Article 77X2D Reverse-engineering Apple’s Find My people

Reverse-engineering Apple’s Find My people

by
Thom Holwerda
from OSnews on (#77X2D)

So that is the whole pipeline exercised end-to-end. GrandSlam authenticates the Apple Account and obtains the IDS delegate. authenticateDS and id-register turn the Linux process into a registered Apple messaging identity. The Friends sequence attaches that identity to the existing accepted relationship. A missing-key SubscribeAndFetch makes the sharing device deliver its current P-224 key over APNs/IDS, inside a sender-verified P-256 NGM envelope. A second SearchParty fetch returns the encrypted report, and the P-224 key opens it locally.

So yeah, in one sentence: authenticate to Apple's private services, register the Linux machine as an IDS client, receive the existing Find My share key, and use it to fetch and decrypt a consented friend's latest location.

Zerotistic

I wonder if it would be possible to build a proper third-party client for Apple's Find My network like this, or if it would be trivial for the company to block it. I'm fairly sure quite a few people would love to be able to keep using Find My when moving away from Apple's operating systems.

External Content
Source RSS or Atom Feed
Feed Location http://www.osnews.com/files/recent.xml
Feed Title OSnews
Feed Link https://www.osnews.com/
Reply 0 comments