If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.
> We need Purism-style hardware kill switches for microphones, cameras and radios. And accelerometers and ...
SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
241–250 of 259 posts
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#242Earlier quoted context omitted.
If HN were a representative sample of what most users wanted from their phones you would think they wanted to spend half the day compiling the Linux kernel on their phone and the other half bemoaning if only they had the “right to repair” they could put their own headphone jack on their phone and get rid of those pesky AirPods
Still salty about their decision to remove the headphone jack and the industrywide adoption forcing me onto that ngl.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#243Earlier quoted context omitted.
Conceivably, a state actor could use this bug to eavesdrop on an espionage target, no? There is a market for zero-day exploits, where state espionage entities and criminal organizations both pay to learn about the existence of vulnerabilities like this—with prices in the hundreds of thousands to the millions of dollars. Are you saying that this particular bug would not be worth more than $7000 in one of these markets…
Conceivably, a state actor could use this bug to eavesdrop on an espionage target, no? Well, let's try to conceive it. Our state level actor is now in possession of an exploit that lets them eavesdrop on a target when they text-dictate or activate Siri, while wearing particular Apple headphones. After getting the target to install a specific malicious app from the App Store. And to run it. And to give it Bluetooth pe…
Remember, at the end of the day the sale is to the government and they have big pockets and less common sense.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#244If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.
There have been reports that the 2020 iPhone SE cannot be used without a microphone:
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#245Earlier quoted context omitted.
> I know people that use dictation for the majority of their text messages and email. Yeah, I'm one of them. The iOS keyboard has slowly become so bad that it's easier to dictate instead, and my partner does the same while driving via CarPlay. This is horrible to read about.
I recently saw a conversation somewhere about this, people said turning off swipe-typing made a significant difference in the keyboard experience. Haven't tested it myself as I use swipe, and have no issues. But might be worth a try.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#246Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
"Siri, timer, one hour thirty"
"Timers can't be set for a time of day, so I set your Timer alarm for 1:30"
Every damn time. Siri hates Brits.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#247Earlier quoted context omitted.
Conceivably, a state actor could use this bug to eavesdrop on an espionage target, no? Well, let's try to conceive it. Our state level actor is now in possession of an exploit that lets them eavesdrop on a target when they text-dictate or activate Siri, while wearing particular Apple headphones. After getting the target to install a specific malicious app from the App Store. And to run it. And to give it Bluetooth pe…
You're not wrong from a technical perspective, but typically the purchaser would be a broker that re-sells these types of exploits to a state-level actor, or even to another broker. Said brokers are interested in acquiring exploits that check certain boxes for their gov buyers, and anything that checks the iOS box is always going to be a hot commodity. Remember, at the end of the day the sale is to the government and…
Shadowy brokers are buying up impractical exploits by mistake seems like an essentially unfalsifiable claim.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#248Earlier quoted context omitted.
Afaik if you care about that, you should be able to fully turn off Find My integration? The idea does have some benefit though. For example, if you enable “Express Transit” for Apple Pay and your phone runs out of battery, you still will be able to tap-to-pay for a subway / bus ride home. The payment NFC subsystem is also separate and has its own battery reserve.
Apple could better describe the action that will be performed, e.g. "Slide to Suspend".
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#249Earlier quoted context omitted.
There actually is a physical microphone disconnect for new Mac laptops (~2019 and later). When the clamshell is closed, the mic’s connection to the MLB is physically severed. I actually just learned this exists on new iPad models too, with any MFi-compliant case! I know this isn’t strictly relevant, since the vulnerability discussed here is during active use, just thought you might find it interesting. https://suppor…
It's not a physical disconnect. More like firmware disconnect. Purism have a physical kill switch for the microphone in their laptop.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#250Earlier quoted context omitted.
It's not really a question, hardware switches work and companies refuse to put them in so they can... shrink the profile of devices in ways that rely on rare earth minerals to an unsustainable degree when combined with the typical replacement rate.
Hopefully legislated right-to-repair can open the door to aftermarket mods, including phone body with new switches that can electrically disconnect specific sensors.
I worry about requiring switches in the same way one can require a universal standard for power delivery. (The EU did that recently... good move IMO, though I can understand the delay since discussions about amperages and whatnot do take time.[0])
Maybe requiring anyone who wants to contract with the US government to offer such a model, and that said model be available for consumer purchase as well, would be a simple solution.
They sometimes won't let say, Russia, buy the same stuff as say... Canada... but that's usually stuff like night vision goggles. The exact same phone or laptop, just slightly larger with more switches shouldn't have any... I think the word is "export controls"?
Please keep in mind, I am not a lawyer, and I'm very stupid -- I only have a master's degree -- so sometimes the things I say are wrong... please only credit me for the times I'm right. Thx!
I'm off to do more drugs now... have a nice Thursday!!
- Greg from Pennsylvania
[0] https://www.npr.org/2022/10/07/1127543116/eu-mandate-for-a-s...