Earlier quoted context omitted.
so you are saying apple is doing something they already knew is a bad idea?
No. I’m saying your information is outdated and wrong.
macOS is background scanning and following downloaded QR codes?
51–60 of 95 posts
Re: macOS is background scanning and following downloaded QR codes?
#52Earlier quoted context omitted.
No. I’m saying your information is outdated and wrong.
how can you be so confident that it's "closed"? the last time apple announced the high protection mode for state sponsored targets in new ios (whatever it's called), they disable all auto previews in that mode. if they are as confident as you are that it's "closed" that doesn't seem necessary?
As for the high protection mode - of course that reduces the attack surface.
Re: macOS is background scanning and following downloaded QR codes?
#53Re: macOS is background scanning and following downloaded QR codes?
#54I'll be interested to see if anyone else can reproduce this. I created a request bin [0], then created a QR code pointing at it, then downloaded that QR code. I'm not sure how often this "image scanning" is supposed to occur but just downloading it didn't cause a hit nor did the 10min I waited, nor did using QuickLook, nor opening it Preview, nor scanning it with my iPhone, the only thing that caused a request was cl…
Indeed. This is a really bold claim and so far we have one person who has reproduced it on a single machine.
I'm no Apple apologist by any means but I'm a little skeptical of the claims in the twitter thread. It's easy enough to imagine that the poster made some kind of mistake in his methodology or some other variables are at play that he didn't consider. I'd withhold judgment until there's some corroboration.
Re: macOS is background scanning and following downloaded QR codes?
#55Earlier quoted context omitted.
What are you talking about? It sounds like you don’t understand what is going on here. Perhaps you think some data is going to Apple?
Having read the article I entirely understand what is going on here. Do you expect your images to be scanned on disk and the links in them to be opened, leaking your ip? What if you do something as simple as screenshot an address bar in a browser? Save a menu QR code? Now you are sending out traffic, accidentally, with your full ip to random places due to a service Apple inserted that you have no knowledge of.
Re: macOS is background scanning and following downloaded QR codes?
#56Earlier quoted context omitted.
Scanning your images and followong links in them without user consent is pretty malicious.
What are you talking about? It sounds like you don’t understand what is going on here. Perhaps you think some data is going to Apple?
Re: macOS is background scanning and following downloaded QR codes?
#57So, if I send you a QR code via iMessage the URL in it will automatically be hit, using your IP address and browser/OS details . Wow that's quite an attack vector.
Re: macOS is background scanning and following downloaded QR codes?
#58Re: macOS is background scanning and following downloaded QR codes?
#59I'll be interested to see if anyone else can reproduce this. I created a request bin [0], then created a QR code pointing at it, then downloaded that QR code. I'm not sure how often this "image scanning" is supposed to occur but just downloading it didn't cause a hit nor did the 10min I waited, nor did using QuickLook, nor opening it Preview, nor scanning it with my iPhone, the only thing that caused a request was cl…
> I'll be interested to see if anyone else can reproduce this. Indeed. This is a really bold claim and so far we have one person who has reproduced it on a single machine. I'm no Apple apologist by any means but I'm a little skeptical of the claims in the twitter thread. It's easy enough to imagine that the poster made some kind of mistake in his methodology or some other variables are at play that he didn't consider…
Re: macOS is background scanning and following downloaded QR codes?
#60Earlier quoted context omitted.
Having read the article I entirely understand what is going on here. Do you expect your images to be scanned on disk and the links in them to be opened, leaking your ip? What if you do something as simple as screenshot an address bar in a browser? Save a menu QR code? Now you are sending out traffic, accidentally, with your full ip to random places due to a service Apple inserted that you have no knowledge of.
I don't know, but I wouldn't be surprised if this is being done via Apple's private relay. If so, your IP address is not being leaked to anyone.