Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

231–240 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#231

Earlier quoted context omitted.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

Edit: Deleted my comment because I felt it wasn’t constructive.

I used to see this regularly but haven't noticed it in a long while. I always assumed they were doing something like a double-buffering type trick and switching framebuffers before wiping stale content from the destination.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#232
post #160

Earlier quoted context omitted.

That’s not his Apple email.

I know. I didnt want to post his supposedly actual public email for fear of being accused of doxxing him.

That's what the sockpuppet account and TOR is for.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#233

Earlier quoted context omitted.

Not sure if this was intentional but in security, Alice and Bob wre the names in hypotheticals for the attacker and unwitting victim since the RSA paper. https://en.m.wikipedia.org/wiki/Alice_and_Bob

Your comment shows a clear lack of contextual insight into general software security. Alice (A) and Bob (B) are ubiquitous in discussions: https://en.wikipedia.org/wiki/Alice_and_Bob

ITT: lack of social cues all around, classic Hackernews

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#234

Earlier quoted context omitted.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

Edit: Deleted my comment because I felt it wasn’t constructive.

There was one guy on reddit who had a scare when his computer flashed a picture of a dead person when shutting down, and he thought his computer was haunted. It turned out to be a frame from a youtube video he was watching earlier. It may be that macOS is not that good at clearing out GPU memory sometimes.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#236
post #12

Security and privacy are two big parts of the marketing for the iPhone. I'm curious how they can mitigate the reputational damage. Edit: It gets worse: https://www.theverge.com/2019/1/28/18201383/apple-facetime-b... If the recipient rejects the call by pressing the power button, it starts sending video.

As someone who bought an iPhone specifically for privacy reasons, I'm not really upset about this. What I'm concerned about is passive, mass-scale corporate surveillance, not a one-off bug that allows an individual with mal-intent to listen through my microphone for a few seconds and also let me know about it.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#237

Earlier quoted context omitted.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

Edit: Deleted my comment because I felt it wasn’t constructive.

Yes, I experience this routinely. As do many other people at my company.

In particular it happens when attaching external monitors while the screen is locked. There's a flash of the unlocked desktop.

I am guessing this is because the screen lock is an application drawing over top of the monitor, like XScreensaver on Linux does. A more secure-by-default architecture would have screen locking built into the display server at some lower level: If the screen is not unlocked, it will not allow the data to be passed to the GPU. It's easy for me to arm-chair architect though.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#239

Earlier quoted context omitted.

Edit: Deleted my comment because I felt it wasn’t constructive.

There was one guy on reddit who had a scare when his computer flashed a picture of a dead person when shutting down, and he thought his computer was haunted. It turned out to be a frame from a youtube video he was watching earlier. It may be that macOS is not that good at clearing out GPU memory sometimes.

I have the exact opposite problem. When I reboot after system updates, half a dozen YouTube videos in Chrome tabs start playing over each other on the password screen. They get through about 20 seconds before I can stop the last of them.

Audio only on the password screen, but all audible.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#240

Earlier quoted context omitted.

It reminds me of this MacOS bug from last year, where simply hitting the login box over and over with no password would eventually bypass the security entirely: https://www.theregister.co.uk/2017/11/28/root_access_bypass_... And this other MacOS bug, also from last year, where the password hint would contain the plain text encryption password: https://www.theregister.co.uk/2017/10/05/apple_patches_passw... All within…

Not Apple related, but you could log into any linux box using a specific few versions of grub2 by hitting backspace 28 times: https://motherboard.vice.com/en_us/article/ezpdqz/hack-into-...

Also, you can bypass screen lock in Ubuntu by removing the HDD [1]. The bug still is not fixed.

[1] https://bugs.launchpad.net/ubuntu/+source/unity/+bug/1777415

Post reply on HN