8 ms·
Apple disables Walkie Talkie app due to eavesdropping vulnerability
- gbil 7y agoI prefer this verge link https://www.theverge.com/2019/7/11/20689983/apple-watch-walkie-talkie-bug-disabled https://www.theverge.com/2019/7/11/20689983/apple-watch-walk... as techcrunch privacy settings are yahoo driven and I was never able to manage them - not sure they really give you an option
- Nextgrid 7y agoThe EU should fine that company out of existence. Yahoo/Oath/whatever they’re called now is cancer.
- josteink 7y agoThanks for the alternate link. In general I think HN should consider just banning TechCrunch links verbatim. That would lead to people actually submitting stories from sites which respects people’s privacy instead, and everyone wins.
- kmlx 7y agowhat privacy setting? i never get that popup. techcrunch is ok imo. the verge on the other hand won’t load for 3 seconds if i have an ad-blocker turned on. so i stopped visiting it since their ads are 90s level of terrible.
- tjoff 7y agotechcrunch is using oauth, one of the absolute worst offenders. They should be banned from hn altogether.
- sealjam 7y agoI assume you're referring to the media company 'oath'[1] not the auth framework 'oauth'[2]? [1]: https://www.oath.com/ https://www.oath.com/ [2]: https://oauth.net/ https://oauth.net/
- tjoff 7y agoMy bad, I've read it incorrectly. It's Oath.
- icebraining 7y agoNitpick: they aren't using OAuth, they are owned by Oath (now Verizon Media).
- Sahhaese 7y agoThis is all you see when clicking techcrunch articles: https://imgur.com/a/mId1Jfi https://imgur.com/a/mId1Jfi If you "manage" your settings to block everything it'll just be back next time. As a consequence, I haven't read a techcrunch article since June 2018.
- jonknee 7y agoInteresting, I have never seen that and even tried in an Incognito tab and with Safari which I don't use regularly.
- Sahhaese 7y agoI'm guessing you're not in the EU then? I see this everywhere.
- jaclaz 7y agoI don't know, I use an old browser with javascript disabled, and I seem to read techcrunch articles just fine.
- pygy_ 7y agoWith Safari/iOS, all I see when I click your link is a full screen GDPR cookie notice with truncated text (the start is missing), that can only be dismissed by accepting tracking.
- the_other 7y agoThe Verge doesn’t give me, in the UK, any options to control my level of cookie acceptance. They offer me two policies to read an an accept button.
- Nextgrid 7y agoAt least they don’t redirect the page so you can block the overlay with an ad blocker and be done. Not saying this is OK (and definitely not compliant with the GDPR) but still slightly better.
- icebraining 7y agoTC's webdevs have been forced to put up that crap, but to their credit their site works very well without JS, so you can just block it wholesale. I still wouldn't share their links, though.
- donkeyd 7y agoI have to say, I think it's great that Apple doesn't try to do damage control on their reputation, but instead does damage control toward the customer. They could've kept the service working, created a fix and silently pushed it, but they didn't.
- Nextgrid 7y agoIt’s kind of sad that we live in a world where this behaviour is considered exceptional and something to be applauded, instead of being the normal way to do business, thanks to both morals and regulations with huge fines to control those who lack morals.
- donkeyd 7y agoYeah, I fully agree. This was in the back of my mind while writing the previous comment too. It's also why think it's important to acknowledge it, since that might help people become aware that we're not doing things right. Only slightly related, but as a lead developer I've had some business people get angry, because I refused to build features that violated customer privacy (and GDPR). It's not just the business that should be responsible, it's IT too, but we tend to use business demands as an excuse (see: Facebook).
- nier 7y agoI’d like to add that job safety and the home that needs money brought to is also used as an excuse. People need to feel safer that they can act upon their morals and overcome whatever consequences arise. Friendships and family ties are one important ingredient for that. Sensible frugality another.
- donkeyd 7y agoDefinitely true. I ended up quitting and moving to another job because of unreasonable demands like this. I do imagine though, that in SV, where data is considered the new gold, it must be a lot harder to find jobs at ethical companies.
- abalone 7y agoI've found that it's pretty easy to get people to inadvertently accept FaceTime calls if you continuously spam them. (I was on the receiving end of this attack.) Here's how it works. 1- It's very easy and instantaneous to redial someone on FaceTime if they decline your call. You can just spam the call button and the target will get a continuous ring, basically. 2- Even if they turn on Do Not Disturb, many people have "Repeated Calls" enabled, which lets repeat FaceTime calls break through Do Not Disturb. Neat! 3- Now they are frustrated and want to throw their phone in a bucket of water to shut it up. The only way to block you is now to get your "info" in the recent callers list, scroll down and hit the "Block this caller" option. However the constant stream of incoming FaceTime calls takes over the UI every couple seconds. As they fiddle with their phone trying to navigate to your info and/or hit decline, eventually they inadvertently hit accept, and you see their face.
- Phenomenit 7y agoAirplane mode in quick action bar to the rescue!
- VvR-Ox 7y agoJust wrap your phone into some tinfoil and it's over ;-)
- dewey 7y agoLuckily that feature was built in on the iPhone 4 ;) https://en.wikipedia.org/wiki/IPhone_4#Antenna https://en.wikipedia.org/wiki/IPhone_4#Antenna
- Blackstone4 7y agoAre you doing this to your friends or strangers? The attack requires plenty of effort and an Apple iCloud account so not the eeasiest thing to scale.
- cma 7y agoStill had if it doesn't scale. The people who are going to want a quick peek at camera are stalkers, political opponents (get a view of compromising activities or visitors) , drug dealer conflict retribution (get location), etc.
- dwighttk 7y agoI have a series two Apple Watch and while the app shows up I was unable to get it to work back when I tried. I didn’t care that much so I just tried a couple times and gave up.
- applecrazy 7y agoDon’t know why you’re being downvoted. I tried to make it work with my friends and for some reason, I could never get it to set up.
- mikestew 7y agoDon’t know why you’re being downvoted. Were I to guess, the original comment is at best peripherally related to the topic at hand ("the app", I'll assume, refers to the Walkie-Talkie app). IOW, it doesn't contribute much.
- HA-gayyyyyy 7y agoJoke's on you. I have FaceTime completely disabled because it's patently obnoxious to witness random people using it in public. Actually, all cell phone use in public is obnoxious, but FaceTime is even worse.
- GershwinA 7y ago"It turned out that the teen who discovered the bug, Grant Thompson, had attempted to contact Apple about the issue but was unable to get a response." Good they fixed this. Too often security vulnerabilities remain unaddressed, I think that was the case with Mariot hotels data leak, the staff knew for quite some there are privacy troubles. Now they're being fined for not taking action.
- oregontechninja 7y agoAlso: apple mail is so horrendously broken, any multipart email is likely to fall apart and attachments get chopped off or corrupted every other email.
- ru999gol 7y agoremember this idea how weird it is that everybody runs around with spying equipment, you have a always-online device with multiple cameras and microphones. I think people would be uncomfortable knowing that someone was listening or recording video without their knowledge, that's why people put stickers on their laptop cameras. I think its obvious by now that manufacturers aren't capable of developing software that keeps the cameras/microphones secured. In the future we can just assume that any camera/mic in any phone is recording at any given moment and sending it to some malicious entity. Since there is no practical way of disabling the cameras/mics on phones, we just have to learn to live with it.
- 420codebro 7y agoDurr, what is a hardware switch?