11 ms·
SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri
- _hhkc 4y ago"iOS bug allowed apps to eavesdrop on your conversations with Siri" should be "iOS bug allowed apps to eavesdrop on your interactions with Siri and dictation over bluetooth"
- sneak 4y agoIf you care about privacy, you should disable Siri and Dictation and blacklist guzzoni.apple.com.
- atlex2 4y agoConfused why you can’t use this to transcribe from any AirPods in your vicinity? I thought anyone could subscribe to a btle gatt attribute.
- semireg 4y agoThe BLE peripheral (AirPods) have to be connected and paired. Then, this connected device was “explorable” via other apps on the same device because the actual connection is maintained by the middleware/OS… e.g. an app may disconnect from a peripheral but it’s only a request, and the OS will only truly disconnect if all apps are “disconnected.”
- runjake 4y agoA $7,000 bounty for eavesdropping and TCC (app permissions) vulnerabilities. Insulting.
- javajosh 4y agoThat's incredibly low. This is a terrifying bug that deserved $70k, at least.
- pxmpxm 4y agoMy first thought as well - the author must be doing this stuff as a hobby/for fun, because that's not nearly enough to comp you for the time spent.
- deleted 4y ago[deleted]
- rtev 4y agoThis is why people sell bugs.
- pvg 4y agoIt's an example of why people report bugs to vendor bounty programs since you could not sell this bug for $7000.
- hu3 4y agoWhat makes you think it wasn't sold? Even if by another party that could have found it before?
- pvg 4y agoWho would you sell it to and what would the buyer do with it? Outline the scenario you have in mind and we can try to sort out how to leverage this specific bug for $7000 worth of some kind of value.
- legutierr 4y agoConceivably, a state actor could use this bug to eavesdrop on an espionage target, no? There is a market for zero-day exploits, where state espionage entities and criminal organizations both pay to learn about the existence of vulnerabilities like this—with prices in the hundreds of thousands to the millions of dollars. Are you saying that this particular bug would not be worth more than $7000 in one of these markets, or are you questioning the very existence of these markets?
- saagarjha 4y agoThe former.
- pvg 4y agoConceivably, a state actor could use this bug to eavesdrop on an espionage target, no? Well, let's try to conceive it. Our state level actor is now in possession of an exploit that lets them eavesdrop on a target when they text-dictate or activate Siri, while wearing particular Apple headphones. After getting the target to install a specific malicious app from the App Store. And to run it. And to give it Bluetooth permission. And to make sure to restart it whenever they reboot their phone or the phone kills it for any reason. The value of this as state-level actor surveillance malware feels a lot closer to $0 than $7000 to me but I'm happy to hear a different conception of how this might work.
- concinds 4y agoNot just insulting to the dev, but to users as well. Any app on my Mac being able to eavesdrop at all times when wearing AirPods is "worth" just $7k to Apple? I'm reminded about the Apple Music passage in the After Steve book, where Apple tried to fuck over musicians just because they thought they could get away with it (zero royalty payments during Apple Music trials, so the trial was 100% subsidized by labels and artists), before walking it back. The executives are clearly far more concerned with bad PR, and not guided by values or principles.
- urbandw311er 4y agoAlso a $7k bounty 'when I reached out'. The guy actually had to chase it up by the sounds of it.
- jdelman 4y ago$7k feels like a paltry sum for this discovery. Rambo is doing yeoman's work.
- deleted 4y ago[deleted]
- QuackyTheDuck 4y agoSigh … I so much want Apple to get their shit together. To me it feels like software quality reached a new low.
- freeplay 4y agoCouldn't agree more. As stupid as it may be, the only reason I haven't moved to Andoid/GrapheneOS is iMessage.
- deleted 4y ago[deleted]
- alphabetting 4y agothat's the main reason for most iphone users i know and exactly why Apple will stall for as long as possible on RCS compatibility
- scarface74 4y agoYes I’m sure that Apple’s 95% retention rate is based on iMessage based on the sample size of “people you know”.
- alphabetting 4y agoI didn't claim that. It's just the main reason for not switching according to my friends. The imessage moat in the US is pretty heavily discussed on here.
- scarface74 4y agoIf HN were a representative sample of what most users wanted from their phones you would think they wanted to spend half the day compiling the Linux kernel on their phone and the other half bemoaning if only they had the “right to repair” they could put their own headphone jack on their phone and get rid of those pesky AirPods
- mikece 4y agoI don't want stories like this to be the reason I'm glad I switched to Graphene OS. I don't want anyone hacked or spied on.
- aaronharnly 4y agoPro tip: all systems have bugs.
- NayamAmarshe 4y agoNot all systems come with easy eavesdropping mechanisms. Especially the ones focused on Privacy.
- deleted 4y ago[deleted]
- devX3 4y agoKinda funny that you have to buy/support hardware from a company but then need to use a opensoure nonprofit OS to protect yourself against said hardware producer.
- henriquez 4y agoSeems like $70,000 would have been a more fair bounty. This is a really nasty bug.
- deleted 4y ago[deleted]
- pvg 4y ago$70,000 would have been more fair There's really no basis for this beyond its reflexive repetition on messageboards. You might as well type 'million dollar logout CSRF' in every vulnerability report thread.
- lapcat 4y agoHere are the listed payouts from the Apple Security Bounty program, starting at $25,000. https://developer.apple.com/security-bounty/payouts/ https://developer.apple.com/security-bounty/payouts/
- pvg 4y agoThe closest is $25,000. App access to a small amount of sensitive data normally protected by a TCC prompt. In this case you get a misleading prompt, the access requires additional interactions. It's a serious bug and I'm all for reporters of serious bugs getting bigger bounties from companies that have more cash than they know what to do with. But simply dropping a random number in every single one of these threads is just noise, not even advocacy or technical discussion.
- lapcat 4y ago"Full TCC Bypass on macOS"
- deleted 4y ago[deleted]
- 4y ago
- freeplay 4y agoI think they burried the lede here. Conversations with Siri are probably pretty generic but being able to evesdrop on keyboard dictation is pretty severe. I know people that use dictation for the majority of their text messages and email.
- cstejerean 4y agoEven worse, it looks like on MacOS you can just straight up start recording on-demand, no need for dictation or siri. > Even worse, this particular exploit would also allow the app to request DoAP audio on-demand, bypassing the need to wait for the user to talk to Siri or use dictation.
- SamuelAdams 4y agoAnd this is why I have the internal microphone disconnected on my macbook pro. The only time a mike is attached is when I'm actively using it, and even then they have hardware kill switches. Simple kill switches would be nice to see but I doubt Apple would ever implement something like that.
- lilyball 4y agoThe internal microphone is entirely unrelated to this bug.
- coldtea 4y agoIt's not this bug that's the reason he has the internal microphone disconnected. It's the presense of such bugs...
- metafunctor 4y ago
- spaghettiToy 4y ago
- yazzku 4y ago
- TheLoafOfBread 4y ago> Find out how much the vuln is worth in the black market, then ask Apple double that. Well, because he is not a corporation, he will get jumped on by lawyers and will go to jail for blackmailing Apple.
- dylan604 4y agoBlackmailing? It's called negotiating from a strong position.
- TheLoafOfBread 4y agoThat really depends how will judge and lawyers look on it.
- encryptluks2 4y agoSo now people that discover exploits should be bullied and threatened by corporations for asking for more money? Heck, I hope Apple does this so that no one will ever want to use them again.
- TheLoafOfBread 4y agoI mean, that's the station where we are heading. The moment you will come to corporation and say: "I have this and this vulnerability, black market offers me X, I want 2X from you." Corporation will then subpoena you to get the knowledge from you and then cease and desist you to prevent you from spreading that knowledge further. You will try to threaten that you will release it to black market if they won't pay you 2X? Yeah, that's blackmailing. So what else can you do? Either you will start blackmailing them (then I hope you know what you are doing) or you will outright sell it on black market and bypass communication to company altogether.
- TheLoafOfBread 4y ago
- bryceacc 4y agofirst sentence: "and audio from the iOS keyboard dictation feature"
- TheLoafOfBread 4y agoAnd who is using that? Half of characters are misspelled, second half misunderstood. Nobody has time to argue with a phone.
- asah 4y agoAndroid it works pretty much perfectly and you can speak at normal speed. With Android it pretty much works perfectly and you can speak at normal speed. <== Same sentence dictated at full speed.
- TheLoafOfBread 4y agoYeah not for me. Android, nor Siri, nor Alexa.
- encryptluks2 4y agoIt'll suck if you ever lose function to type with your fingers.
- asah 4y agoAccent? This is me speaking through a mask at normal speed. The quick brown fox jumped over the lazy dog - that was spoken really fast. Obviously depends on what you're speaking because sentences like the previous one are pretty easy to predict.
- walterbell 4y agoIf an iOS app did not have "Background App Refresh" permission, could it still have exploited this vulnerability? Can physical microphones be removed from Apple devices by a repair shop, while still allowing use of wired/wireless headsets? We need Purism-style hardware kill switches for microphones, cameras and radios.
- MBCook 4y agoNote this Bluetooth only.
- walterbell 4y agoYes, the question is how to permanently restrict the attack surface / time windows for audio and video surveillance attacks.
- dontbenebby 4y agoIt's not really a question, hardware switches work and companies refuse to put them in so they can... shrink the profile of devices in ways that rely on rare earth minerals to an unsustainable degree when combined with the typical replacement rate.
- walterbell 4y agoHopefully legislated right-to-repair can open the door to aftermarket mods, including phone body with new switches that can electrically disconnect specific sensors.
- dontbenebby 4y agoEhhhh... is right to repair the right phrasing? I worry about requiring switches in the same way one can require a universal standard for power delivery. (The EU did that recently... good move IMO, though I can understand the delay since discussions about amperages and whatnot do take time.[0]) Maybe requiring anyone who wants to contract with the US government to offer such a model, and that said model be available for consumer purchase as well, would be a simple solution. They sometimes won't let say, Russia, buy the same stuff as say... Canada... but that's usually stuff like night vision goggles. The exact same phone or laptop, just slightly larger with more switches shouldn't have any... I think the word is "export controls"? Please keep in mind, I am not a lawyer, and I'm very stupid -- I only have a master's degree -- so sometimes the things I say are wrong... please only credit me for the times I'm right. Thx! I'm off to do more drugs now... have a nice Thursday!! - Greg from Pennsylvania [0] https://www.npr.org/2022/10/07/1127543116/eu-mandate-for-a-single-universal-charger-could-become-world-standard https://www.npr.org/2022/10/07/1127543116/eu-mandate-for-a-s...
- hazyc 4y agoIs anyone else an avid iPhone user, yet also someone who never uses Siri? I've used an iPhone exclusively for the past 8 years, and I can count on one hand the number of times I've used Siri. Interestingly, the one person I know who loves using Siri is my 70yr old dad.
- zippergz 4y agoYes, I have had iPhones from the beginning and I never use Siri.
- BudaDude 4y agoI use Siri for setting timers and reminders. It's pretty good at parsing numbers. Other than that, It hasn't been very reliable for me. Apple really needs to overhaul Siri's intelligence.
- trap_goes_hot 4y agoI use it for things like 'will it rain today' or sending quick texts when I am driving.
- dfee 4y agoI use Siri all the time and am half your dads age. “Get directions to the nearest gas station.”, “What’s the score of the Giant’s game?”, “Play Master of Puppets”, “What is 4’3” in centimeters?” And many, many more.
- Firmwarrior 4y agoMan, I used to love using Siri, until I had a daughter and named her "Sarah" big mistake. Turns out I say "Hey Sarah" a hundred times a day, and all my iDevices pipe up and simultaneously say "Yeah?" "WHAT'S UP" "HEY OVER HERE" "Hi it's me Siri what do you need?"
- keepquestioning 4y agoWhy did you pick 'Sarah'
- lapcat 4y agoDon't forget that iOS and macOS silently re-enable Bluetooth on every software update. https://lapcatsoftware.com/articles/bluetooth.html https://lapcatsoftware.com/articles/bluetooth.html
- walterbell 4y agoEven worse, Control Panel buttons only "suspend" BT/WiFi, you have to go into Settings to turn them off again ... and again ... and again.
- sixstringtheory 4y agoI called this a data grab from day 1 and stand by that. The amount of fellow iOS developers I've had argue for the "convenience" is astounding. There should be a settings toggle to control the auto-reenable behavior.
- happyopossum 4y ago> I called this a data grab from day 1 and stand by that Option 1 is a reasonable explanation based on the behavior that arguably works best for 99% of users . Option 2 is a “data grab” with no evidence or theories about who is grabbing what data and for what purpose.
- sixstringtheory 4y agoAirTags wouldn’t work as well if everyone’s phones weren’t constantly transmitting/receiving, for one thing, and grabbing data on all nearby WiFi SSIDs and beacons helps with location services and probably advertising.
- walterbell 4y ago> grabbing what data and for what purpose One possible motive: a billion dollars of AirTag revenue, https://macdailynews.com/2022/06/20/apple-estimated-to-sell-55-million-airtag-item-trackers-in-first-2-years/ https://macdailynews.com/2022/06/20/apple-estimated-to-sell-...
- jalla 4y ago
- dylan604 4y agoIs that you NSA?
- tinus_hn 4y agoWonder if it’d also be possible to send commands to Siri, that could also have some implications.
- traceroute66 4y agoI'm an avid iPhone user but have never had the need or the desire to use Siri. I suggest people do what I do, load a profile that disables Siri - easily created using the Apple Configurator tool (under "Restrictions" untick "Allow Siri"). N.B. I've never looked closely under Settings on the phone itself, there may well be Siri off option there ? But I just load profiles as I find its easier for hardening.
- greenicon 4y agoI wouldn’t have expected Opus in the AirPods. Unexpected from Apple and a quite interesting workaround around the mode switching.
- walterbell 4y agoOpus patent trolls are pleasantly surprised :(
- deleted 4y ago[deleted]
- 2T1Qka0rEiPr 4y agoThe struck-through: > and then receive a reply in the form of "here's what I found on the web... Really made me chuckle. As a non-Apple user who has to put up with Homepods, this rings so very true.
- nick88msn 4y agoIs there actually people using siri? It’s pretty useless here in Italy. Most conversations I guess could be something like “raise the volume” “call mom” or stuff like that.
- mfbx9da4 4y agoYes when I’m cycling. Also for setting reminders and weather forecast
- veronikamartin 4y ago[flagged]