macOS is background scanning and following downloaded QR codes?
twitter.com
twitter.com
Though I gotta say, this is still an attack vector that I hadn't considered. If you use a VPN and occasionally rotate IPs, this Firefox "recents" feature can leak your new IP to websites that you previously visited.
The behavior's still concerning in any case, whether it's macOS silently doing it or Firefox silently doing it.
But I wouldn't be surprised if it fetches URL's in QR codes in order to index the title text associated with the URL for Spotlight. It's not so different from when you text someone a URL in Messages, it automatically shows a title and thumbnail to both parties. Or, if it's just a shared "preview" library used across thumbnails and iMessage.
I'm not sure what to think about it. Previews, smart text, showing URL information on hover, prefetching, indexing, etc. -- it's all pretty standard stuff. On the other hand, it does feel a little weird for previews on a local filesystem to query the internet -- we're totally used to it in e-mail and messaging though. But, I used to keep bookmarks as URL (.url) files. It would seem natural for a thumbnail of the page to show up in Finder (though I don't think it does this?).
As for it being an "attack" to get someone's IP -- seems like that ship has long since sailed, as it's common for any messaging and e-mail client to already show previews. If you need to protect yourself against all of those, you pretty much need to figure out what level of Little Snitch or turning off internet or airgapping is required for your security concerns.
It's not exactly malicious, but weird "we know better than you" behavior like this ultimately drove me away from MacOS as a daily-driver.
These aren't scanned, they're located inside .png image files you can download or generate locally on your computer.
> You're going to be fetching/caching the favicon and framebuffer for the page anyways, there's literally no reason not to get that data at runtime rather than 3 hours later.
No one asked the OS to fetch the favicon/framebuffer. Also, I would prefer the favicon of an image containing a QR code to be a thumbnail of the QR code, not the page it points to. I expect this delay is not a nefarious Little Snitch bypassing tool but a search cache update process that only runs when the computer is very idle. Better to run background tasks lazily than every time you commit an image that might contain a QR code to the filesystem.
In general, these things frustrate me just as much as they did on Windows. I don't want random processes jumping up to use 100% of my CPU for no reason. I can't even count the number of times my Mac gets pinned by mdworker processes running in the background. It's reminiscent of pulling my hair out trying to understand why OneDrive or Edge is pinning one of my cores even though it isn't open.
My overall gripe is this pattern of behavior. I'd rather spend 2-5 seconds waiting for my QR code to load instead of my OS deciding to randomly cache it at some indeterminate point. Maybe other people disagree, though. Us HN users don't really tend to reflect the opinions of Joe Shmoe and his feelings towards modern computing.
...on the other hand, this is the exact same technology Apple lets China use to hunt down their religious and political minorities. Maybe they don't intend harm to Americans, but one thing is for certain; Apple doesn't treat privacy as a human right. If you can live with that, then more power to you.
QR codes? HTTP requests? I’m not sure what technology you’re referring to.
> one thing is for certain; Apple doesn't treat privacy as a human right.
They have put a huge amount of effort into privacy technology; more than any comparable company I can think of. I don’t think your certainty is even remotely justified.
Do you expect your images to be scanned on disk and the links in them to be opened, leaking your ip? What if you do something as simple as screenshot an address bar in a browser? Save a menu QR code?
Now you are sending out traffic, accidentally, with your full ip to random places due to a service Apple inserted that you have no knowledge of.
Do you know every site that has received your ip address?
I think the honest answer to both of these questions has to be no.
Throw that to disk for me so I can map where you are, where you go, when your machine is up and how often your search indexing runs.
I could send you a QR code that I've setup specifically to get your IP address.
And that's how the pegasus/etc. pwned iPhones
As for the high protection mode - of course that reduces the attack surface.
facebookexternalhit/1.1 Facebot Twitterbot/1.0
What.
"This is the iMessages app's crawler [...] Apple has chosen to use this useragent in their iMessages app to ensure the unfurling of the URL and the rich preview works more often than not."²
Or maybe we should group up a massive list of poor decisions into a formal complaint?
Neither of which require, nor to be honest even makes any sense to, go to the URL that the QR code represents.
Obviously if this is a background daemon that runs periodically then my test wouldn't catch it (unless I got "lucky") and for a longer-term test I'd probably want to use something other than request bin. That said request bin says it keeps bins for 48 hours so that might be enough time.
Indeed. This is a really bold claim and so far we have one person who has reproduced it on a single machine.
I'm no Apple apologist by any means but I'm a little skeptical of the claims in the twitter thread. It's easy enough to imagine that the poster made some kind of mistake in his methodology or some other variables are at play that he didn't consider. I'd withhold judgment until there's some corroboration.
Messages on my iPhone shows me link previews for links sent to me via SMS, not just via iMessage. I just checked to make sure. Those are necessarily generated on the recipient's end.
This could be due to it being sent from someone in your contact list: https://support.twilio.com/hc/en-us/articles/360013199334-Ho...
If macOS really is background-scanning all images, and if Messages.app actually writes all received images out to disk as individual image files, then the background scanning could conceivably scan it. However I haven't seen anyone make this claim, it certainly doesn't seem necessary (why write it out to a file on disk?), and if this scanning is triggered by e.g. Spotlight indexing then it wouldn't be indexing cache files anyway.
So, has anyone actually demonstrated that sending a QR code over iMessage causes the recipient's device to fetch the URL? Because so far this just seems like complete speculation presented as fact.
I have, just now. Nothing happened at either end - the URL was not accessed at all. I can get it to recognise it's a QR code on my iPhone by tapping to focus the image, waiting for the OCR badge, tapping that, and then tapping the image again to bring up a small menu with the URL as a title and headed by "Open in Safari". None of those steps accesses the URL. You have to make a conscious action to access the URL...
It was between two devices on the same Apple ID though via AirDrop, so maybe it only did it because the device was "trusted".
Question is, can you disable it?
Anyone want to buy a lightly used MacBook Air M1?