Live data from Hacker News

SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

rambo.codes

191–200 of 259 posts

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#191

Earlier quoted context omitted.

Do you mean to say that “slide to power off” leaves Wi-Fi radios active?

https://9to5mac.com/2021/06/07/ios-15-find-my-network-can-fi... > With iOS 15, your iPhone is still traceable through the Find My network even when the device is powered off. It seems that with iOS 15, the phone is not really fully ‘powered off’, it stays in a low-power state and acts like an AirTag, allowing any nearby iOS device to pick up the Bluetooth signal and send back its location.

Oh my. Thanks.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#192

If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.

> Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? Yes, this is what I do. The mike is actually still in the laptop but it's disconnected from the motherboard. On a 2021 M1 Macbook pro all you need to do is pop off the back cover and disconnect one cable on the right side of the motherboard. All in all takes about 10 minutes of work.

There actually is a physical microphone disconnect for new Mac laptops (~2019 and later). When the clamshell is closed, the mic’s connection to the MLB is physically severed.

I actually just learned this exists on new iPad models too, with any MFi-compliant case!

I know this isn’t strictly relevant, since the vulnerability discussed here is during active use, just thought you might find it interesting.

https://support.apple.com/en-ca/guide/security/secbbd20b00b/...

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#194

Earlier quoted context omitted.

I called this a data grab from day 1 and stand by that. The amount of fellow iOS developers I've had argue for the "convenience" is astounding. There should be a settings toggle to control the auto-reenable behavior.

> I called this a data grab from day 1 and stand by that Option 1 is a reasonable explanation based on the behavior that arguably works best for 99% of users . Option 2 is a “data grab” with no evidence or theories about who is grabbing what data and for what purpose.

AirTags wouldn’t work as well if everyone’s phones weren’t constantly transmitting/receiving, for one thing, and grabbing data on all nearby WiFi SSIDs and beacons helps with location services and probably advertising.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#195
post #164

Earlier quoted context omitted.

Even worse, Control Panel buttons only "suspend" BT/WiFi, you have to go into Settings to turn them off again ... and again ... and again.

As a half solution: You can create a Shortcut that turns of BT/Wi-Fi completely. You can then add that Shortcut to your home screen for easy access. That's what I do and it's way nicer than going to Settings, though I wish it was just in Control Center.

Seconding this, I do the same thing. It turns turning everything fully off into one press.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#196

Earlier quoted context omitted.

I didn't claim that. It's just the main reason for not switching according to my friends. The imessage moat in the US is pretty heavily discussed on here.

If HN were a representative sample of what most users wanted from their phones you would think they wanted to spend half the day compiling the Linux kernel on their phone and the other half bemoaning if only they had the “right to repair” they could put their own headphone jack on their phone and get rid of those pesky AirPods

What are you even getting at? I didn't say it was a representative sample, just that it was discussed on here. It's a real thing.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#197

Earlier quoted context omitted.

So now people that discover exploits should be bullied and threatened by corporations for asking for more money? Heck, I hope Apple does this so that no one will ever want to use them again.

I mean, that's the station where we are heading. The moment you will come to corporation and say: "I have this and this vulnerability, black market offers me X, I want 2X from you." Corporation will then subpoena you to get the knowledge from you and then cease and desist you to prevent you from spreading that knowledge further. You will try to threaten that you will release it to black market if they won't pay you 2…

I would hope you wouldn't threaten that and just ask for more money. If your end goal is to do that, then hopefully you'll be security conscious enough to do so and say... hm, have no idea how that got there. Me personally... I'd release it to the public and watch as the corporation suffers until the next one where they'll be glad to pay more.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#198

Earlier quoted context omitted.

I called this a data grab from day 1 and stand by that. The amount of fellow iOS developers I've had argue for the "convenience" is astounding. There should be a settings toggle to control the auto-reenable behavior.

> I called this a data grab from day 1 and stand by that Option 1 is a reasonable explanation based on the behavior that arguably works best for 99% of users . Option 2 is a “data grab” with no evidence or theories about who is grabbing what data and for what purpose.

> grabbing what data and for what purpose

One possible motive: a billion dollars of AirTag revenue, https://macdailynews.com/2022/06/20/apple-estimated-to-sell-...

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#199
post #170

Earlier quoted context omitted.

Yeah, this behavior sounds a bit anti-user to me. The action pretty much boils down to, "Oh, you disabled Bluetooth and left it that way? Well, we know better so we're going to turn it back on without your knowledge or approval. You're welcome." I don't buy the convenience excuse either otherwise the behavior could be disabled if desired.

You mean it’s anti user when it says in big letters “turn off Bluetooth until tomorrow” when you click on the button in control center?

It's an anti-user and anti-dictionary dark pattern when "turn off" doesn't mean Turn Off, but only stops new connections.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#200

If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.

> Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? Yes, this is what I do. The mike is actually still in the laptop but it's disconnected from the motherboard. On a 2021 M1 Macbook pro all you need to do is pop off the back cover and disconnect one cable on the right side of the motherboard. All in all takes about 10 minutes of work.

It's a good idea, but I can imagine how frustrating it would be if someone called and I didn't have my headset. The EV of avoiding that experience seems slightly higher than the EV of avoiding risk of being eavesdropped on by a wayward smartphone process by disabling the internal mic.
Post reply on HN