Apple

User avatar
tek
Posts: 2319
Joined: Mon Feb 22, 2021 10:15 am

Apple

#26

Post by tek »

They decided it was to their advantage to keep iMessage because it would force families to buy iPhones when kids got a phone.
The raging capitalist's version of "competition"
qbawl
Posts: 754
Joined: Mon Feb 22, 2021 11:05 am

Apple

#27

Post by qbawl »

Apparently Apple will be implementing RCS this fall. RCS is the replacement for SMS which is how iMessage implements interoperability when dealing with Android phones. RCS. is an industry (carrier) standard that does NOT support end to end encryption. Google however has an implementation of RCS which does support E2E and that is what most but not all Android phones use. Rumor says Apple will utilize the Google implementation of RCS though there is some talk of Apple implementing its own version (smart money is on using Google). This will mitigate all the valid criticism of Apples interoperability issue. However the bubbles will still be green!
User avatar
Rolodex
Posts: 1118
Joined: Fri Oct 20, 2023 12:06 pm

Apple

#28

Post by Rolodex »

tek wrote: Sat Mar 30, 2024 11:42 am
They decided it was to their advantage to keep iMessage because it would force families to buy iPhones when kids got a phone.
The raging capitalist's version of "competition"
Yeah I had a discussion with my applespouse who insists "well Apple sells more because it's a better product. It's how capitalism works!"
The bubbles will still be green.
Yes so Apple users will know they're texting to a superior phone (LOL)
I'm actually pretty sure that droid is the most common phone world-wide. The US is an outlier with iPhones.
Do the right thing. It will gratify some people and astonish the rest. - Mark Twain
User avatar
raison de arizona
Posts: 19049
Joined: Mon Feb 22, 2021 10:21 am
Location: Nothing, Arizona
Occupation: bit twiddler
Verified: ✔️ he/him/his

Apple

#29

Post by raison de arizona »

IMG_7627.png
IMG_7627.png (243.81 KiB) Viewed 227 times
https://worldpopulationreview.com/count ... by-country
“Remember, democracy never lasts long. It soon wastes, exhausts, and murders itself. There never was a democracy yet that did not commit suicide.” —John Adams
qbawl
Posts: 754
Joined: Mon Feb 22, 2021 11:05 am

Apple

#30

Post by qbawl »

Worldwide the split is roughly 70% to 30% Android. In the US the split is roughly 60% to 40% iOS.
Which is why I find the EU's market actions hard to understand re. Apple.
User avatar
RTH10260
Posts: 15318
Joined: Mon Feb 22, 2021 10:16 am
Location: Switzerland, near the Alps
Verified: ✔️ Eurobot

Apple

#31

Post by RTH10260 »

New Apple Wi-Fi Vulnerability Exposes Real-Time Location Data
Apple Wi-Fi vulnerability risks real-time location leaks; researchers demonstrate potential covert tracking with AirTags.

Monday, May 27, 2024

Aside from Find My, maps, routes, and emergency SOS, Apple's location services are quite handy, and they have many useful features. A research team at the University of Maryland has uncovered a critical vulnerability in Apple's location services, which might allow an unauthorized person to access the location information of millions of routers and potentially even information about a person's movements in a matter of seconds.

It has been reported that Erik Rye and Dave Levin from the University of Maryland have found that Apple's location services are working strangely, according to Krebs on Security. It is possible to sneak information from one place to another using a passing Apple device, such as a computer on the other side of the world, over the air, without any other connection to the internet at all.

Using Bluetooth Low Energy (BLE) broadcasts and microcontrollers programmed to function as modems, Fabian Bräunlein, co-founder of Positive Security, devised a way of transmitting a limited amount of arbitrary data from devices without an internet connection to Apple's iCloud servers. Using a Mac application, he can retrieve data from the cloud and subsequently use a Mac application to retrieve that data from the cloud. His proof-of-concept service Send Me was dubbed in a blog post that he wrote on Wednesday.

As a crowd-sourced location-tracking system, the Find My network on Apple devices functions as a crowdsourced location-tracking tool when it is enabled. Participating devices broadcast via BLE to nearby attentive Apple devices, which relay the data back to Cupertino's servers through their network connection to Cupertino's servers via their network connection. Through Find My iPhone, an iOS/macOS version of the company's Find My app, authorized device owners will be able to receive location reports about enrolled hardware using iCloud.

To reduce energy consumption, smartphone manufacturers are trying to use alternatives to GPS and its constant queries. To determine the precise location of a device, it is necessary to analyze the data from surrounding Wi-Fi networks and calculate a device's location based on the number of networks that are detected and how strong the signal is at the moment. In Apple’s and Google’s databases, active Wi-Fi networks are used as names for active networks (Wi-Fi-based Positioning Systems, also known as WPS) to make calculations a great deal of time.

Researchers discovered that Apple's WPS system had an oddity: it sent the necessary data to the user's device, which enabled the user to make these calculations locally, as opposed to sending the necessary data to the server on the user's computer. Apple's WPS server also appears to be sending out up to 400 other known Wi-Fi networks in the approximate vicinity of the device as part of its location database that has been crowdsourced by users of the app.

From this list, the requested device searches for eight possible variants and then calculates its location by that data. WPS technology on Apple's iOS device, the router on which the network is based, and the MAC address of the device are all identified using the so-called BSSID (Basic Service Set Identification) and are usually accompanied by a MAC address, which is usually static. ESP32 microcontrollers running OpenHaystack-based firmware were used by Bräunlein as the basis of his data exfiltration scheme because it was able to broadcast a hardcoded default message and to listen to new data over the serial port.

The signals will be picked up by nearby Apple devices that are using Find My Broadcasting and transmitted to Apple's servers if they have this feature enabled. It is necessary to use an Apple Mail plugin that is running with elevated privileges to obtain the location data from a macOS device, as Apple requires authentication to access location data stored on Macs. For the user to be able to view unsanctioned transmissions, OpenHaystack must also be installed as well as DataFetcher, which was developed by Bräunlein under the Mac OS X platform.

This is not exactly a high-speed attack since Send Me does not have a lot of speed. Considering that the microcontroller can send three bytes per second and can retrieve sixteen bytes in five seconds, along with latency ranging from one to sixty minutes depending on the number of devices in the vicinity, there are certainly faster channels of data transmission than what is available through the microcontroller. The fact that Send Me can be used by sophisticated adversaries does not make it impossible for an adversary could find a way to exploit it.
Post Reply

Return to “Computers and Internet”