@ryanaraine
Ryan Naraine
5 years
Everytime I bump into Apple security friends at cons, I ask them to peek at my iOS settings for red-flags. The first place they tap is to look at installed configuration profiles
20
259
608

Replies

@nptacek
CuddlySalmon | nptacek.eth
5 years
@ryanaraine From the link you posted: “Apple has removed some apps from the App Store that install root certificates that could allow monitoring of data.” — article was originally posted back in September, any idea what apps they were referring to back then?
1
0
6
@ryanaraine
Ryan Naraine
5 years
@nptacek No idea. I know there are tons in the VPN space doing this on the downlow
1
0
5
@Mao_Ware
Brian Bartholomew
5 years
@ryanaraine So you're saying you're like that Uncle who always asks you to make their computer faster when you go to their house for dinner?
1
0
3
@ryanaraine
Ryan Naraine
5 years
@Mao_Ware Which reminds me, I need you to look at something on my new Traeger smoker.
1
0
5
@marksiple
Mark Siple
5 years
@ryanaraine I deleted the app and the config profile disappeared from the config profiles by itself. Has that been your experience?
1
0
1
@ryanaraine
Ryan Naraine
5 years
@marksiple I never had a problematic profile, so I have no first-hand experience. I believe deleting the app automatically removes the profile but it doesn't hurt to double check
1
0
1
@Jose_Pagliery
Jose Pagliery
5 years
@ryanaraine You lost me. Settings > General > then what?
2
0
6
@ryanaraine
Ryan Naraine
5 years
Tweet media one
3
0
18
@lclaytonparker
Lee Parker
5 years
@ryanaraine It's VPN renewal time... anyone know where to find a list of providers that *don't* track?
2
0
0
@ryanaraine
Ryan Naraine
5 years
@lclaytonparker You may not even need a VPN. Think about that as well...
2
0
0
@rjunkapoor
Arjun
5 years
@ryanaraine Any VPN companies you would trust/not trust?
1
0
0
@ryanaraine
Ryan Naraine
5 years
@a_r_j_u_n_e My company's corporate VPN :)
1
0
0
@ehansalytics
Ed Hansberry - MVP
5 years
@ryanaraine Apps that use hockeyapp vs test flight usually require these certs.
0
0
0
@finnigja
Jamie Finnigan
5 years
@ryanaraine Is that like asking your doctor friends to check out the weird oozing lump on your backside?
1
0
4
@cuniiform
CUNII🧚🏻FORM 🆗✖️
5 years
@ryanaraine @hacks4pancakes I once clicked on a pop up ad (i know I know I shouldn’t have done that) advertising an app that gives earthquake alerts or something. Instead of sending me to the App Store it opened settings asked to install a profile. I noped out immediately
1
0
10
@drunknbass
ssɐquʞunɹp  𝕏 ᯅ
5 years
@ryanaraine Tell that to the older folks that install root CA via config profiles because they get "daily horoscope emails". 🛴
1
1
1
@JohnMar36377819
John Marks
5 years
@ryanaraine Thank you.
0
0
0
@deepthoughts10
Brian Clark
5 years
@ryanaraine Great tip!
0
0
0
@ryanaraine
Ryan Naraine
5 years
@ivladdalvi That’s some cringe-worthy targeting of ads. Jeebus.
0
0
2