
Just days after the launch of the iPhone 6 and iPhone 6 Plus in China, anti-censorship watchdog GreatFire.org reports the country’s authorities are staging a man-in-the-middle (MITM) attack on Apple’s cloud storage service, iCloud. The attack is limited to users who access iCloud on a desktop or mobile browser where they are required to enter their username and password.
(Updated on October 23: Yesterday, Apple CEO Tim Cook held talks in Beijing with Vice Premier Ma Kai “on user data protection.” Apple has acknowledged concerns about iCloud lapses in China (see this new support page) but has not apportioned blame for the attacks. GreatFire reported on October 20, shortly after this post was published, that Apple promptly changed the iCloud.com DNS in China so as to avoid the attack. Today Cook tweeted a photo of his visit to a Foxconn factory. Note: this article was published originally on October 20.)
A MITM attack happens when two parties – iCloud users and iCloud, in this case – believe they are communicating directly to each other, when in fact a third party is collecting and relaying all the messages in between them.
“We first noticed this on Saturday morning China time. There were limited user reports then,” a source from GreatFire.org told Tech in Asia. “But today, there are far more user reports so we think it is more prevalent. We will likely continue to see more user reports as long as this attack is still in place.”
The attack affects anyone who accesses their iCloud from within China, even if they set up their account outside of China.
iCloud stores information like documents, iMessages, photos, and contacts. GreatFire says the attack is nationwide. It advises iCloud users in China to use secure browsers like Chrome and Firefox, which will prevent users from accessing iCloud while the MITM is in effect. The article notes that 360 Browser, a popular browser in China made by Qihoo, is not secure in this way. Additionally, a VPN and two-step verification for iCloud can help prevent accounts from being compromised.

A secure browser alerting the user that the connection to iCloud is not secure.
In August, Apple soothed Beijing’s ire over NSA snooping by adding state-run telco China Telecom as a data center provider, according to the Wall Street Journal. Apple assured users that the telco would not have access to the encrypted content.
“Even if the data is secure, this attack is about gleaning usernames and passwords from Apple customers in China,” said the GreatFire source. “If the authorities have your username and password, they have access to your data, regardless of encryption.”
iCloud isn’t the first major American internet company to be targeted by MITM attacks from China. Google, Yahoo, and Microsoft have all been hit in the past. GreatFire provides technical evidence of this latest attack on its website.
We have reached out to Apple for more information on the attack and will update this article if it responds.
(Source: GreatFire)
Editing by Steven Millward
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.





