Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
willstrafach
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
29 ms
·
1.
▲
by
willstrafach
2y ago
“Facebook Research” was the Onavo codebase, under a different name, signed by Facebook’s Enterprise certificate.
2.
▲
by
willstrafach
3y ago
iOS devices must be activated to use them. This is indeed stored in a database. AppleCare and third-party repair centers can query activation information using GSX. You are correct about pre-T1 Intel Macs though. Apple will have a blind spo
3.
▲
by
willstrafach
4y ago
This may help: https://chrome.google.com/webstore/detail/icloud-passwords/p...
4.
▲
by
willstrafach
4y ago
> That said, doesn’t iOS notify you when an app wants to use location services? Did all of these users just opt into that? That seems crazy, if so. Not so crazy. Local news, weather, and similar apps with a reasonable rationale for Locat
5.
▲
by
willstrafach
4y ago
They have some pretty bad past practices: https://www.zdnet.com/article/accuweather-caught-sending-geo... And they have continued, off-and-on, to use other location-collecting SDKs.
6.
▲
by
willstrafach
5y ago
I think the pitch here is “Semi-managed WireGuard peer provisioning and NAT punching as a service” usable by anyone who may not otherwise have a clue how WireGuard works (eg. friends sharing access to a file/media server), within 5 min
7.
▲
by
willstrafach
5y ago
How would that work? Connections are mainly peer-to-peer with Tailscale. An attack (I suppose pushing new key pairs to specific peers and pointing them through a malicious endpoint?) would likely require a very noisy and detectable process.
8.
▲
by
willstrafach
5y ago
This may make sense if they were replying via e-mail to the issue.
9.
▲
by
willstrafach
5y ago
Different poster here but just curious: Are you a Deutsche Telekom user, by chance?
10.
▲
by
willstrafach
5y ago
The face:b00c part is in the Interface ID, so this did not even need a large block (Though I am sure they have one).
11.
▲
by
willstrafach
5y ago
In current versions? What permission is this?
12.
▲
by
willstrafach
5y ago
.icu, .club, and a few other gTLDs can often be found for sale at $1-2/year, so they are used by entities in need of low cost disposable domains.
13.
▲
by
willstrafach
5y ago
That is incorrect, Corellium does not ship Apple code.
14.
▲
by
willstrafach
6y ago
If it had a T2, that will store the Apple ID.
15.
▲
by
willstrafach
6y ago
1. You’re allowed to use IDFA. But users will now have to allow access, as a permission dialog will pop up first. 2. The IDFA is just a simple static UUID. It cannot do a very good job at preventing fraud. There is no way to validate anythi
16.
▲
by
willstrafach
6y ago
Pager messages collected on September 11, 2001. They are also a type of communication which is transmitted without encryption.
17.
▲
by
willstrafach
6y ago
The list can be found here: https://support.apple.com/en-us/HT210770
18.
▲
by
willstrafach
6y ago
This one is well worth a try: https://www.amazon.com/Remote-Control-Alternative-Replacemen...
19.
▲
by
willstrafach
6y ago
Do you have a source on Apple “killing IDFA”? My understanding is that they are going to simply show a consent dialog before allowing an app to access the IDFA, similar to what they have done for years to access other sensitive data like Co
20.
▲
by
willstrafach
6y ago
This exists, though not exactly as you describe: https://en.wikipedia.org/wiki/ASmallWorld
21.
▲
Mysterious meme gets Tech Twitter to clamor for invite to app that doesn't exist
(businessinsider.com)
86 points
by
willstrafach
6y ago
|
56 comments
22.
▲
by
willstrafach
6y ago
> There is nothing stopping someone for using this technique to publish an app in the AppStore officially. It has not happened though. Only app which has been in the App Store and utilized private entitlements, from what I’ve seen anyway
23.
▲
by
willstrafach
6y ago
They would be caught if this was submitted to the App Store. This applies to self-signed apps by those with a developer certificate.
24.
▲
by
willstrafach
7y ago
Not replace, rather, you boot Linux over USB. That is why they describe the ephemeral device use case.
25.
▲
by
willstrafach
7y ago
Source code: https://github.com/corellium/projectsandcastle/ The backstory is also incredibly interesting: https://projectsandcastle.org/history
26.
▲
Corellium releases tool to run Android on an iPhone: Sandcastle
(projectsandcastle.org)
7 points
by
willstrafach
7y ago
|
1 comments
27.
▲
by
willstrafach
7y ago
Specifically, I was asked about how Clearview can make their iOS app available again.
28.
▲
Apple subpoenas Santander and US intelligence contractor on use of Corellium
(forbes.com)
66 points
by
willstrafach
7y ago
|
20 comments
29.
▲
by
willstrafach
7y ago
Important to note, our app is a VPN as well. This way, with the bulk of our business logic on the server-side, device battery is saved and we can do real-time block list updates rather than the app needing to pull down a new rule set. The $
30.
▲
by
willstrafach
7y ago
That's not the real licensing cost at all. The cloud and on-premise options are both available for substantially less.
More ›