Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
51–60 of 259 posts
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#52Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
Siri killer apps for me are asking for factoids via my watch, and opening my garage door as I approach while driving (my building uses an app that requires multiple taps + swipes to open the garage door, using Siri makes it palatable.)
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#53Earlier quoted context omitted.
Ooo that's a big depends on the situation. Making only phone calls. Sure iPhones are great. Running LOB apps. Lol have fun passing that crap through apples store. Androids way easier for LOB. Remote MDM? Lol nightmare using apples gear. Warranty services? Also a nightmare. Fleet level warranty support? Ahahhahhaha have fun paying folks like IBM out the kazoo. No thanks. iPhones are rock solid if you played w Fischer…
What are LOB and MDM?
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#54Earlier quoted context omitted.
$70,000 would have been more fair There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.
Here are the listed payouts from the Apple Security Bounty program, starting at $25,000. https://developer.apple.com/security-bounty/payouts/
$25,000. App access to a small amount of sensitive data normally protected by a TCC prompt.
In this case you get a misleading prompt, the access requires additional interactions. It's a serious bug and I'm all for reporters of serious bugs getting bigger bounties from companies that have more cash than they know what to do with. But simply dropping a random number in every single one of these threads is just noise, not even advocacy or technical discussion.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#55I think they burried the lede here. Conversations with Siri are probably pretty generic but being able to evesdrop on keyboard dictation is pretty severe. I know people that use dictation for the majority of their text messages and email.
I agree with your take!!
If you scroll to the "Full TCC Bypass on macOS" portion, you can see that this bug allows folks to turn on an Airpod and direct that audio to a macOS device. This could enable what is known as a Tempest Attack[0,1]
>BTLEServerAgent did not have any entitlement checks or TCC prompts in place for its com.apple.BTLEAudioController.xpc service, so any process on the system could connect to it, send requests, and receive audio frames from AirPods. This exploit would only work on macOS, because the more restricted sandbox of iOS prevents apps from accessing most global mach services directly.
Stuff like that are why I hate Bluetooth in general, and I'm on the fence if either my laptop OR phone will be Apple products when I replace them.
(They seem to cater to people who replace their devices every year and camp out outside the Apple store for new Apple stuff like nerds rather than the folks who didn't want to spend every weekend messing with kernel drivers and thus adopted what I will continue to refer to as "shiny BSD" even though they long since changed the name from OSX to macOS.)
-- [0] https://en.wikipedia.org/wiki/Tempest_(codename)#Public_rese... [1] http://m6rqq6kocsyugo2laitup5nn32bwm3lh677chuodjfmggczoafzw[...
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#56Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
I use Siri all the time and am half your dads age. “Get directions to the nearest gas station.”, “What’s the score of the Giant’s game?”, “Play Master of Puppets”, “What is 4’3” in centimeters?” And many, many more.
big mistake. Turns out I say "Hey Sarah" a hundred times a day, and all my iDevices pipe up and simultaneously say "Yeah?" "WHAT'S UP" "HEY OVER HERE" "Hi it's me Siri what do you need?"
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#57Earlier quoted context omitted.
Note this Bluetooth only.
Yes, the question is how to permanently restrict the attack surface / time windows for audio and video surveillance attacks.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#58Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#59Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
[deleted]
Re: SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
#60Is anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
Siri is a better option than the alternative "voice assistants" on the market, but they're all bad in my book, and I don't want any of them.