Live data from Hacker News

Viewing profile — willstrafach

willstrafach

HN member
Joined
Fri, Feb 19, 2016, 4:18 AM UTC
HN karma
1,179
Public activity
678 items

About willstrafach

information security and privacy research.

Chief Executive Officer @ Guardian (https://guardianapp.com).

previously: founder of "Chronic Dev Team" & worked on many years of iOS jailbreaking solutions (24kPwn, absinthe, corona, greenpois0n, etc).

Recent public activity

  1. comment
    Comment #41094148

    “Facebook Research” was the Onavo codebase, under a different name, signed by Facebook’s Enterprise certificate.

  2. comment
    Comment #38674976

    iOS devices must be activated to use them. This is indeed stored in a database. AppleCare and third-party repair centers can query activation information using GSX. You are correct…

  3. comment
    Comment #31649637

    This may help: https://chrome.google.com/webstore/detail/icloud-passwords/p...

  4. comment
    Comment #31610305

    > That said, doesn’t iOS notify you when an app wants to use location services? Did all of these users just opt into that? That seems crazy, if so. Not so crazy. Local news, weathe…

  5. comment
    Comment #31610129

    They have some pretty bad past practices: https://www.zdnet.com/article/accuweather-caught-sending-geo... And they have continued, off-and-on, to use other location-collecting SDKs…

  6. comment
    Comment #30704694

    I think the pitch here is “Semi-managed WireGuard peer provisioning and NAT punching as a service” usable by anyone who may not otherwise have a clue how WireGuard works (eg. frien…

  7. comment
    Comment #30695336

    How would that work? Connections are mainly peer-to-peer with Tailscale. An attack (I suppose pushing new key pairs to specific peers and pointing them through a malicious endpoint…

  8. comment
    Comment #30510043

    This may make sense if they were replying via e-mail to the issue.

  9. comment
    Comment #30305982

    Different poster here but just curious: Are you a Deutsche Telekom user, by chance?

  10. comment
    Comment #28761490

    The face:b00c part is in the Interface ID, so this did not even need a large block (Though I am sure they have one).

  11. comment
    Comment #28298219

    In current versions? What permission is this?

  12. comment
    Comment #27701869

    .icu, .club, and a few other gTLDs can often be found for sale at $1-2/year, so they are used by entities in need of low cost disposable domains.

  13. comment
    Comment #26970463

    That is incorrect, Corellium does not ship Apple code.

  14. comment
    Comment #26188432

    If it had a T2, that will store the Apple ID.

  15. comment
    Comment #25432365

    1. You’re allowed to use IDFA. But users will now have to allow access, as a permission dialog will pop up first. 2. The IDFA is just a simple static UUID. It cannot do a very good…

  16. comment
    Comment #25404714

    Pager messages collected on September 11, 2001. They are also a type of communication which is transmitted without encryption.

  17. comment
    Comment #24828179

    The list can be found here: https://support.apple.com/en-us/HT210770

  18. comment
    Comment #24681192

    This one is well worth a try: https://www.amazon.com/Remote-Control-Alternative-Replacemen...

  19. comment
    Comment #24327312

    Do you have a source on Apple “killing IDFA”? My understanding is that they are going to simply show a consent dialog before allowing an app to access the IDFA, similar to what the…

  20. comment
    Comment #23910984

    This exists, though not exactly as you describe: https://en.wikipedia.org/wiki/ASmallWorld

  21. story
  22. comment
    Comment #23083419

    > There is nothing stopping someone for using this technique to publish an app in the AppStore officially. It has not happened though. Only app which has been in the App Store and …

  23. comment
    Comment #23081873

    They would be caught if this was submitted to the App Store. This applies to self-signed apps by those with a developer certificate.

  24. comment
    Comment #22498159

    Not replace, rather, you boot Linux over USB. That is why they describe the ephemeral device use case.

  25. comment
    Comment #22495746

    Source code: https://github.com/corellium/projectsandcastle/ The backstory is also incredibly interesting: https://projectsandcastle.org/history