Live data from Hacker News

SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

rambo.codes

31–40 of 259 posts

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#33
post #28
post #18

Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.

Occasionally I ask her (it?) to set a timer or add a reminder, but mostly I don't. Siri is quite slow and frustratingly limited. The other day in a hurry and driving somewhere, I ended up w/ both Apple Maps and Google Maps open, simultaneously giving me directions. "Hey Siri, close Google Maps" "To close an application, swipe up from the bottom of the phone..." To paraphrase a quote from Steve Jobs, if your voice ass…

Seconded. I get way too many "Im sorry Dave, I just can't do that" moments

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#34
post #18

Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.

Siri killer apps for me are asking for factoids via my watch, and opening my garage door as I approach while driving (my building uses an app that requires multiple taps + swipes to open the garage door, using Siri makes it palatable.)

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#35

Seems like $70,000 would have been a more fair bounty. This is a really nasty bug.

$70,000 would have been more fair

There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#39

If an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.

Note this Bluetooth only.

Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri

#40
post #35

Seems like $70,000 would have been a more fair bounty. This is a really nasty bug.

$70,000 would have been more fair There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.

Here are the listed payouts from the Apple Security Bounty program, starting at $25,000. https://developer.apple.com/security-bounty/payouts/
Post reply on HN