Showing posts with label iOS. Show all posts
Showing posts with label iOS. Show all posts

Tuesday, June 17, 2025

Watch Out for LEGAL Scams: App that Cost WAY TOO MUCH on Subscription

For those who don't operate multiple phones... Androids use JPEG (or JPG), but iPhones use HEIC. The two standards are NOT compatible. If you share a photo from iPhone straight to Android, it will not be viewable. So what do you do? 

You convert it. 

Except the first convert I ran into is... essentially a scam. It basically won't do anything unless you engage the "free trial" which means you'll be charged in 3 days. It didn't exactly mention what's the cost. Then I looked at the email I just got:

Auto-renew subscription of $14.99 PER WEEK for an image converter?!

This app subscription costs $14.99 PER WEEK. 

Not per year. Not per month. PER WEEK?!

And this app doesn't even do HEIC to JPG, despite its name, "Image Converter Premium". 

Needless to say, I cancelled ASAP. 

Thursday, May 15, 2025

Cybersecurity: Seems Most People Think Most Cybercriminals are Uberhackers... They aren't!

One of the things I do on Reddit is hang out in /r/cybersecurity_help, and tell people what they claim was impossible. Like "I got hacked through ______". 

I don't mind people not believing me. Honest truth is sometimes hard to believe, or let's use Chinese proverb, 忠言逆耳. 

Two MONTHS ago, someone decided to post a portion of their iPhone's log, believing it contains evidence of them being monitored. Except it contained no such thing. It's quite easy to Google all the suspicious keywords like "tracked" and "proactiveHarvesting"... They are all built by Apple. So I replied there's nothing here that indicates anything about you being monitored. 

OP pivoted to a different theory, like "what if they hack me through Bluetooth or something else? I can find evidence of intrusion? "

I replied that you can't be hacked through Bluetooth nowadays, esp. if you have a modern iPhone and keep stuff updated. And evidence of intrusion had to be gathered by forensic analysis. It's not something regular folks can just run an app and "voila, evidence!". 

Then yesterday, some OTHER random guy decided to necro the topic from 2 months ago (and even OP had left the topic), and started blabbing about "Bluetooth hacking, just search for it."

As a cybersecurity professional, I am QUITE familiar with state of Bluetooth hacking. With noderm iPhones, the best you *can* do without some Zero-day exploit was Bluespam (keep popping up "trying to connect") 

There are other Bluetooth hacks, but they don't result in being able to control the iPhone. Just to summarize: 

Bluejacking -- the targeted user accepts the pairing attempt from a peripheral, which of course, results in the peripheral, acting as a keyboard and mouse, gaining some control of the iPhone. This is NOT done easily, as the user must ACCEPT the pairing attempt. It's not done invisibly or automatically. 

Bluesnarfing -- by using some exploits on VERY old firmware, hacker can transfer files the target phone. Again, only on very old firmware with problems. And most files "shared" this way are just regular stuff, like calendar, contacts, photos, texts, videos, and such. Stuff you normally use BT to transfer. They can't suddenly reach out into Banking app and take your account number and balance (at least, not with bluesnarfing alone). 

Bluebugging -- the most dangerous, but requires a VERY dangerous exploit that basically gave the attacker full control of the device through Bluetooth. You pretty much have to be running ANCIENT (like 5-10 year old) hardware and firmware with no security updates. 

Blueborne hacking -- a bunch of vulnerabilities discovered in 2017 (yes, 8 years ago) that got grouped together even though they are spread across iOS, Android, Windows, and even Linux, and some embedded OS, due to a Bluetooth problem. When it came to iOS, Blueborne problem was... an audio protocol over Bluetooth, called LEAP: Low Energy Audio Protocol. Guess what iOS was this fixed in? iOS 10. That's right. iOS 10. We're now on... iOS 18.5. 

Really, that's it. 

So I replied something like "Bluetooth hacking is from YEARS ago and usually doesn't even involve smartphones, but peripherals." 

His reply? "Those Flipper devices are something huh?"

Except there's only one: Flipper Zero, and while it *can* "hack" BT and BLE, the worst they can do to iOS is Bluespam. They are not capable of anything like Bluejack, Bluesnarf, Bluebug, or Blueborne. So it's completely irrelevant to the original topic. 

What was the purpose of the reply and who was he supposed to impress by mentioning a few keywords? I honestly have idea. Was he expecting to stump me? 

Frankly, to the average "civilian" (who's not in cybersecurity), the "hackers" seems like wizards, when most of them are actually scriptkiddo that can barely follow instructionss on a PC. They may be lead by someone who's somewhat more skilled, but they are hardly a "live in parents' basement" misunderstood genius stereotypical geek. 

Cybercriminals are usually NOT uberhackers. They can barely follow standard script. They are worse than scriptkiddies (or scriptkiddos). 

In fact, most civilians can't even distinguish device being hacked vs. account being hacked. 

Whether this is due to lack of compuiter literacy, I have no idea. 

And with the advent of AI, which can be used to further disguise the lack of compute literacy, things can only get worse. 

Guess that keeps us cybersecurity experts employed. 

Friday, March 14, 2025

App Discovery: Spacedesk by Datronicsoft

As you use more and more tech, you object have extra old tech left over. If you have an old tablet left over, have you wondered what you should do with it? 

How about turn it into an extra display for your desk accesories that you don't want to take up extra desktop space? 

I have an old Nexus 7 (2nd gen) tablet, too old and too slow for 2025, but it's fast enough to act as a secondary display. I cleaned it up (removed all the old apps I don't use), uninstalled a bunch of crap, then went to 

https://www.spacedesk.net/

And downloaded the "driver" for the PC. Then went to Google Play Store (yes, my Nexus 7 can still access it) and downloaded the Spacedesk app.  I connected the USB cable between the 2, set the tablet on file transfer mode, fiddled with it a bit, the driver software saw the app, and voila, I have a 4th screen. 

This will also work in Wifi, but wired is more secure and faster. 

My triple-wide desktop, now with a small 4th display.
I stuck my desktop widgets and other stuff there.  

The software is FREE for personal use. If you have Spotify or Stock Ticker or Weather, Clock, and so on, put in on that display for extra clean look of your desktop. 

And happy "Pi" Day. 

(3/14, get it?)

Sunday, December 29, 2024

App Discovery: Destiny, the secure cross-platform file transfer method

Want to transfer a file across platforms (Windows, MacOS, iOS, Android, Linux) but can't find common ground? Destiny can help. Download from

https://github.com/LeastAuthority/destiny?tab=readme-ov-file#installation

There is nothing to set. If both platforms are on the same network (i.e. phone to PC, or vice versa), simply sender run the app and pick SEND, and receiver pick RECEIVE. Then sender choose the file to send, and a passphrase is generated, easy to type in English. As soon as receiver type in the same passphrase, file transfer will start, and since it's happening at local network speed, it's almost instantaneous.  

The client, using "magic-wormhole" protocol, will automatically negotiate alternative protocols if you are on different networks, through the Internet, and so on. And the traffic is encrypted. No interception. Remember, cross platform too. You can go any client to any other client. You can send the passphrase through any "normal" means: SMS, encrypted chat, email, or even call them up and tell them. 

I've tested Android to PC and vice versa on local network. It works great. Previously I had to rely on Google Drive or DropBox to sync the files, and I've also purchased a "Wifi Server" where the Android app hosts a GUI that allows a browser to access the local storage. First is slow, second is a little PITA to run. This manages to be neither. 

My only nitpick is you can only transfer ONE FILE AT A TIME. For each file, you have to initiate a send, and thus, a new passphrase. Not quite frictionless, but for the amount of security it provides, it's almost unbeatable. 

So if you need to frequently transfer single file between your devices, this is a very simple way to do it. Worth a try, at least.