Security expert hijacks Apple's Find My network to share data with a Linux device

https://cdn.mos.cms.futurecdn.net/AkzcwhimnzzysrwQDQfyAe-2000-80.jpg
  • Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware
  • The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users
  • The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed

Apple keeps the full Find My experience locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.

A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE