Proxy server for Siri
github.com
github.com
- Installing root CA. - Setting up the proxy on ec2 instance. - Setting up a custom DNS server on that instance, to override the Siri domain. - Setting up the iPhone to use that DNS server, or if not possible, setting it up to use a VPN and through the custom DNS.
And the end result is a Siri that always works and that you can use to run code on an ec2 instance. You'd be able to hook it up to third parties APIs, like Twitter or Facebook.
Edit: Success! I'm not running it on EC2 yet, just my home network. Basically I've got dnsmasq on my router redirecting guzzoni.apple.com to my home fileserver with SiriProxy running. The router is also running a PPTP VPN server. I can use the VPN over 3g to make Siri requests and see the output on my local machine. Thanks again for the VPN idea; that's gold. Next step - to the cloud!
If you're running it on Linux, use iptables to redirect the port to something you can use without root: http://www.cyberciti.biz/faq/linux-port-redirection-with-ipt...
From Daniel Bernstein(qmail creator) at http://cr.yp.to/qmail/qmailsec-20071101.pdf
"I have become convinced that this “principle of least privilege” is fundamentally wrong. Minimizing privilege might reduce the damage done by some security holes but almost never fixes the holes. Minimizing privilege is not the same as minimizing the amount of trusted code, does not have the same benefits as minimizing the amount of trusted code, and does not move us any closer to a secure computer system."
If you're a software developer who is not doing security research, and who is mainly interested in some functionality offered by a module, you'd be better off giving the module exactly the privileges it needs, not more and not less. If not, wouldn't OS's run all user-space programs in ring-0? (Maybe I am stretching it a bit)
If Bernstein meant that this principle has been misquoted/abused/understood in all wrong ways (like most of the "premature optimization" quotes), then perhaps it makes some sense. :)
Just use "curl http://www.example.com/install_this.sh | sudo sh"!
Since you're not tampering with the iPhone's hosts file, and use, let's say, your home PC for handling the guzzoni.apple.com dns + CA for level certs.. I'm wondering how you send the request to the actual guzzoni.apple.com? I mean, if you do $ curl -s https://guzzoni.apple.com on the home PC, it would respond with the localhost server as you've rerouted it to 127.0.0.1 in the home PC's hosts file - or am I missing something here?
Should I use two PC's, one for handling the iPhone interaction, and one as "backbone" which can reach the real guzzoni.apple.com?
Or am I suppose to run a dns service which responds <internal ip of home PC> for SOME devices, but real dns for others (e.g. home PC)?
make sure that computer is not using your DNS server!
So, your iPhone uses your special DNS server, while your computer doesn't."Siri start my truck" "Siri feed the dog"
Probably in less than one month will be available.
In any case, I don't see why would they care unless more than one person starts using the same UUID. If you bought an iPhone to use the service, they already got the money.
In the future, they will sell analytics, access to be included and potentially ads.
https://www.apple.com/pr/library/2011/04/27Apple-Q-A-on-Loca...
At some point in the past they hadn't broken into the phone market, or had a music store, right? Think of it a bit like how Google created AdWords/AdSense alongside their search engine.
I got a 4s the other day and outside of the US at this point, Siri is pretty basic. Can't ask for directions. Can't find a business. Too many things get directed to a basic web search which I could've pulled up myself in the time being. Didn't take too long to realise how quickly they could monetise the experience my charging for third-party involvement, for data, etc. "When's the next SportsTeam game?" "April 1, do you need tickets?"
Apple is a company. They're there to make money. I can't see how they could not take that route if they handled it very carefully.
Technically, I suppose they could be shared, but I guess Apple would find out and terminate the account pretty soon.
Unlike iOS develoeprs, Android developers are not a homogenous group with a single vision. They are a diverse group of people, and there will no doubt be someone amongst them who will make such an app.
> In the middle of a patent trial?
I don't see the relevance of "a patient trial" to a 3rd party developer unaffiliated with Google making an app to harness Siri on Android.
> I'd expect all the big markets to not allow the app.
Fortunately, unlike iOS, Android doesn't suffer from a locked down app installation procedure that prevents sideloading. So the developer could just offer the .apk file on his site for all and sundry to download and use.
However, IANAL, and I would definitely wait for at least a few weeks after release before trying it out myself.