‹ BackHN Continuity

Thread

WaveDigger: Dig into wireless signals to discover their physical locations

139 points · 28 comments · 882542F3884314B

  1. oulipo · · focus · HN ↗
    Interesting, wondering why Apple doesn't restrict the queries to its server using a certificate that would be pinned on the devices, etc, so at least you would need a legit iPhone/Mac to be able to do a query?
    1. mcculley · · focus · HN ↗
      Are you imagining some certificate unique to each device? What would prevent someone copying it?
      1. oulipo · · focus · HN ↗
        This is quite common, you add the private key to some secure hardware module, so that only that device can sign using the certificate, and then use TLS to connect
        1. mcculley · · focus · HN ↗
          I get that this is how iMessage works, as I understand it. I am wondering what tradeoffs make Apple decide to use the Secure Enclave versus more mundane certificate infrastructure and how they would make it hard for us to get at this with a debugger if they chose that route.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.