Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission.

Scheduled Pinned Locked Moved Uncategorized
privacyappleiosinfosec
13 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mysk@mastodon.socialM mysk@mastodon.social

    Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
    #Apple #iOS #infosec

    Link Preview Image
    nemo@mas.toN This user is from outside of this forum
    nemo@mas.toN This user is from outside of this forum
    nemo@mas.to
    wrote last edited by
    #2

    @mysk Great πŸ™‚ what will be the name of the app? πŸ€”

    mysk@mastodon.socialM 1 Reply Last reply
    0
    • nemo@mas.toN nemo@mas.to

      @mysk Great πŸ™‚ what will be the name of the app? πŸ€”

      mysk@mastodon.socialM This user is from outside of this forum
      mysk@mastodon.socialM This user is from outside of this forum
      mysk@mastodon.social
      wrote last edited by
      #3

      @nemo This is the toughest part of the project πŸ˜‚

      nemo@mas.toN 1 Reply Last reply
      0
      • mysk@mastodon.socialM mysk@mastodon.social

        @nemo This is the toughest part of the project πŸ˜‚

        nemo@mas.toN This user is from outside of this forum
        nemo@mas.toN This user is from outside of this forum
        nemo@mas.to
        wrote last edited by
        #4

        @mysk Hahaha xD oh… oops πŸ˜… 🀣 πŸ™ maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

        In the animal kingdom, some birds or other animals shout to alert others to predators β€” maybe something along those lines. πŸ€”
        The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

        nemo@mas.toN 1 Reply Last reply
        0
        • nemo@mas.toN nemo@mas.to

          @mysk Hahaha xD oh… oops πŸ˜… 🀣 πŸ™ maybe along the lines of Little Snitch or Snoop Snitch. Something like Privacy Rat or something xD idk

          In the animal kingdom, some birds or other animals shout to alert others to predators β€” maybe something along those lines. πŸ€”
          The behavior is called an alarm call (or more broadly, alarm signalling); when individuals watch for predators and warn the group, it's also called sentinel behaviour. 1/2

          nemo@mas.toN This user is from outside of this forum
          nemo@mas.toN This user is from outside of this forum
          nemo@mas.to
          wrote last edited by
          #5

          @mysk 2/2

          Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

          Or maybe lighthouse πŸ€”

          d5v3@masto.aiD 1 Reply Last reply
          0
          • mysk@mastodon.socialM mysk@mastodon.social

            Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
            #Apple #iOS #infosec

            Link Preview Image
            A This user is from outside of this forum
            A This user is from outside of this forum
            atom0@mamot.fr
            wrote last edited by
            #6

            @mysk thank you for this

            I know for example that the device accelerometer is accessible.
            That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
            I don’t know why Apple didn’t make a portal for this yet

            In fact only an orientation api is required…

            mysk@mastodon.socialM 1 Reply Last reply
            0
            • A atom0@mamot.fr

              @mysk thank you for this

              I know for example that the device accelerometer is accessible.
              That means that the app can log this data and know if I’m on a desk, standing up, using my phone in movement, etc
              I don’t know why Apple didn’t make a portal for this yet

              In fact only an orientation api is required…

              mysk@mastodon.socialM This user is from outside of this forum
              mysk@mastodon.socialM This user is from outside of this forum
              mysk@mastodon.social
              wrote last edited by
              #7

              @Atom0 Exactly, the app will cover all these signals and present them to the user in a nice and informative way.

              1 Reply Last reply
              0
              • nemo@mas.toN nemo@mas.to

                @mysk 2/2

                Examples of birds that do this include the black-capped chickadee (its calls encode predator size), various jays and magpies, and many social species like swifts and starlings.

                Or maybe lighthouse πŸ€”

                d5v3@masto.aiD This user is from outside of this forum
                d5v3@masto.aiD This user is from outside of this forum
                d5v3@masto.ai
                wrote last edited by
                #8

                @nemo @mysk

                I always liked the French word for bird:

                Oiseau

                Wah zoh

                1 Reply Last reply
                0
                • mysk@mastodon.socialM mysk@mastodon.social

                  Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source.
                  #Apple #iOS #infosec

                  Link Preview Image
                  mysk@mastodon.socialM This user is from outside of this forum
                  mysk@mastodon.socialM This user is from outside of this forum
                  mysk@mastodon.social
                  wrote last edited by
                  #9

                  For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

                  Link Preview ImageLink Preview ImageLink Preview Image
                  mysk@mastodon.socialM 1 Reply Last reply
                  0
                  • mysk@mastodon.socialM mysk@mastodon.social

                    For example, there's an API that returns a global counter which increments every time you copy something to the clipboard in any app. In this early prototype, the count is 1349. All installed apps can silently read this value and potentially abuse it for fingerprinting.

                    Link Preview ImageLink Preview ImageLink Preview Image
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.socialM This user is from outside of this forum
                    mysk@mastodon.social
                    wrote last edited by
                    #10

                    Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                    Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                    #privacy #infosec

                    Link Preview Image
                    mysk@mastodon.socialM 1 Reply Last reply
                    0
                    • mysk@mastodon.socialM mysk@mastodon.social

                      Yes, every app installed on your iPhone can see your local IP address if you're connected to a Wi-Fi. No permission is required for this and a VPN cannot prevent it.

                      Knowing the local IP address could for example allow an app to infer if you’re at home or visiting a friend if the two networks use different subnet values (e.g. 192.168.x.x and 10.0.x.x)

                      #privacy #infosec

                      Link Preview Image
                      mysk@mastodon.socialM This user is from outside of this forum
                      mysk@mastodon.socialM This user is from outside of this forum
                      mysk@mastodon.social
                      wrote last edited by
                      #11

                      🀯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                      The UUID seems to be the same for all devices.

                      Link Preview Image
                      mysk@mastodon.socialM 1 Reply Last reply
                      0
                      • mysk@mastodon.socialM mysk@mastodon.social

                        🀯 Every app installed on the iPhone can read the iPhone's storage volume creation timestamp (down to the second). No permission required. This value remains the same until the volume is erased. Yikes!!
                        The UUID seems to be the same for all devices.

                        Link Preview Image
                        mysk@mastodon.socialM This user is from outside of this forum
                        mysk@mastodon.socialM This user is from outside of this forum
                        mysk@mastodon.social
                        wrote last edited by
                        #12

                        So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPsπŸ€·β€β™‚οΈ

                        Link Preview Image
                        vestige@sleepyhe.adV 1 Reply Last reply
                        0
                        • mysk@mastodon.socialM mysk@mastodon.social

                          So, every installed app can see your device's local IPs (Wi‑Fi, cellular SIM, VPN). A VPN doesn't prevent that. I tested iVPN, Mullvad VPN, and Proton VPN. I tried several options such as blocking LAN traffic. Nothing worked to hide the IPsπŸ€·β€β™‚οΈ

                          Link Preview Image
                          vestige@sleepyhe.adV This user is from outside of this forum
                          vestige@sleepyhe.adV This user is from outside of this forum
                          vestige@sleepyhe.ad
                          wrote last edited by
                          #13

                          @mysk oh man wait till folks hear about carrier enrichment

                          1 Reply Last reply
                          0
                          • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • World
                          • Users
                          • Groups