Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mysk🇨🇦🇩🇪

@mysk@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity 🇨🇦🇩🇪

3230 Followers
168 Following
50 Posts
Joined February 14, 2023
X:
https://x.com/mysk_co
Blog:
https://mysk.blog
YouTube:
https://youtube.com/@mysk
Old Mastodon:
https://defcon.social/@mysk
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3w ago
RE: https://mastodon.social/@mysk/117264670021439841 Happy iOS 27 Day! Bookmark this post if you want to disable Apple Intelligence. Apple buries the option in "Screen Time". Apple joins other Big Tech companies in making it tougher to opt out of AI features that send data off-device.
Open quoted post
Quoting
Mysk🇨🇦🇩🇪
@mysk@mastodon.social
In iOS 27, there’s no longer simple toggle to disable Apple Intelligence entirely. Some features like Writing Tools can also send data off-device for processing through Private Cloud Compute After some digging, here’s how to disable Writing Tools: 1️⃣ Settings → Screen Time 2️⃣ Content & Privacy Restrictions → turn it on 3️⃣ Siri → Writing Assistance → Don’t Allow #Apple #Privacy
Open quoted post
mastodon.social

Mysk🇨🇦🇩🇪: "In iOS 27, there’s no longer simple toggle to dis…" - Mastodon

184
1
238
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3w ago
In iOS 27, there’s no longer simple toggle to disable Apple Intelligence entirely. Some features like Writing Tools can also send data off-device for processing through Private Cloud Compute After some digging, here’s how to disable Writing Tools: 1️⃣ Settings → Screen Time 2️⃣ Content & Privacy Restrictions → turn it on 3️⃣ Siri → Writing Assistance → Don’t Allow #Apple #Privacy
161
0
112
1
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 1w ago
So on a Pixel 9 with Android 17, there’s no way to copy text from a photo offline and without sending it to Google? All these AI features on Pixel phones and basic OCR still can’t run locally?
5
1
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
RE: https://mastodon.social/@mysk/116974847786124516 🚨 PSA: Uninstalling Google Chrome on macOS doesn't remove Chrome's background updater. It keeps running until you remove: ~/Library/Application Support/Google/GoogleUpdater ~/Library/LaunchAgents/com.google.GoogleUpdater.wake.plist Then, restart.
mastodon.social
76
0
113
1
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 1mo ago
📝 New Blog Post: Thoughts on Responsible Disclosure We recently disclosed issues in WebKit that affected Psylo and iCloud Private Relay. This has sparked some debate, so we want to explain our reasoning and share some thoughts on responsible disclosure https://mysk.blog/2026/08/25/responsible-disclosure/
mysk.blog
7
1
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago

🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇

#privacy #Apple #security #infosec #cybersecurity

mastodon.social

Mastodon

33
5
41
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
RE: https://mastodon.social/@mysk/116889369517349322 iOS 26.6 resets the clipboard counter after a reboot. This is the same change that Apple introduced in iOS 27 beta a while ago. Sadly no acknowledgment to Team Mysk or Project Loupe in the security release notes 😑
Open quoted post
Quoting
Mysk🇨🇦🇩🇪
@mysk@mastodon.social
Apparently Apple has fixed the clipboard counter in iOS 27 beta 3 thanks to Loupe. ✌️ Now the counter resets after a restart. Hey Apple, a little shoutout to the Loupe project would have been nice! Loupe is free and open source. You can download Loupe here: https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470 #privacy #iOS #Apple #beta #infosec #security
Open quoted post
mastodon.social
14
0
3
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps. Mullvad is aware of this issue. It is described in this blog: https://mullvad.net/en/help/why-wireguard You can download Loupe here: https://apps.apple.com/app/id6766152470 #iOS #privacy #infosec #security #cybersecurity
mullvad.net
31
0
26
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Apparently Apple has fixed the clipboard counter in iOS 27 beta 3 thanks to Loupe. ✌️ Now the counter resets after a restart. Hey Apple, a little shoutout to the Loupe project would have been nice! Loupe is free and open source. You can download Loupe here: https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470 #privacy #iOS #Apple #beta #infosec #security
Loupe: What Apps Can See App - App Store
App Store

Loupe: What Apps Can See App - App Store

Download Loupe: What Apps Can See by Mysk Inc. on the App Store. See screenshots, ratings and reviews, user tips, and more apps like Loupe: What Apps Can See.

19
2
11
1
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3w ago
Replying to
@wdormann@infosec.exchange No idea. It's puzzling that one has to change such important settings in "Screen Time". For me, the most important thing is to disable the writing tools of Apple Intelligence because it doesn't process text on-device.
1
1
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Good news to hackers: this hasn't been fixed in 26.6. Actually, it won't be fixed. Enjoy what you collect from people's clipboards. BTW you can also do the same with Microsoft Edge. Cheers! https://youtu.be/lLJkxWR71B0
8
1
8
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago

Loupe has earned 1,000 5-star ratings on the App Store and its GitHub repo has reached 1,2k stars. ✌️

11
0
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Cool, so in the future we should expect an email like this: https://blog.playstation.com/2026/07/01/physical-disc-production-ending-in-january-2028-for-new-games-releasing-on-playstation-consoles/
blog.playstation.com
7
0
3
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
RE: https://mastodon.social/@mysk/116969508089535193 appleinsider inaccurately assumed that for the attack to succeed the user has to perform certain steps like archiving an restoring. This is wrong. All the user needs to do is run the malicious script. Now all websites are citing appleinsider 🤬 https://appleinsider.com/articles/26/07/24/trusted-mac-apps-could-possibly-be-swapped-out-for-malware
mastodon.social

Mysk🇨🇦🇩🇪: "🚨 We're disclosing a macOS security bug that Appl…" - Mastodon

4
1
3
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago

Just out of curiosity, I let Claude attempt to port Loupe to Android using skiptools. If you haven’t heard of Skip, it’s a tool that lets you produce native Android apps from a SwiftUI codebase. Loupe is written entirely in Swift and SwiftUI, so it should be a good match

It’s still so surprising to me that this works at all. That said, I don’t think Loupe for Android is coming anytime soon since we have other stuff going on right now

7
0
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago

Techlore reviewed Loupe in this great video:

#privacy

https://youtu.be/_n_SpEWtqog

6
0
3
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Replying to
Of course, now we publish, it goes viral, then Apple fixes it quietly in the next update. It happened before. At least it is not a duplicate 💪 Any tech journalists interested in covering this bug, please reach out. We're gonna do an embargo before we publish the blog
3
2
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago

Bill C-22 would impact @psylo@infosec.exchange since Mysk is registered in Canada and we have proxy servers in Canada too.

We will not change Psylo’s no-log policy. If bill C-22 passes as is, we would likely have to move out of Canada.

https://mobilesyrup.com/2026/05/14/signal-threatens-canada-exit-over-law-bill-c-22/

mobilesyrup.com
8
0
7
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Replying to on corteximplant.com
@0@corteximplant.com Oh, I stopped dragging and dropping things in the Terminal since we published this: https://mysk.blog/2026/05/19/cve-2026-28910/
mysk.blog
4
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
This exchange from X adds some context: https://infosec.exchange/@psylo/116633092694513326
infosec.exchange
6
1
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@erlenmayr@chaos.social There are rules for app acquisitions that eventually enable one developer, in this case Meta, to own all apps owned through acquisitions even if they have different bundle IDs
5
0
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Replying to
The data Michael received should also include way more detailed events than just search queries. Every click, every app screenshot you open and for how long you view it, every app video you play and which parts of the video you view, when you pause the video, and resume playing it, all these events are recorded. But Michael's post was about search queries and key-logging: https://mjtsai.com/blog/2026/06/12/app-store-personalized-recommendations-and-keylogging/
mjtsai.com
3
0
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
Polishing the rough edges. We're good to publish today ✌️
4
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
This is when we discovered the bug: https://mastodon.social/@mysk/115283952511882565
mastodon.social
4
0
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org @xorhex@infosec.exchange @freediverx@mastodon.social @psylo@infosec.exchange 🤣 Psylo by default uses the toughest anti-fingerprinting options. Some websites don't like it. You can always relax the options per silo in the settings. Can you share the website?
1
1
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Replying to
@ajn142@infosec.exchange We're busy working on a Psylo update. It could either be late next week or Monday the following week.
1
1
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@__ic@mastodon.social Hey, alternative sources to what? I took the screenshot today, but I haven't used WhatsApp on my Mac since 2024. During our testing as shown in the demo we use VMs. I just wanted to show the containers quickly and didn't have a VM ready 🫣. I didn't know the post would be shared that much. The bug is not related to WhatsApp. Apps published by the same developer can access their shared containers by design.
2
2
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
macOS Security: Archive Utility Bug Could Expose 1Password Secrets — Fixed in 26.4 (CVE-2026-28910) https://m.youtube.com/watch?v=Hp5NLDtxmzo

macOS Security: Archive Utility Bug Could Expose 1Password Secrets — Fixed in 26.4 (CVE-2026-28910)

2
1
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
macOS Security: Archive Utility bug can expose Safari, Messages, and WhatsApp data - CVE-2026-28910 https://m.youtube.com/watch?v=Naq5IojVoNs

macOS Security: Archive Utility bug can expose Safari, Messages, and WhatsApp data - CVE-2026-28910

2
1
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
macOS Archive Utility Bug Could Let Attackers Hijack Signal Sessions—Fixed in 26.4 (CVE-2026-28910) https://m.youtube.com/watch?v=WuH0pIE7j2Y

macOS Archive Utility Bug Could Let Attackers Hijack Signal Sessions—Fixed in 26.4 (CVE-2026-28910)

2
1
2
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
The bug severity level has been updated to low. No idea what caused this. We're working hard to publish demoes illustrating the impact of the bug on "protected" macOS apps. Our team is handling 5 projects at the moment. We hope we will be able to publish by Friday.
2
1
1
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3mo ago
Replying to
@bub4don@mastodon.social @mjtsai@mastodon.social Thank you. Homebrew is open source. One can easily block its analytics endpoint. But you can switch analytics off in the settings. The problem with the App Store is that you cannot use a different store to download apps on your iPhone. Please let us know about what shocks you the most when you get your data.
1
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@jamesbooker@floss.social Yep
1
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@softmaus@mastodon.social Oh wow. Light mode is broken. We're fixing it. Thanks
1
3
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
macOS Bug Lets Attackers Hijack Background Apps to Spy on Clipboard — Fixed in 26.4 (CVE-2026-28910) https://m.youtube.com/watch?v=NUm5068G5eM

macOS Bug Lets Attackers Hijack Background Apps to Spy on Clipboard — Fixed in 26.4 (CVE-2026-28910)

1
0
3
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@winterknight1337@infosec.exchange It seems to be rubbish. The vector doesn't reflect the attack at all. For example, the attack needs user interaction, but the vector doesn't include it. Anyhow, we will publish the blog and videos soon (targeting Friday). https://www.tenable.com/cve/CVE-2026-28910
tenable.com
1
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@softmaus@mastodon.social Thanks a lot for reporting it.
0
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Replying to
@neurovagrant@masto.deoan.org @freediverx@mastodon.social @psylo@infosec.exchange Thanks a lot Ian 🙏We would like to open-source Psylo or have it audited, or both. However, that would only provide distraction at the moment and prevent us from delivering nice privacy features. This is why we started with Loupe as an open-source project. We're evaluating how that goes. We're committed to privacy. Psylo is actually the only browser that collects zero in-app analytics. No opt-in, no opt-out. And it will stay like this.
0
1
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 3w ago
Replying to
@ajn142@infosec.exchange @wdormann@infosec.exchange It is under Settings -> Notifications
0
5
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Many of you have asked for a way to support the Loupe project. We want to keep Loupe free of in-app purchases, so instead we’ve created a Buy Me a Coffee page for anyone who’d like to show their appreciation. ☕ https://buymeacoffee.com/mysk
buymeacoffee.com
0
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Another change seems to be motivated by Loupe. Apple has deprecated the canOpenURL API that apps use to detect which apps are installed on the iPhone in iOS 27 Beta 4. Moreover, the deprecated API will only allow a maximum of 25 apps to be queried instead of 50 #privacy #infosec #Apple #ioS
0
0
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 2mo ago
Replying to
@xorhex@infosec.exchange @neurovagrant@masto.deoan.org @freediverx@mastodon.social @psylo@infosec.exchange It seems to work. I used the default settings in a German silo:
0
1
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@softmaus@mastodon.social Fixed!
0
2
0
0
Open post
Mysk🇨🇦🇩🇪 @mysk@mastodon.social
· 4mo ago
Replying to
@softmaus@mastodon.social Where? Can you show a screenshot?
0
5
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 02:03:27 UTC