
Donal Pangihutan - October 20, 2014 at 11:55pm
@LH, cukup dengan tidak login via portal nya dulu, sampai Apple sendiri bilang aman, tapi jika login dari iTunes Or handset (iPhone, iPad) nya langsung saya yakin masih aman
0
Chul - October 21, 2014 at 11:57am
Menurut Arif, Jokowi-JK perlu memastikan pengejawantahan program-program jangka pendek atau menunjukkan sinyal positif perubahan pada masa awal pemerintahan, Karena hal itu merupakan cara efektif untuk menjemput harapan dan kepercayaan rakyat
0
Mewfasa - October 20, 2014 at 10:00pm
And we are waiting for these chinese to bring jailbreak. /trust