Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
willstrafach
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
20 ms
·
61.
▲
by
willstrafach
8y ago
> They're not down and this definitely doesn't compromise the encryption that protects any login credentials That is precisely what it does. Serving an invalid certificate and requiring user click-through allows for a man in th
62.
▲
by
willstrafach
8y ago
If you have this level of distrust, why use their service and expose your IP address to it? At that point, better to set up your own server.
63.
▲
by
willstrafach
8y ago
Unless it was over WhatsApp.
64.
▲
by
willstrafach
8y ago
> There is a finite amount of code on the system. That code would also include any functions related to stenography or remote activation and could be easily called out. Hint: You do not need to manually, personally, audit every single li
65.
▲
by
willstrafach
8y ago
Your comment contains an insult with no additional substance to back up the claim.
66.
▲
by
willstrafach
8y ago
There is a finite amount of code on the system. That code would also include any functions related to stenography or remote activation and could be easily called out. However, do not exist in iOS. Anything can happen in the future, and thos
67.
▲
by
willstrafach
8y ago
You can sniff the network traffic.
68.
▲
by
willstrafach
8y ago
Untrue. You can sniff outgoing connections and reverse engineer whatever you’d like (I sure have and am glad to have a full understanding of everything going out).
69.
▲
by
willstrafach
8y ago
Usually “None” is an available option for payment method. This does depend on your region though.
70.
▲
by
willstrafach
8y ago
This data is on-device precisely to avoid the usual route of uploading it to the cloud. None of that is uploaded to Apple.
71.
▲
by
willstrafach
8y ago
> 3.) It can only see IMSIs when a phone first connects. I don't think the IMSI is sent when making a call or transferring data. I believe this is correct, in fact (someone please correct me if I've got this wrong?) it looks as
72.
▲
by
willstrafach
8y ago
This is Rx-only though, so the target device(s) cannot forced down to 2G.
73.
▲
by
willstrafach
8y ago
> timagine adtech companies starting a PR war against Apple's closed garden system, arbitrary app store decisions, labor conditions (I'm sure we can find some dirt somewhere in their vast business) to get laws enacted to regula
74.
▲
A new ‘smart firewall’ iPhone app promises to put your privacy before profits
(techcrunch.com)
1 points
by
willstrafach
8y ago
|
0 comments
75.
▲
by
willstrafach
8y ago
Time to wake up then. When you log in on this page, both temporary deactivation as well as true deletion are both also offered.
76.
▲
by
willstrafach
8y ago
The implant you describe sounds much like this: https://nsa.gov1.info/dni/nsa-ant-catalog/usb/FIREWALK.jpg
77.
▲
by
willstrafach
8y ago
This is incorrect.
78.
▲
by
willstrafach
8y ago
No, this was for a locked iPhone. They were after encrypted data-at-rest. Warantless surveillamce would not apply, as they had a warrant - I believe - seeing as they went after the iCloud data and said it was not helpful (No backup stored t
79.
▲
by
willstrafach
8y ago
My device is experiencing this strange problem as well. Glad to know it is not just me.
80.
▲
by
willstrafach
8y ago
This will be available in the future, but was deemed too complicated for most mainstream users. The initial default will be to simply offer a button called “Protect” and app handles all the rest.
81.
▲
by
willstrafach
8y ago
This will be a commercial service, in order to fund ongoing research efforts allowing us to quickly discover and block all possible forms of tracking, phishing, and other malicious traffic. That said, in the future, lists will be published
82.
▲
by
willstrafach
8y ago
Approving entitlements is exceptionally rare honestly. The only app I have found this happen with is Uber: https://www.businessinsider.com/uber-iphone-app-secret-acces...
83.
▲
by
willstrafach
8y ago
Not certain what you mean about the IP address, but for signing it, they would need to bundle a key and that could be extracted. It is a genuinely tricky challenge from their perspective.
84.
▲
by
willstrafach
8y ago
Do any of these companies at least take security seriously, considering the extreme sensitivity of the massive amounts of data they collect?
85.
▲
by
willstrafach
8y ago
I personally believe this is unlikely, because then the firms paying for this data will not be so sure that the information is legitimate, whereas collecting directly from user devices makes fraud more difficult.
86.
▲
by
willstrafach
8y ago
Respectfully, one goal of doing this research was to shine a light on those who are engaging in these practices, so that users who dislike it can potentially find alternatives. This is a good thing for any apps who do things right.
87.
▲
by
willstrafach
8y ago
For iOS, there will be: https://guardianapp.com Also, we will either provide a searchable app index, or freely share findings/info with parties such as Exodus (This has not been fully decided as of yet).
88.
▲
by
willstrafach
8y ago
To be somewhat fair in this case, the TC author got an advance copy of the reporting and data in order to get some company responses included, so I suppose there is a value-add in that respect.
89.
▲
by
willstrafach
8y ago
Anonymous tips accepted at hello@sudosecuritygroup.com
90.
▲
by
willstrafach
8y ago
> Niche startup idea, VPN for your mobile device that can analyze and block traffic. This is indeed what we (originators of this location tracking research) do.
More ›