12 ms·
Apple Watch Ultra 2 Hacked
- rollulus 3y agoSo an attacker has gained remote access, yet needs to perform operations using a sort of Remote Desktop approach? Plausible — in movies.
- jeroenhd 3y agoApple Watch does have a remote control feature, intended for controlling the watch from your phone, as part of the accessibility options. It's certainly technically possible that this feature is being abused to get access to data that would otherwise be locked down by Apple's strict sandbox post-exploitation. Or, more likely, it's some kind of shitty prank by someone nearby to the users.
- smilespray 3y agoThis is probably not hacking, but the ghost touch issue. https://www.zdnet.com/article/ghost-touches-are-haunting-some-apple-watch-users-heres-what-to-do-if-youre-affected/ https://www.zdnet.com/article/ghost-touches-are-haunting-som...
- nixgeek 3y agoIn the discussion thread, it's stated: I stared pressing the button to return home and they popped up the keyboard and typed “We are in control”. That would be a very unusual ghost touch issue, if true.
- smilespray 3y agoGhost touch plus autocorrect. Also check out the YouTube video.
- mips_r4300i 3y agoThe video looks a lot like ghost touch. Could be 2 separate issues.
- ddalex 3y agomaybe the ghost is english-speaking ?
- bhaney 3y agoUnless the "ghost touch" issue randomly typed "we are in control" on the author's watch like he claims, then I don't think it's related. If this isn't hacking, then the author is just lying (which is what I suspect, based on all the similar claims being made and upvoted by new accounts that have never engaged in any other topic on the Apple support forums before this).
- 10729287 3y agoMy guess is the same but I’ll just add that to this day I only have one message in my apple support forum account, posted when I encountered a nasty bug with iOS few weeks ago.
- anaxamander 3y agoThat part seems made up. I don't think the watch possesses the capability for the level of remote control they are talking about, especially on production builds.
- deleted 3y ago[deleted]
- Swizec 3y agoI had a similar issue a few days ago. Watch started pressing random buttons and wouldn’t let me intervene. After a while it stopped. The presses were completely random and amounted to nothing. Looked like the process that reads touch went into an infinite loop of some sort. Has only happened the one time. Lasted about 2 minutes. I may have rebooted the watch to make the issue go away, can’t remember.
- Toutouxc 3y ago> they popped up the keyboard and typed “We are in control” This reads like bad hacking fiction, complete with the guy typing that wearing a Guy Fawkes mask. Why the hell would the (hypothetical) attacker lose precious time doing something like that.
- bowsamic 3y agoA lot of people hack because it’s fun to freak out the victim, and also we have a huge number of historical examples of hackers taunting the victim.
- UberFly 3y agoTrue or not it really does sound like hacking fan fiction.
- pmontra 3y agoTyping "We are in control" looks like kids bragging about their hacking skills. Not the usual hackers but who knows. Furthermore it means that the hack was not automated (yet.) A person was there, typing commands. Again, unusual. On the other side hacking a watch is something that probably doesn't get unnoticed by the wearer if it must go through the UI. Are they subtler ways to get in control?
- maven29 3y agoNot too keen on the anecdote either, but with the Flipper Zero script kiddies around, you can never be too sure. Just a couple of months ago, you saw headlines of low-skill pairing dialog DOS attacks. I believe HID-over-GATT was recently introduced to iOS (only a decade late), and implementation details could potentially be relevant here. https://arstechnica.com/security/2023/11/flipper-zero-gadget-that-doses-iphones-takes-once-esoteric-attacks-mainstream/ https://arstechnica.com/security/2023/11/flipper-zero-gadget...
- mrzool 3y ago> Why the hell would the (hypothetical) attacker lose precious time doing something like that. Because it’s probably kids messing around.
- hyperhello 3y agoIs it possible there’s an exploit to remotely touch, which at first looked random, but as people figured it out learned to actually operate the device?
- Szpadel 3y agolet's imagine that that's the case. imagine that you are the attacker that figured that out, what are you going to do? start attacking random people with random clicks on their screen or keep it in private until you figure out details how to make it useful? thats why this sound like some kind of hardware malfunction (or some substance on touch screen - I personally experienced ghost touches on my phone from dirty screen) or it's some kind of prank by kids using some flipper and previously authorized device or something similar
- rvz 3y agoTLDR: Their watch digitizer got messed up. Likely submerged it in water and it was all over. Case closed.
- titaniumtown 3y agoand it typed "We are in control"? Very unlikely.
- midtake 3y agoNot as unlikely as one might think. The random inputs, after unlocking the watch with a passcode, might hit the messages app if that is set up as a complication. Then something similar to we are in control is written (drawn letter by letter), which might autocorrect to what OP in TFA saw. Apple autocorrect can come up with some wild sentence constructions.
- dingdong33 3y agoIt is very unlikely
- NavinF 3y agoI was with you until "Likely submerged it in water and it was all over". Flagship phones and watches have been waterproof for many years now. I use my iphone and my apple watch in both the pool and the shower regularly with no issues
- scarface_74 3y agoMy Apple Watch 3 was suppose to be safe to swim in. But it did mess up after going swimming in it a few times. Admittedly, this was last year and the watch was already 4 years old.
- Toutouxc 3y agoI think you just got unlucky. It's a mixed bag with "waterproof" phones, but [flagship] smartwatches should be pretty solid. My GF and I both had Galaxy Active watches, now we have Apple watches, we go swimming and kayaking with them, zero issues.
- moribvndvs 3y agoSince when can you arbitrarily pop open the keyboard and display typed text from the Home Screen?
- Astraco 3y agoOn anonymous comments on the internet and in movies.
- Toutouxc 3y agoYeah, if you told me I had 5 seconds to pop up the keyboard on my Apple Watch, I would probably lose. Maybe I'd try to go through my GF's button to her profile and then to messages? Where else can I get a text input really fast?
- LeoPanthera 3y agoThis is so hard to believe that I simply don't. Either the user had a bad digitizer, and misread and/or hallucinated the "We are in control" message, or the entire story is made up. Perhaps a group of people working together to post "Hey me too!" stories? I'm not sure what the motive would be, though. Extraordinary claims require extraordinary evidence, and this is beyond believability.
- sebazzz 3y agoI wonder how such hack would even work. The watch does have the option to control it remotely, through the iPhone accessibility options, but obviously this only works with the paired iPhone and not over the internet.
- pstuart 3y agoThat multiple people reported a "spam" phone call right before the incident makes it look like they've found some zero day cellular exploit. If this is for real I expect we'll hear more about it soon enough.
- Jtsummers 3y agoOnly one person reported the spam call in that thread, the Marcus-II commenter. Their comment shows up twice in the first page and once on the second page. No one else mentions the spam call.
- supriyo-biswas 3y agoThe baseband processor is entirely separate, with some basic commands and responses communicated from the phone's CPU to the baseband, so even this explanation is suspect.
- _kbh_ 3y agoNo one is burning a baseband 0day to write "we are in control" on a screen.
- steve_adams_86 3y ago
- rudedogg 3y agoI think the OP in the linked thread is a complete hoax, and all the commenters are experiencing the random phantom/ghost input issues, googling it and hitting that thread. If you read carefully they all sound like their watch is receiving random inputs.
- herbst 3y agoSo not hoax then but scared users that need to help understand their device and it's honestly very bad bugs? Not sure it does matter at this point, these people paid $800 and now feel their device is heavily insecure, they need help and a explanation from official side they understand.
- anonymousiam 3y agoIf governments can hack your devices, so can private bad actors. https://www.cnn.com/2018/10/13/middleeast/khashoggi-apple-watch-analysis-intl/index.html https://www.cnn.com/2018/10/13/middleeast/khashoggi-apple-wa...
- tinycoder25 3y agoI wonder why most of the comments take it very casually and say may be issue with digitizer/ghost touch. Had it been any other OEM, this would have been such a big issue with anecdotes of why people trust apple products.
- jeppester 3y agoExactly. This comment section really is a display of the Apple bias on HN. I don't doubt that this might be nothing, but seeing all these commenters completely dismissing it is rather odd. Hopefully Apple is less dismissive of this potential security issue.
- deleted 3y ago[deleted]
- account-5 3y ago[flagged]
- nicolas_t 3y agoIt’s because a lot of people on HN have dealt with bug reports from users that were clearly fabulations after investigating thoroughly
- numpad0 3y agoI had been locked out of iPhone in my pocket in hot summers due to presumably ghost touches. Maybe people know it happens with Apple products.
- rpy 3y agoIf you were genuinely remotely hacking a smartwatch, you’d be executing background processes to exfiltrate data entirely invisible to the user, not doing some bizarre remote desktop thing randomly tapping around on apps. The claim doesn’t pass the sniff test irrespective of the manufacturer.
- caleb-allen 3y ago
- j-pb 3y agoModern software is bad enough that I wouldn't be surprised if this is true, but the modern stock marked is also detached from reality enough, that I wouldn't be surprised if this was an attempt at market manipulation either.
- MichaelMug 3y agoI don't know what the catalyst for this was, but a lot of 20 years olds and younger seem to use the word hacked so casually. I read it all the time, "my insta was hacked", etc. I would really like to know if hacking is as common as it is reported rather than a successful phishing campaign, a simple issue of forgotten password or getting locked out of email, account ban for rule violation, or something else entirely unrelated to actual hacking. In this case my skepticism skyrocketed when the hackers write "we are in control".
- whycome 3y agoThere's this site that provides news for these "hackers" and I'm not convinced any of them actually do any hacking.
- Dalewyn 3y agoHack in popular tongue has always meant authentication breaches in general, the method is not important. It's been this way for as long as internet has been a household word.
- caskstrength 3y ago> I don't know what the catalyst for this was, but a lot of 20 years olds and younger seem to use the word hacked so casually. It is a mechanism of shifting responsibility. If your password is "1234" and you gave it away to a totally legit MS support center employee that called you recently because MS has detected that your iPhone has a virus, then it is on you. But if North Korean hackers compromised your watch via elaborate hacking campaign to mine bitcoin on it, then it is "not your fault".
- TheAceOfHearts 3y agoFirst of all, why would anyone even care about you enough to want to steal whatever health data is available? Is there any particularly sensitive personal info stored there? Second, presumably if one gains access to the device through a sophisticated hack they'd probably also be able to exfiltrate data without having to alert the user. With all of that being said, I wish there was some sort of black box mechanism for logging certain events in such a way that the device itself can't tamper with it. That way you'd have a log that can be easily analyzed to judge whether or not a hack is likely to have taken place. Right now if you open the syslog on an Apple device it's filled with so much crap that it's basically impossible to detect if anything nefarious was likely to be happening.
- kfreds 3y ago> .. I wish there was some sort of black box mechanism for logging certain events in such a way that the device itself can't tamper with it.. This is called an append-only log. It can be built in many ways. Which way is suitable largely depends on the security requirements. My personal favorite kind of append-only logging is transparency logging. If you'd like to learn more you can check out e.g. sigsum.org, an open-source project my colleagues and I have been working on for several years now.
- saagarjha 3y agoI just looked through what Health stores and it has fields for your lab test results and sexual history. Seems fairly sensitive?
- yreg 3y ago> First of all, why would anyone even care about you enough to want to steal whatever health data is available? Is there any particularly sensitive personal info stored there? This is a strange argument. Of course there can be sensitive data there. Photos, (i)Messages, eMail, calendar events, addressbook, health data, voice recordings, location data. The device is password-protected for a reason. It is also usually connected to a paired iPhone and to the Internet. You might be able to do some shady stuff with the phone using private APIs.
- nocsi 3y agoThere’s a feature to use your iPhone to do keyboard input on an Apple Watch. Could it be that? Don’t tell me Apple left out some authentication. I know you can do something similar with text input when you’re on the same network as an Apple TV and someone’s inputting text. It’ll prompt on your iPhone to submit keyboard input.
- deleted 3y ago[deleted]
- rockbruno 3y agoOne of the posters posted a video of the problem: https://www.youtube.com/watch?v=G6dazJk9AtU https://www.youtube.com/watch?v=G6dazJk9AtU It seems like the ghost touch issue, and not actual hacking.
- veunes 3y agoThis is a very frustrating issue, as it can make it difficult to use the watch...
- pflenker 3y agoTyping „we are in control“ would go beyond the ghost touch issue, if we believe the first reporter.
- nneonneo 3y agoI am inclined to believe that the first reporter only thinks they saw this, not that it actually occurred (or they saw some random words appear on the keyboard that resembled this phrase).
- pflenker 3y ago„Popping up a keyboard“ as the user described is also not something trivially possible on the watch. That raised a red(ish) flag for me.
- justsomehnguy 3y agoAnyone who worked with users would tell you stories about the stories the users tell to support about how they "didn't do anything at all, didn't touch it and now everything is gone! it's your fault!" By the way, yesterday my Apple Watch 2 popped up a keyboard and wrote "pflenker is leichtgläubigertyp!" can you believe it?!
- teekert 3y agoCongrats you were selected voor LLM Siri testing! There may still be some issues…
- methou 3y agoI had exactly the same problem last week. Random touch & drags on the watch, it took me some effort to shutdown the watch without making an accidental emergency call. Given apple's security track of record and the fact that I pose no value as a target for the such an hacking effort. I deducted that it just was ghost touch.
- saos 3y agoHas anyone noticed such behaviour for iPhone lately?
- a9ex 3y agoI had a similar issue with my Apple Watch a couple weeks back. It would randomly input touches without me interacting with the display at all. I restarted it and the issue was gone - I doubt there was any hacking involved.
- meindnoch 3y ago"Everybody having similar issues should report that directly to Apple by using the Feedback link." Ahahahahahahaha. This must be satire!
- CodeNest 3y ago[flagged]
- BSDobelix 3y agoThis whole thread is filled with terrible advice and wannabe Snow-Crash writers, plus people who think "hackers" are scrolling through your files just to get to your fitness files. I am kind of shocked, that state of mind was acceptable around 95-2000, but not a quarter millennium later. I for sure live i a bubble, but are people really like that?
- herbst 3y agoThe apple forum really is a special place. Stuck in time, weirdly toxic and surprisingly unhelpful.
- jeroenhd 3y agoI've only had to browse it for information a few times, but it really is shockingly useless. I've never found an actual answer on those forums. Even Google's practically useless forums have helpful users who suggest workarounds between the hundreds of "I have the same problem" comments. Microsofd's near-useless forums have some good information if the thread doesn't die once a Certified Super Microsoft Systems Engineer tells you to reinstall Windows (because that seems to be all they can come up with). But for some reason, Apple's forums are somehow worse. Maybe it's because of Apple targeting a more tech-averse audience, I don't know, but when it comes to Apple's forums, nobody has any real answers.
- herbst 3y agoI think a lot of it has to do with there often not being actual answers as most of the system is hidden from the user anyway. But I have had the exact same experience. Up to really hostile behaviour and suggestions to reinstall from scratch. (I didn't know I need to start 'code' to agree to a license to update the c compiler, absolutely new to the OS coming from Linux and stuck for nearly a day) got plenty of feedback in a short time but most were along 'go back to windows' or 'did you try [obscure third party tool]', literally none actually helpful. Could be bad question asking, or just unlucky experience but it stuck to me. I rather get ignored in Microsoft forums or semi angry 'where are your complete logs!?!1' in the Linux forums.
- emsy 3y agoI know a person who reported something similar (saying his PS4 got hacked and was under control). Turns out he had paranoid delusions.
- herbst 3y agoIf this is actually a bug as most of you think. It's likely a hardware bug and all these devices are kinda faulty? Isn't that the real news here. If it's an hardware issue with touch it just means that no software patch can actually fix it enough to not waste battery in future. And that there is a realistic change that the issue gets worse when the devices get older.
- rf15 3y agoI think the "We are in control" thing is a dead giveaway that this is fake. Communicating with the victim might be essential to get access, but afterwards it's just about extracting whatever you need as fast as possible in my understanding.
- rock_artist 3y agoBased on others comments, and the fact it's only Ultras 2 and series 9 is it hacking or ghosting issue? https://www.macrumors.com/2024/02/10/apple-watch-series-9-ultra-2-touch-screen-issue/ https://www.macrumors.com/2024/02/10/apple-watch-series-9-ul...
- veunes 3y agoApple has a strong security track record, and its devices are generally considered to be more secure than other brands. However, no device is completely immune to hacking... This is the first time i've heard about Apple Watch hack
- MissTake 3y agoThis has nothing to do with hacking and everything to do with the ghost touch issues that apparently affect multiple Series 9 and Ultra 2 users (although I’ve not seen it on my series 9 myself). Way back in the early days of Android (pre Ice Cream Sandwich), I spoke to one co-worker who told me that when they looked at their Google Map app while driving it would show their actual physical car (and all the other surrounding vehicles etc.) on the satellite view - in motion - in real time. No manner of attempts by me to state why this was impossible would dissuade them and they went away thinking I was the technical idiot as a result. So “we are in control”? Yeah, no. This is what happens when folk think that shows like NCIS and their ilk are factual based docudramas. Obligatory link: https://m.youtube.com/watch?t=14&v=u8qgehH3kEQ&feature=youtu.be https://m.youtube.com/watch?t=14&v=u8qgehH3kEQ&feature=youtu...
- melomac 3y agoThis looks very much like the accessibility feature “Control Watch with iPhone” when AssistiveTouch color is set to Grey in the Watch accessibility settings… https://support.apple.com/en-my/guide/watch/apd890848603/watchos https://support.apple.com/en-my/guide/watch/apd890848603/wat...
- deleted 3y ago[deleted]
- layer8 3y agoThus is very likely the screen ghosting issue that Apple is currently investigating: https://www.macrumors.com/2024/02/13/apple-watch-false-touches-issue/ https://www.macrumors.com/2024/02/13/apple-watch-false-touch...
- TrevorMaynard 3y ago[dead]
- deleted 3y ago[deleted]
- jmull 3y agoMy clever idea to explain this is: It's a factory test script is getting triggered on the watch somehow. It would normally be run near the end of the manufacturing process to ensure everything is working as expected. It automatically runs through a series of steps hitting a wide swath of watch functionality and would look a lot like someone rifling through a watch remotely. But a persons watch wouldn't have test data or factory password, so the script soon ends up getting the watch locked (or maybe that's just part of the test). It could even conceivably type the message "We are in control" (though I have my doubts about that part of the story), because, as those of us who know some hardware verification folks, that's right where their sense of humor is.
- nullstyle 3y agoThis happened to my watch; it was not a fun day at all. Not sure if it was a glitch or a hack but it was very disconcerting and I did a full factory reset, re-pair and a different passcode.
- dagmx 3y agoI believe it may be the ghost touch issue like others mention, but with the addition that watchOS 10.3 dropped a week or two prior to these reports. Possible it tried to do something about the ghost touch and made it worse in a subset of devices. That feels more likely than a bunch of random people all being targeted with no other commonality like region or status
- someonehere 3y agoAll the people claiming this happened are level 1 posters so I’d take it with a grain of salt at this point.
- deleted 3y ago[deleted]
- davidhariri 3y agoThis is likely related? https://www.macrumors.com/2024/02/10/apple-watch-series-9-ultra-2-touch-screen-issue/ https://www.macrumors.com/2024/02/10/apple-watch-series-9-ul... Edit: A hardware issue that appears like a remote take over?