Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anthropic CEO calls for pacing AI frontier model development and warns ‘in 6–12 months such a swarm [of agents] could be capable of taking over the entire internet’

    September 12, 2026

    Android malware creates a hidden copy of your banking app

    September 12, 2026

    iPhone 18 Pro and iPhone 18 Pro Max Now Available to Pre-Order

    September 12, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Saturday, September 12
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Security expert hijacks Apple’s Find My network to share data with a Linux device
    Reviews

    Security expert hijacks Apple’s Find My network to share data with a Linux device

    myappsplusBy myappsplusAugust 26, 2026004 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Security expert hijacks Apple’s Find My network to share data with a Linux device
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Researcher registers Linux machine as a trusted device on <a href="https://myappsplus.com/apple-just-turned-mac-minis-into-ai-supercomputers/” title=”Apple Just Turned Mac Minis Into AI Supercomputers”>Apple‘s Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware
    • The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users
    • The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed

    Apple keeps the full Find My experience locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.

    A 22-year-old security researcher who goes by “Zerotistic” documented how they registered an ordinary Linux machine as a trusted node on Apple’s network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.

    Find My, Apple’s catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.

    An interesting trick that still requires consent to get the job done

    The task is not an easy one to begin with: convincing Apple’s back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information sharedt going

    It is important to clarify here that Apple’s system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.

    Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple’s private language to query its servers and process the information it received.

    It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple’s internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.

    Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.

    The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend’s Apple device to the Linux box, masquerading as one.

    What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn’t require a jailbreak, a leaked key, or even a Mac to do the job. Instead, open-nd-error approach that eventually paid off

    The technique has its limitations: attacks can not target a stranger, and consent is required to track even one’s friends. It shows that Apple’s boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.

    Apple has yet to respond to media queries about whether it plans to address the demonstrated trick or patch the loop in the near future.

    Computing Computing Security Cyber Crime Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    How to watch Ohio State vs Texas: live streams of NCAA college football 2026 Week 2

    September 12, 2026

    NEC drops its quantum computing work, marking an end to nearly 30 years of development

    September 12, 2026

    Ryan Garcia vs Conor Benn live stream — how to watch boxing online from anywhere, non-PPV options, fight card

    September 12, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20263 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    myappsplusAugust 18, 2026

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    myappsplusAugust 18, 2026

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Apple Wallet driver’s licenses are coming to North Carolina, but there’s a catch

    August 18, 20260 Views

    3 Japanese AI Stocks Turning Automation Spending Into Real Revenue

    August 18, 20260 Views

    Apple: DOJ’s latest challenge in antitrust case ‘fails at every level’

    August 18, 20260 Views
    Our Picks

    Anthropic CEO calls for pacing AI frontier model development and warns ‘in 6–12 months such a swarm [of agents] could be capable of taking over the entire internet’

    September 12, 2026

    Android malware creates a hidden copy of your banking app

    September 12, 2026

    iPhone 18 Pro and iPhone 18 Pro Max Now Available to Pre-Order

    September 12, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.