news.volyx.in

SiriSpy – iOS bug allowed apps to eavesdrop on your conversations with Siri (rambo.codes)

551 points by mnem · 1413 days ago · 236 comments on HN

Article summary

A security researcher discovered an iOS bug that allowed apps to eavesdrop on conversations with Siri and audio from the iOS keyboard dictation feature when using AirPods or Beats headsets. The bug, which was reported to Apple and has since been fixed, allowed apps to record audio without requesting microphone access permission. The researcher was awarded a total of $29,500 for reporting the issue. The bug was found to affect not only iOS but also macOS, where apps could access the microphone without any permissions at all.

Main themes

  • iOS security bug
  • Siri and dictation vulnerability
  • Apple software quality
  • Bug bounty payments
  • Bluetooth security risks
  • Security research and privacy

What commenters say

  • The bug bounty payment of $29,500 was seen as adequate by some, but others felt it was too low considering the severity of the bug.
  • Some commenters felt that Apple's software quality has declined in recent years, leading to more bugs and security vulnerabilities.
  • The discovery of the bug highlights the importance of security research and the need for companies to prioritize security and privacy.
  • The use of AirPods and other Bluetooth devices can pose security risks if not properly secured.
  • Some argued that the issue was not as severe as it seemed, since it required a malicious app to be installed on the device.
  • Others pointed out that the bug was particularly problematic because it allowed apps to access sensitive user data, such as dictation audio, without permission.
  • There was disagreement over whether the bug was a major flaw or a relatively minor issue that was blown out of proportion.
  • Some commenters noted that the bug was a reminder of the need for greater transparency and accountability in the tech industry, particularly when it comes to security and privacy.