3 ms·
If I were to design a spying device, I would definitively put it on both the client device and the server. That is because third party apps are not required to
by babesh 5y ago
If I were to design a spying device, I would definitively put it on both the client device and the server. That is because third party apps are not required to put their contents on Apple servers. By putting it on the client, you can potentially hoover up any app’s data. Just write a background service that scans the client’s file system and track all calls to encryption APIs.
The list of apps is such a treasure trove. Signal? Clubhouse? Telegram?
https://developer.apple.com/documentation/security/complying_with_encryption_export_regulations https://developer.apple.com/documentation/security/complying...
I need to research what Signal does on iOS. My next canary is encryption of messaging apps other than iMessage.