jiska's Avatar

jiska

@naehrdine.bsky.social

ɿɘɘniϱnɘ ɘƨɿɘvɘɿ 🎦 youtube.com/@jiskac 📝 naehrdine.blogspot.com 🐥 twitter.com/naehrdine 🎓 hpi.de/classen 📱 reversing.training

1,491 Followers  |  582 Following  |  73 Posts  |  Joined: 23.12.2023
Posts Following

Posts by jiska (@naehrdine.bsky.social)

Preview
Apple Sued by West Virginia for Allegedly Allowing CSAM Distribution Through iCloud West Virginia's Attorney General JB McCuskey today announced a lawsuit against Apple, accusing the company of knowingly allowing iCloud to be used to distribute and store child sexual abuse material (...

Here we go again with iCloud photo scanning. www.macrumors.com/2026/02/19/a...

19.02.2026 23:01 — 👍 33    🔁 11    💬 1    📌 0
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska [0x12] Reversing Shorts :: AirDrop on Android?!

Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look!

youtu.be/qBsNoa0FOPw

14.02.2026 14:57 — 👍 5    🔁 1    💬 0    📌 0
[0x12] Reversing Shorts :: AirDrop on Android?!
YouTube video by jiska [0x12] Reversing Shorts :: AirDrop on Android?!

Google's Pixel 10 supports Apple's AirDrop protocol. Curious about how they did this? Let's take a look!

youtu.be/qBsNoa0FOPw

14.02.2026 14:57 — 👍 5    🔁 1    💬 0    📌 0
Call History
Available for: iPhone 11 and later, iPad Pro
12.9-inch 3rd generation and later, iPad Pro
11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later
Impact: A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions
Description: A logic issue was addressed with improved checks.
CVE-2026-20638: Nils Hanff
(@nils1729@chaos.social) of Hasso Plattner
Institute

Call History Available for: iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later Impact: A user with Live Caller ID app extensions turned off could have identifying information leaked to the extensions Description: A logic issue was addressed with improved checks. CVE-2026-20638: Nils Hanff (@nils1729@chaos.social) of Hasso Plattner Institute

Wallet
We would like to acknowledge Aaron Schlitt (@aaron_sfn) of Hasso Plattner Institute, Cybersecurity - Mobile & Wireless, Jacob Prezant (prezant.us), Lorenzo Santina (@BigNerd95) and Marco Bartoli (@wsxarcher) for their assistance.

Wallet We would like to acknowledge Aaron Schlitt (@aaron_sfn) of Hasso Plattner Institute, Cybersecurity - Mobile & Wireless, Jacob Prezant (prezant.us), Lorenzo Santina (@BigNerd95) and Marco Bartoli (@wsxarcher) for their assistance.

Two students I supervised in today's iOS release notes 🎉🎉🎉
support.apple.com/en-us/126346

11.02.2026 22:22 — 👍 17    🔁 0    💬 0    📌 1
Preview
WOOT '26 Call for Papers The 20th USENIX WOOT Conference on Offensive Technologies (WOOT '26) will take place at the Baltimore Marriott Waterfront in Baltimore, MD, USA, on August 10–11, 2026. The USENIX WOOT Conference aims ...

The Cycle 2 deadline for the USENIX WOOT Conference is in ~ 3 weeks (March 3, 2026)!

WOOT continues to include both a Systematization of Knowledge (SoK) track and an Up-and-Coming track (industry-focused).

Details are available in the Call for Papers:
www.usenix.org/conference/w...

09.02.2026 22:26 — 👍 0    🔁 1    💬 0    📌 0
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska [0x11] Reversing Shorts :: macOS "Private" Window Picker

In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering

youtu.be/P7hYg2GpsTk

07.02.2026 15:07 — 👍 9    🔁 3    💬 1    📌 1
[0x11] Reversing Shorts :: macOS "Private" Window Picker
YouTube video by jiska [0x11] Reversing Shorts :: macOS "Private" Window Picker

In this video, I'm analyzing a really confusing dialog on macOS. Let's dig a bit deeper into what it should do and what it's actually doing. #reverseengineering

youtu.be/P7hYg2GpsTk

07.02.2026 15:07 — 👍 9    🔁 3    💬 1    📌 1
YouTube
Share your videos with friends, family, and the world YouTube

Last weekend, Telekom changed their network name from "Telekom.de" to "Im besten Netz." 📶

Curious about how they did this? Will more ad campaigns follow? And what can you do to change it back?

More details in this video: youtu.be/-PchHdFhl5M

31.01.2026 12:41 — 👍 2    🔁 2    💬 0    📌 0
Post image

The new AirTags 2 just arrived!

Time to take them apart 🧵

28.01.2026 11:34 — 👍 145    🔁 30    💬 4    📌 1
Post image

Don't miss out on Jiska Classen's - @naehrdine.bsky.social - training on "Practical iOS Reverse Engineering" at #OffensiveCon26

Find more details here🔗https://buff.ly/psTxdyG

20.01.2026 18:45 — 👍 12    🔁 7    💬 0    📌 0
Preview
A Glimpse Into DexProtector | Romain Thomas This blog post provides a high-level overview of DexProtector's security features and their limitations

I reverse engineered DexProtector, the security solution protecting applications like Revolut and other banking apps.

From custom ELF loaders to vtable hooking, here is an insight into how these protections work and their limitations.

www.romainthomas.fr/post/26-01-d...

05.01.2026 06:11 — 👍 33    🔁 12    💬 0    📌 0
Preview
Cracking open what makes Apple's Low-Latency WiFi so fast This talk presents Apple's link-layer protocol Low-Latency WiFi and how it achieves its real-time capabilities to enable Continuity featu...

The Apple LLW recording is already available: media.ccc.de/v/39c3-crack...

28.12.2025 19:16 — 👍 6    🔁 0    💬 0    📌 0
Preview
[39c3] Cracking open what makes Apple's Low-Latency WiFi so fast Apple's Continuity features make up a big part of their walled garden. From AirDrop and Handoff to AirPlay, they all connect macOS and iOS devices wirelessly. In recent years, security researchers hav...

Want to know how Apple's Low Latency WiFi works?

Today, 3:40pm CET, Hall 1, #39c3.

More details: events.ccc.de/congress/202...
Stream: streaming.media.ccc.de/39c3/one

28.12.2025 10:45 — 👍 10    🔁 2    💬 1    📌 0
Post image

In 2026, Jiska Classen - @naehrdine.bsky.social - returns to OffensiveCon with a training on "Practical iOS Reverse Engineering". More details here🔗https://buff.ly/psTxdyG

🚀 Don't miss this chance to improve your skills—sign up now!

17.12.2025 13:48 — 👍 2    🔁 1    💬 0    📌 0

WOOT deadline approaching 👀

09.12.2025 09:06 — 👍 6    🔁 0    💬 0    📌 0

This is Limburg BE, not NL - though they are pretty close.

www.bsides-limburg.be/home

03.12.2025 01:22 — 👍 6    🔁 4    💬 0    📌 0

GrapheneOS released some innovative mitigations prior to Apple. Yet, it needs Big Tech to apply such ideas and make phones more secure at scale.

26.11.2025 11:39 — 👍 8    🔁 0    💬 1    📌 0

Using an iPhone 17, which now also ships with EMTE, Inactivity Reboot, SPTM, TXM, Conclaves, ...? — Oh, just the average Apple fangirl/boy who gets a new device every year due to camera improvements. ✅

26.11.2025 11:39 — 👍 4    🔁 1    💬 1    📌 0
GrapheneOS im Visier der Strafverfolgung
Quelle der Bedenken scheinen Berichte mehrerer französischer Medien zu sein, darunter einer der Tageszeitung Le Parisien.
Darin wird GrapheneOS als "Geheimwaffe" bezeichnet, mit der Drogenhändler und andere Kriminelle ihre Daten vor der Polizei schützten.
Dass sich das Betriebssystem im Vergleich zum Standard-Android besonders schwer knacken lässt, hatte zuletzt eine geleakte Präsentationsfolie des Forensikdienstleisters
Cellebrite gezeigt.

GrapheneOS im Visier der Strafverfolgung Quelle der Bedenken scheinen Berichte mehrerer französischer Medien zu sein, darunter einer der Tageszeitung Le Parisien. Darin wird GrapheneOS als "Geheimwaffe" bezeichnet, mit der Drogenhändler und andere Kriminelle ihre Daten vor der Polizei schützten. Dass sich das Betriebssystem im Vergleich zum Standard-Android besonders schwer knacken lässt, hatte zuletzt eine geleakte Präsentationsfolie des Forensikdienstleisters Cellebrite gezeigt.

Using a Pixel with GrapheneOS that features Inactivity Reboot, MTE, and more? — You must be a drug dealer. 🚨

26.11.2025 11:39 — 👍 6    🔁 0    💬 1    📌 0
Preview
A Simple WhatsApp Security Flaw Exposed 3.5 Billion Phone Numbers By plugging tens of billions of phone numbers into WhatsApp’s contact discovery tool, researchers found “the most extensive exposure of phone numbers” ever—along with profile photos and more.

Researchers tried plugging every possible phone number into WhatsApp's web app. They found they could collect 3.5 billion users' phone numbers, plus photos for half and profile text for more than a third, the biggest personal data exposure ever by some measures. www.wired.com/story/a-simp...

18.11.2025 14:04 — 👍 162    🔁 74    💬 6    📌 11
Post image

Binary Ninja 5.2, Io, is live and it's out of this world! binary.ninja/2025/11/13/b...

With some of our most requested features of all time including bitfield support, containers, hexagon, Ghidra import, and a huge upgrade to TTD capabilities, plus a ton more, make sure to check out the changelog!

13.11.2025 21:16 — 👍 9    🔁 3    💬 1    📌 0
Post image

USENIX WOOT Conference 2026: two submission deadlines this year!

- Cycle 1: December 12, 2025 *only one month away* !
- Cycle 2: March 3, 2026

WOOT still has a SoK track and an "Up-and-coming track" (~Industry), CFP for details:
www.usenix.org/conference/w...

12.11.2025 11:00 — 👍 5    🔁 6    💬 0    📌 0
Preview
Dein erster Congress? Die Chaospat:innen sind für dich auf dem 39C3 da! Auch in diesem Jahr sind die Chaospat:innen wieder beim Chaos Communication Congress in Hamburg am Start! Interessierte Mentor:innen und Mentees können sich bis zum 25. November 2025 um 23:59 Uhr…

Dein erster Congress und pures Chaos? Die Chaospat:innen sind für dich da. Melde dich bis zum 25. November. Willkommen sind alle, die den #39c3 offener und vielfältiger machen wollen! events.ccc.de/2025/11/10/3...

09.11.2025 10:59 — 👍 27    🔁 10    💬 1    📌 0
Preview
OBTS v8.0: Diving into C1 Learn more about my talk “What’s at the Bottom of the Sea, One Baseband? - Diving into the C1” at eight edition of the Objective by the Sea conference.

I just published the slides of my #OBTS v8.0 talk about Apple's #C1 baseband. Our C1 #binja loader is now available on GitHub, and you can find a recording on YouTube.

lukasarnold.de/posts/obtsv8...

27.10.2025 15:48 — 👍 4    🔁 1    💬 0    📌 0
Preview
39C3 Presale: Modus Operandi Wir freuen uns, euch den Vorverkauf für den diesjährigen Chaos Communication Congress anzukündigen. Der Vorverkauf wird dieses Jahr ziemlich genau ablaufen wie letztes Jahr: Der Vorverkauf wird…

Wir freuen uns, den Vorverkauf für den #39c3 anzukündigen. Im Anschluss an die Voucherphase gibt es zwei offene Verkaufstermine. (Fast) alle Engel erhalten heute eine E-Mail mit Voucher events.ccc.de/2025/10/16/3...

16.10.2025 21:57 — 👍 48    🔁 18    💬 0    📌 1

On a Saturday night I stumbled across something on the internet that made me feel like ****** my pants. A giant dataset of real surveillance operations targeting 1000s of people across nearly every country. Unraveling it and the mysterious company behind it has consumed 1.5 years of my life

14.10.2025 16:48 — 👍 272    🔁 96    💬 7    📌 8
Preview
Modern iOS Security Features -- A Deep Dive into SPTM, TXM, and Exclaves The XNU kernel is the basis of Apple's operating systems. Although labeled as a hybrid kernel, it is found to generally operate in a monolithic manner by defining a single privileged trust zone in whi...

Want to know more details on Apple's SPTM, TXM, and Exclaves? Read more on this in the paper based on Moritz Steffin's thesis. Lots of low-level details including their security implications are covered.

arxiv.org/abs/2510.09272

13.10.2025 16:54 — 👍 11    🔁 2    💬 0    📌 0
Preview
CCC | Lectures, music, art, punk: Join us at the 39th Chaos Communication Congress! Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung.

Lectures, music, art, punk: Join us at the 39th Chaos Communication Congress and please submit! The deadline for all submissions for the stages is October 24. #39C3 will take place from December 27 to 30 www.ccc.de/en/updates/2...

27.09.2025 23:14 — 👍 34    🔁 18    💬 0    📌 0

USB Restricted Mode already does that - data lines are disabled when the phone is locked. There's logic to still allow devices to maintain a connection when you connected them while unlocked, making it usable but still increasing security a lot. In Lockdown Mode, the policy is more aggressive.

12.09.2025 08:47 — 👍 2    🔁 0    💬 0    📌 0
Preview
Apple's latest iPhone security feature just made life more difficult for spyware makers | TechCrunch Buried in an ocean of flashy novelties announced by Apple this week, the tech giant also revealed new security technology for its latest iPhone 17 and

NEW: Apple launched a new security feature specifically to fight against spyware and zero-day exploit makers.

We spoke to a researcher who sells zero-days to the U.S. government, who thinks this will make their life much harder and raise the cost of developing and selling hacking tolls for iPhones.

11.09.2025 22:05 — 👍 44    🔁 22    💬 2    📌 3