4 ms·
I've previously seen this done with SMS gateways, which allow you to specify/spoof the sender number (it's how you get a text addressed from 'COMCAST' for insta
by flashman 9y ago
I've previously seen this done with SMS gateways, which allow you to specify/spoof the sender number (it's how you get a text addressed from 'COMCAST' for instance). Your phone will trust that the spoofed number is genuine, so if I send you a message with Bob's details, your phone will tell you it's from Bob.
Unlike the OP, the attacker can't receive replies from the recipient.
- azinman2 9y agoThat also wouldn’t work over iMessage. I’d like to know if this is actually being done in the wild. Certainly once caught would be banned from the App Store and possibly a lawsuit or two filed. The author didn’t note that a new thread would have started on iOS, which would provide some visual feedback that something was different. You could click for further info and see the different number. I know it would foil most but it’s something.
- Rjevski 9y ago> once caught would be banned from the App Store But the issue is that it's impossible to detect. An app could've added the extra number months ago, and you've deleted the app since then. There is no way to find out which app did it.
- dannyw 9y agoApple’s security team can always collaboratively filter on reports and find out what is the intersection app.
- Rjevski 9y agoAssuming this is used widely for there to be enough reports. I expect this to only be used sparingly so I'd be surprised if there is even a single report of this; as the targeted people will mostly have no idea this is even possible.
- azinman2 9y agoSo you’re telling me that someone went to all the trouble of building an app, getting people to download it, and then only used its main purpose (phishing/malware) for a couple people?