Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

401–410 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#401
post #336
post #292

Earlier quoted context omitted.

Stock manipulation perhaps? Happens a lot with Tesla apparently, short sellers will pump up any negative story and try to get it into press. This person was making several attempts to get in contact with press after all, and a story about a teenager finding a big privacy bug in a company that publicly touts its privacy chops has ‘news at 11’ written all over it. Personally I think a bug report story is not a particul…

Is it still called stock manipulation if the bug is critical and for real and the company deserves to lose shareholder value simply for the critical nature of the bug? Imagine how many people are vulnerable out there - I'm already starting to read some complaints on the internet that some people were unknowingly sharing a video of them taking a shower, etc.

Yes, as they would have lost less stock price if a fix had been prepared and released along with the announcement.

Yes, if options purchases were made before the market found out.

Yes, if their intentions were to change stock prices with the announcement in any respect whatsoever, whether up down in price and/or in volatility.

No, if they were not intending to change the stock market with the announcement, regardless of the fact that they did. (Naïveté happens. So does unconcern. Still, No.)

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#402
post #61

Earlier quoted context omitted.

This has been disproven time and time again.

OP is referring to the ability to tap into any Alexa device, a feature Amazon calls Drop In ( https://www.amazon.com/gp/help/customer/display.html?nodeId=... ).

The receiving device has to grant permission, and every time you drop-in it plays a sound effect to alert the user they've been dropped-in on.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#404
post #268

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

I too found it odd and only looked into it because she chose to tag one (and only one) "news org" in the post @foxnews - Without the bug report, her account looks like many that have been "taken over" or re-purposed by political operatives.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#405

Earlier quoted context omitted.

I think it's much more likely their code is a mess and it's not super obvious when stuff starts and ends and this is just an unintentional mistake.

You hear this excuse all the time, don't FAANG employ the world's very best developers? Maybe their code is a mess for orthogonal reasons - management, profit-motive? Aside: I thought I'd heard devs have automated analysers that step through and find all possible code paths, allowing complex code to be audited for security issues and such? Presumably that's how these sorts of bugs should be found in testing.

>> world's very best developers

And some of the world's very worst. There are not 10s of thousands of world-class developers to hire in the first place and they would be focused on much higher-level details than implementing basic features and maintenance.

That gruntwork requires solid reliable workers with experience but the current screening processes do more harm more than help in getting that talent.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#406
I feel like around three years ago Apple engineering changed QA leadership or restructured org in that dept and the quality has been down. Prior to IOS9, I have had barely noticed bugs. But now I am in that "used-to" mode that I have learned to ignore such bugs or nuances.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#407

Earlier quoted context omitted.

That's a pretty huge flaw. Millions if not... Is it just me, or is such a phrase applicable to Apple far too many times in the past several years? I think their engineering is losing quality or is falling behind on what they have to cover.

Comparable examples?

Just off the top of my head: I think on three separate occasions, specifically crafted text messages have made the Messages app disappear from iOS, requiring a reboot. There was a comparable MacOS login bug not too long ago.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#408
post #183

Apple has disabled group FaceTime on their end. https://www.apple.com/support/systemstatus/

Amazing, a status page that automatically converts to the local timezone.

It’s showing me ‘AM’ and I’m on a 24 hour clock locale

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#409
post #319

I must admit that when reading yet another privacy-invasion-headline I saw "Facebook", not FaceTime/Apple. Not sure whether it's more indicative of unjustified prejudice or actual precedent.

The difference is that Facebook does it intentionally.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#410
post #260
post #236

Earlier quoted context omitted.

As someone who bought an iPhone specifically for privacy reasons, I'm not really upset about this. What I'm concerned about is passive, mass-scale corporate surveillance, not a one-off bug that allows an individual with mal-intent to listen through my microphone for a few seconds and also let me know about it.

Are you able to root an iPhone or use one without signing in with an Apple account (that's tied to a credit card, etc)? If not, then I believe the devices are still very much part of a mass-scale corporate surveillance network.

> Are you able to root an iPhone

You can root, but it's security-suicide because the OS' security model isn't designed for that.

> or use one without signing in with an Apple account

Technically yes, although you couldn't download any apps so you really don't want to.

> If not, then I believe the devices are still very much part of a mass-scale corporate surveillance network.

What I always tell people is to look at the economic incentives. Apple makes the vast majority of its money from paying customers, not advertisers, so it has less use for big data. It has also invested huge amounts of money in marketing itself as a champion of privacy, a key diversifier from its competitors. If it tried to do some shady data-gathering, it would have relatively little to gain and everything to lose when that inevitably leaked. Apple usually can't even keep the next iPhone a secret; there's no way they could conceal a massive conspiracy to secretly collect data on customers. And if they did, and it became public knowledge, their sales would go down the tube. It's just bad business. I don't trust any corporation to do what's right out of the goodness of their hearts, but I certainly trust them to do what's best for business.

Post reply on HN