Live data from Hacker News

Apple Watch Ultra 2 Hacked

discussions.apple.com

131–140 of 182 posts

Re: Apple Watch Ultra 2 Hacked

#131

Earlier quoted context omitted.

So true. Normies be using security questions like “What was your fist dog called?” while posting about their first dog’s name in public #insta while complaining about being targeted by a 1337 h4x0r.

Ah yes, many fond memories of my dog dumfyg-gycpid-8Vujmi

"What was your first dog's name?"

"Oh, something random."

"Ah yes, correct, welcome back."

Re: Apple Watch Ultra 2 Hacked

#132

> they popped up the keyboard and typed “We are in control” This reads like bad hacking fiction, complete with the guy typing that wearing a Guy Fawkes mask. Why the hell would the (hypothetical) attacker lose precious time doing something like that.

To be fair, one famous malware literally just says "you are an idiot"[1] out loud.

1. https://www.youtube.com/watch?v=LSgk7ctw1HY

Re: Apple Watch Ultra 2 Hacked

#133
post #128

This is so hard to believe that I simply don't. Either the user had a bad digitizer, and misread and/or hallucinated the "We are in control" message, or the entire story is made up. Perhaps a group of people working together to post "Hey me too!" stories? I'm not sure what the motive would be, though. Extraordinary claims require extraordinary evidence, and this is beyond believability.

Obviously this guy was fooled by a friend who was using his iPhone to remotely operate the watch (which explains the „we are in control“ phrase). Now in this forum numerous people that simply have a broken digitizer chime in. Case closed.

It wasn't obvious at all to me that that's even possible. But as it turns out: it's an accessibility feature (1) to mirror the watch screen on iPhone in order to voice control it or use assistive touch.

1: https://support.apple.com/guide/watch/apple-watch-mirroring-...

Re: Apple Watch Ultra 2 Hacked

#134

I don't know what the catalyst for this was, but a lot of 20 years olds and younger seem to use the word hacked so casually. I read it all the time, "my insta was hacked", etc. I would really like to know if hacking is as common as it is reported rather than a successful phishing campaign, a simple issue of forgotten password or getting locked out of email, account ban for rule violation, or something else entirely u…

Perhaps there is more to hack? At least when I was 20 years old, the only thing to be hacked was the dial-phone, a paper phonebook and perhaps a fax. Social media didn't exist. Having so many accounts where some stuff might (or might not) be important, folks get very sensitive to being "hacked". Or in other words, having a stranger break in and rummage through their underwear.

I remember on boring days reading the factual entries in the beginning of the phonebook. I remember it as a broad description of how the bell system worked and how to use it.

In the late 70s in a central Pennsylvania farmhouse that was some of the earliest technical documentation I ran into.

Re: Apple Watch Ultra 2 Hacked

#135
post #77

Earlier quoted context omitted.

The apple forum really is a special place. Stuck in time, weirdly toxic and surprisingly unhelpful.

I've only had to browse it for information a few times, but it really is shockingly useless. I've never found an actual answer on those forums. Even Google's practically useless forums have helpful users who suggest workarounds between the hundreds of "I have the same problem" comments. Microsofd's near-useless forums have some good information if the thread doesn't die once a Certified Super Microsoft Systems Engine…

I think a lot of it has to do with there often not being actual answers as most of the system is hidden from the user anyway.

But I have had the exact same experience. Up to really hostile behaviour and suggestions to reinstall from scratch. (I didn't know I need to start 'code' to agree to a license to update the c compiler, absolutely new to the OS coming from Linux and stuck for nearly a day) got plenty of feedback in a short time but most were along 'go back to windows' or 'did you try [obscure third party tool]', literally none actually helpful. Could be bad question asking, or just unlucky experience but it stuck to me.

I rather get ignored in Microsoft forums or semi angry 'where are your complete logs!?!1' in the Linux forums.

Re: Apple Watch Ultra 2 Hacked

#136

So an attacker has gained remote access, yet needs to perform operations using a sort of Remote Desktop approach? Plausible — in movies.

Apple Watch does have a remote control feature, intended for controlling the watch from your phone, as part of the accessibility options. It's certainly technically possible that this feature is being abused to get access to data that would otherwise be locked down by Apple's strict sandbox post-exploitation.

Or, more likely, it's some kind of shitty prank by someone nearby to the users.

Re: Apple Watch Ultra 2 Hacked

#137

Earlier quoted context omitted.

I am inclined to believe that the first reporter only thinks they saw this, not that it actually occurred (or they saw some random words appear on the keyboard that resembled this phrase).

„Popping up a keyboard“ as the user described is also not something trivially possible on the watch. That raised a red(ish) flag for me.

Anyone who worked with users would tell you stories about the stories the users tell to support about how they "didn't do anything at all, didn't touch it and now everything is gone! it's your fault!"

By the way, yesterday my Apple Watch 2 popped up a keyboard and wrote "pflenker is leichtgläubigertyp!" can you believe it?!

Re: Apple Watch Ultra 2 Hacked

#138

I don't know what the catalyst for this was, but a lot of 20 years olds and younger seem to use the word hacked so casually. I read it all the time, "my insta was hacked", etc. I would really like to know if hacking is as common as it is reported rather than a successful phishing campaign, a simple issue of forgotten password or getting locked out of email, account ban for rule violation, or something else entirely u…

If the original account is to be believed, they did not know the owner’s passcode/PIN. The attackers gained remote access to a device without the passcode/PIN. This suggests it was not phishing.

It sounds like a legitimate usage of the word “hacked” to me. Maybe not the most critical vulnerability because they did not gain full access, but they managed to gain some level of control of the owner’s watch without their permission, and it sounds like the reason was not that they left it lying around unlocked (to be clear it sounds like they got control because the watch was unlocked in the owner’s wrist, but they were accessing it wirelessly- sounds like an issue with Apple’s security model that can be fixed).

Re: Apple Watch Ultra 2 Hacked

#139
post #51

Earlier quoted context omitted.

It's pretty obviously fake. A bunch of "level 1" (new) users, all with the same story? They literally mention the exact time & date in the same style, and mention the 1-minute lockout in the same way as well. Two of them use the same timestamp even, down to the minute. Also, something I noticed working for large orgs with over 100K staff and 1M users: An appreciable fraction of the human population is simply mentally…

I own an iPhone and i would be a level 1 / new user if i had issues. Otherwise, why on earth would i care about signing up to apple forums? I’d only go there if i had issues (obviously)

A lot of the people here are much more experienced with technology, so our behaviour is going to be different, but I have a hard time understanding why someone would sign up for a forum as a first step for obtaining assistance. Calling the vendor, sure. Using vendor support options that connect me directly to their staff, sure. None of the people posting about the issue mention taking other prior steps in obtaining support (even though a couple of posts from established members say they should).

I suppose posting to the vendor forums is fine if you need support. On the other hand, I do not think it is an acceptable source of information about a security flaw in a product. There information provided is not verified. The sources are not verified. We don't know whether the details are true, a misinterpretation (innocent or malicious), or made up. In other words, there is no reason to trust what is being said. If I came in here suggesting that my computer was hacked, I would expect people to respond with similar incredulity. (I am simply someone who posts to a forum. There is no reason for people to trust anything I say, particularly if the posting doesn't contain detail on reproducing the problem.)

Re: Apple Watch Ultra 2 Hacked

#140

Since when can you arbitrarily pop open the keyboard and display typed text from the Home Screen?

Yeah, if you told me I had 5 seconds to pop up the keyboard on my Apple Watch, I would probably lose. Maybe I'd try to go through my GF's button to her profile and then to messages? Where else can I get a text input really fast?
Post reply on HN