TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

iMessage Preview Problems; leak your location by receiving a text message

36 pointsby deep_attentionover 8 years ago

11 comments

jonkneeover 8 years ago
tl;dr iMessage now previews links automatically<p>&gt; The updated iMessage loads the link preview and in essence clicks the link for you! That’s what irks us with this, the choice. OK we might not stop people clicking links anytime soon but Apple have taken this very choice away from us and facilitate the information leakage. The very act of receiving an SMS message can reveal your rough geographic location, your cellular operator, your current WiFi network.
评论 #12677806 未加载
评论 #12677632 未加载
jxyover 8 years ago
<p><pre><code> &gt; Early 2016 we were the first company in the UK to offer &gt; SMShing services. These SMS messages are like phishing &gt; emails and contain a pretext alongside a link within the &gt; message. When a mark receives an SMS message and clicks the &gt; link a host of details are available to us. </code></pre> This kind of thing happens with email too. In Apple Mail you can disable the loading of external contents. Does anyone know in detail how the preview in iMessage work?
omarforgotpwdover 8 years ago
Sending the requests from the client is probably not the most secure idea. Requests should be proxied through a cloud server on Apple&#x27;s end to reduce the security risk of these previews.
评论 #12677780 未加载
评论 #12678007 未加载
siskover 8 years ago
Incidentally, I received a bit of iMessage spam this weekend that I looked into. Was a series of 302s to an affiliate link. So this is actively being used right now for financial gain.
jafingiover 8 years ago
Apple should fetch the data via their servers instead of the clients&#x27;. It leaks way too much information.
评论 #12677701 未加载
O5vYtytbover 8 years ago
Many comments are in regards to fixing this feature. I think this is one of those situations where the feature (previewing links) is not a good idea in the first place, or at least do not enable it by default.
diegorbaqueroover 8 years ago
What&#x27;s wrong with web hosts nowadays? a few 100 users and everything dies.<p>Cached: <a href="https:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache%3Ahttps%3A%2F%2Ftheantisocialengineer.com%2Fimessage-preview-problems%2F&amp;ie=utf-8&amp;oe=utf-8" rel="nofollow">https:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache%3Ahttp...</a>
评论 #12677694 未加载
评论 #12678027 未加载
digi_owlover 8 years ago
I find myself thinking a recent story of an middle eastern human rights activist who&#x27;s iPhone was attempted hacked via a sms url. He avoided it by not tapping the url. I do wonder if this preview &quot;feature&quot; will help automate future attacks.<p>It seems that whenever we try to make software helpful we produce more problems.
0x006Aover 8 years ago
it also happens on the macOS and there is no way to disable it.
评论 #12677773 未加载
m0r0c4shover 8 years ago
Well it&#x27;s possible to disable imessage right?<p>Go to settings &gt; messages &gt; and disable iMessage.<p>That should be a temporary fix right?
osiover 8 years ago
imessage won&#x27;t auto-load previews until you ask it to do it the first time.
评论 #12677757 未加载