Along with the myriad other problems with Apple’s MobileMe service — syncing conflicts, corrupted data, dropped connections — users can now add another concern: spam.
Apple has provided spammers with a “dead simple way to easily spider their iDisk property to retrieve the entire MobileMe user name list,” Michael Arrington charged Thursday on his TechCrunch blog.
Every MobileMe user gets a public iDisk file-sharing site where they can post files for their public or private use, Arrington explained. Even if users set their pages to private, “it still shows the username if you go to the page,” Arrington said. “There is no way as a user to hide or delete your public folder. If you are a MobileMe customer, you have one.”
A simple dictionary attack to gather e-mail addresses by appending @mac.com or @me.com should be trivial.
Well-Known Tactic
Apple confirmed that users cannot remove their account names from iDisk. A spokesman discounted the risk, saying, “We’ve never had a complaint from a customer about people spamming them because of their iDisk public folder name. There is no way to remove your account name from the iDisk folders. I’m very sorry.”
That’s a very weak response, according to Andrew Storms, director of security operations for nCircle Network Security. “Every public Internet service needs to be concerned with this kind of information-gathering tactic,” he said. “It’s both a well-known and long-standing issue that some people just don’t see where the problem lies.”
The data on an iDisk is “enough information to seed spam and phishing databases,” Storms added.
‘Unneeded Disclosure’
“Simply put, this is unneeded information disclosure,” Storms asserted. “The right thing for Apple to have done would be to default to the closed state. Everything should be set to private unless the user chooses differently.” Instead of telling the world that the user has selected the “private”…