Show HN: First iOS app to use technique that finds latest variants of spyware

https://apps.apple.com/us/app/am-i-secure/id6468312814
{
"by": "screwNSO",
"descendants": 1,
"id": 40240197,
"kids": [
40240490
],
"score": 1,
"text": "Background\nIn 2021, my iPhone was exploited with spyware (Pegasus) by a client of the NSO Group due to my employment at the time (i.e. I worked for a target organization). From there I began helping other at risk users identify when their iPhones were compromised via manual forensic analysis of their devices. Wanted to scale this manual forensic analysis to a wider audience to make it widely available to find more victims of spyware companies like NSO Group (Pegasus) and Cytrox (Predator) so created an app to do it called Am I Secure? that is on the App Store now. It is able to detect the latest variants of spyware (including those deployed against victims in April 2024). The app also performs a number of other security checks, more than any other iOS app.<p>Key Differentiator\nAll iOS apps operate within an &quot;app sandbox&quot;, a restricted space within iOS that limits an app to accessing only its own data and specific data a user has provided permission to, such as contacts or location data. This is to ensure security and privacy. Due to these restrictions, no iOS apps, including security focussed ones, are able to directly access the operating system and other data necessary to perform an analysis of the operating system for spyware or malware. While some iOS apps market themselves as antivirus solutions, unlike real antivirus solutions that run on Windows or macOS, they are not actually able to perform any traditional antivirus functions on iOS and these apps add little, if any, security value. Usually they just provide sketchy VPN and “identity protection” services while making it appear that they protect your device but with no actual device security at all and the web sites they block, if you do use their VPN, are all malicious sites targeting Windows, irrelevant to iOS security.<p>Am I Secure? bypasses the limitations of the app sandbox by having users of the app share iOS system diagnostic data with the app so access can be obtained. Without access to this data, no app can perform a proper analysis for spyware. Via the app, this data is then uploaded to our servers where it is analyzed and the results are reported back to the user within the app and, if spyware is found, to the email address tied to their account. No private user data such as messages or photos are contained within the system diagnostic data so user privacy is preserved. No other app is using this technique or analyzing actual system data.<p>Beyond detecting previously discovered and publicly known Indicators of Compromise (IoCs), the automated AI&#x2F;ML augmented analysis on our servers goes deeper. It looks for any anomalies in the submitted data versus what is expected from a &quot;known good&quot; iOS device as well as comparing against other submissions from across the user base. Any anomalies are then manually analyzed to detect new previously unknown IoCs. Looking for publicly known IoCs only finds yesterday&#x27;s spyware, spyware vendors rapidly change their spyware after public disclosure occurs to ensure prior IoCs are ineffective. Our analysis techniques though will continue to find spyware as the anomalies they leave change but continue to stand out.",
"time": 1714676636,
"title": "Show HN: First iOS app to use technique that finds latest variants of spyware",
"type": "story",
"url": "https://apps.apple.com/us/app/am-i-secure/id6468312814"
}
{
"author": null,
"date": null,
"description": null,
"image": null,
"logo": null,
"publisher": "Apple",
"title": null,
"url": "https://apps.apple.com/us/app/am-i-secure/id6468312814"
}
null