Earlier quoted context omitted.
MITM it, it's your phone that you physically control.
> it's your phone I can't even tell whether it's sarcasm… All those services are closed-source, exchanging over binary protocols, of which there is no public description/documentation, and no stability guarantee.
Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
111–120 of 130 posts
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#112Earlier quoted context omitted.
Can’t you root both of those to setup a proxy to decrypt and see for yourself? If it’s encrypted, how can you tell that’s what it's doing to say with such certainty there?
On Android the certificate pinning makes it very hard even with root. On iPhone where the owner of the phone (Apple) actively fights against your ability to gain root, I can't imagine it's easier, but if it is I'd appreciate being corrected.
But I don't get you. You complained that droid makes it hard and apple makes it impossible. But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#113Even Twitter got in the game and made Grok.
Wow! So unambitious coming from Apple.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#114Earlier quoted context omitted.
On Android the certificate pinning makes it very hard even with root. On iPhone where the owner of the phone (Apple) actively fights against your ability to gain root, I can't imagine it's easier, but if it is I'd appreciate being corrected.
mitproxy lets you one tap install a config profile that does it. You know like you sometimes need to do in Korea or Kazakhstan... It's routine. But I don't get you. You complained that droid makes it hard and apple makes it impossible. But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
Apple's mea-culpa is that unlike Android they do not ship an Open Source OS ROM for developers to modify. Google's telemetry can be entirely neutralized by removing Google Play services and using Android without Google software. iPhones don't have that escape hatch, leading to a pretty literal limitation of how you "own" your phone and the software on it. On top of that, iOS has a permissions architecture Apple designed to give the user second-class control over the network. You cannot MITM Apple services - they will go around whatever user-land profile you think you've set. On top of that, there are modem emissions that you're never going to catch with a MDM profile hack and certificate pinning. You have fully drank the kool-aid if you think an empty aircrack-ng screen means "you won" against the multitrillion dollar company and coalition of government regulatory bodies.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#115Earlier quoted context omitted.
> it's your phone I can't even tell whether it's sarcasm… All those services are closed-source, exchanging over binary protocols, of which there is no public description/documentation, and no stability guarantee.
You overdramatize, they mostly just push json around. mitmproxy is your friend. And since you only need to see for yourself once who cares about stability.
I believe on Android MITMing even most third party applications (that make zero-to-no effort to prevent this) requires a rooted phone or an emulator running and older Android (8) without Google Play Services and doing a little bit of RE (for instance using some Frida user scripts to patch the apk to circumvent the certificate pinning). I reckon MITMing the actual traffic Google itself can collect would require a lot more RE and network wizardry than I’m even aware of (feel free to link some reading though). Here’s a recent walkthrough I saw in the wild: https://youtu.be/c4wS9n7yilA?si=xAfwCyWIzdrvOiHc
For Apple devices afaict since rooting was…ahem rooted out, no viable amateur-DIY methods for monitoring your devices traffic exist.
I know everything is open source if you’re good enough at assembly but at some point it’s gone from something a tinkerer can do to something you need significant talent and in-depth knowledge to do.
I’d love to read any write-ups or guides to the contrary though.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#116Imagine a world where every phone gets turned into a useful digital assistant that can order things for us online via APIs. I wonder if Amazon is ready for this.
Is this sarcasm?
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#117Earlier quoted context omitted.
I can't even use text summarization on my Pixel 8 Pro.
do you use Chrome browser? It doesn't work for me either but I use firefox mobile, so I suspect that may be why.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#118Earlier quoted context omitted.
do you use Chrome browser? It doesn't work for me either but I use firefox mobile, so I suspect that may be why.
No, afaik, it's still a region locked feature. US only. Pretty convenient that all popular product reviewers are US based and advertise the Pixel 8 as an AI powered device.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#119Earlier quoted context omitted.
On Android the certificate pinning makes it very hard even with root. On iPhone where the owner of the phone (Apple) actively fights against your ability to gain root, I can't imagine it's easier, but if it is I'd appreciate being corrected.
mitproxy lets you one tap install a config profile that does it. You know like you sometimes need to do in Korea or Kazakhstan... It's routine. But I don't get you. You complained that droid makes it hard and apple makes it impossible. But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
I didn't complain about anything, I just stated the facts, with a possible exception regarding the snark about how Apple "owns" the device, although I do think that's a defensible position since they have higher access to it than it's "owner". I do think it's shitty though that they don't provide a way (even with some hoops) for the "owner" of the device to get the highest level of access to it, but that wasn't in the comment.
> But it would be better for average user security if they could not do it (aka "did not own the device" in anti-apple propaganda), right?
Why would that be better? I highly doubt it would make any difference at all to the average user. I doubt it even impacts the majority of power users.
The people who are impacted by these restrictions are the technical users who want to capture and inspect their own device's traffic, usually on their own network. Conveniently, these are also the researchers who might publish blog posts and articles about what kind of data and surveillance the device is sending home about the user, without their knowledge.
Re: Apple Is in Talks to Let Google's Gemini Power iPhone Generative AI Features
#120I don't see why everyone is so surprised by this. Google already provides the default search engine for iOS, and it's clear that Apple's on-device stuff is going to be years away. They don't have the infrastructure to do this themselves either, so they're going to need a partner. Steve Jobs always saw Apple and Google as natural partners, he just couldn't get over that Google launched Android. I think Apple by now re…