Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Scheduled Pinned Locked Moved Uncategorized
privacyappleiosinfosec
13 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mysk@mastodon.socialM mysk@mastodon.social

    @nemo This is the toughest part of the project 😂

    nemo@mas.toN This user is from outside of this forum
    nemo@mas.toN This user is from outside of this forum
    nemo@mas.to
    wrote last edited by
    #4

    @mysk Hahaha xD oh… oops 😅 🤣 🙏 maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

    In the animal kingdom, some birds or other animals shout to alert others to predators — maybe something along those lines. 🤔
    The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

    nemo@mas.toN 1 Reply Last reply
    0
    • nemo@mas.toN nemo@mas.to

      @mysk Hahaha xD oh… oops 😅 🤣 🙏 maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

      In the animal kingdom, some birds or other animals shout to alert others to predators — maybe something along those lines. 🤔
      The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

      nemo@mas.toN This user is from outside of this forum
      nemo@mas.toN This user is from outside of this forum
      nemo@mas.to
      wrote last edited by
      #5

      @mysk 2/2

      Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

      Or maybe lighthouse 🤔

      d5v3@masto.aiD 1 Reply Last reply
      0
      • mysk@mastodon.socialM mysk@mastodon.social

        Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
        #Apple #iOS #infosec

        Link Preview Image
        A This user is from outside of this forum
        A This user is from outside of this forum
        atom0@mamot.fr
        wrote last edited by
        #6

        @mysk thank you for this

        I know for example that the device accelerometer is accessible.
        That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
        I don’t know why Apple didn’t make a portal for this yet

        In fact only an orientation api is required…

        mysk@mastodon.socialM 1 Reply Last reply
        0
        • A atom0@mamot.fr

          @mysk thank you for this

          I know for example that the device accelerometer is accessible.
          That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
          I don’t know why Apple didn’t make a portal for this yet

          In fact only an orientation api is required…

          mysk@mastodon.socialM This user is from outside of this forum
          mysk@mastodon.socialM This user is from outside of this forum
          mysk@mastodon.social
          wrote last edited by
          #7

          @Atom0 Exactly, the app will cover all these signals and present them to the user in a nice and informative way.

          1 Reply Last reply
          0
          • nemo@mas.toN nemo@mas.to

            @mysk 2/2

            Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

            Or maybe lighthouse 🤔

            d5v3@masto.aiD This user is from outside of this forum
            d5v3@masto.aiD This user is from outside of this forum
            d5v3@masto.ai
            wrote last edited by
            #8

            @nemo @mysk

            I always liked the French word for bird:

            Oiseau

            Wah zoh

            1 Reply Last reply
            0
            • mysk@mastodon.socialM mysk@mastodon.social

              Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
              #Apple #iOS #infosec

              Link Preview Image
              mysk@mastodon.socialM This user is from outside of this forum
              mysk@mastodon.socialM This user is from outside of this forum
              mysk@mastodon.social
              wrote last edited by
              #9

              For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

              Link Preview ImageLink Preview ImageLink Preview Image
              mysk@mastodon.socialM 1 Reply Last reply
              0
              • mysk@mastodon.socialM mysk@mastodon.social

                For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

                Link Preview ImageLink Preview ImageLink Preview Image
                mysk@mastodon.socialM This user is from outside of this forum
                mysk@mastodon.socialM This user is from outside of this forum
                mysk@mastodon.social
                wrote last edited by
                #10

                Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                #privacy #infosec

                Link Preview Image
                mysk@mastodon.socialM 1 Reply Last reply
                0
                • mysk@mastodon.socialM mysk@mastodon.social

                  Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                  Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                  #privacy #infosec

                  Link Preview Image
                  mysk@mastodon.socialM This user is from outside of this forum
                  mysk@mastodon.socialM This user is from outside of this forum
                  mysk@mastodon.social
                  wrote last edited by
                  #11

                  🤯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                  The UUID seems to be the same for all devices.

                  Link Preview Image
                  mysk@mastodon.socialM 1 Reply Last reply
                  0
                  • mysk@mastodon.socialM mysk@mastodon.social

                    🤯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                    The UUID seems to be the same for all devices.

                    Link Preview Image
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.social
                    wrote last edited by
                    #12

                    So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPs🤷‍♂️

                    Link Preview Image
                    vestige@sleepyhe.adV 1 Reply Last reply
                    0
                    • mysk@mastodon.socialM mysk@mastodon.social

                      So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPs🤷‍♂️

                      Link Preview Image
                      vestige@sleepyhe.adV This user is from outside of this forum
                      vestige@sleepyhe.adV This user is from outside of this forum
                      vestige@sleepyhe.ad
                      wrote last edited by
                      #13

                      @mysk oh man wait till folks hear about carrier enrichment

                      1 Reply Last reply
                      0
                      • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups