mysk_co Profile Banner
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ Profile
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ

@mysk_co

Followers
16K
Following
4K
Media
1K
Statuses
5K

We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 🎬 https://t.co/JGKIHaSEgs πŸ“https://t.co/69k7WAGSBT πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ

Canada - Germany
Joined November 2010
Don't wanna be here? Send us removal request.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🚨 NEW: Private Wi-Fi addresses had been useless ever since they were introduced in iOS 14. When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network. In these requests, iOS sends the device's real Wi-Fi MAC address. 🎬 Watch the
Tweet media one
Tweet media two
Tweet media three
15
60
303
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
We confirm that iOS 16 does communicate with Apple services outside an active VPN tunnel. Worse, it leaks DNS requests. #Apple services that escape the VPN connection include Health, Maps, Wallet. We used @ProtonVPN and #Wireshark. Details in the video:. #CyberSecurity #Privacy
434
6K
20K
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment:. - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app).- I ran the script in the Terminal and
Tweet media one
135
509
3K
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on. The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
108
1K
3K
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
iOS 16.5.1 still bypasses the VPN. New tests show that Apple Push Notification traffic completely ignores the VPN connection. Apple Maps sends many requests outside the VPN, including unencrypted DNS requests. This also happens in the Lockdown Mode. 🎬.
Tweet media one
39
365
1K
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🚨 New Findings:.🧡 1/6.Apple’s analytics data include an ID called β€œdsId”. We were able to verify that β€œdsId” is the β€œDirectory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you πŸ‘‡
Tweet media one
Tweet media two
Tweet media three
Tweet media four
54
512
1K
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
Hey @elonmusk, will 𝕏 publish the algorithm that determines which replies are most relevant? The Algorithm's repository on Github hasn't been updated since last year. Thank you!
Tweet media one
Tweet media two
21
37
530
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
I know what you're asking yourself and the answer is YES. #Android communicates with #Google services outside an active VPN connection, even with the options "Always-on" and "Block Connections without VPN.".I used a #Pixel phone running #Android13, its IP is 192.168.2.14 πŸ‘‡
Tweet media one
Tweet media two
32
222
886
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
10 months
Speaking of outdated, @MicrosoftEdge is the only browser on macOS that still requires administrative privileges to install. 🫠
Tweet media one
@MicrosoftEdge
Microsoft Edge
10 months
You. Yes, you. It's time to leave that outdated browser 🫡.
19
50
876
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🚨PSA: iOS 17 turns these sensitive location options back on. If you have disabled significant locations as well as adding your location information to your iPhone analytics before upgrading to iOS 17, iOS 17 will turn the options on as shown in the screenshot. While significant
Tweet media one
71
346
821
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 months
Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entriesβ€”a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :
22
80
859
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
iPhone storage is encrypted with the iPhone's passcode. Based on iOS security model, it's impossible to recover data after a factory reset. If this bug is proven to be true, the entire iOS security model is at risk.
23
65
743
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🧡.1/5.The recent changes that Apple has made to App Store ads should raise many #privacy concerns. It seems that the #AppStore app on iOS 14.6 sends every tap you make in the app to Apple.πŸ‘‡This data is sent in one request: (data usage & personalized ads are off).#CyberSecurity
38
299
708
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
You can easily monitor the network traffic of any device using this simple method. You don't need a custom router for that. You just need a Mac and #Wireshark, and enjoy ✌️.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
At Mysk we use this simple method to monitor the network activity of a device:.β–ΊConnect your Mac to the internet via LAN.β–ΊShare the internet from LAN to Wi-Fi.β–ΊConnect the device to this Wi-Fi.β–ΊStart #Wireshark on your Mac and pick brdige100.β–ΊStart capturing. #SecurityTips
Tweet media one
Tweet media two
Tweet media three
14
73
629
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
8 months
WhatsApp messages are end-to-end encrypted, but user data is not only about messages. That also includes the metadata such as user location, which contacts the user is communicating with, the patterns of when the user is online, etc. This metadata according to your privacy policy
Tweet media one
@wcathcart
Will Cathcart
8 months
Many have said this already, but worth repeating: this is not correct. We take security seriously and that's why we end-to-end encrypt your messages. They don't get sent to us every night or exported to us. If you do want to backup your messages, you can use your cloud provider.
34
114
637
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
This is the folder structure of Signal's local data on macOS. The encrypted database and encryption key are stored next to each other. The folder is accessible to any app running on the Mac. How could such a blunder be approved by an open-source project reviewed by many experts?
Tweet media one
Tweet media two
Tweet media three
35
107
628
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Our recent encounter with Signal has revealed a new face of Signal as a project and team; one of exclusion, dismissal, and denial. We can no longer recommend Signal as a secure chat app. And we will no longer review, report, or disclose any security bugs related to Signal.
40
79
595
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
It's official. iOS will not support Progressive Web Apps in the EU. It would be great if Apple provides the basis of this claim:. "We expect this change to affect a small number of users"
Tweet media one
62
113
566
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
5 months
The top two grossing apps in the Utilities category on the Brazilian App Store are VPN apps:
Tweet media one
10
33
514
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
This video shows that @signalapp (7.15.0) on macOS stores photos and docs sent through the app locally without encryption. Worse, the files are stored in a location accessible by any app or script. However, text messages are stored locally in an encrypted DB. #privacy #security
35
110
501
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
@mer__edith Hi Meredith, let me address your points:. 1) The issue we highlighted does not require β€œfull” access to the device. Signal desktop stores the chat database in an unprotected area of the file system that’s accessible by any user process. This would allow any program without any.
16
41
435
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
The community note is wrong and @elonmusk is right. Signal's desktop apps encrypt local chat history with a key stored in plain text and made accessible to any process. This leaves users vulnerable to exfiltration. The issue was reported in 2018, but it hasn't been addressedπŸ‘‡.
@elonmusk
Elon Musk
9 months
@realchrisrufo There are known vulnerabilities with Signal that are not being addressed. Seems odd ….
19
55
445
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 months
This is an example of what the App Store app shares with #Apple when you search for an app. Everything you type in the search field is recorded as an event and associated with your Apple ID before it is sent to Apple. When I search for "Google Authenticator," events are recorded
Tweet media one
Tweet media two
Tweet media three
Tweet media four
23
83
419
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
The community note is inaccurate. The claim "Find My is end-to-end encrypted" generally is misleading. Online devices report their location to Apple without end-to-end encryption even with Advanced Data Protection is on. This makes it possible to look up a device’s location
Tweet media one
@TimSweeneyEpic
Tim Sweeney
6 months
@9to5mac @benlovejoy This feature is super creepy surveillance tech and shouldn’t exist. Years ago, a kid stole a Mac laptop out of my car. Years later, I was checking out Find My and it showed a map with the house where the kid who stole my Mac lived. WTF Apple? How is that okay?!.
16
76
364
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
It seems it's not allowed to criticize Signal on Reddit. This is the second post that gets removed by the moderators. Users in the comments make wrong claims that physical access is required, others claim that full disk access is required. This is wrong. If you really have the
Tweet media one
Tweet media two
Tweet media three
31
54
400
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
11 months
Apple decided to remove PWAs, then walked back the decision. Apple terminated Epic Games developer account, now they walked back the decision. What's going on with Apple?."Trust is built in drops and lost in buckets". How many buckets has Apple lost so far?.
@EpicNewsroom
Epic Games Newsroom
11 months
Update - Apple has told us and committed to the European Commission that they will reinstate our developer account. We are moving forward as planned to launch the Epic Games Store and bring Fortnite back to iOS in Europe. More below⬇️.
20
52
384
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
8 months
On Android, several Google services bypass an active VPN connection. As a result, a VPN connection won't hide your IP address from Google. And since YouTube is a first-party app on Android, it will get your real IP address and roughly determine your location despite using a VPN.
@AndroidAuth
Android Authority
8 months
YouTube confirms crackdown on VPN-based cheaper Premium subscriptions
13
126
376
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
Well it would be nice to get a little more detail on that β€œdatabase corruption” issue, wouldn’t it?.
@zollotech
Aaron Zollo
9 months
iOS 17.5.1 is out. Video later…
Tweet media one
17
24
361
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 months
In iOS 18.2, EU users will be able to delete the App Store app. You get a warning message before deleting the app. You can re-install the app from the Settings app. A similar but shorter warning message is also shown when deleting an alternative marketplace app. #iOS #DMA #EU
Tweet media one
Tweet media two
Tweet media three
13
37
369
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
The security bug about storing the encryption key in plain text wasn't considered a bug by Signal in 2018, wasn't considered a bug by Signal's president today, and even demanded responsible disclosure for it. Well, that not bug thing is getting a fix now:.
27
46
341
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
On macOS, iMessage stores the chat history locally in plain text, but the data is sandboxed and no other process can access it without permission. @Whatsapp also stores the local history in plain text but stores the data in a location accessible by any process/app/script started.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
So does @WhatsApp and @Apple iMessage, and likely many other apps. Open a terminal on a Mac and check:. strings ~/Library/Group\ Containers/group.net.whatsapp.WhatsApp.shared/ChatStorage.sqlite. strings ~/Library/Messages/chat.db.
11
45
339
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🧡 .1/6. Apple's Data & Privacy statement starts with the calming phrase "Apple believes privacy is a fundamental human right" then goes on to describe how the platform aggressively collects your data. You must accept the statement or stop using your iPhone. #CyberSecurity
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
116
324
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
πŸ”” Soon after we published our findings about the App Store collecting exhaustive and identifiable usage data, we were approached by law enforcement in the U.S. to help them navigate through the usage data they obtained from Apple for a suspect. They presented a court order to
Tweet media one
Tweet media two
8
63
320
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Apparently reporting on actual longstanding security issues in Signal is considered right-wing πŸ€·β€β™‚οΈ. Plus, they will fix the issue, which is good for everybody.
@Gizmodo
Gizmodo
7 months
A sudden flood of right-wing attention has pushed Signal to close a vulnerability in its desktop app.
16
34
309
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
BREAKING: The EU Commission designates iPadOS as a gatekeeper under the Digital Market App. Apple will have to allow alternative marketplaces on the iPad too.
4
57
308
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
5 months
Just realized that the Passwords app communicates with 147 websites. It turns out the app calls every website of your added accounts to download its icon. The request has this user-agent:.User-Agent: Passwords/8619.1.26.30.5 CFNetwork/1568.100.1 Darwin/24.0.0. #iOS18
Tweet media one
Tweet media two
Tweet media three
19
26
302
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🧡.The App Store on #macOS 13.2 sends detailed usage data and analytics to Apple. All interactions are associated with the user's iCloud ID, or dsid. This happens even when you turn off sharing usage data and analytics. (1/6) πŸ‘‡.#Privacy #InfoSec
Tweet media one
Tweet media two
7
84
293
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
Holy moly!.iPhone users in the EU: DO NOT delete your alternative marketplace apps. iOS 17.5 breaks alternative marketplace app re-installation. MarketplaceKit now generates a different client_id every time it is called. Now there's no way for alternative marketplace developers
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
50
291
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Apple blocked Spotify's update for including a button that emailed a link for purchasing audiobooks. Amazon is doing exactly the same. If you tap on the "I Want This Book" button in the #iOS app, you get a link to purchase the book outside the app. Apple Review Team approved it.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
41
269
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
🚨@signalapp on its website presents both mobile and desktop versions to be equally secure. As we showed, the desktop versions are vulnerable to data exfiltration and session hijacking. This is consistent with early reports from 2018 and results from developers who successfully.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment:. - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app).- I ran the script in the Terminal and
Tweet media one
12
39
271
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
Signal for desktop has been updated twice since we reiterated the known security issues related to storing the database encryption key and media attachments in plaintext, and in a location accessible to any process. None of the release notes mention this issue. The privacy chat
Tweet media one
Tweet media two
10
50
274
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
To the unknown future dissident, activist, or freedom seeker whose life will be saved as a result of the enhanced security added to Signal Desktop: You're welcome.
@BleepinComputer
BleepingComputer
7 months
Signal is finally tightening its desktop client's security by changing how it stores plain text encryption keys for the data store after downplaying the issue since 2018.
14
28
262
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🚨🎬 Privacy Concerns about Apple Push Notifications. TL;DR: data-hungry apps use push notifications as a trigger to send app analytics and device information to their remote servers, even if the apps aren't running at all on your iPhone. Such apps include TikTok, Facebook, FB
12
86
257
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
3 years
Dear #Android users,.Chrome shares your motion sensor with all the websites you visit by default. This video shows how you can disable it. Please do it now. You can learn more about this here:. #CyberSecurity #Privacy
18
197
243
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
At Mysk we use this simple method to monitor the network activity of a device:.β–ΊConnect your Mac to the internet via LAN.β–ΊShare the internet from LAN to Wi-Fi.β–ΊConnect the device to this Wi-Fi.β–ΊStart #Wireshark on your Mac and pick brdige100.β–ΊStart capturing. #SecurityTips
Tweet media one
Tweet media two
Tweet media three
9
45
245
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
Still don't understand why Safari does this? It happens on iOS too. Any explanation?
25
4
248
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
As @PrivacyMatters speculated, Authy sends too much analytics for an authenticator app. It associates analytics with the user's ID, which is tied to phone number and email. The analytics include the issuer name of each scanned QR code. Try to use a different #2FA app. #Privacy
Tweet media one
Tweet media two
Tweet media three
24
56
244
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Signal's message is clear: end-to-end encryption is only about protecting the transmission of chat messages, not protecting the local chat history stored on device. This message is toxic and has a huge impact on our #privacy. @UKZak explains that very well:
Tweet media one
11
54
226
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Philips Hue will soon force users to create a Hue account and sign in to continue to use the app and control the smart lights. The best security model to protect smart devices is to keep them disconnected from the internet, or at least keep this option available. #Privacy
Tweet media one
23
41
219
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
An open-source project should embrace an open mindset. Signal has positioned itself as the "secure" communication tool for users in troubled parts of the world. A fix should be pushed forward to make the app more secure for its users, not because a call for the fix "is getting
Tweet media one
10
23
195
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
A lot of accounts promote crypto scams on X and they hardly get suspended. And now this:. @ProtonWallet
Tweet media one
18
22
204
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
8 months
@VeraJourova The draft mandates providers to perform human oversight of content sent over a private and end-to-end encrypted channel so that they detect false positives. How would employees view such content without breaking encryption and invading one's privacy?
Tweet media one
Tweet media two
2
12
200
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
This screenshot shows the app analytics data sent by two different iOS apps: @duolingo and @Tinder. What's the likelihood that both apps are installed on the same device? πŸ’―? 🀯. Both apps use @unity Ads. The data in the screenshot is collected by the Unity Ads framework included
Tweet media one
12
72
204
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Just detected a call made by my iPhone seemingly sending my iOS keyboard data to an iCloud server. The domain name icloud-content[.]com is owned by Apple but not the one normally used for syncing iCloud data. The 316 KB of keyboard data is marked as "UserWords". The data is
Tweet media one
Tweet media two
21
42
200
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Signal has positioned itself as the secure communication tool that activists and users in troubled regions can trust. In 2021, Signal introduced simple TLS proxy to bypass government censorship. In 2018, Signal knew that their desktop app had security issues regarding protecting
Tweet media one
Tweet media two
Tweet media three
14
28
198
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
It's May 1. Instagram for iOS just got updated. It still sends the device's system uptime to remote servers. Starting today developers are no longer allowed to access this API without providing a reason. And in no way can the app send the value off-device. #Privacy
Tweet media one
Tweet media two
5
28
195
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
3 months
Sorry Signal and WhatsApp, you're not getting full access to my contacts. Stop begging. Be grateful you have access to a dummy contact. Both apps now check for the new #iOS18 authorization status "limited" and complain if the user authorizes access to some contacts only.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
11
15
204
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🎬 The App Store will continue to be the only place to install apps on the iPhone, even in the EU. Users should be aware that the App Store collects exhaustive usage data and sends it to #Apple. This can't be turned off. We made this video to show how tapping an app link gets.
4
48
187
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
You need to be careful when you search for an authenticator app. This app sends the scanned QR codes to the developer's #Google analytics service. You won't miss it. It's running an ad campaign on the #AppStore. #Privacy #CyberSecurity #2FA
Tweet media one
Tweet media two
Tweet media three
Tweet media four
15
58
179
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
9 months
Nice! @brave for iOS just got updated to support the new "marketplace-kit" scheme. Brave only calls the scheme when trackers blocking is disabled. As we reported earlier, Apple implemented the new scheme in a way that allows tracking across websites based on the unique client_id.
Tweet media one
Tweet media two
Tweet media three
5
29
187
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
BREAKING: The App Store has taken down the scam #2FA app that steals secrets. We warned about this app four months ago. This wouldn't have happened without your support to spread the word. Thank you! πŸ™πŸ™βœŒοΈ
Tweet media one
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🎬 So this scam #2FA app is using custom product pages of Apple Search Ads to trick users. It has different campaigns per search keywords. When searching for "Microsoft Authenticator", it shows screenshots highlighting "Microsoft". and when searching for "Google Authenticator",
Tweet media one
Tweet media two
12
30
182
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
The title should be clearer. Apple didn't do this willingly. This is a more accurate title:. "EU Regulators finally force Apple to allow Spotify to show pricing info to EU users on iOS"
Tweet media one
@TechCrunch
TechCrunch
6 months
Apple finally allows Spotify to show pricing info to EU users on iOS
5
23
187
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
More context:.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
This video shows that @signalapp (7.15.0) on macOS stores photos and docs sent through the app locally without encryption. Worse, the files are stored in a location accessible by any app or script. However, text messages are stored locally in an encrypted DB. #privacy #security
6
10
185
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
🧡.1/7.During our research on link previews, we discovered that Instagram servers execute #JS code in links sent in DM. We contacted Facebook security team. They said it was expected behavior, no issue. We published the work. @TeamYouTube took down the video and sent us a warning
Tweet media one
Tweet media two
10
65
184
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
This old thread by @signalapp's president addresses a report by johnjhacking about the same desktop app vulnerability we highlighted. The response downplays the risks on the basis that the level of access required to hijack a session is "only available if the device is already.
@mer__edith
Meredith Whittaker
2 years
The report by johnjhacking is confused. What they propose requires a level of access that's only available if the device is already completely compromised: β€œFirst and foremost, you need access to the device.” TLDR someone compromising your device is not a problem with Signal. 1/.
14
26
185
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Just got the "ad free" subscription of Prime Video in the iOS app and paid with my credit card directly to Amazon. I didn't see an option to pay with the App Store's in-app purchase, neither did I see a "scare screen.".Digital content? Yes. Can other apps do this? 🫠
Tweet media one
Tweet media two
7
12
180
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
11 months
Google Authenticator still syncs two-factor authentication secrets without E2EE. If you enable cloud syncing, this means:.1️⃣ Google can read the secrets and generate one-time passwords for your accounts.2️⃣ Google knows the services you use.3️⃣ #Google knows your usernames.#Privacy.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on. The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
10
65
178
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
Apple "pressures" ByteDance and Tencent, but immediately suspended Epic Games' Apple Developer account and removed their apps from the App Store.
@MacRumors
MacRumors.com
6 months
Apple Pressures ByteDance and Tencent Over App Fee Loopholes in China
10
16
177
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 month
We’ve been a little quiet recently, and not just because it’s the holiday season πŸŽ„β„οΈ. Over the last several months we’ve been working on a brand new privacy-focused app for iOS. We plan on launching this app soon and we can’t wait to share more details with you.
13
7
180
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 month
It still doesn't sound right that a password manager app communicates with 130 different websites (for downloading icons). That's more than X on my device 🀯. Thanks to our report, all these connections now use HTTPS, but 130. 😩
Tweet media one
17
17
180
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Thank you @Apple! We were rewarded a bounty of $5,000 for reporting this bug. πŸ™. CVE-2023-42846.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🚨 NEW: Private Wi-Fi addresses had been useless ever since they were introduced in iOS 14. When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network. In these requests, iOS sends the device's real Wi-Fi MAC address. 🎬 Watch the
Tweet media one
Tweet media two
Tweet media three
16
14
177
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
6/6.It is worth noting that the DSID is also sent by other Apple apps for analytics purposes. You just need to know three things:.1- The App Store sends detailed analytics about you to Apple.2- There's no way to stop it.3- Analytics data are directly linked to you.
8
39
163
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
This statement is from a court document submitted by Apple's lawyers regarding the App Store data privacy class action lawsuit:. "Given Apple’s extensive privacy disclosures, no reasonable user would expect that their actions in Apple’s apps would be private from Apple."
Tweet media one
9
53
167
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
The "Advanced Tracking and Fingerprinting Protection" introduced in Safari in iOS 17 leaks DNS queries to Apple DNS server. Users who rely on custom DNS to block malware domains will be unprotected. We reported this bug to Apple, but Apple says it is not an issue. In our
Tweet media one
Tweet media two
Tweet media three
Tweet media four
9
39
164
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
3 years
We prepared this video to illustrate why access to the accelerometer should get a permission in iOS. Unrestricted access to accelerometer data can breach user privacy. We used Facebook as an example in the video. #Cybersecurity #Privacy #iOS .
11
89
168
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
2/6.Apple states in their Device Analytics & Privacy statement that the collected data does not identify you personally. This is inaccurate. We also showed earlier that the #AppStore keeps sending detailed analytics to Apple even when sharing analytics is switched off.
Tweet media one
5
40
165
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
So does @WhatsApp and @Apple iMessage, and likely many other apps. Open a terminal on a Mac and check:. strings ~/Library/Group\ Containers/group.net.whatsapp.WhatsApp.shared/ChatStorage.sqlite. strings ~/Library/Messages/chat.db.
@MacRumors
MacRumors.com
7 months
ChatGPT Mac App Stored User Chats in Plain Text Prior to Latest Update
7
27
168
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
@PrivacyMatters @signalapp It's a known issue:.
2
7
171
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Many comments suggest that if you don't want Apple to collect this private data about you, don't buy an iPhone. Well, many users already bought iPhones based on Apple's privacy promises. What should they do?.Moreover, Apple has its own definition of the term "tracking" πŸ‘‡
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🎬 The App Store will continue to be the only place to install apps on the iPhone, even in the EU. Users should be aware that the App Store collects exhaustive usage data and sends it to #Apple. This can't be turned off. We made this video to show how tapping an app link gets.
11
35
161
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
3 months
Microsoft Defender marks emails from Microsoft as spam. Good job!
Tweet media one
12
14
164
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Many iOS users report losing their 2FA codes after updating their Google Authenticator app. Meanwhile, Android users took to Google Play reviews to complain about the lack of end-to-end encryption. #Google #2FA #Security #cybersecurity #InfoSec #iOS #Android
Tweet media one
Tweet media two
19
34
152
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
8 months
YES!! iOS 18 will let users decide which contacts an app can access. This is sad news for data harvesting apps such as LinkedIn. #iOS18 #WWDC #Privacy.
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
#iOS17 should stop apps from harvesting contact details when they have access to contacts and calendars. This video shows the data that LinkedIn syncs when it has access to contacts and calendars. 🀯.#WWDC23  #privacy #cybersecurity #cybersecuritytips.
6
18
155
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
First thoughts on having the opportunity to install apps from various app stores on the iPhone: it feels right, fair, and independent. Every iPhone user, not just those in the EU, should have that option.
Tweet media one
4
16
151
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
When you view the tweet below by @signalapp on an iPhone, you'll see a card showing the Signal app with a button to install the app. If you tap on the button, a sheet is presented within the Twitter app showing more details about Signal. Even though the sheet is presented inside
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@signalapp
Signal
2 years
Announcement! Signal is refreshing our board as we grow. We’re delighted to welcome @krmaher, @ambaonadventure, and @jaysullivan as Signal’s new Directors. Learn more here:
13
37
152
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Signal now addresses vulnerabilities that have been known since 2018. Two CVEs were filed in this regard in 2023: CVE-2023-24068 & CVE-2023-24069.This proves the community note on @elonmusk' post wrong. Now do the right thing and vote against it. Thank you πŸ™βœŒοΈ.More links below:.
@elonmusk
Elon Musk
9 months
@realchrisrufo There are known vulnerabilities with Signal that are not being addressed. Seems odd ….
7
28
153
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
Again, iOS 17.0.3 changed my privacy settings and turned these settings on:.Significant Locations.iPhone Analytics.HomeKit and more 🀬. Check your iPhones before and after the upgrade and let us know πŸ™. Settings -> Privacy & Security-> Location Services-> System Services
Tweet media one
Tweet media two
29
29
152
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Update: The Lockdown Mode leaks more traffic outside the VPN tunnel than the "normal" mode. It also sends push notification traffic outside the VPN tunnel. This is weird for an extreme protection mode. Here is a screenshot of the traffic (VPN and Kill Switch enabled) #iOS
Tweet media one
6
32
145
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
Many iPhone users are asking us to recommend safe authenticator apps. Well, the @AppStore is making it useless to recommend any app. No matter what you search for, the top hit is almost always an ad for a scam app. #Apple #AppStore #2FA
Tweet media one
Tweet media two
Tweet media three
Tweet media four
12
31
147
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
The definition of app sideloading:. #Apple v #Google
Tweet media one
Tweet media two
2
20
149
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🚨🎬.Here is what happens when you insert an unlocked SIM card into a locked iPhone:. - The #iPhone accepts the SIM card and connects to the internet 😳.- Apple immediately adds the phone number of the SIM card to the Apple ID of the iPhone owner 😲.- Apple accepts the new phone
Tweet media one
12
33
149
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6 months
As we reported earlier, if a bad actor inserts a SIM card into a locked iPhone, the phone number of the SIM card will immediately be associated with the iPhone's Apple ID and iMessage while the iPhone is locked. Although we couldn't find a scenario to exploit this, we just find.
4
34
149
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
10 days
A new mysterious location permission option has been added in iOS 18.2: .Privacy & Security ➑️ Location Services ➑️ System Services ➑️ "In-App Web Browsing".It's on by default. Still figuring out what it's for πŸ€”.#Apple #Privacy
Tweet media one
Tweet media two
11
17
174
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
@hugelgupf @Apple Order an iPhone or iPad. Sign in to your iCloud account, accept the new terms, reset the device, and then send the device back to Apple. You can always return items purchased from Apple within 2 weeks. It's not good for the environment, but it should work.
11
4
142
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
✌️.
@9to5mac
9to5Mac
7 months
Signal encryption key vulnerability being fixed on Mac (and less fully on Windows) by @benlovejoy.
9
10
138
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
A few remarks about the #CrowdStrike outage:. ➑️ A broken update rolled out to customers without sufficient testing. The bug is clearly so easily reproducible. ➑️ The update was released on Friday. Not a great sign. ➑️ A staged rollout would’ve avoided most of the damage.
5
16
143
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
1 year
🎬 Finally, iOS treats all browsers equally when it comes to PWAs. Previously, only Safari was able to install and run PWA apps. With iOS 17.4 beta in the EU, no browser can install PWA apps, even Safari. It seems PWAs have been disabled entirely. Oh yes, when you set a
22
29
134
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
7 months
Back in the day, the rules to obtain the blue checks were absolutely arbitrary. Those who had "friends" at Twitter got it easily. Also Twitter employees allegedly sold the blue checks. Verified accounts used to have a clear advantage over unverified accounts. There was no clear.
@ThierryBreton
Thierry Breton
7 months
Back in the day, #BlueChecks used to mean trustworthy sources of informationβœ”οΈπŸ¦. Now with X, our preliminary view is that:. ❌They deceive users. ❌They infrige #DSA. X has now the right of defence β€”but if our view is confirmed we will impose fines & require significant changes.
Tweet media one
8
15
145
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
11 months
If you leave the EU for "too long," you won't be able to update apps installed from alternative app marketplaces. This is not the case for the App Store. A German account can install apps and purchase content from the German App Store even if you're gone for "too long"
Tweet media one
13
24
134
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
@narenkram @ProtonVPN 🀣🀣. You caught me. I'm doing it right now πŸ˜‚.
1
2
130
@mysk_co
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
2 years
3/6.Apple uses DSID to uniquely identify Apple ID accounts. DSID is associated with your name, email, and any data in your iCloud account. This is a screenshot of an API call to iCloud, and DSID it can be clearly seen alongside a user's personal data:
Tweet media one
Tweet media two
1
22
133