Live data from Hacker News

iMessage Preview Problems; leak your location by receiving a text message

theantisocialengineer.com

11–20 of 51 posts

Re: iMessage Preview Problems; leak your location by receiving a text message

#13
post #6

tl;dr iMessage now previews links automatically > The updated iMessage loads the link preview and in essence clicks the link for you! That’s what irks us with this, the choice. OK we might not stop people clicking links anytime soon but Apple have taken this very choice away from us and facilitate the information leakage. The very act of receiving an SMS message can reveal your rough geographic location, your cellula…

It's an unusual and disappointing error on Apple's part. I wouldn't be surprised to see it corrected in the first iOS 10 update. (And this is why we never install the .0 version of anything, and counsel our friends and loved ones likewise.)

never install the .0 version of anything

We're already on 10.0.2, so we've already had a few updates.

Re: iMessage Preview Problems; leak your location by receiving a text message

#14

What's wrong with web hosts nowadays? a few 100 users and everything dies. Cached: https://webcache.googleusercontent.com/search?q=cache%3Ahttp...

Wordpress with no caching plugin on a $5-a-month droplet, that's what. It's a pleasant enough platform to use, but if you don't cache content and you make the HN frontpage, you're gonna have a bad time.

Re: iMessage Preview Problems; leak your location by receiving a text message

#15
post #11

Apple should fetch the data via their servers instead of the clients'. It leaks way too much information.

Messages are end-to-end encrypted in iMessage, meaning Apple cannot read the message contents. This solution would require Apple to bypass that encryption for URLs (which are often privacy-sensitive).

A good approach would be for the sender to fetch the URL and embed the preview as metadata along with the message. The only downside is that the sender could spoof the preview, but I think that's an acceptable trade-off here (not much of a phishing vector when you end up loading the original site once you open the link anyway).

Re: iMessage Preview Problems; leak your location by receiving a text message

#16

Earlier quoted context omitted.

It's an unusual and disappointing error on Apple's part. I wouldn't be surprised to see it corrected in the first iOS 10 update. (And this is why we never install the .0 version of anything, and counsel our friends and loved ones likewise.)

never install the .0 version of anything We're already on 10.0.2, so we've already had a few updates.

Are we? Go figure - I've been getting the installer popups from Springboard for a while, but I guess it doesn't show minor versions if the major versions differ; it's just been saying "iOS 10", and I took that to mean no patches had been released.

So I suppose I should say rather I would expect to see it corrected in iOS 10.1, at latest.

Re: iMessage Preview Problems; leak your location by receiving a text message

#18

Earlier quoted context omitted.

It's an unusual and disappointing error on Apple's part. I wouldn't be surprised to see it corrected in the first iOS 10 update. (And this is why we never install the .0 version of anything, and counsel our friends and loved ones likewise.)

never install the .0 version of anything We're already on 10.0.2, so we've already had a few updates.

I would have figured Apple proxied the preview to their own URL crawler which could automagically pluck the best preview image, similar to the magic that FB / Slack do when sharing a link. This would mask the IP / Geo and Apple could cache a preview image.

Re: iMessage Preview Problems; leak your location by receiving a text message

#19
post #15
post #11

Apple should fetch the data via their servers instead of the clients'. It leaks way too much information.

Messages are end-to-end encrypted in iMessage, meaning Apple cannot read the message contents. This solution would require Apple to bypass that encryption for URLs (which are often privacy-sensitive). A good approach would be for the sender to fetch the URL and embed the preview as metadata along with the message. The only downside is that the sender could spoof the preview, but I think that's an acceptable trade-off…

> Messages are end-to-end encrypted in iMessage, meaning Apple cannot read the message contents.

Ha. Cute.

Re: iMessage Preview Problems; leak your location by receiving a text message

#20
post #18

Earlier quoted context omitted.

never install the .0 version of anything We're already on 10.0.2, so we've already had a few updates.

I would have figured Apple proxied the preview to their own URL crawler which could automagically pluck the best preview image, similar to the magic that FB / Slack do when sharing a link. This would mask the IP / Geo and Apple could cache a preview image.

It would also expose any URL you send or receive via iMessage to Apple, whereas messages are otherwise end-to-end encrypted.
Post reply on HN