Live data from Hacker News

SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

rambo.codes

141–150 of 259 posts

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#141

Earlier quoted context omitted.

And this is why I have the internal microphone disconnected on my macbook pro. The only time a mike is attached is when I'm actively using it, and even then they have hardware kill switches. Simple kill switches would be nice to see but I doubt Apple would ever implement something like that.

Quoted post unavailable.

Credit card numbers, social security numbers, passwords. People say all of these things around loved ones all the time without worrying about hardware being "around." Hardware, shockingly, is always around.

And despite the author's dismissal of the Facebook listening "myth," everyone I know has an uncomfortable advertising eavesdropping anecdote. Maybe we can agree it's more correctly an unsubstantiated claim.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#142

If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.

> Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? Yes, this is what I do. The mike is actually still in the laptop but it's disconnected from the motherboard. On a 2021 M1 Macbook pro all you need to do is pop off the back cover and disconnect one cable on the right side of the motherboard. All in all takes about 10 minutes of work.

Excellent, thanks for the field report.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#143

Earlier quoted context omitted.

And this is why I have the internal microphone disconnected on my macbook pro. The only time a mike is attached is when I'm actively using it, and even then they have hardware kill switches. Simple kill switches would be nice to see but I doubt Apple would ever implement something like that.

Quoted post unavailable.

I mean, you might be surprised but I'm sure there are more than a few users on HN that discus digital security configurations of large companies in their day jobs. I've been party to more than one conversation where some company unintentionally opened a security flaw for a short period of time that we discussed over a meeting, that if some evil 3rd party listened to may have gave them a window to exploit services.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#144
post #18

Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.

I have never even setup Siri. Sometimes I've been tempted to enable it so I can say, "Siri, call 911!" if I'm assaulted or injured on the trail. I doubt it would help, but it's occasionally disconcerting when my phone isn't quickly accessible.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#145
post #143

Earlier quoted context omitted.

Quoted post unavailable.

I mean, you might be surprised but I'm sure there are more than a few users on HN that discus digital security configurations of large companies in their day jobs. I've been party to more than one conversation where some company unintentionally opened a security flaw for a short period of time that we discussed over a meeting, that if some evil 3rd party listened to may have gave them a window to exploit services.

The probability of someone just happening on that conversation while listening in, at just the right time, to just the right security engineer of the many security engineers in the company, approaches the probability of someone accidentally discovering the security flaw on their own. I think. It's hard to know with probabilities that are vanishingly small.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#146

Earlier quoted context omitted.

Even worse, it looks like on MacOS you can just straight up start recording on-demand, no need for dictation or siri. > Even worse, this particular exploit would also allow the app to request DoAP audio on-demand, bypassing the need to wait for the user to talk to Siri or use dictation.

And this is why I have the internal microphone disconnected on my macbook pro. The only time a mike is attached is when I'm actively using it, and even then they have hardware kill switches. Simple kill switches would be nice to see but I doubt Apple would ever implement something like that.

The internal microphone is entirely unrelated to this bug.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#147

I think they burried the lede here. Conversations with Siri are probably pretty generic but being able to evesdrop on keyboard dictation is pretty severe. I know people that use dictation for the majority of their text messages and email.

> I know people that use dictation for the majority of their text messages and email.

Yeah, I'm one of them. The iOS keyboard has slowly become so bad that it's easier to dictate instead, and my partner does the same while driving via CarPlay. This is horrible to read about.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#148
post #79

I think they burried the lede here. Conversations with Siri are probably pretty generic but being able to evesdrop on keyboard dictation is pretty severe. I know people that use dictation for the majority of their text messages and email.

How many people use diction? I'm surprised cause I know virtually no one who uses diction, myself included.

My partner uses it constantly while driving. It's illegal to use a phone while driving, and we have cameras everywhere that will catch you if you have it in your hand and smack you with a near $500 fine and points on your license. So dictation is extremely common.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#149
post #40
post #35

Earlier quoted context omitted.

$70,000 would have been more fair There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.

Here are the listed payouts from the Apple Security Bounty program, starting at $25,000. https://developer.apple.com/security-bounty/payouts/

Interesting that the page defines "sensitive data" as data "from Contacts, Mail, Messages, Notes, Photos, and real-time or historical precise location data — or similar user data — that would normally be prevented by the system." Notably missing is access to the microphone or camera.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#150
post #63
post #54

Earlier quoted context omitted.

The closest is $25,000. App access to a small amount of sensitive data normally protected by a TCC prompt. In this case you get a misleading prompt, the access requires additional interactions. It's a serious bug and I'm all for reporters of serious bugs getting bigger bounties from companies that have more cash than they know what to do with. But simply dropping a random number in every single one of these threads i…

"Full TCC Bypass on macOS"

[deleted]
Post reply on HN