Log inSign up
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
6,632 posts
Image
user avatar
Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
@mysk_co
We're two #iOS developers and occasional #security researchers on two continents. #CyberSecurity πŸ“mysk.blog πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ Current Project: @psylo_app
Canada - Germany
mysk.blog
Joined November 2010
526
Following
20.5K
Followers
  • Pinned
    user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Jun 17, 2025
    Psylo is finally available for download today. We can’t wait for you to try it. apps.apple.com/ca/app/psylo-p…
    user avatar
    Psylo: Privacy Browser & Proxy
    @psylo_app
    Jun 17, 2025
    πŸš€πŸ€˜Introducing Psylo: A New Kind of Private Browser After 9 months of development, we're super excited to finally launch Psylo, a new kind of private web browser for iOS and iPadOS. In Psylo, each tab is its own β€œsilo” with isolated storage, cookies, and even its own IP
    Image
    86K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Oct 12, 2022
    We confirm that iOS 16 does communicate with Apple services outside an active VPN tunnel. Worse, it leaks DNS requests. #Apple services that escape the VPN connection include Health, Maps, Wallet. We used @ProtonVPN and #Wireshark. Details in the video: #CyberSecurity #Privacy
    Image
    00:00
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Sep 14, 2025
    🀯 Instagram is testing new iOS push notifications that include a profile photo. Each time the notification is shown on your screen, it triggers a GET request to fetch that image, letting Meta track every on-screen impression. The app still misuses push notifications to send
    Image
    Image
    429K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Jul 5, 2024
    TL;DR: Don't install @signalapp for macOS, it is not secure. I carried out this small experiment: - I wrote a simple Python script that copies the directory of Signal's local storage to another location (to mimic a malicious script or app) - I ran the script in the Terminal and
    Image
    913K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Apr 26, 2023
    Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices. TL;DR: Don't turn it on. The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.
    Image
    Image
    Image
    Image
    943K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Sep 22, 2025
    🚨 iMessages in iOS 26 leaks the sender's keyboard language when sending reactions to devices with iOS 17 or older, and Android phones via RCS! 😱 #privacy #Apple #iOS26
    Image
    00:00
    950K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Jul 23, 2023
    iOS 16.5.1 still bypasses the VPN. New tests show that Apple Push Notification traffic completely ignores the VPN connection. Apple Maps sends many requests outside the VPN, including unencrypted DNS requests. This also happens in the Lockdown Mode. 🎬 youtu.be/tttO_E2STHA
    Image
    248K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Nov 21, 2022
    🚨 New Findings: 🧡 1/6 Apple’s analytics data include an ID called β€œdsId”. We were able to verify that β€œdsId” is the β€œDirectory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you πŸ‘‡
    Image
    Image
    Image
    Image
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Aug 10, 2024
    Hey @elonmusk, will 𝕏 publish the algorithm that determines which replies are most relevant? The Algorithm's repository on Github hasn't been updated since last year. Thank you!
    Image
    Image
    28K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Oct 12, 2022
    Replying to @mysk_co
    I know what you're asking yourself and the answer is YES. #Android communicates with #Google services outside an active VPN connection, even with the options "Always-on" and "Block Connections without VPN." I used a #Pixel phone running #Android13, its IP is 192.168.2.14 πŸ‘‡
    Image
    Image
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Apr 11, 2024
    Speaking of outdated, @MicrosoftEdge is the only browser on macOS that still requires administrative privileges to install. 🫠
    Image
    user avatar
    Microsoft Edge
    @MicrosoftEdge
    Apr 8, 2024
    You. Yes, you. It's time to leave that outdated browser 🫡
    56K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Dec 11, 2024
    Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entriesβ€”a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :
    Image
    00:00
    156K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Sep 23, 2023
    🚨PSA: iOS 17 turns these sensitive location options back on. If you have disabled significant locations as well as adding your location information to your iPhone analytics before upgrading to iOS 17, iOS 17 will turn the options on as shown in the screenshot. While significant
    Screenshot of the location services settings that iOS 17 switches on even if they were disabled before.
    534K
  • user avatar
    Mysk πŸ‡¨πŸ‡¦πŸ‡©πŸ‡ͺ
    @mysk_co
    Sep 29, 2025
    I love seeing vestiges of pre-iOS 7 design still exist in iOS 26: the network link conditioner under developer options in settings. Look at that bold font, and the checkmark βœ”οΈ
    Image
    290K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

TermsΒ·PrivacyΒ·CookiesΒ·AccessibilityΒ·Ads InfoΒ·Β© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement