ɿɘɘniϱnɘ ɘƨɿɘvɘɿ
🎦 youtube.com/@jiskac
📝 naehrdine.blogspot.com
🐥 twitter.com/naehrdine
🎓 hpi.de/classen
📱 reversing.training

@naehrdine.bsky.social
ɿɘɘniϱnɘ ɘƨɿɘvɘɿ
🎦 youtube.com/@jiskac
📝 naehrdine.blogspot.com
🐥 twitter.com/naehrdine
🎓 hpi.de/classen
📱 reversing.training
My hands-on iOS reverse engineering training that covers user space, kernel space, and firmware internals will be at #OBTS on Hawaii in November!
Register here: reversing.training/obtsv9/
NEW: An iPhone hacking company claims it can freeze the iPhone in a state that makes it easier for cops to access data.
The iPhone has an automatic reboot feature that reverts the device to a state where data is harder to extract. This would defeat that feature.
Are you a PostDoc and want to stay in academia? We just opened 10 tenure track professor positions. HPI is close to Berlin, with the campus located next to a beautiful lake. We have excellent students and friendly colleagues.
I'm not sure how much that depends only on Apple any more (security.apple.com/blog/expandi...). If it's through a change in the PCC firmware it should show up in the transparency logs. But if it's through hardware, which Apple no longer owns, there are further parties that could be asked.
With Siri Recap, Apple sends everything people say to Private Cloud Compute. Apple Reference Image extends this and also sends your photos to PCC.
Henri Jäger-Menn made huge progress in reverse engineering and reimplementing Apple's proprietary Low-Latency WiFi on Linux. The #mrmcd26 recording is already online: talks.mrmcd.net/2026/talk/3R...
With this sensitive data being recorded across many devices, it'll be only a matter of time until governments request Apple to turn of end-to-end encryption of Siri Recap in iCloud.
Siri Recap privacy features will prevent that a restroom visit 💩 will be transcribed. The information it won't strip are who one interacted with and which decisions were made. While the former might be embarrassing, the latter is why at-risk users get hacked.
TL;DR: "security" and "privacy" mentioned a lot of times, and it seems like local processing at first sight. However, towards the end of the processing chain, the data is sent to third parties (via PCC, which is no longer running on Apple's hardware) and synced across all of your devices.
Apple shared details on how Siri Recap works, a new feature where your Apple Watch can listen to your surroundings 24/7 and take notes.
Source: www.apple.com/privacy/docs...
Watching this Apple event tout how iPhones will soon be able to record ambient audio/conversations and transcribe "high level notes" for you. It's billed as private and end-to-end encrypted, but I think the bigger harm is the normalization of always-listening devices. It's creepy and not normal.
Trainerinnen geben dort Workshops über Anwendungssicherheit allgemein, Bedrohungsanalysen, KI, bis hin zu einem Workshop von mir zur IoT-Firmwareanalyse.
Über den German OWASP Day kannst du dich kostenlos für die PreCon anmelden. Mehr Infos: god.owasp.de/2026
Du interessierst dich für Anwendungssicherheit und wohnst in Karlsruhe oder der Umgebung? Dann schau doch am 23. September beim OWASP Diversity PreCon Day vorbei, einem Angebot für Frauen und queere Menschen.
Did you know macOS binaries can run on iOS? It needs rewriting architecture information and adjusting library paths. I automated this, including DYLD shared cache library extraction and replacement, allowing many macOS command line tools to run on iOS.
Google: "We shipped MTE hardware for 3 years and only academics enabled this optional feature to demonstrate practical attacks against it, so we decided to no longer ship it on the latest Pixels."
Apple: "We had to work on MTE stability and security improvements for 5 years, but we finally ship it with the iPhone 17 and enable it by default."
You're a full-time student and can't afford this but would love to attend? You can apply for a scholarship that covers your travel expenses, a training, and a conference ticket here: objectivebythesea.org/v9/attending...
My hands-on iOS reverse engineering training that covers user space, kernel space, and firmware internals will be at #OBTS on Hawaii in November!
Register here: reversing.training/obtsv9/
Mobilfunknetze übertrugen Handydaten an Anrufer #Mobilfunknetz #Datenschutz #Sicherheitslücke
Want to learn firmware reverse engineering on an IoT device? I'll be giving a free, women-only workshop with BlackHoodie at Hexacon in Paris on October 15. #reverseengineering