Live data from Hacker News

FaceTime bug lets you hear audio of person you are calling before they pick up

9to5mac.com

271–280 of 458 posts

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#271
post #268

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

The genuineness of the Twitter account is absolutely irrelevant in contrast to the validity of the bug itself.

Apple was reported a high priority bug at a specific time. Who reported it, how they look like, what their Twitter profile looks like should have no impact on Apple's bug fixing process and how long/short they took to fix the bug.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#272
post #268

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

While the account does seem a bit odd — especially in our current state — it stills boils down to the fact someone discovered a bug and they seem to have receipts.

Linked tweet shows an email signature on reply from “Deven” of “Apple Product Security” and the senders original message. >> https://twitter.com/mgt7500/status/1090079031666438144?s=21

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#273
post #271
post #268

Earlier quoted context omitted.

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

The genuineness of the Twitter account is absolutely irrelevant in contrast to the validity of the bug itself. Apple was reported a high priority bug at a specific time. Who reported it, how they look like, what their Twitter profile looks like should have no impact on Apple's bug fixing process and how long/short they took to fix the bug.

Oh I’m not questioning the existence or importance of the bug. It’s important and a big screwup.

However, I am extra sensitive to the degree to which twitter is being manipulated for all sorts of ends. Sometimes things look more than a bit fishy. Usually major bug reports don’t come from 2019’s version of egg avatar + letters/numbers username + very recent activity consisting almost entirely of political posts + past tweets with interactions with obvious political manipulation bots. That is on the stranger end of things, you have to admit. To be clear I think it’s real, but also real weird.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#274
post #268

Earlier quoted context omitted.

Interesting twitter account. First tweet 1/1/19, few followers, mostly politics, then a major bug report (not only in discovery but in knowing how to go through the reporting process). Not saying it’s fake at all - it looks 100% legitimate - but it adds some extra bit of weirdness to this story. Quite the providence, and a really bad bug. (edited for clarity)

While the account does seem a bit odd — especially in our current state — it stills boils down to the fact someone discovered a bug and they seem to have receipts. Linked tweet shows an email signature on reply from “Deven” of “Apple Product Security” and the senders original message. >> https://twitter.com/mgt7500/status/1090079031666438144?s=21

Ya that poorly obscured email in the message is strongest evidence to suggest this is a real twitter account & story - I believe it’s legitimate. Which makes this story really interesting, that the kid found it, the parent knew how to bug report, the parent went to a twitter account they only recently started using to try to get the word out, and nothing happened. Goes to show process needs improvement and that bug reports truly can come from anywhere.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#276
post #170

Earlier quoted context omitted.

Oh dear, I remember something similar was possible on iOS lockscreen multiple times. What version of Windows was that?

95. 98 had an even better one... just hitting cancel on some login boxes would let you in.

Pretty sure I've seen a similar trick on XP or later as well. (I learned it from someone I didn't meet until long after I last saw a 95/98/2000 machine.)

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#278
post #260
post #236

Earlier quoted context omitted.

As someone who bought an iPhone specifically for privacy reasons, I'm not really upset about this. What I'm concerned about is passive, mass-scale corporate surveillance, not a one-off bug that allows an individual with mal-intent to listen through my microphone for a few seconds and also let me know about it.

Are you able to root an iPhone or use one without signing in with an Apple account (that's tied to a credit card, etc)? If not, then I believe the devices are still very much part of a mass-scale corporate surveillance network.

Yes, you can use an iPhone without signing into any account.

Re: FaceTime bug lets you hear audio of person you are calling before they pick up

#280

Rumor mill: FaceTime bug was submitted to Apple on 20 January 2019 by a concerned mother after .. her 14-year-old son discovered it. >My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport...waiting to hear back to provide details. Scary stuff! #apple #bugreport @foxnews [0] https://twitter.com/mgt7500/sta…

If the mother did in fact submit a ticket a week ago, it's pretty shameful that the escalation / verification process took more than a week for a bug of this severity.

[deleted]
Post reply on HN