
Mysk 🇨🇦🇩🇪
@mysk_co • 19,066 subscribers
We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 📝https://t.co/69k7WAphKl 🇨🇦🇩🇪 Current Project: @psylo_app
Shorts
Videos

😱 iOS 26.4.2 still leaks the real IP when updating VPN apps. Motivated by Mullvad's recent blog, we made a website that logs the iPhone IP every second. We started Mullvad VPN, opened the website, then let Mullvad updated in the background. See the leaks in action.. 🤯
Mysk 🇨🇦🇩🇪724,338 Aufrufe • vor 1 Monat

😎🔬 Proton VPN just got updated. When iOS updated the app with the kill switch on, it was a total mess: iOS blocked internet for nearly 6 minutes, then terminated the app and its VPN tunnel, exposing iPhone traffic and IP. The VPN required a manual restart 😠. Watch this demo:
Mysk 🇨🇦🇩🇪103,363 Aufrufe • vor 1 Monat

Signal Desktop is not secure. With every vulnerability we discover on macOS, we find Signal Desktop to be an easy target. In this video, we show how a Signal session can be stolen and restored on a remote Mac without the user being aware. Only use Signal on iPhone or Android
Mysk 🇨🇦🇩🇪36,576 Aufrufe • vor 15 Tagen

Found another example: iTunes Store Zero Liquid Glass and untouched since the iOS 7 flattening, but still you can get the latest Taylor Swift album The best part: the app still lets you customise the bottom tab bar, a feature that existed when iOS was still called iPhone OS
Mysk 🇨🇦🇩🇪80,590 Aufrufe • vor 7 Monaten

Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entries—a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :
Mysk 🇨🇦🇩🇪156,170 Aufrufe • vor 1 Jahr

🎬 So this scam #2FA app is using custom product pages of Apple Search Ads to trick users. It has different campaigns per search keywords. When searching for "Microsoft Authenticator", it shows screenshots highlighting "Microsoft". and when searching for "Google Authenticator", it highlights "Google". Watch the video 🤯 It's worth noting that custom product pages need to be approved by App Store Connect and Apple Search Ads. This app steals 2FA secrets and its model is very suspicious as noted below. #Privacy #Apple #iOS #cybersecuritytips
Mysk 🇨🇦🇩🇪66,693 Aufrufe • vor 2 Jahren

This is how you choose a default browser in iOS 17.4 in the EU. The prompt shows a list of browser options. Tapping on a browser option opens the browser's page on the App Store. What happens if any of these browsers is only available on an alternative marketplace?
Mysk 🇨🇦🇩🇪13,023 Aufrufe • vor 2 Jahren
Keine weiteren Inhalte verfügbar