“Facebook Research” was the Onavo codebase, under a different name, signed by Facebook’s Enterprise certificate.
HN user
willstrafach
information security and privacy research.
Chief Executive Officer @ Guardian (https://guardianapp.com).
previously: founder of "Chronic Dev Team" & worked on many years of iOS jailbreaking solutions (24kPwn, absinthe, corona, greenpois0n, etc).
iOS devices must be activated to use them. This is indeed stored in a database. AppleCare and third-party repair centers can query activation information using GSX.
You are correct about pre-T1 Intel Macs though. Apple will have a blind spot by design, until support is dropped for old machines.
That said, doesn’t iOS notify you when an app wants to use location services? Did all of these users just opt into that? That seems crazy, if so.
Not so crazy.
Local news, weather, and similar apps with a reasonable rationale for Location Services access are often the culprits.
They will put phrases like “See privacy policy.” in the justification text (When asking permission) so they can claim that the user consented.
They have some pretty bad past practices: https://www.zdnet.com/article/accuweather-caught-sending-geo...
And they have continued, off-and-on, to use other location-collecting SDKs.
I think the pitch here is “Semi-managed WireGuard peer provisioning and NAT punching as a service” usable by anyone who may not otherwise have a clue how WireGuard works (eg. friends sharing access to a file/media server), within 5 minutes or less from download/login to “done”
How would that work? Connections are mainly peer-to-peer with Tailscale. An attack (I suppose pushing new key pairs to specific peers and pointing them through a malicious endpoint?) would likely require a very noisy and detectable process.
This may make sense if they were replying via e-mail to the issue.
Different poster here but just curious: Are you a Deutsche Telekom user, by chance?
The face:b00c part is in the Interface ID, so this did not even need a large block (Though I am sure they have one).
In current versions? What permission is this?
.icu, .club, and a few other gTLDs can often be found for sale at $1-2/year, so they are used by entities in need of low cost disposable domains.
That is incorrect, Corellium does not ship Apple code.
If it had a T2, that will store the Apple ID.
1. You’re allowed to use IDFA. But users will now have to allow access, as a permission dialog will pop up first.
2. The IDFA is just a simple static UUID. It cannot do a very good job at preventing fraud. There is no way to validate anything about it or affirm that it ties to a genuine device.
Pager messages collected on September 11, 2001. They are also a type of communication which is transmitted without encryption.
The list can be found here: https://support.apple.com/en-us/HT210770
This one is well worth a try: https://www.amazon.com/Remote-Control-Alternative-Replacemen...
Do you have a source on Apple “killing IDFA”?
My understanding is that they are going to simply show a consent dialog before allowing an app to access the IDFA, similar to what they have done for years to access other sensitive data like Contacts, Location, etc.
This exists, though not exactly as you describe: https://en.wikipedia.org/wiki/ASmallWorld
There is nothing stopping someone for using this technique to publish an app in the AppStore officially.
It has not happened though. Only app which has been in the App Store and utilized private entitlements, from what I’ve seen anyway, has been Uber.
They would be caught if this was submitted to the App Store. This applies to self-signed apps by those with a developer certificate.
Not replace, rather, you boot Linux over USB. That is why they describe the ephemeral device use case.
Source code: https://github.com/corellium/projectsandcastle/
The backstory is also incredibly interesting: https://projectsandcastle.org/history
Specifically, I was asked about how Clearview can make their iOS app available again.
Important to note, our app is a VPN as well. This way, with the bulk of our business logic on the server-side, device battery is saved and we can do real-time block list updates rather than the app needing to pull down a new rule set.
The $1/day / $10/month / $100/year has been fairly well received, but may not be for everyone, especially those who enjoy running their own VPN server and/or curating their own block lists.
That's not the real licensing cost at all. The cloud and on-premise options are both available for substantially less.
Corellium heavily modifies iOS. Parallels and whatnot run unmodified Mac (not i)OS.
Not quite. The optional "modifications" are pretty much the small byte patches in the kernel and bootloader which are normally done in a jailbreak. It is similar to how "Parallels Tools" is automatically loaded; Not entirely required, but makes the experience better.
This test would not yield a useful result in this particular case, as the data is processed locally on-device and is not sent to a remote server.
Technically, that is the hardware product codenames (Closely tracking with AirPods it seems, B188 and B288)