Earlier quoted context omitted.
What makes you think it wasn't sold? Even if by another party that could have found it before?
Who would you sell it to and what would the buyer do with it? Outline the scenario you have in mind and we can try to sort out how to leverage this specific bug for $7000 worth of some kind of value.
SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
171–180 of 259 posts
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#172Earlier quoted context omitted.
Even worse, Control Panel buttons only "suspend" BT/WiFi, you have to go into Settings to turn them off again ... and again ... and again.
It’s good UX - presumably most users want to turn off WiFi/bluetooth temporarily when using these buttons and this saves you from forgetting to turn it back on. I was delighted when they changed. I agree it’d be nice to have a choice for how it works on your device, but current behavior would still be a good default.
Apple has since extended this helpful "innovation" to the power button, which no longer turns off iPhones, requiring a faraday bag to block WiFi/BT/UWB radios from communicating while iPhone is "powered off".
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#173If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.
And accelerometers and ...
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#174Earlier quoted context omitted.
It’s good UX - presumably most users want to turn off WiFi/bluetooth temporarily when using these buttons and this saves you from forgetting to turn it back on. I was delighted when they changed. I agree it’d be nice to have a choice for how it works on your device, but current behavior would still be a good default.
> and this saves you from forgetting to turn it back on Apple has since extended this helpful "innovation" to the power button, which no longer turns off iPhones, requiring a faraday bag to block WiFi/BT/UWB radios from communicating while iPhone is "powered off".
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#175Earlier quoted context omitted.
What makes you think it wasn't sold? Even if by another party that could have found it before?
Who would you sell it to and what would the buyer do with it? Outline the scenario you have in mind and we can try to sort out how to leverage this specific bug for $7000 worth of some kind of value.
Google The NSO Group for an example, and that’s just private entities. nation state actors are a whole other market for such things.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#176Earlier quoted context omitted.
Even worse, Control Panel buttons only "suspend" BT/WiFi, you have to go into Settings to turn them off again ... and again ... and again.
I called this a data grab from day 1 and stand by that. The amount of fellow iOS developers I've had argue for the "convenience" is astounding. There should be a settings toggle to control the auto-reenable behavior.
Option 1 is a reasonable explanation based on the behavior that arguably works best for 99% of users .
Option 2 is a “data grab” with no evidence or theories about who is grabbing what data and for what purpose.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#177Earlier quoted context omitted.
> and this saves you from forgetting to turn it back on Apple has since extended this helpful "innovation" to the power button, which no longer turns off iPhones, requiring a faraday bag to block WiFi/BT/UWB radios from communicating while iPhone is "powered off".
Do you mean to say that “slide to power off” leaves Wi-Fi radios active?
> With iOS 15, your iPhone is still traceable through the Find My network even when the device is powered off. It seems that with iOS 15, the phone is not really fully ‘powered off’, it stays in a low-power state and acts like an AirTag, allowing any nearby iOS device to pick up the Bluetooth signal and send back its location.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#178Earlier quoted context omitted.
Yes, the question is how to permanently restrict the attack surface / time windows for audio and video surveillance attacks.
Instead of Bluetooth defaulting to on, and re-enabling itself next day if you turn it off from the control center, I'd like for Bluetooth to default to off. You'd have to enable it from the control center, and it would disable itself after a certain period of inactivity. I suppose that won't happen, as it would wreck the Find My network if it depends solely on Bluetooth.
For security this is probably something that could be brought in to lockdown mode for people who want absolute security over convenience.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#179Earlier quoted context omitted.
Who would you sell it to and what would the buyer do with it? Outline the scenario you have in mind and we can try to sort out how to leverage this specific bug for $7000 worth of some kind of value.
Zerodium would happily buy this for probably $50k minimum.
I would happily pick $7,000 clean money over $50,000 dirty.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#180Earlier quoted context omitted.
Zerodium would happily buy this for probably $50k minimum.
Is it legal to sell these exploits? Obviously using it is illegal but I wonder if even selling it to someone else who would use it is illegal. I would happily pick $7,000 clean money over $50,000 dirty.