One hundred celebrities had been hacked with their photos in the cloud. A lot of my jpegs are in the iCloud and Dropbox. I wonder how secures my photos are going to be. Sounds pretty scary.
First, it now appears (and this info could be wrong) that the photos were hacked by getting in to people's phones, by phishing, and by dedicated efforts to crack passwords. The latest report I've seen doesn't attribute any of this to Cloud vulnerabilities.
Apple says hackers targeted celebrity accounts, not iCloud systems - The Washington Post
Second, yes, it's correct to be concerned. But not just about Cloud vulnerabilities. For instance, the only true way of cyber and system security for civilians is "two factor" authentication. Assuming you follow all the other basic 101 advice (password of at least 8 characters with caps and non-cap, number and symbol, nothing that spells a word, not written down anyplace, not used on other accounts or sites, no symbology to you such as your birthdate....oh...and you change it monthly; a personal firewall to your system plus password protected home wifi so someone on your sidewalk can't access your network; maintaining at least two different malware checkers on your machine and using both regularly; screening all attachments and incoming messages; security on your phone; no auto sync with your laptop/computer and any backup systems; running a magnet and then a drill through any hard drive or flash drive that you discard or give away), "two factor" authentication (which most systems allow for) is a major pain. But it's pretty effective for civilians in mainstream life. It means that before you sign on to any site or log-on to any program, you have to enter a small code. But that code changes every time you enter that program or that website. So for instance, you decide to check our your favorite website The Photo Forum to see if there any any interesting threads by Runnah. You put in your name and password and click enter. You aren't allowed in the site. Instead, a message is texted to your phone with the code. You then enter that code into TFP sign-in and you're allowed entry where you discover, sadly, that Runnah has been on vacation and has started no new threads. It only took you about 5 minutes to sign-on to the site (b/c you had trouble reading the text on your phone and typed it in wrong once).
I have no illusions here. If someone wants to really break in to one of my systems and they have the resources (and no, I don't mean the FSB or the NGA or the Chinese), then they'll be successful. They can go through my garbage. They can contact my clients (who may have a password to a photosharing site I sent them to review their photos). They can engage in a range of scam activities (most of them person to person over the phone) to get info to engage in a brute force attack.