Mysk🇨🇦🇩🇪
mysk@mastodon.social
<p>We're two <a href="https://mastodon.social/tags/iOS" class="mention hashtag" rel="tag">#<span>iOS</span></a> developers and occasional <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a> researchers on two continents. <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="tag">#<span>CyberSecurity</span></a> 🇨🇦🇩🇪</p>
Posts
-
View post
So on a Pixel 9 with Android 17, there’s no way to copy text from a photo offline and without sending it to Google? All these AI features on Pixel phones and basic OCR still can’t run locally?
-
View post
RE: https://mastodon.social/@mysk/117264670021439841 Happy iOS 27 Day! Bookmark this post if you want to disable Apple Intelligence. Apple buries the option in "Screen Time". Apple joins other Big Tech companies in making it tougher to opt out of AI features that send data off-device.
-
View post
In iOS 27, there’s no longer simple toggle to disable Apple Intelligence entirely. Some features like Writing Tools can also send data off-device for processing through Private Cloud Compute After some digging, here’s how to disable Writing Tools: 1️⃣ Settings → Screen Time 2️⃣ Content & Privacy Restrictions → turn it on 3️⃣ Siri → Writing Assistance → Don’t Allow #Apple #Privacy
-
View post
📝 New Blog Post: Thoughts on Responsible Disclosure We recently disclosed issues in WebKit that affected Psylo and iCloud Private Relay. This has sparked some debate, so we want to explain our reasoning and share some thoughts on responsible disclosure https://mysk.blog/2026/08/25/responsible-disclosure/
-
View post
Good news to hackers: this hasn't been fixed in 26.6. Actually, it won't be fixed. Enjoy what you collect from people's clipboards. BTW you can also do the same with Microsoft Edge. Cheers! https://youtu.be/lLJkxWR71B0
-
View post
RE: https://mastodon.social/@mysk/116889369517349322 iOS 26.6 resets the clipboard counter after a reboot. This is the same change that Apple introduced in iOS 27 beta a while ago. Sadly no acknowledgment to Team Mysk or Project Loupe in the security release notes 😑
-
View post
Many of you have asked for a way to support the Loupe project. We want to keep Loupe free of in-app purchases, so instead we’ve created a Buy Me a Coffee page for anyone who’d like to show their appreciation. ☕ https://buymeacoffee.com/mysk
-
View post
RE: https://mastodon.social/@mysk/116974847786124516 🚨 PSA: Uninstalling Google Chrome on macOS doesn't remove Chrome's background updater. It keeps running until you remove: ~/Library/Application Support/Google/GoogleUpdater ~/Library/LaunchAgents/com.google.GoogleUpdater.wake.plist Then, restart.
-
View post
RE: https://mastodon.social/@mysk/116969508089535193 appleinsider inaccurately assumed that for the attack to succeed the user has to perform certain steps like archiving an restoring. This is wrong. All the user needs to do is run the malicious script. Now all websites are citing appleinsider 🤬 https://appleinsider.com/articles/26/07/24/trusted-mac-apps-could-possibly-be-swapped-out-for-malware
-
View post
Another change seems to be motivated by Loupe. Apple has deprecated the canOpenURL API that apps use to detect which apps are installed on the iPhone in iOS 27 Beta 4. Moreover, the deprecated API will only allow a maximum of 25 apps to be queried instead of 50 #privacy #infosec #Apple #ioS
-
View post
UPDATE: Apple doesn't see an issue here. We will disclose this issue on our blog. Stay tuned. https://mastodon.social/@mysk/116816065579359109
-
View post
@0@corteximplant.com Oh, I stopped dragging and dropping things in the Terminal since we published this: https://mysk.blog/2026/05/19/cve-2026-28910/
-
View post
Apparently Apple has fixed the clipboard counter in iOS 27 beta 3 thanks to Loupe. ✌️ Now the counter resets after a restart. Hey Apple, a little shoutout to the Loupe project would have been nice! Loupe is free and open source. You can download Loupe here: https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470 #privacy #iOS #Apple #beta #infosec #security
-
View post
Cool, so in the future we should expect an email like this: https://blog.playstation.com/2026/07/01/physical-disc-production-ending-in-january-2028-for-new-games-releasing-on-playstation-consoles/
-
View post
Just out of curiosity, I let Claude attempt to port Loupe to Android using skiptools. If you haven’t heard of Skip, it’s a tool that lets you produce native Android apps from a SwiftUI codebase. Loupe is written entirely in Swift and SwiftUI, so it should be a good match It’s still so surprising to me that this works at all. That said, I don’t think Loupe for Android is coming anytime soon since we have other stuff going on right now
-
View post
Loupe has earned 1,000 5-star ratings on the App Store and its GitHub repo has reached 1,2k stars. ✌️
-
View post
UPDATE: Michael Tsai @mjtsai confirms that all his search queries were included in the data he requested from Apple. Every iPhone user should learn that Apple&#39;s definition of privacy is different. Think different. Visit https://privacy.apple.com and request a copy of your data. #privacy #Apple #infosec
-
View post
🚨PSA: If you think you&#39;re a targeted individual, don&#39;t install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇 #privacy #Apple #security #infosec #cybersecurity
-
View post
Techlore reviewed Loupe in this great video: #privacy https://youtu.be/_n_SpEWtqog
-
View post
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps. Mullvad is aware of this issue. It is described in this blog: https://mullvad.net/en/help/why-wireguard You can download Loupe here: https://apps.apple.com/app/id6766152470 #iOS #privacy #infosec #security #cybersecurity
-
View post
On iOS and macOS, WhatsApp stores chat databases unencrypted in an app group container accessible to apps from the same developer. So all Meta apps on the same iPhone (e.g., Facebook) can read WA chats in plaintext without permission, and users wouldn't be notified. https://blog.cryptographyengineering.com/2026/02/02/whatsapp-encryption-a-lawsuit-and-a-lot-of-noise/ This is a demo we prepared recently to show a macOS bug that allowed unrestricted access to protected app containers. WhatsAp...
-
View post
RE: https://mastodon.social/@mysk/116557912618505785 This bug was reported to Apple on October 17, 2025. It has now been fixed and can be disclosed. Our initial assessment found it to be critical, so we paused all @psylo activities and focused on preparing excellent demoes to convince Apple of the bug&#39;s severity. After 206 days the issue was addressed. We were surprised it remained unpatched for so long, perhaps Apple had higher priority bugs.
-
View post
RE: https://mastodon.social/@mysk/116557828381660916 🚨 If you use Signal or 1Password on macOS, make sure you upgrade to: Tahoe 26.5 Tahoe 26.4 Sequoia 15.7.7 Sonoma 14.8.7 We&#39;re working hard to get the blog and videos out ASAP
-
View post
Bill C-22 would impact @psylo since Mysk is registered in Canada and we have proxy servers in Canada too. We will not change Psylo’s no-log policy. If bill C-22 passes as is, we would likely have to move out of Canada. https://mobilesyrup.com/2026/05/14/signal-threatens-canada-exit-over-law-bill-c-22/
-
View post
RE: https://mastodon.social/@mysk/116557828381660916 The blog post with all the technical details about this issue, which was addressed in macOS 26.4, is coming along nicely. We’re hoping to publish this week 🙌
-
View post
📝🚨 New blog post: How a bug in Archive Utility allowed access to protected app data (including iMessage and WhatsApp chats, and Safari cookies) without any permissions. The bug could also be exploited to hijack installed apps such as Signal and 1Password to perform phishing attacks. Apple fixed the issue in macOS 26.4 as CVE-2026-28910, five months after we reported it #Apple #macOS #privacy #security #cybersecurity #infosec https://mysk.blog/2026/05/19/cve-2026-28910
-
View post
🤯 Just received a spam SMS from an unknown sender and Apple Messages didn&#39;t disable the phishing link. The iPhone is running iOS 26.4.1. Links from unknown senders are normally disabled (not clickable) to protect against phishing attacks. Actually, iMessages enables the phishing link only when the conversation is opened for the first time after launch, then it is disabled until the app is relaunched. Not sure how to explain it. A video shows it better: #iOS #Apple #security #infosec
-
View post
Apple… this when? 👀 #privacy #Apple #iOS #Android
-
View post
RE: https://mastodon.social/@mysk/116442855044780865 The app finally has a name 🎉 More details dropping soon. #privacy
-
View post
iOS 18.4 introduced a new option in System Location Services called &quot;Improve Location Accuracy&quot; and it is enabled by default. You can find it under: Settings &gt; Privacy&amp; Security &gt; Location Services &gt; System Services #Privacy #infoSec