Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Scheduled Pinned Locked Moved Uncategorized
privacyappleiosinfosec
13 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mysk@mastodon.socialM This user is from outside of this forum
    mysk@mastodon.socialM This user is from outside of this forum
    mysk@mastodon.social
    wrote last edited by
    #1

    Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
    #Apple #iOS #infosec

    Link Preview Image
    nemo@mas.toN A mysk@mastodon.socialM 3 Replies Last reply
    1
    0
    • mysk@mastodon.socialM mysk@mastodon.social

      Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
      #Apple #iOS #infosec

      Link Preview Image
      nemo@mas.toN This user is from outside of this forum
      nemo@mas.toN This user is from outside of this forum
      nemo@mas.to
      wrote last edited by
      #2

      @mysk Great πŸ™‚ what will be the name of the app? πŸ€”

      mysk@mastodon.socialM 1 Reply Last reply
      0
      • nemo@mas.toN nemo@mas.to

        @mysk Great πŸ™‚ what will be the name of the app? πŸ€”

        mysk@mastodon.socialM This user is from outside of this forum
        mysk@mastodon.socialM This user is from outside of this forum
        mysk@mastodon.social
        wrote last edited by
        #3

        @nemo This is the toughest part of the project πŸ˜‚

        nemo@mas.toN 1 Reply Last reply
        0
        • mysk@mastodon.socialM mysk@mastodon.social

          @nemo This is the toughest part of the project πŸ˜‚

          nemo@mas.toN This user is from outside of this forum
          nemo@mas.toN This user is from outside of this forum
          nemo@mas.to
          wrote last edited by
          #4

          @mysk Hahaha xD oh… oops πŸ˜… 🀣 πŸ™ maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

          In the animal kingdom, some birds or other animals shout to alert others to predators β€” maybe something along those lines. πŸ€”
          The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

          nemo@mas.toN 1 Reply Last reply
          0
          • nemo@mas.toN nemo@mas.to

            @mysk Hahaha xD oh… oops πŸ˜… 🀣 πŸ™ maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

            In the animal kingdom, some birds or other animals shout to alert others to predators β€” maybe something along those lines. πŸ€”
            The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

            nemo@mas.toN This user is from outside of this forum
            nemo@mas.toN This user is from outside of this forum
            nemo@mas.to
            wrote last edited by
            #5

            @mysk 2/2

            Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

            Or maybe lighthouse πŸ€”

            d5v3@masto.aiD 1 Reply Last reply
            0
            • mysk@mastodon.socialM mysk@mastodon.social

              Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
              #Apple #iOS #infosec

              Link Preview Image
              A This user is from outside of this forum
              A This user is from outside of this forum
              atom0@mamot.fr
              wrote last edited by
              #6

              @mysk thank you for this

              I know for example that the device accelerometer is accessible.
              That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
              I don’t know why Apple didn’t make a portal for this yet

              In fact only an orientation api is required…

              mysk@mastodon.socialM 1 Reply Last reply
              0
              • A atom0@mamot.fr

                @mysk thank you for this

                I know for example that the device accelerometer is accessible.
                That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
                I don’t know why Apple didn’t make a portal for this yet

                In fact only an orientation api is required…

                mysk@mastodon.socialM This user is from outside of this forum
                mysk@mastodon.socialM This user is from outside of this forum
                mysk@mastodon.social
                wrote last edited by
                #7

                @Atom0 Exactly, the app will cover all these signals and present them to the user in a nice and informative way.

                1 Reply Last reply
                0
                • nemo@mas.toN nemo@mas.to

                  @mysk 2/2

                  Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

                  Or maybe lighthouse πŸ€”

                  d5v3@masto.aiD This user is from outside of this forum
                  d5v3@masto.aiD This user is from outside of this forum
                  d5v3@masto.ai
                  wrote last edited by
                  #8

                  @nemo @mysk

                  I always liked the French word for bird:

                  Oiseau

                  Wah zoh

                  1 Reply Last reply
                  0
                  • mysk@mastodon.socialM mysk@mastodon.social

                    Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
                    #Apple #iOS #infosec

                    Link Preview Image
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.social
                    wrote last edited by
                    #9

                    For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

                    Link Preview ImageLink Preview ImageLink Preview Image
                    mysk@mastodon.socialM 1 Reply Last reply
                    0
                    • mysk@mastodon.socialM mysk@mastodon.social

                      For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

                      Link Preview ImageLink Preview ImageLink Preview Image
                      mysk@mastodon.socialM This user is from outside of this forum
                      mysk@mastodon.socialM This user is from outside of this forum
                      mysk@mastodon.social
                      wrote last edited by
                      #10

                      Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                      Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                      #privacy #infosec

                      Link Preview Image
                      mysk@mastodon.socialM 1 Reply Last reply
                      0
                      • mysk@mastodon.socialM mysk@mastodon.social

                        Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                        Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                        #privacy #infosec

                        Link Preview Image
                        mysk@mastodon.socialM This user is from outside of this forum
                        mysk@mastodon.socialM This user is from outside of this forum
                        mysk@mastodon.social
                        wrote last edited by
                        #11

                        🀯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                        The UUID seems to be the same for all devices.

                        Link Preview Image
                        mysk@mastodon.socialM 1 Reply Last reply
                        0
                        • mysk@mastodon.socialM mysk@mastodon.social

                          🀯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                          The UUID seems to be the same for all devices.

                          Link Preview Image
                          mysk@mastodon.socialM This user is from outside of this forum
                          mysk@mastodon.socialM This user is from outside of this forum
                          mysk@mastodon.social
                          wrote last edited by
                          #12

                          So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPsπŸ€·β€β™‚οΈ

                          Link Preview Image
                          vestige@sleepyhe.adV 1 Reply Last reply
                          0
                          • mysk@mastodon.socialM mysk@mastodon.social

                            So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPsπŸ€·β€β™‚οΈ

                            Link Preview Image
                            vestige@sleepyhe.adV This user is from outside of this forum
                            vestige@sleepyhe.adV This user is from outside of this forum
                            vestige@sleepyhe.ad
                            wrote last edited by
                            #13

                            @mysk oh man wait till folks hear about carrier enrichment

                            1 Reply Last reply
                            0
                            • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                            • Login

                            • Login or register to search.
                            • First post
                              Last post
                            0
                            • Categories
                            • Recent
                            • Tags
                            • Popular
                            • World
                            • Users
                            • Groups