Live data from Hacker News

iMessage Preview Problems; leak your location by receiving a text message

theantisocialengineer.com

41–50 of 51 posts

Re: iMessage Preview Problems; leak your location by receiving a text message

#41
post #37

Earlier quoted context omitted.

Why not have the sender do that work so Apple can just stay out of it?

The sender could be a dumb SMS client. I'd be happy to just turn off previews entirely.

I think the idea then would be you'd only ever show embedded previews, so URLs from dumb SMS senders just wouldn't have a preview.

Re: iMessage Preview Problems; leak your location by receiving a text message

#42
post #6

tl;dr iMessage now previews links automatically > The updated iMessage loads the link preview and in essence clicks the link for you! That’s what irks us with this, the choice. OK we might not stop people clicking links anytime soon but Apple have taken this very choice away from us and facilitate the information leakage. The very act of receiving an SMS message can reveal your rough geographic location, your cellula…

What makes this more frustrating is that the link previews are a pretty terrible user experience.

I don't use iMessage but I've noticed this "design pattern" turning up in various other apps, and I hate those bloody things. They're extremely distracting and annoying because they often include "loud" imagery too, when I'm only trying to read the text. I turn them off whenever I can.

Re: iMessage Preview Problems; leak your location by receiving a text message

#44
post #37

Earlier quoted context omitted.

Why not have the sender do that work so Apple can just stay out of it?

The sender could be a dumb SMS client. I'd be happy to just turn off previews entirely.

Which is the right way to do it and exactly how ever email client does. Do you want to see previews? Have the device make the request. Do you not want to see previews? The device shouldn't make those requests.

Re: iMessage Preview Problems; leak your location by receiving a text message

#45
I find myself thinking a recent story of an middle eastern human rights activist who's iPhone was attempted hacked via a sms url. He avoided it by not tapping the url. I do wonder if this preview "feature" will help automate future attacks.

It seems that whenever we try to make software helpful we produce more problems.

Re: iMessage Preview Problems; leak your location by receiving a text message

#46

Sending the requests from the client is probably not the most secure idea. Requests should be proxied through a cloud server on Apple's end to reduce the security risk of these previews.

There have been zero-days in the past that only require loading a website, right? So loading links automatically should be a massive concern for iOS security. Back in August, when zero-days used by the NSO Group were discovered, it was only because activist Ahmed Mansoor didn't click on a link in a text message. https://citizenlab.org/2016/08/million-dollar-dissident-ipho...

Re: iMessage Preview Problems; leak your location by receiving a text message

#47
post #37

Earlier quoted context omitted.

Why not have the sender do that work so Apple can just stay out of it?

The sender could be a dumb SMS client. I'd be happy to just turn off previews entirely.

OK, so just limit it to iMessage users like a lot of other iMessage features.

Re: iMessage Preview Problems; leak your location by receiving a text message

#48

What's wrong with web hosts nowadays? a few 100 users and everything dies. Cached: https://webcache.googleusercontent.com/search?q=cache%3Ahttp...

Any experience how many users you get from the front page? I guess there are a lot more clicks than comments, so it could've been 10k-100k?

Should of course still be no problem for any server that serves cached content, but somehow that number of requests brings down a fair amount of frontpage posts..

Re: iMessage Preview Problems; leak your location by receiving a text message

#49

Earlier quoted context omitted.

never install the .0 version of anything We're already on 10.0.2, so we've already had a few updates.

Are we? Go figure - I've been getting the installer popups from Springboard for a while, but I guess it doesn't show minor versions if the major versions differ; it's just been saying "iOS 10", and I took that to mean no patches had been released. So I suppose I should say rather I would expect to see it corrected in iOS 10.1, at latest.

iOS 10.0.1 was the first public release of iOS 10; iOS 10.0.2 was a patch released a couple weeks afterwards fixing some bugs with Photos, app extensions, and the lightning 3.5mm adapter. (10.0 was not released to the public in any form-- probably some critical issue was discovered late in testing after 10.0 had been tagged internally but before the GM seed of 10.0.1 was released to developers.)

This sort of change (fixing link previews) is similar in scope to changes Apple's made in micro (0.0.1) releases before. Whether it happens in a micro release or wait until 10.1 (or even change anything at all) really depends on how important Apple thinks the issue is.

At any rate, I doubt the feature is going away completely (link previews were a flagship iOS 10 feature): at best, I'd expect a "Automatically preview links" checkbox in Settings, just like external image downloads in Mail.

Re: iMessage Preview Problems; leak your location by receiving a text message

#50
post #20
post #18

Earlier quoted context omitted.

I would have figured Apple proxied the preview to their own URL crawler which could automagically pluck the best preview image, similar to the magic that FB / Slack do when sharing a link. This would mask the IP / Geo and Apple could cache a preview image.

It would also expose any URL you send or receive via iMessage to Apple, whereas messages are otherwise end-to-end encrypted.

ah good point
Post reply on HN