ื”ื‘ื

ื”ืคืขืœื” ืื•ื˜ื•ืžื˜ื™ืช

The [REDACTED] Hacker - Episode 001 Trailer - Apple's Secret API

0 ืฆืคื™ื•ืช โ€ข 24/05/26
ืœึทื—ึฒืœื•ึนืง
ืœึฐืฉืึทื‘ึผึตืฅ
121gamers
121gamers
14 ืžื ื•ื™ื™ื
14

Apple has a secret API to spy on you and the reports coming in are not pretty...

๐Ÿ‘‰๐Ÿผ Watch the trailer for The [REDACTED] Hacker - Episode 001
(with a Person of Interest twist ๐Ÿ˜€)

According to Gizmodo:

A new test of how Apple gathers usage data from iPhones has found that the company collects personally identifiable information while explicitly promising not to.

The privacy policy governing Appleโ€™s device analytics says "none of the collected information identifies you personally".

But an analysis of the data sent to Apple shows it includes a permanent, unchangeable ID number called a Directory Services Identifier, or DSID, according to researchers from the software company Mysk.

Apple collects that same ID number along with information for your Apple ID, which means the DSID is directly tied to your full name, phone number, birth date, email address and more, according to Myskโ€™s tests.

The iPhone Analytics setting makes an explicit promise: Turn it off, and Apple says that it will "disable the sharing of Device Analytics altogether".

However, two app developers and security researchers at the software company Mysk, took a look at the data collected by a number of Apple iPhone apps including the App Store, Apple Music, Apple TV, Books, and Stocks.

They found the analytics control and other privacy settings had no obvious effect on Appleโ€™s data collection. The tracking remained the same whether iPhone Analytics was switched on or off.

According to Appleโ€™s analytics policy, "Personal data is either not logged at all, is subject to privacy-preserving techniques such as differential privacy, or is removed from any reports before theyโ€™re sent to Apple"

But Myskโ€™s tests show that the DSID, which is directly tied to your name, is sent to Apple in the same packet as all the other analytics information.


โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐ŸŸฃ API SECURITY ๐ŸŸฃ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
APIs are everywhere and API Security has never been more important than it is right now. API abuses have risen in the past few years and it is difficult to go even a week without reading about another API that has been attacked. By securing your APIs using API Security solutions and API Management best practices, you can mitigate attacks and protect your organization, your customers, your data, and your reputation from API Hackers.

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐ŸŸข WHAT IS OWASP? ๐ŸŸข โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
OWASP stands for "Open Web Application Security Project" and they are an international non-profit organization dedicated to web application security.

It is important to apply API Security best practices to your cybersecurity strategy.

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ โช SHIFT LEFT โช โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
"Shift Left" is referring to shifting your security focus to the beginning of the API Lifecycle process and integrating it into the design and development of an API that works to help protect it in every other step of the API Lifecycle all the way to the retirement of an API.

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ โฉ SHIELD RIGHT โฉ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
"Shield Right" is talking about the emphasis on continuing to protect your APIs at runtime and beyond. This provides a defense against unknown attacks using AI/ML and defined algorithms and policies.

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐Ÿ”ด WHAT IS API Penetration Testing? ๐Ÿ”ด โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
API penetration testing (or API Pentesting) is an ethical hacking process to assess the security of the API design. API tests involve attempting to exploit identified issues and reporting them to strengthen the API to prevent unauthorized access or a data breach.


โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐ŸŸก OWASP API SECURITY ๐ŸŸก โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
What is the OWASP Top 10 for API Security?
โญ Broken Object Level Authorization
โญ Broken User Authentication
โญ Excessive Data Exposure
โญ Lack of Resources & Rate Limiting
โญ Broken Function Level Authorization
โญ Mass Assignment
โญ Security Misconfiguration
โญ Injection
โญ Improper Assets Management
โญ Insufficient Logging & Monitoring

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐Ÿ’€ API Hacker Resources ๐Ÿ’€ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
๐Ÿ’€ Postman
๐Ÿ’€ Charles Proxy
๐Ÿ’€ MobSF
๐Ÿ’€ Frida
๐Ÿ’€ MITM
๐Ÿ’€ OSINT Tools

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ โค๏ธ LEVEL-UP โค๏ธ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
๐ŸŽฌ Watch โ–ช Check out more API videos! https://youtube.com/apishorts ( bring your own ๐Ÿฟ )
๐Ÿ”” Subscribe โ–ช Get notified when new content is available!
๐Ÿ‘๐Ÿป Thumbs Up! โ–ช Love APIs? ๐Ÿ˜ Like our video and share it!
๐Ÿ’ฌ Comment โ–ช Let us know what you think of this episode!

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐Ÿ‘€ LET'S CONNECT ๐Ÿ‘€ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
โญ LinkedIn ๐Ÿ‘‰๐Ÿผ https://api2.day/linkedin
โญ Twitter ๐Ÿ‘‰๐Ÿผ https://api2.day/twitter
โญ YouTube ๐Ÿ‘‰๐Ÿผ https://api2.day/youtube
โญ Medium ๐Ÿ‘‰๐Ÿผ https://api2.day/medium
โญ Dev.to ๐Ÿ‘‰๐Ÿผ https://api2.day/devto
โญ Software AG ๐Ÿ‘‰๐Ÿผ https://api2.day/sag-brenton

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ โšก SUPERCHARGE โšก โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
โšก Digital Strategist ๐Ÿ‘‰๐Ÿผ https://api2.day/brenton
โšก Software AG Blog ๐Ÿ‘‰๐Ÿผ https://api2.day/sag-blog
โšก API Knowledge Portal ๐Ÿ‘‰๐Ÿผ https://api2.day/knowledge

โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐ŸŽฌ DIGITAL TOOLS ๐ŸŽฌ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ
Apple Final Cut Pro ๐Ÿ‘‰๐Ÿผ https://api2.day/fcp
Adobe After Effects ๐Ÿ‘‰๐Ÿผ https://api2.day/ae

ืœื”ืจืื•ืช ื™ื•ืชืจ
ืชื’ื•ื‘ื•ืช ื‘ืคื™ื™ืกื‘ื•ืง

ื”ื‘ื

ื”ืคืขืœื” ืื•ื˜ื•ืžื˜ื™ืช