4 ms·
I disabled all that, and background app refresh as well. I am getting a huge database of these logs because of my users. Maybe someone can help me investigate
by stanlarroque 9y ago
I disabled all that, and background app refresh as well.
I am getting a huge database of these logs because of my users. Maybe someone can help me investigate because there is definitely something going on.
Here is a preview: https://stan.sh/images/log-example.png https://stan.sh/images/log-example.png
- AdamJacobMuller 9y ago"something" going on? like, the manufacturer of a device who provides cloud services with that device is speaking to their servers to provide services that the customer wants? Very alarming.
- stanlarroque 9y agoI understand iCloud, iTunes, and all other apple services need to communicate with their servers. My point is to question why do they need more than 1000 hosts for their endpoints? It only look suspicious in my eyes. https://stan.sh/images/ios_domains.csv https://stan.sh/images/ios_domains.csv
- flotillo 9y agoWhy is it suspicious? I don't see your reasoning here. Having a diverse range of DNS names requested doesn't seem to me to be an indicator of suspiciousness. On earlier releases of iOS that had a public jailbreak released, I spent quite some time using HttPeek (https://github.com/Yonsm/HttPeek https://github.com/Yonsm/HttPeek) to examine what various OS processes were sending, and found nothing untoward. I'd be surprised if this had changed for the worse in more recent iOS releases.
- TazeTSchnitzel 9y ago1) Every service most likely has many, many different servers providing it. These may have different hostnames. Particularly consider that Apple uses a lot of cloud services. 2) All the services you list in fact consist of many smaller services. iTunes alone is a storefront, a CDN, a payment processing service, a DRM system, a syndication service, an account management service, a media library synchronisation service, a streaming media service, and so on. iCloud is a blanket name for a large collection of big services which themselves may consist of many smaller services. 3) That isn’t even the full set of services. In light of these considerations, 1000 hostnames should not be unexpected. That might even be a surprisingly small figure.
- kalleboo 9y agoOne area where Apple uses a large amount of domain names on purpose is for their captive portal detection. Supposedly they do this on purpose so that captive portals can't try to hard-code a list of domains in order to white-list/fool it.
- tomjakubowski 9y agoWhat benefit would a captive portal derive from hiding from Apple's captive portal detector?
- hmage 9y agoiOS offers a slideover view that gets dismissed once absence of captive portal is detected. That way you can’t redirect people forcibly to your website after auth is done in a way that persists. But if you force people to use a browser rather than auto disappearing modal view, the bounce rate is much lower once you force them to visit your website after captive portal login.
- im3w1l 9y agoDevice: Am I on a captive portal? Nonce. Apple server: No. Same Nonce. Cryptographic signature. If different response: Captive portal. If no response: No internet.
- im3w1l 9y agoOops, this doesn't actually work, because the captive portal can just let that one request through unmodified...
- AdamJacobMuller 9y agoWhy not? I've developed some very large globe-spanning systems that are probably a single-digit % complexity as the Apple ecosystem and we touch hundreds of endpoints. Doesn't seem suspicious to me at all.
- kccqzy 9y agoTry to temporarily log out of iCloud and iTunes Store and disable push notifications. I think that could reduce a lot of the traffic. And then gradually start turning things on one by one.
- laken 9y agoPerhaps it's the recent iOS update? Right now iOS 11 is being rolled out, and it defaults to auto update overnight.
- natch 9y agoIn your logs why don’t you also log whether each device is connected to power and what preferences each user has set on a per app basis for push notifications, background data fetch, background downloads (distinct from background data fetch), as well as their do not disturb settings and timeframe, whether they are on a cell network or wifi, whether the wifi is exposing a networked backed by a cell network, the current battery level at each time, whether the device is changing location, whether the user is moving the device, whether the screen is locked, whether any app is in the foreground, whether any currently installed apps have code that gets invoked when geographic regions change, whether they have any code that is invoked when specific locations are visited, whether they have code that gets invoked when non-specific locations are arrived at or departed from, whether the user has recently changed networks, whether the user has recently plugged or unplugged the power, etc., etc., etc... Don’t have all this data? Then maybe don’t jump to premature conclusions about what your network activity is telling you.