Mysk🇨🇦🇩🇪
mysk@mastodon.social
<p>We're two <a href="https://mastodon.social/tags/iOS" class="mention hashtag" rel="tag">#<span>iOS</span></a> developers and occasional <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="tag">#<span>security</span></a> researchers on two continents. <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="tag">#<span>CyberSecurity</span></a> 🇨🇦🇩🇪</p>
Posts
-
Post #4149282
Good news to hackers: this hasn't been fixed in 26.6. Actually, it won't be fixed. Enjoy what you collect from people's clipboards. BTW you can also do the same with Microsoft Edge. Cheers! https://youtu.be/lLJkxWR71B0
-
Post #4145644
RE: https://mastodon.social/@mysk/116889369517349322 iOS 26.6 resets the clipboard counter after a reboot. This is the same change that Apple introduced in iOS 27 beta a while ago. Sadly no acknowledgment to Team Mysk or Project Loupe in the security release notes 😑
-
Post #4122396
Many of you have asked for a way to support the Loupe project. We want to keep Loupe free of in-app purchases, so instead we’ve created a Buy Me a Coffee page for anyone who’d like to show their appreciation. ☕ https://buymeacoffee.com/mysk
-
Post #4115888
RE: https://mastodon.social/@mysk/116974847786124516 🚨 PSA: Uninstalling Google Chrome on macOS doesn't remove Chrome's background updater. It keeps running until you remove: ~/Library/Application Support/Google/GoogleUpdater ~/Library/LaunchAgents/com.google.GoogleUpdater.wake.plist Then, restart.
-
Post #4065880
RE: https://mastodon.social/@mysk/116969508089535193 appleinsider inaccurately assumed that for the attack to succeed the user has to perform certain steps like archiving an restoring. This is wrong. All the user needs to do is run the malicious script. Now all websites are citing appleinsider 🤬 https://appleinsider.com/articles/26/07/24/trusted-mac-apps-could-possibly-be-swapped-out-for-malware
-
Post #3994149
Another change seems to be motivated by Loupe. Apple has deprecated the canOpenURL API that apps use to detect which apps are installed on the iPhone in iOS 27 Beta 4. Moreover, the deprecated API will only allow a maximum of 25 apps to be queried instead of 50 #privacy #infosec #Apple #ioS
-
Post #3900089
UPDATE: Apple doesn't see an issue here. We will disclose this issue on our blog. Stay tuned. https://mastodon.social/@mysk/116816065579359109
-
Post #3796473
@0@corteximplant.com Oh, I stopped dragging and dropping things in the Terminal since we published this: https://mysk.blog/2026/05/19/cve-2026-28910/
-
Post #3691534
Apparently Apple has fixed the clipboard counter in iOS 27 beta 3 thanks to Loupe. ✌️ Now the counter resets after a restart. Hey Apple, a little shoutout to the Loupe project would have been nice! Loupe is free and open source. You can download Loupe here: https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470 #privacy #iOS #Apple #beta #infosec #security
-
Post #3516487
Cool, so in the future we should expect an email like this: https://blog.playstation.com/2026/07/01/physical-disc-production-ending-in-january-2028-for-new-games-releasing-on-playstation-consoles/
-
Post #3512115
Just out of curiosity, I let Claude attempt to port Loupe to Android using skiptools. If you haven’t heard of Skip, it’s a tool that lets you produce native Android apps from a SwiftUI codebase. Loupe is written entirely in Swift and SwiftUI, so it should be a good match It’s still so surprising to me that this works at all. That said, I don’t think Loupe for Android is coming anytime soon since we have other stuff going on right now
-
Post #3512114
Loupe has earned 1,000 5-star ratings on the App Store and its GitHub repo has reached 1,2k stars. ✌️
-
Post #3512113
UPDATE: Michael Tsai @mjtsai confirms that all his search queries were included in the data he requested from Apple. Every iPhone user should learn that Apple&#39;s definition of privacy is different. Think different. Visit https://privacy.apple.com and request a copy of your data. #privacy #Apple #infosec
-
Post #3512112
🚨PSA: If you think you&#39;re a targeted individual, don&#39;t install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇 #privacy #Apple #security #infosec #cybersecurity
-
Post #3512111
Techlore reviewed Loupe in this great video: #privacy https://youtu.be/_n_SpEWtqog
-
Post #3467217
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps. Mullvad is aware of this issue. It is described in this blog: https://mullvad.net/en/help/why-wireguard You can download Loupe here: https://apps.apple.com/app/id6766152470 #iOS #privacy #infosec #security #cybersecurity
-
Post #2819728
On iOS and macOS, WhatsApp stores chat databases unencrypted in an app group container accessible to apps from the same developer. So all Meta apps on the same iPhone (e.g., Facebook) can read WA chats in plaintext without permission, and users wouldn't be notified. https://blog.cryptographyengineering.com/2026/02/02/whatsapp-encryption-a-lawsuit-and-a-lot-of-noise/ This is a demo we prepared recently to show a macOS bug that allowed unrestricted access to protected app containers. WhatsAp...
-
Post #2723168
RE: https://mastodon.social/@mysk/116557912618505785 This bug was reported to Apple on October 17, 2025. It has now been fixed and can be disclosed. Our initial assessment found it to be critical, so we paused all @psylo activities and focused on preparing excellent demoes to convince Apple of the bug&#39;s severity. After 206 days the issue was addressed. We were surprised it remained unpatched for so long, perhaps Apple had higher priority bugs.
-
Post #2723167
RE: https://mastodon.social/@mysk/116557828381660916 🚨 If you use Signal or 1Password on macOS, make sure you upgrade to: Tahoe 26.5 Tahoe 26.4 Sequoia 15.7.7 Sonoma 14.8.7 We&#39;re working hard to get the blog and videos out ASAP
-
Post #2723166
Bill C-22 would impact @psylo since Mysk is registered in Canada and we have proxy servers in Canada too. We will not change Psylo’s no-log policy. If bill C-22 passes as is, we would likely have to move out of Canada. https://mobilesyrup.com/2026/05/14/signal-threatens-canada-exit-over-law-bill-c-22/
-
Post #2723165
RE: https://mastodon.social/@mysk/116557828381660916 The blog post with all the technical details about this issue, which was addressed in macOS 26.4, is coming along nicely. We’re hoping to publish this week 🙌
-
Post #2723164
📝🚨 New blog post: How a bug in Archive Utility allowed access to protected app data (including iMessage and WhatsApp chats, and Safari cookies) without any permissions. The bug could also be exploited to hijack installed apps such as Signal and 1Password to perform phishing attacks. Apple fixed the issue in macOS 26.4 as CVE-2026-28910, five months after we reported it #Apple #macOS #privacy #security #cybersecurity #infosec https://mysk.blog/2026/05/19/cve-2026-28910
-
Post #2342607
🤯 Just received a spam SMS from an unknown sender and Apple Messages didn&#39;t disable the phishing link. The iPhone is running iOS 26.4.1. Links from unknown senders are normally disabled (not clickable) to protect against phishing attacks. Actually, iMessages enables the phishing link only when the conversation is opened for the first time after launch, then it is disabled until the app is relaunched. Not sure how to explain it. A video shows it better: #iOS #Apple #security #infosec
-
Post #2342606
Apple… this when? 👀 #privacy #Apple #iOS #Android
-
Post #2342605
RE: https://mastodon.social/@mysk/116442855044780865 The app finally has a name 🎉 More details dropping soon. #privacy
-
Post #2093255
iOS 18.4 introduced a new option in System Location Services called &quot;Improve Location Accuracy&quot; and it is enabled by default. You can find it under: Settings &gt; Privacy&amp; Security &gt; Location Services &gt; System Services #Privacy #infoSec
-
Post #2059840
🚨 .de domains are currently unreachable. Their DNS records seem to have been wiped out. The German central registry DENIC doesn&#39;t respond. #infosec #security #cybersecurity
-
Post #1729745
😱 iOS 26.4.2 still leaks the real IP when updating VPN apps. Motivated by Mullvad&#39;s recent blog, we made a website that logs the iPhone IP every second. We started Mullvad VPN, opened the website, then let Mullvad update in the background. See the leaks in action.. 🤯 Link to Mullvad blog post: https://mullvad.net/en/blog/force-all-app-traffic-into-the-tunnel #privacy #iOS #security #infosec
-
Post #1558894
Announcement: we are working on a new #privacy app for iOS that raises awareness about which device signals and data a native app can see once installed on the iPhone even without requesting any permission. The app is going to be free and open-source. #Apple #iOS #infosec
-
Post #1346148
RE: https://infosec.exchange/@psylo/115805879481993019 Psylo 1.2.0 was just approved by Apple 😁 You can now bring your own proxies, configure direct connection profiles (i.e. bypass proxies), and more Check it out today! https://apps.apple.com/ca/app/psylo-private-browser-proxy/id6741358035