Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

391–400 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#391
post #137

Earlier quoted context omitted.

iPhones already have a "mute" slider switch. When I first looked into iPhones (after years of Androids), my instant reaction upon seeing the slider switch was "Ah! FINALLY! I can feel at peace in the knowledge that software vulnerabilities are powerless to hack my camera or microphone!" Of course, stupidly, the slider doesn't "mute" my camera or microphone, but only my speaker. For Apple to modify this slider so that…

Frankly, I’m totaly in favour of hardware interrupt switches for the camera/mic - but I think I understand why it’s not likely to happen. First, to a lot of people it will look like admitting your thing is hackable, which makes it seem vulnerable. Second, now every time I accept a call I have to check this switch - sounds like a switch most people will leave in the on-position 100% of the time and then when it accide…

I agree, I don't think it's going to happen with the iPhone.

I realize most people aren't paranoid enough to want this. I am. I only hope that some company starts manufacturing a phone with this feature at some point, so people like me who have read too many Philip K Dick novels can feel at peace.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#392
post #268

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

They just contacted Apple Support to report the bug. The "proper" way to report bugs to apple would be to use bugreport.apple.com.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#393
post #351

I'm always curious how a bug like this ships. I mean QA & Testing should catch it, sure. But even before then. Some engineer wrote code for FaceTime that has it open the microphone before the call is accepted. And transmit the audio over the network before the call is accepted. Who did that? And why? I'm not suggesting malice but I do wonder at the lack of defensive programming.

Possibly a product owner trying out the latest build, receiving a call, accepting it, and then waiting for the call initiator to receive the message that the call has been accepted, and then start sending data and asking: "Why doesn't it take X seconds before I can start talking". To which the engineers possibly explained the reasons and the product owner saying: "But I want it instant, let's bypass all this extra st…

I wish this conversation didn't sound so familiar.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#394
post #260

Earlier quoted context omitted.

Are you able to root an iPhone or use one without signing in with an Apple account (that's tied to a credit card, etc)? If not, then I believe the devices are still very much part of a mass-scale corporate surveillance network.

Yes, you can use an iPhone without signing into any account.

Well, that's a plain and simple lie, since you can't download apps from the App Store without an Apple account, nor do I believe you can install software updates.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#395
post #12

Security and privacy are two big parts of the marketing for the iPhone. I'm curious how they can mitigate the reputational damage. Edit: It gets worse: https://www.theverge.com/2019/1/28/18201383/apple-facetime-b... If the recipient rejects the call by pressing the power button, it starts sending video.

For me, reputational damage would be having a bug that allowed a phone to be compromised via text message and then not sending any kind of fix for months, or years. Oh wait.

If Apple fixes this bug this week, I will consider it a significant bug with a good response, and move on. If I wanted more privacy, what would I switch to anyway? Android? Ha!

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#396
post #230

Earlier quoted context omitted.

Each person only uploading one copy of video in a multiparty situation is a huge win for quality on mediocre connections.

Skype used to be "P2P" where one party would act as the host in a group call.

True for audio, not video.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#397
post #351

I'm always curious how a bug like this ships. I mean QA & Testing should catch it, sure. But even before then. Some engineer wrote code for FaceTime that has it open the microphone before the call is accepted. And transmit the audio over the network before the call is accepted. Who did that? And why? I'm not suggesting malice but I do wonder at the lack of defensive programming.

Possibly a product owner trying out the latest build, receiving a call, accepting it, and then waiting for the call initiator to receive the message that the call has been accepted, and then start sending data and asking: "Why doesn't it take X seconds before I can start talking". To which the engineers possibly explained the reasons and the product owner saying: "But I want it instant, let's bypass all this extra st…

I think this is very close to spot on, though the version I've heard from developers involved with mobile involves VP's using the app/feature once it's been deployed: "Why is my group call taking 20 seconds to connect, this is unacceptable!". Fire drill ensues.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#398
post #260

Earlier quoted context omitted.

Are you able to root an iPhone or use one without signing in with an Apple account (that's tied to a credit card, etc)? If not, then I believe the devices are still very much part of a mass-scale corporate surveillance network.

Of course you don't need an Apple ID.

Really? This post makes it sound otherwise: https://gist.github.com/iosecure/357e724811fe04167332ef54e73...

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#399
post #273

Earlier quoted context omitted.

Oh I’m not questioning the existence or importance of the bug. It’s important and a big screwup. However, I am extra sensitive to the degree to which twitter is being manipulated for all sorts of ends. Sometimes things look more than a bit fishy. Usually major bug reports don’t come from 2019’s version of egg avatar + letters/numbers username + very recent activity consisting almost entirely of political posts + past…

What possible motivation would anyone have for reporting a real bug of this nature like this? Other than, yeah, found a crazy bug.

If the bug was held by a nation state, and their use of it was burned for whatever reason, then the nation state could release it in this manner to sow chaos in lots of fun ways:

1) The entire world of iPhone users

2) The financial markets (Apple suffers)

3) The financial markets (non-Apple benefits)

4) The political sphere (distraction from)

5) Deniability (they got their recording and leaked the bug to deny how)

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#400

Earlier quoted context omitted.

Not sure if this was intentional but in security, Alice and Bob wre the names in hypotheticals for the attacker and unwitting victim since the RSA paper. https://en.m.wikipedia.org/wiki/Alice_and_Bob

Your comment shows a clear lack of contextual insight into general software security. Alice (A) and Bob (B) are ubiquitous in discussions: https://en.wikipedia.org/wiki/Alice_and_Bob

Geez that was harsh...
Post reply on HN