4 ms·
I’m curious if more will come out of this but it sounds like the attackers probably already attacked Julie or her employer (she appears to have worked for Tile,
by codezero 6y ago
I’m curious if more will come out of this but it sounds like the attackers probably already attacked Julie or her employer (she appears to have worked for Tile, Oculus and others) and just signed the app with her ID. I bet they have a ton of these credentials in their pocket from previous infections.
Since this didn’t go through the App Store it probably wasn’t reviewed but the developer’s certificate would be checked when it’s run - hence the revocation now.
- codezero 6y agoEdit: I'm also pretty sure this means they breached her iCloud account entirely - as I am pretty sure you need to sign in to your account to sign applications. That's pretty scary, and I hope if it's possible that is the case, someone is looking into it!