19 ms·
SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
- jdelman 4y ago$7k feels like a paltry sum for this discovery. Rambo is doing yeoman's work.
- deleted 4y ago[deleted]
- QuackyTheDuck 4y agoSigh … I so much want Apple to get their shit together. To me it feels like software quality reached a new low.
- deleted 4y ago[deleted]
- gw99 4y agoThe scary thing is it's the least bad option when it comes to overall reliability.
- gtvwill 4y agoOoo that's a big depends on the situation. Making only phone calls. Sure iPhones are great. Running LOB apps. Lol have fun passing that crap through apples store. Androids way easier for LOB. Remote MDM? Lol nightmare using apples gear. Warranty services? Also a nightmare. Fleet level warranty support? Ahahhahhaha have fun paying folks like IBM out the kazoo. No thanks. iPhones are rock solid if you played w Fischer price toys as a kid and only ever plan to be on the public consumer end of the game, making calls and using apps someone else has decided are ok for you. Go up the line to fleet rollout or bulk purchasing/warranty work or running custom line of business apps. Ahahhahhaha have fun w apple I've done the work when I was w/ ibm, I refuse to touch it these days.
- plugin-baby 4y agoWhat are LOB and MDM?
- gtvwill 4y agoLine of Business, Mobile Device Management.
- codalan 4y agoI think it depends on the phone. The Google Pixel series seems pretty solid for reliability. I have a Pixel 7 Pro and it's been really good so far in terms of software and build quality. I strongly prefer it to my iPhone 13 Pro, which I'm currently selling off. But iPhone vs Samsung Galaxy? iPhone wins by a mile. I never got used to the custom interface Samsung loaded onto those phones, and hated that it included Samsung-specific apps that just duplicated those already available by default on stock Android.
- JamesonNetworks 4y agoPixels had a defect where emergency calls didnt work with MS teams installed. Both platforms wither under the lights
- Tijdreiziger 4y agoThey still have problems with emergency calls. https://www.androidpolice.com/google-pixel-phones-struggling-to-reach-emergency/ https://www.androidpolice.com/google-pixel-phones-struggling...
- gw99 4y agoI have an iPhone 13 Pro. I found that Android is almost a brick the moment you lose an Internet connection where as the iPhone is still productive and I can do stuff offline and it'll sync everything later no problems. That is a complete dealbreaker for me for Android. Also, Google.
- thaumasiotes 4y agoI mainly use my phone for three things: 1. Pleco 2. Wechat 3. Kindle app Pleco (a dictionary) and Kindle (an ebook reader) work fine offline. Why wouldn't they? Wechat, of course, can't do anything offline, because it's communication software. It is not even clear what "use wechat offline" would mean. Android itself obviously works equally well whether you're connected to the Internet or not. What do you mean by becoming "almost a brick"?
- freeplay 4y agoCouldn't agree more. As stupid as it may be, the only reason I haven't moved to Andoid/GrapheneOS is iMessage.
- deleted 4y ago[deleted]
- alphabetting 4y agothat's the main reason for most iphone users i know and exactly why Apple will stall for as long as possible on RCS compatibility
- scarface74 4y agoYes I’m sure that Apple’s 95% retention rate is based on iMessage based on the sample size of “people you know”.
- alphabetting 4y agoI didn't claim that. It's just the main reason for not switching according to my friends. The imessage moat in the US is pretty heavily discussed on here.
- scarface74 4y agoIf HN were a representative sample of what most users wanted from their phones you would think they wanted to spend half the day compiling the Linux kernel on their phone and the other half bemoaning if only they had the “right to repair” they could put their own headphone jack on their phone and get rid of those pesky AirPods
- alphabetting 4y agoWhat are you even getting at? I didn't say it was a representative sample, just that it was discussed on here. It's a real thing.
- z9znz 4y agoThere were some stubborn bad decisions that Steve Jobs stuck to (1 button mouse, windows that don't appear when you cmd-tab to them), but his Apple seemed to have better software. Since him, it really seems to have gone downhill in terms of bugs and UI consistency.
- mikece 4y agoI don't want stories like this to be the reason I'm glad I switched to Graphene OS. I don't want anyone hacked or spied on.
- deleted 4y ago[deleted]
- aaronharnly 4y agoPro tip: all systems have bugs.
- NayamAmarshe 4y agoNot all systems come with easy eavesdropping mechanisms. Especially the ones focused on Privacy.
- devX3 4y agoKinda funny that you have to buy/support hardware from a company but then need to use a opensoure nonprofit OS to protect yourself against said hardware producer.
- henriquez 4y agoSeems like $70,000 would have been a more fair bounty. This is a really nasty bug.
- deleted 4y ago[deleted]
- pvg 4y ago$70,000 would have been more fair There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.
- lapcat 4y agoHere are the listed payouts from the Apple Security Bounty program, starting at $25,000. https://developer.apple.com/security-bounty/payouts/ https://developer.apple.com/security-bounty/payouts/
- pvg 4y agoThe closest is $25,000. App access to a small amount of sensitive data normally protected by a TCC prompt. In this case you get a misleading prompt, the access requires additional interactions. It's a serious bug and I'm all for reporters of serious bugs getting bigger bounties from companies that have more cash than they know what to do with. But simply dropping a random number in every single one of these threads is just noise, not even advocacy or technical discussion.
- _hhkc 4y ago"iOS bug allowed apps to eavesdrop on your conversations with Siri" should be "iOS bug allowed apps to eavesdrop on your interactions with Siri and dictation over bluetooth"
- yazzku 4y ago
- eastbound 4y agoThe right amount for a security bounty is the sum of all assets covered by that vulnerability minus $1. This is the only way companies will take the right processes to protect those assets.
- kube-system 4y agoThe impact and difficulty of exploit are pivotal parts of assessing the risk of a vulnerability. It doesn’t really matter how many dollars of things are involved if the exploit can’t be exploited or if it’s not a big deal if anyone does.
- deleted 4y ago[deleted]
- MBCook 4y agoSo he should have sold this? He’s always seemed like a good person to me who would do that. Sit on it knowing others may find it and users are at risk? Who cares he got paid. That’s not why he did it, he found it while developing one of his apps and reported it. Good for him. It’s nice Apple paid him. I can understand thinking it should have been more. But what ethical alternative is there to reporting it?
- TheLoafOfBread 4y ago> Find out how much the vuln is worth in the black market, then ask Apple double that. Well, because he is not a corporation, he will get jumped on by lawyers and will go to jail for blackmailing Apple.
- dylan604 4y agoBlackmailing? It's called negotiating from a strong position.
- freeplay 4y agoI think they burried the lede here. Conversations with Siri are probably pretty generic but being able to evesdrop on keyboard dictation is pretty severe. I know people that use dictation for the majority of their text messages and email.
- cstejerean 4y agoEven worse, it looks like on MacOS you can just straight up start recording on-demand, no need for dictation or siri. > Even worse, this particular exploit would also allow the app to request DoAP audio on-demand, bypassing the need to wait for the user to talk to Siri or use dictation.
- SamuelAdams 4y agoAnd this is why I have the internal microphone disconnected on my macbook pro. The only time a mike is attached is when I'm actively using it, and even then they have hardware kill switches. Simple kill switches would be nice to see but I doubt Apple would ever implement something like that.
- metafunctor 4y ago
- spaghettiToy 4y ago
- xbar 4y agoCredit card numbers, social security numbers, passwords. People say all of these things around loved ones all the time without worrying about hardware being "around." Hardware, shockingly, is always around. And despite the author's dismissal of the Facebook listening "myth," everyone I know has an uncomfortable advertising eavesdropping anecdote. Maybe we can agree it's more correctly an unsubstantiated claim.
- 4y ago
- TheLoafOfBread 4y ago
- bryceacc 4y agofirst sentence: "and audio from the iOS keyboard dictation feature"
- TheLoafOfBread 4y agoAnd who is using that? Half of characters are misspelled, second half misunderstood. Nobody has time to argue with a phone.
- asah 4y agoAndroid it works pretty much perfectly and you can speak at normal speed. With Android it pretty much works perfectly and you can speak at normal speed. <== Same sentence dictated at full speed.
- TheLoafOfBread 4y agoYeah not for me. Android, nor Siri, nor Alexa.
- encryptluks2 4y agoIt'll suck if you ever lose function to type with your fingers.
- asah 4y agoAccent? This is me speaking through a mask at normal speed. The quick brown fox jumped over the lazy dog - that was spoken really fast. Obviously depends on what you're speaking because sentences like the previous one are pretty easy to predict.
- walterbell 4y agoIf an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.
- MBCook 4y agoNote this Bluetooth only.
- walterbell 4y agoYes, the question is how to permanently restrict the attack surface / time windows for audio and video surveillance attacks.
- dontbenebby 4y agoIt's not really a question, hardware switches work and companies refuse to put them in so they can... shrink the profile of devices in ways that rely on rare earth minerals to an unsustainable degree when combined with the typical replacement rate.
- walterbell 4y agoHopefully legislated right-to-repair can open the door to aftermarket mods, including phone body with new switches that can electrically disconnect specific sensors.
- dontbenebby 4y agoEhhhh... is right to repair the right phrasing? I worry about requiring switches in the same way one can require a universal standard for power delivery. (The EU did that recently... good move IMO, though I can understand the delay since discussions about amperages and whatnot do take time.[0]) Maybe requiring anyone who wants to contract with the US government to offer such a model, and that said model be available for consumer purchase as well, would be a simple solution. They sometimes won't let say, Russia, buy the same stuff as say... Canada... but that's usually stuff like night vision goggles. The exact same phone or laptop, just slightly larger with more switches shouldn't have any... I think the word is "export controls"? Please keep in mind, I am not a lawyer, and I'm very stupid -- I only have a master's degree -- so sometimes the things I say are wrong... please only credit me for the times I'm right. Thx! I'm off to do more drugs now... have a nice Thursday!! - Greg from Pennsylvania [0] https://www.npr.org/2022/10/07/1127543116/eu-mandate-for-a-single-universal-charger-could-become-world-standard https://www.npr.org/2022/10/07/1127543116/eu-mandate-for-a-s...
- hazyc 4y agoIs anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
- BudaDude 4y agoI use Siri for setting timers and reminders. It's pretty good at parsing numbers. Other than that, It hasn't been very reliable for me. Apple really needs to overhaul Siri's intelligence.
- zippergz 4y agoYes, I have had iPhones from the beginning and I never use Siri.
- trap_goes_hot 4y agoI use it for things like 'will it rain today' or sending quick texts when I am driving.
- dfee 4y agoI use Siri all the time and am half your dads age. “Get directions to the nearest gas station.”, “What’s the score of the Giant’s game?”, “Play Master of Puppets”, “What is 4’3” in centimeters?” And many, many more.
- Firmwarrior 4y agoMan, I used to love using Siri, until I had a daughter and named her "Sarah" big mistake. Turns out I say "Hey Sarah" a hundred times a day, and all my iDevices pipe up and simultaneously say "Yeah?" "WHAT'S UP" "HEY OVER HERE" "Hi it's me Siri what do you need?"
- keepquestioning 4y agoWhy did you pick 'Sarah'
- lapcat 4y agoDon't forget that iOS and macOS silently re-enable Bluetooth on every software update. https://lapcatsoftware.com/articles/bluetooth.html https://lapcatsoftware.com/articles/bluetooth.html
- deleted 4y ago[deleted]
- walterbell 4y agoEven worse, Control Panel buttons only "suspend" BT/WiFi, you have to go into Settings to turn them off again ... and again ... and again.
- sixstringtheory 4y agoI called this a data grab from day 1 and stand by that. The amount of fellow iOS developers I've had argue for the "convenience" is astounding. There should be a settings toggle to control the auto-reenable behavior.
- noptd 4y agoYeah, this behavior sounds a bit anti-user to me. The action pretty much boils down to, "Oh, you disabled Bluetooth and left it that way? Well, we know better so we're going to turn it back on without your knowledge or approval. You're welcome." I don't buy the convenience excuse either otherwise the behavior could be disabled if desired.
- scarface74 4y agoYou mean it’s anti user when it says in big letters “turn off Bluetooth until tomorrow” when you click on the button in control center?
- walterbell 4y agoIt's an anti-user and anti-dictionary dark pattern when "turn off" doesn't mean Turn Off, but only stops new connections.
- jalla 4y ago
- dylan604 4y agoIs that you NSA?
- runjake 4y agoA $7,000 bounty for eavesdropping and TCC (app permissions) vulnerabilities. Insulting.
- pxmpxm 4y agoMy first thought as well - the author must be doing this stuff as a hobby/for fun, because that's not nearly enough to comp you for the time spent.
- rtev 4y agoThis is why people sell bugs.
- pvg 4y agoIt's an example of why people report bugs to vendor bounty programs since you could not sell this bug for $7000.
- hu3 4y agoWhat makes you think it wasn't sold? Even if by another party that could have found it before?
- pvg 4y agoWho would you sell it to and what would the buyer do with it? Outline the scenario you have in mind and we can try to sort out how to leverage this specific bug for $7000 worth of some kind of value.
- legutierr 4y agoConceivably, a state actor could use this bug to eavesdrop on an espionage target, no? There is a market for zero-day exploits, where state espionage entities and criminal organizations both pay to learn about the existence of vulnerabilities like this—with prices in the hundreds of thousands to the millions of dollars. Are you saying that this particular bug would not be worth more than $7000 in one of these markets, or are you questioning the very existence of these markets?
- tinus_hn 4y agoWonder if it’d also be possible to send commands to Siri, that could also have some implications.
- traceroute66 4y agoI'm an avid iPhone user but have never had the need or the desire to use Siri. I suggest people do what I do, load a profile that disables Siri - easily created using the Apple Configurator tool (under "Restrictions" untick "Allow Siri"). N.B. I've never looked closely under Settings on the phone itself, there may well be Siri off option there ? But I just load profiles as I find its easier for hardening.
- sneak 4y agoIf you care about privacy, you should disable Siri and Dictation and blacklist guzzoni.apple.com.
- atlex2 4y agoConfused why you can’t use this to transcribe from any AirPods in your vicinity? I thought anyone could subscribe to a btle gatt attribute.
- semireg 4y agoThe BLE peripheral (AirPods) have to be connected and paired. Then, this connected device was “explorable” via other apps on the same device because the actual connection is maintained by the middleware/OS… e.g. an app may disconnect from a peripheral but it’s only a request, and the OS will only truly disconnect if all apps are “disconnected.”
- greenicon 4y agoI wouldn’t have expected Opus in the AirPods. Unexpected from Apple and a quite interesting workaround around the mode switching.
- walterbell 4y agoOpus patent trolls are pleasantly surprised :(
- deleted 4y ago[deleted]
- nick88msn 4y agoIs there actually people using siri? It’s pretty useless here in Italy. Most conversations I guess could be something like “raise the volume” “call mom” or stuff like that.
- mfbx9da4 4y agoYes when I’m cycling. Also for setting reminders and weather forecast
- 2T1Qka0rEiPr 4y agoThe struck-through: > and then receive a reply in the form of "here's what I found on the web... Really made me chuckle. As a non-Apple user who has to put up with Homepods, this rings so very true.
- veronikamartin 4y ago[flagged]