Live data from Hacker News

Apple Watch Ultra 2 Hacked

discussions.apple.com

41–50 of 182 posts

Re: Apple Watch Ultra 2 Hacked

#41
post #25

> they popped up the keyboard and typed “We are in control” This reads like bad hacking fiction, complete with the guy typing that wearing a Guy Fawkes mask. Why the hell would the (hypothetical) attacker lose precious time doing something like that.

> Why the hell would the (hypothetical) attacker lose precious time doing something like that. Because it’s probably kids messing around.

Their own kids, not unlikely.

Re: Apple Watch Ultra 2 Hacked

#43
post #14

TLDR: Their watch digitizer got messed up. Likely submerged it in water and it was all over. Case closed.

and it typed "We are in control"? Very unlikely.

Not as unlikely as one might think. The random inputs, after unlocking the watch with a passcode, might hit the messages app if that is set up as a complication. Then something similar to we are in control is written (drawn letter by letter), which might autocorrect to what OP in TFA saw. Apple autocorrect can come up with some wild sentence constructions.

Re: Apple Watch Ultra 2 Hacked

#44

I wonder why most of the comments take it very casually and say may be issue with digitizer/ghost touch. Had it been any other OEM, this would have been such a big issue with anecdotes of why people trust apple products.

It’s because a lot of people on HN have dealt with bug reports from users that were clearly fabulations after investigating thoroughly

Re: Apple Watch Ultra 2 Hacked

#45

First of all, why would anyone even care about you enough to want to steal whatever health data is available? Is there any particularly sensitive personal info stored there? Second, presumably if one gains access to the device through a sophisticated hack they'd probably also be able to exfiltrate data without having to alert the user. With all of that being said, I wish there was some sort of black box mechanism for…

> .. I wish there was some sort of black box mechanism for logging certain events in such a way that the device itself can't tamper with it..

This is called an append-only log. It can be built in many ways. Which way is suitable largely depends on the security requirements.

My personal favorite kind of append-only logging is transparency logging. If you'd like to learn more you can check out e.g. sigsum.org, an open-source project my colleagues and I have been working on for several years now.

Re: Apple Watch Ultra 2 Hacked

#46

I wonder why most of the comments take it very casually and say may be issue with digitizer/ghost touch. Had it been any other OEM, this would have been such a big issue with anecdotes of why people trust apple products.

Exactly. This comment section really is a display of the Apple bias on HN. I don't doubt that this might be nothing, but seeing all these commenters completely dismissing it is rather odd. Hopefully Apple is less dismissive of this potential security issue.

[deleted]

Re: Apple Watch Ultra 2 Hacked

#47
post #24
post #20

Earlier quoted context omitted.

I wonder how such hack would even work. The watch does have the option to control it remotely, through the iPhone accessibility options, but obviously this only works with the paired iPhone and not over the internet.

That multiple people reported a "spam" phone call right before the incident makes it look like they've found some zero day cellular exploit. If this is for real I expect we'll hear more about it soon enough.

No one is burning a baseband 0day to write "we are in control" on a screen.

Re: Apple Watch Ultra 2 Hacked

#48

Is it possible there’s an exploit to remotely touch, which at first looked random, but as people figured it out learned to actually operate the device?

let's imagine that that's the case. imagine that you are the attacker that figured that out, what are you going to do? start attacking random people with random clicks on their screen or keep it in private until you figure out details how to make it useful?

thats why this sound like some kind of hardware malfunction (or some substance on touch screen - I personally experienced ghost touches on my phone from dirty screen) or it's some kind of prank by kids using some flipper and previously authorized device or something similar

Re: Apple Watch Ultra 2 Hacked

#49

This is so hard to believe that I simply don't. Either the user had a bad digitizer, and misread and/or hallucinated the "We are in control" message, or the entire story is made up. Perhaps a group of people working together to post "Hey me too!" stories? I'm not sure what the motive would be, though. Extraordinary claims require extraordinary evidence, and this is beyond believability.

It's pretty obviously fake. A bunch of "level 1" (new) users, all with the same story? They literally mention the exact time & date in the same style, and mention the 1-minute lockout in the same way as well. Two of them use the same timestamp even, down to the minute.

Also, something I noticed working for large orgs with over 100K staff and 1M users: An appreciable fraction of the human population is simply mentally ill. Hallucinations, drug use, psychosis, etc... all have a non-zero rate. Given enough users, you'll get the same type that imagines being abducted by aliens and even makes police reports that sound suspiciously like the sci-fi movie that's popular at the time.

Re: Apple Watch Ultra 2 Hacked

#50
I had exactly the same problem last week. Random touch & drags on the watch, it took me some effort to shutdown the watch without making an accidental emergency call.

Given apple's security track of record and the fact that I pose no value as a target for the such an hacking effort. I deducted that it just was ghost touch.

Post reply on HN