Hacker News with Generative AI: Mobile Security

Homomorphic Encryption in iOS 18 (boehs.org)
You are Apple. You want to make search work like magic in the Photos app, so the user can find all their “dog” pictures with ease. You devise a way to numerically represent the concepts of an image, so that you can find how closely images are related in meaning. Then, you create a database of known images and their numerical representations (“this number means car”), and find the closest matches. To preserve privacy, you put this database on the phone.
Ask HN: Why do banking apps care about your phone OS (ycombinator.com)
Many banking apps require a non rooted phone and up to date OS, but even those phones can run a browser which provides access to the bank website, often with more functionality than the app.
A New Phone Scanner That Detects Spyware Has Found 7 Pegasus Infections (wired.com)
The mobile device security firm iVerify has been offering a tool since May that makes spyware scanning accessible to anyone—and it’s already turning up victims.
FBI Warns iPhone and Android Users–Stop Sending Texts (forbes.com)
Timing is everything. Just as Apple’s adoption of RCS had seemed to signal a return to text messaging versus the unstoppable growth of WhatsApp, then along comes a surprising new hurdle to stop that in its tracks. While messaging Android to Android or iPhone to iPhone is secure, messaging from one to the other is not.
Android Trojan that intercepts voice calls to banks just got more stealthy (arstechnica.com)
Researchers have found new versions of a sophisticated Android financial-fraud Trojan that’s notable for its ability to intercept calls a victim tries to place to customer-support personnel of their banks.
Man locked out of Google Drive and loses 9 year old photos after SIM Swap attack (bbc.co.uk)
A man says he has lost files, business records and all his online photos after "failings" by his mobile phone provider allowed fraudsters to take control of his phone.
Google Chrome will soon block password autofills if Android phone gets stolen (androidauthority.com)
Google Chrome for Android is preparing to add support for Identity Check, an upcoming feature that will force apps to use biometric authentication when your phone is outside of a trusted location.
Understanding the Android Virtualization Framework (AVF) (medium.com)
As the complexity of mobile applications and the sensitivity of the data they handle increase, so does the need for robust security solutions. Enter the Android Virtualization Framework (AVF), a groundbreaking innovation designed to enhance security, efficiency, and flexibility in Android devices.
Has my mobile security advice changed? (shkspr.mobi)
A decade ago, I appeared on the 361 Podcast to give my advice about mobile security.
Jailbreak Your Enemies with a Link: Remote Execution on iOS (jacobbartlett.substack.com)
This is the story of the Trident exploit chain: 3 zero-day vulnerabilities in iOS that enabled the first remote jailbreak. Part #1 dives into the internals of the JavaScriptCore runtime: where a vulnerability lurks in WebKit which would crack your iPhone wide open.
New Phishing Technique Bypasses Security on iOS and Android to Steal Bank Creds (securityweek.com)
Flaw has Microsoft Authenticator overwriting MFA accounts, locking users out (csoonline.com)
Hackers Steal Phone, SMS Records for Nearly All AT&T Customers (krebsonsecurity.com)
Europol says Home Routing mobile encryption feature aids criminals (bleepingcomputer.com)
Twilio breach leaks over 30M Authy-linked phone numbers (androidpolice.com)
3M iOS and macOS apps were exposed to potent supply-chain attacks (arstechnica.com)
British duo arrested for SMS phishing via homemade cell tower (theregister.com)
Apple has rejected UTM SE from the iOS and third party App Stores (twitter.com)
Attacking Android Binder (androidoffsec.withgoogle.com)
Hacking phones is too easy (economist.com)
Deleted iPhone photos show up again after iOS update (malwarebytes.com)
Bank scammers using genuine push notifications to trick their victims (shkspr.mobi)
Cracked Rabbit R1 APKs running on Android phone (twitter.com)
Over a billion users could be at risk from keyboard logging app security flaw (techradar.com)