News
GoPro has built its name on cameras you can strap to anything and forget about. The Mission 1 Pro ILS is pretty much the opposite, requiring you to slow down, think about your settings and focus, and work much harder for the shot you want.
It's the third and quirkiest member of the new Mission 1 family, swapping the fixed lens of its siblings for a Micro Four Thirds mount. It's a major change that drastically reshapes the nature of this camera. Instead of a rugged companion for your next surf session or mountain bike run, it's a creative tool that opens GoPro's superb 1-inch sensor up to hundreds of lenses, from cheap vintage primes to specialist optics that would never fit inside a traditional action cam body.
The Mission 1 Pro ILS with a Laowa 7.5mm F/2.0 lens and GoPro's Point-and-Shoot Grip. (Image credit: Future | Sam Kieldsen)I spent a week shooting with it, mostly paired with a manual Laowa prime, and found it to be a camera that's as rewarding as it is demanding. There's a real skill curve here that longtime GoPro shooters may not be comfortable with, and the payoff — sharper, more considered footage and stills — only arrives once you've put the work in.
Where the ILS earns its keep is its sheer versatility. Want to shoot extreme close-ups a regular GoPro physically can't manage? Fit a close-focusing lens. Chasing a specific look? There's a lens for that too. It's arguably the most flexible camera GoPro has ever made.
That flexibility incurs trade-offs, though — not only is the ILS expensive, it's also less rugged than other GoPro's and lacks autofocus and horizon lock. GoPro's Quik app doesn't make life easier either, constantly nudging you toward a subscription rather than just getting out of the way and letting you shoot. None of that stops the ILS from being a compelling and genuinely different kind of GoPro; it's just one that asks a lot more of you than the ones that came before it.
GoPro Mission 1 Pro ILS: Price and release date- $699 / £599.99 / AU$1,099.95 (non-member price)
- $599 / £509.99 / AU$949.95 (member price)
- Other models in the series are the Mission 1 and Mission 1 Pro
The GoPro Mission 1 Pro ILS is priced at $699.99 / £599.99 / AU$1,099.95, or $599.99 / £509.99 / AU$949.95 if you're already a GoPro subscriber. That's body-only pricing, of course — you'll need to budget separately for a Micro Four Thirds lens (GoPro doesn't sell any of its own). It's a big chunk of money to spend on a little camera, but at the same time there's not much out there to compare it to, and no direct competitors to undercut it.
It officially launches on September 2 2026, alongside a companion iOS app called Mission Monitor.
Interestingly, the ILS costs exactly what the standard Mission 1 Pro did at launch. But at the time of writing, GoPro has quietly dropped the Mission 1 Pro's price by $100, down to $599.99. That means (for now at least) that you're paying a $100 premium for the ILS's interchangeable lens mount over the Mission 1 Pro that also gets you 20m waterproofing, autofocus and a built-in lens — features the ILS lacks. It's worth considering this trade-off carefully, depending on what you actually plan to shoot.
- Price score: 4/5
Type:
Action camera
Sensor:
50MP 1-inch type CMOS
Lens mount:
Micro Four Thirds
Displays:
Front: 1.4-inch LCD
Rear: 2.59-inch OLED touchscreen
Memory:
No internal storage; supports V30 and Class A2 rated microSD cards
Video:
8K Open Gate up to 30fps (no crop) / 8K/60p (cropped)
ISO range:
Video: 25-6400
Photo: 100-3200
Burst shooting
60fps
Processor:
GP3 SoC
Connectivity:
BlueTooth, USB-C, 5GHz Wi-Fi 6
Dimensions:
89.6 x 58.7 x 46.1mm
Weight:
197g / 6.94oz (inc. battery but excluding lens)
GoPro Mission 1 Pro ILS: Design- Same compact, dual-screened GoPro body, but with a Micro Four Thirds mount up front
- Weatherproof only — loses the standard Mission 1 Pro's 20m waterproofing
- Weighs under 200g before adding a lens
In many ways, you'd struggle to tell the Mission 1 Pro ILS apart from the standard Mission 1 Pro. They have largely the same boxy, dual-screened body, the same 2.59-inch rear OLED touchscreen and 1.4-inch front display, the same big, chunky buttons, the same tripod thread, magnetic clips and mounting fingers on the base (that'll fit any GoPro accessory you already own). GoPro hasn't reinvented the shell here, and given how well the Mission 1 Pro works, that's no bad thing.
What has changed sits right at the front. Instead of the Mission 1 Pro's fixed 14mm lens, the ILS carries a native Micro Four Thirds mount, opening the door to hundreds of compatible lenses — GoPro maintains an official compatibility list if you want to check before you buy, and it already spans everything from fisheyes to vintage manual primes with the right adapter. If you've got a drawer full of old glass, this is the first GoPro that can accommodate it.
Future | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenThat flexibility comes at a cost to GoPro's trademark ruggedness, though: the ILS is weatherproof rather than waterproof. Unlike the standard Mission 1 Pro's 20m dive-ready housing-free design, you shouldn't be dunking this one in the sea. For a company that made its name letting you bolt or strap a camera to anything and dive into the deep blue, it's quite a shift.
Despite the added complexity of a lens mount, GoPro has kept things impressively compact; at 89.6 x 58.7 x 46.1mm and 197g, it's slightly lighter than the fixed-lens Mission 1 Pro. Of course, you'll have the weight of a lens to add to that. It's a world away from my everyday MFT camera, the lumpen — if lovable — Panasonic Lumix GH6. If you need to wedge an interchangeable lens into a tight spot, the ILS is hard to beat.
- Design score: 4/5
- Manual focus only, with no subject tracking or horizon lock
- Can focus far closer than the standard Mission 1 Pro's 60cm minimum
- Battery life of up to 96 minutes with 8K 4:3 recording
Losing autofocus is the single biggest adjustment coming from a standard Mission 1 Pro. GoPro has equipped the ILS with focus peaking to help you nail manual focus, but on the ILS's small screens I found it a real challenge — my shots weren't always in focus when I thought they were, and I lost a handful of otherwise good clips to softness as a result. Frustratingly, focus peaking doesn't work at all on the front-facing screen, which stings if you're trying to frame up a selfie or vlog shot. I'd like to see GoPro patch that in with a firmware update, since I can't see a technical reason why it wouldn't be possible.
There are better ways to nail focus than squinting at the rear screen, though. GoPro's Quik app offers a focus peaking preview, and there's also the new Mission Monitor app (sadly iOS-only at launch) for a bigger, clearer view. That one requires a wired connection between the camera and your iPhone or iPad, and since I don't own a USB-C to Lightning data cable, I wasn't able to put it through its paces myself. What I could do was hook the ILS up to an external monitor via a USB-C to HDMI adapter, and that worked well as a live-preview solution.
(Image credit: Future | Sam Kieldsen)I tested the ILS with two lenses: a Laowa 7.5mm f/2.0 that GoPro loaned to me alongside my review sample, and my own Panasonic 12-60mm zoom. The Laowa — a manual focus, manual aperture prime — is how this camera wants to be used. I couldn't get the Panasonic zoom to focus properly at all. If you've got a stash of vintage manual glass and a MFT adapter, you're in for a good time.
It's important to note that, despite the MFT lens mount, the ILS isn't an MFT camera. Its 1-inch sensor is smaller than an MFT's, which results in a larger crop factor. For example, if you fitted the Laowa 7.5mm lens to a standard MFT camera, MFT's 2x crop means its effective 35mm equivalent focal length is 15mm. The ILS has a 2.7x crop factor, rising to 3x with HyperSmooth stabilization on. So that means the same lens will have a 20.5mm focal length, or 22.5mm with stabilization. Consequently, you'll need a very wide fisheye lens to get the sort of ultra-wide focal length offered by most GoPros, but conversely it's easier to achieve tighter framing for portraits and so on.
I was pleased to discover that the ILS, at least paired with that Laowa lens, could focus far closer than the standard Mission 1 Pro is capable of. The regular Mission 1 Pro has an almost comically long 60cm / 24-inch minimum focus distance that rules out close-up work entirely. The ILS has no such limitation, opening the door to macro-style shots and detail work that's simply off the table on GoPro's fixed-lens model. It's not enough to make me recommend the ILS to vloggers, mind you — the lack of autofocus and subject tracking still counts heavily against it there. The Hero 13 Black with macro Lens Mod is a decent alternative for such uses.
In addition to subject tracking, horizon lock is also unavailable here. Both are present on the standard Mission 1 Pro, and so if you're relying on GoPro's software smarts to keep you level and in frame, you'll need to look at the fixed-lens models instead of the ILS.
Audio quality is solid, if unremarkable — echoing what my colleague Hamish Hector found when testing the Mission 1 Pro's built-in mics, the ILS captures voices and everyday sound clearly, with wind noise capably filtered out of the mix (up to a point).
(Image credit: Future | Sam Kieldsen)Battery life is very respectable. GoPro rates the included Enduro 2 battery at 96 minutes for 8K Open Gate at 30fps, or 74 minutes for 16:9 8K at 60fps, and my own real-world testing lined up closely with those figures. Thermal management is similarly solid — I only ran into overheating issues when shooting at the top end of the spec sheet (50/60fps in 8K or 200/240fps in 4K), and with decent airflow around the camera you may not experience overheating at all.
There's no built-in storage, as with virtually every GoPro. You'll need a fast V30, Class A2-rated microSD card, and you'll want it to have lots of space too — those 8K Open Gate files are huge.
- Performance score: 4/5
- Supports 8K video up to 30fps (Open Gate) and 60fps (16:9), plus slo-mo up to 960fps in burst mode
- Maximum bitrate of 300Mbps when using experimental GoPro Labs firmware
- Photos in JPEG and RAW up to 50MP resolution
When I actually managed to nail focus, the results were exactly what you'd hope for from that 1-inch sensor. For video, I shot most of my test footage with the Laowa 7.5mm lens, which plays nicely with GoPro's HyperSmooth stabilization. For anyone planning to color grade their own footage, I'd recommend GoPro's suggested settings — GP-Log2 color profile, 10-bit color depth, and the maximum bitrate available (240Mbps on regular firmware, or 300Mbps if you install the experimental GoPro Labs firmware — less stable than standard firmware but intended for enthusiasts who want to push performance to its limits) — shooting in 16:9 8K at 60fps.
I also tried Open Gate, which is one of the headline features shared with the standard Mission 1 Pro, but found the combination of huge file sizes and a 30fps ceiling too restrictive for how I like to shoot. It's a useful option to have, especially if you want maximum reframing flexibility in post, but it's not where I ended up spending most of my time.
For my main test clip, I mounted the ILS to my car using a single SmallRig suction cup — the camera's light weight meant I didn't need the full triple-cup rig I'd normally reach for, which kept setup quick. I edited the footage by applying one of GoPro's official LUTs before fine-tuning the color in DaVinci Resolve, and I'm really pleased with how it turned out. I'm no post-production expert, but anyone who is will have a field day pairing this sensor with the right glass.
Stills tell a similarly promising story, with caveats. I took the ILS out with the Laowa lens and GoPro's Point-and-Shoot Grip for a photo walk along the coast, shooting in RAW format at 50MP and, in lower light, 12MP. Editing in Adobe Lightroom afterward, the RAW files gave me a huge amount of latitude to shape the final look — much more than I'm used to getting out of an action camera. The Laowa itself let the side down slightly, with softness and a tendency to flare, but that's a lens characteristic rather than anything to do with the camera; pair the ILS with sharper glass and I'd expect noticeably cleaner results.
Future | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenFuture | Sam KieldsenLow-light performance carries over the big step up we saw on the standard Mission 1 Pro, the 1-inch sensor being a huge differentiator over GoPro's Hero Black range. As ever with an interchangeable-lens setup, the lens you choose plays a big part in how far that advantage stretches: wide-aperture glass will get you noticeably further after dark than anything narrower.
- Image quality score: 5/5
Attribute
Notes
Score
Price
A premium over the standard Mission 1 Pro, but there's nothing else like this on the market.
4/5
Design
Familiar, compact GoPro build with a Micro Four Thirds mount bolted on, but weatherproof rather than waterproof.
4/5
Performance
Manual focus is a genuine hurdle, but closer focusing than the Pro is a strong compensation. Battery life is excellent.
4/5
Image quality
Superb once in focus, with the 1-inch sensor delivering strong video and raw stills, though results depend heavily on the lens you pair it with.
5/5
Should I buy the GoPro Mission 1 Pro ILS?(Image credit: Future | Sam Kieldsen)Buy it if…You want to pair MFT glass with GoPro's best-ever sensor
The Mission 1 Pro ILS finally lets you put real lenses in front of GoPro's excellent 1-inch sensor, opening up creative options that no fixed-lens GoPro can match.
You need close-up focusing an action camera normally can't do
Where the standard Mission 1 Pro tops out at an awkward 60cm minimum focus distance, the right lens on the ILS lets you get close to your subject, opening the door to macro-style shooting.
You're a cinematographer who wants manual control over convenience
If you're used to pulling focus and dialing in aperture by hand, the ILS's manual approach will feel like a feature rather than a limitation. It rewards that kind of deliberate, considered shooting.
You want an underwater-ready action camera
The ILS loses the standard Mission 1 Pro's 20m waterproofing. If diving or watersports are on the agenda, the regular Mission 1 Pro is the one to get.
You want simple point-and-shoot ease
There's no autofocus, no horizon lock, and no subject tracking here — all things the standard Mission 1 Pro handles automatically. The ILS demands more effort for every shot.View Deal
You're budget-conscious
At $699.99, the ILS costs $100 more than the standard Mission 1 Pro, before you've even bought a lens. If you're watching your spending, GoPro's Hero13 Black remains a far cheaper way into the ecosystem.View Deal
Nikon ZR
If you want a "real" compact cinema camera rather than an action cam with a lens mount bolted on, the Nikon ZR is a strong alternative. It packs a full-frame sensor, 6K RAW recording, and RED color profiles into a body that's still remarkably compact and weather-resistant, undercutting most of its rivals on price in the process. It lacks the ILS's tiny size and mounting versatility, but for serious filmmaking it's a far more complete, if pricier, cinema tool.
Read our Nikon ZR review
GoPro Mission 1 Pro
If you want everything the ILS offers minus the lens-swapping hassle, the standard Mission 1 Pro is worth a close look. You get the same 50MP 1-inch sensor and GP3 processor, plus 20m of housing-free waterproofing, autofocus and horizon lock, all wrapped around a fixed ultra-wide lens. It's the easier camera to live with day to day, but you're trading away the ILS's lens flexibility.
Read our GoPro Mission 1 Pro review
- One week of testing with a Laowa 7.5mm F/2.0 C-Dreamer prime lens
- Real-world video shot mounted to a car, plus a coastal stills photo walk
- Battery life and thermal performance checked across the camera's most demanding modes
I spent a week with the Mission 1 Pro ILS, shooting with a Laowa 7.5mm f/2.0 lens that GoPro loaned me for the review.
Video testing included mounting the ILS to my car for real-world stabilization footage, shot largely in 16:9 8K at 60fps using GoPro's recommended color-grading settings, plus a run through Open Gate to see how it held up for reframing flexibility. I edited footage in DaVinci Resolve, applying an official GoPro LUT before making my own color adjustments.
For stills, I took the ILS out on a Sunday photo walk along the coast near where I live, shooting raw at both 50MP and 12MP resolutions with GoPro's Point-and-Shoot Grip attached, and edited the results in Adobe Lightroom.
I also tested the camera's monitoring options, connecting it to an external monitor via a USB-C to HDMI adapter, though I wasn't able to test the iOS-only Mission Monitor app myself, lacking the necessary USB-C to Lightning data cable. Battery life and thermal performance were assessed through everyday use across a range of resolutions and frame rates, including the highest-demand 8K/60fps and 4K/240fps modes.
First reviewed: August 2026
- SOCRadar uncovers AnonyMousKIT, a phishing kit abusing Apple’s Lost Mode contact info
- Crooks spoof Find My pages, trick victims into giving credentials to unlock stolen iPhones
- Active since 2024, it operates like a criminal software business with 500+ domains and AI‑driven vishing
Security researchers have discovered AnonyMousKIT, a new phishing kit designed to bypass the last line of defense for stolen iPhones, which has been in use for more than two years.
Apple devices come with several anti-theft mechanisms working together to make iPhones a lot less attractive to thieves, including Find My, Activation Lock, and Lost Mode.
If a user’s device is lost or stolen, they can use their tablet, laptop, or a similar device to enable Find My iPhone, which can then locate the device through an app or a website. They can also see its location on a map, make it play a sound, remotely wipe it, or receive a notification when it’s found. Enabling the Find My feature also turns on Activation Lock, which locks the phone and prevents it from being set up by someone else.
Even if the thief factory resets it, the phone remains connected to the real owner’s Apple account, and they simply can’t set it up. To do that, they would need the iPhone device passcode to exit Lost Mode, and the Apple account password, if Activation Lock/setup authentication is required.
But there is another feature Apple added, just in case the device isn’t actually stolen, but rather lost. For these occasions, there is an option to display the owner’s contact information on the screen so that a good samaritan who finds it can return it to its rightful owner.
As is the case with many other well-intended features, this one is now also being abused as part of the AnonyMousKIT phishing kit.
This is why we can't have nice thingsAccording to security researchers SOCRadar, crooks are using AnonyMousKIT to create fake Find My or Apple pages. Then, they use the contact information displayed on the stolen iPhone to reach out to the victim. Through the kit, they can send emails, SMS messages, WhatsApp texts, or even AI-powered phone calls. Reaching out to the victim, the attackers introduce themselves as Apple customer support agents, and tell the victim their smartphone had been retrieved.
They also provide the victim with the correct model and IMEI details to confirm the authenticity of their claims. Then they require the victim to confirm their identity by visiting the spoofed Find My page and providing the credentials needed to unlock the phone.
The credentials end up with the attackers, who can then unlock the phone, wipe it, and sell it on the black market for a much higher price.
"Software business"SOCRadar says the earliest records of the AnonyMousKIT date back to early 2024. Since then it has grown into a major operation, counting more than 500 domains, and having more than 150 storefront brands working as resellers and affiliates.
As part of their investigation, the researchers found records of roughly 200 calls, which the crooks made to victims between August 2025 and May 2026. The calls were done using five different AI agent personas and 55 different interaction transcripts.
Every call had cost the attackers $0.10, and most of them - 90% - were made to Brazilian victims. A small percentage of email correspondence was made towards government and corporate addresses, as well. Just under 30 attempts were made towards South African government domains, and three to a local university. While the campaign is global in its reach, it’s mostly focused on South Africa, Indonesia, India, Kenya, Brazil, and Italy.
SOCRadar describes AnonyMousKIT "not as a phishing kit but as a small software business with a criminal customer base."
"Its primary innovation is an automated, LLM-driven voice vector. At ~$0.10 per call, the platform initiates dynamic vishing across three languages using structured pretexts synced with email and SMS lure data, removing the need for fluent human callers."
At the moment the report was published, the campaign was still ongoing, and the researchers are still tracking it.
Via BleepingComputer
- The FDA has approved the Libre Duo 10 Day CGM wearable
- It can continuously measure both ketones and blood sugar levels
- It’s worn by diabetics as a continuous glucose monitor (CGM)
The US Food and Drug Administration (FDA) has approved the first wearable device capable of simultaneously monitoring both ketone and bloody sugar levels, which the organization says is “a breakthrough for the safety of children and adults living with diabetes".
The device in question is the Libre Duo 10 Day monitor. Worn on your arm as a continuous glucose monitor (CGM), it provides minute-by-minute glucose updates that are sent to your smartphone. It also monitors ketone levels and sends you an alert if they rise above a certain threshold.
In terms of who can use it, the Libre Duo 10 Day wearable has been approved for use by people aged two or over who are living with diabetes. It takes the form of a small wearable sensor that measures glucose and ketone levels held within the fluids under your skin.
Made by Abbott Diabetes Care, there are few other specific details about the device for the time being, but the potential is huge.
Simplifying the process(Image credit: Abbott Diabetes Care)In approving the Libre Duo 10 Day, the FDA’s intention is to help prevent diabetic ketoacidosis (DKA). This condition occurs when your body starts using fat instead of glucose for energy, which in turn leads to it producing too much ketone. DKA can become a life-threatening medical emergency if left untreated.
One of the benefits of the Libre Duo 10 Day is that it can track ketone levels in real time. Rather than using a standalone test kit that only provides a snapshot of your situation in that exact moment, the Libre wearable can display trends over time, notifying you if your ketone levels are rising or falling — which could help keep you better informed of whether your risk of DKA is changing.
The fact that it combines ketone monitoring with blood sugar analysis also means you don’t need two separate devices in order to stay on top of your diabetes. Having a single wearable helps keep things straightforward.
We don’t know when the Libre Duo 10 Day will become available, and its manufacturer’s website simply says it is “coming soon.” When it does arrive, it might help simplify the process of ketone and blood sugar monitoring for the 2.1 million Americans with type 1 diabetes for whom DKA is a real threat.
- ShinyHunters adds CyrusOne to its victim list, demanding $13m ransom
- Claimed theft includes 12.9 million Salesforce records, 600GB SharePoint data, PII, contracts, and facility diagrams
- Breach could enable physical intrusions and supply‑chain attacks; CyrusOne has not commented or paid
The infamous ShinyHunters ransomware crew has added CyrusOne, a major US data center operator, to its list of victims, claiming to have stolen a treasure trove of highly sensitive data which, if proven true, could turn this into a bonafide catastrophe for the company and its customers.
Overall, ShinyHunters claims to have exfiltrated 12.9 million Salesforce records, more than 182,000 rows from the Salesforce Contacts object, more than 600 GB of SharePoint data, more than 8,300 employee records containing personally identifiable information (PII), executed contracts, master service agreements, NDAs, and service agreements, data center floor plans, electrical diagrams, access-control records and badge audits, physical key inventories, security policies, critical Environment Reliability Management documentation, and various passwords and credential artifacts.
No samples have been posted just yet, but researchers don’t see it as suspicious, but rather as a pressure tactic.
What makes this attack differentIn exchange for deleting all of the stolen data, ShinyHunters is demanding $13 million from CyrusOne which, at this time, is not commenting on the claims, and is seemingly not interested in negotiations.
“They are refusing to pay a $13 million demand. They have 24 hours left to engage with us. We hold 12.9 million Salesforce records,” the attackers allegedly wrote.
Ransomware groups steal sensitive corporate data all the time, but this incident has the potential to be among the most devastating data breaches ever. Some of the secrets that were nabbed cannot simply be changed: data center floor plans, electrical diagrams, access-control records, badge audits, physical key inventories, this kind of intelligence can be used for physical breaches.
If criminals know how keys are assigned, how the data center is organized, where surveillance cameras are located, and how guards operate, it makes it easier to physically break it.
“You can’t patch a building,” the researchers warned, noting that some of the things that can be changed, such as physical keys and access zones, still take months and “real money”, they added, hinting at just how big the problem could be.
CyrusOne runs some 50 facilities all across the United States and serves hundreds of companies and corporations. Some of its clients include Fortune 1000 companies, as well as big tech names such as Microsoft, Meta, Verizon, AT&T, IBM, and CME Group.
Compounding the problem even further is the fact that ShinyHunters stole information about CyrusOne’s customers, such as Meta, or Microsoft. Information about the locations of certain customers, the services they’re paying for, the NDAs, service-level agreements, and contact information, can all be used for highly tailored, sophisticated phishing attacks that could turn this incident into an unprecedented third-party supply-chain attack.
“Contracts, MSAs, and NDAs identify the tenants as a customer list overlaid on a building map, with pricing and SLAs attached,” the researchers added.
No reactionTo add insult to injury, ShinyHunters also seems to have stolen information about the company’s power, cooling, and critical-environment reliability processes, which they could leverage to physically attack the servers, causing disruptions, outages, and possibly fires.
The group first added CyrusOne to their site on August 20 2026, although at that moment, the name of the victim was redacted, the researchers said. Instead, ShinyHunters posted a warning, saying “Final warning - pay or leak”. The company was given until August 24 to reach out which, it would seem, did not happen.
Three days later, on August 23, ShinyHunters publicly named CyrusOne as their victim, and stated that they demanded $13 million for the files. We are now well past the deadline, and nothing’s changed - the victim hasn’t spoken out, and ShinyHunters did not leak the files.
Via Cybernews
- Researcher registers Linux machine as a trusted device on Apple's Find My network and pulled live people-tracking data that Apple normally reserves for its own hardware
- The work is not a mass-surveillance exploit: it is limited in scope and only reads a location share that a friend had already agreed to, and it cannot silently locate arbitrary Apple users
- The approach took less than a week of protocol reverse engineering, and Apple has maintained silence on queries about the technique employed
Apple keeps the full Find My experience locked to its own devices, but a recent attempt by security researchers suggests that wall may be a relatively weak barrier to entry.
A 22-year-old security researcher who goes by "Zerotistic" documented how they registered an ordinary Linux machine as a trusted node on Apple's network and used its new status to receive live people-location data that Apple otherwise shares only with its own devices, such as iPhones and iPads.
Find My, Apple's catch-all tool for locating hardware such as AirTags, iPhones, and iPads, also lets people share their whereabouts with family and friends, and while Apple has historically guarded this particular feature very closely, it is also the same one the security researcher targeted to introduce a device that Apple does not otherwise have complete control over as part of its ecosystem.
An interesting trick that still requires consent to get the job doneThe task is not an easy one to begin with: convincing Apple's back end that a Linux process was a legitimate Apple device that was part of its ecosystem and therefore could be trusted with information shared via the Find My platform required a lot of trial and error to get going.
It is important to clarify here that Apple's system is not exactly compromised here; the approach still requires a friend to share data that the Linux client that the security researcher built can then read.
Apple currently sends people-location data over its private Push Notification service only after it trusts that the receiving machine belongs to the account and can handle the data. This means the Linux machine would have to speak Apple's private language to query its servers and process the information it received.
It involved obtaining an Apple Identity Services (IDS) certificate, a specialized device and messaging credential Apple's internal framework uses to link an Apple Account to specific hardware, end-to-end encryption keys, and push notification tokens. This meant crafting a certificate signing request and sending it to a legacy Apple enrollment endpoint.
Once done, a Linux box with a signed certificate could sign its own requests and register as a Find My device, but it still had to subscribe to six different subservices to function. The registration request also had to be signed using an IDS certificate and an APNs certificate obtained during initial network setup.
The researcher then issued a SubscribeAndFetch request that provided an encrypted location key from his friend's Apple device to the Linux box, masquerading as one.
What might concern Apple is how fast things moved: the whole pipeline came together in a week. It also didn't require a jailbreak, a leaked key, or even a Mac to do the job. Instead, open-source clients and decompiled daemons were the norm, with a trial-and-error approach that eventually paid off.
The technique has its limitations: attacks can not target a stranger, and consent is required to track even one's friends. It shows that Apple's boundary around Find My stems from an obscure protocol it enforces rather than a cryptographic lock; once a device acts like it is from Apple, the ecosystem treats it as a family member rather than an untrusted node.
Apple has yet to respond to media queries about whether it plans to address the demonstrated trick or patch the loop in the near future.
- A new leak sheds fresh light on the Samsung Galaxy Aero smartwatch
- The device might ditch Wear OS and use the RTOS operating system instead
- It could fix some of the mistakes of the Samsung Galaxy Watch FE
It’s safe to say that we weren’t huge fans of the Samsung Galaxy Watch FE, with our reviewer scoring it a measly two stars and branding it “one of the most confusing smartwatches I’ve ever tested.” Yet despite the disappointment, a new leak suggests that Samsung is going to take another stab at the entry-level smartwatch market — but the result might look very different.
The latest hints come from Gadgets & Wearables, which investigated the Samsung Health and Galaxy Wearable apps to uncover hints of what might be to come. And according to the news outlet, the forthcoming device could take the form of a new Samsung watch dubbed the Galaxy Aero.
What’s interesting about this product is that, unlike many of the best Samsung watches, it might not run on Google’s Wear OS. Previous reporting from SamMobile found hints pointing towards the use of RTOS, or ‘real-time operating system,’ as Samsung software contained references to ‘Galaxy Aero’ and ‘galaxy_rtos_watch.’ The implication here is that these devices were the same product.
RTOS is the platform that Samsung’s Galaxy Fit devices run on and is a far more lightweight system than Wear OS. If RTOS ends up powering the Galaxy Aero, it would suggest that the product will be at the lower end of Samsung’s wearable spectrum.
Further investigation from Gadgets & Wearables suggests that several Samsung apps and services have the capability of handling RTOS and devices that use it. And it’s that capability that supposedly opening the door for the Galaxy Aero.
Righting the wrongs of the past(Image credit: Future)One of our main criticisms of the Samsung Galaxy Watch FE was that it was strangely positioned — at the time, it offered worse performance than the Samsung Galaxy Watch 6, despite being available to buy for the same price or more. With the Galaxy Aero, that uncomfortable quirk might be remedied.
That’s because SamMobile suggests it could be priced below the Watch FE, making it a more sensible proposition for a low-cost smartwatch. If true, that could make it much less of a tough sell.
And there’s another consideration. By using RTOS instead of Wear OS, Samsung could conceivably cut down on battery usage, solving another major problem with the Watch FE. It would mean making some compromises, with limited support for the Google Play Store and third-party apps both possible. But if Samsung can keep the cost down, it’s likely that many users won’t mind.
If Samsung makes that move, it would join rivals like Amazfit and Huawei in launching an affordable fitness tracker that doesn’t rely on Wear OS. Whether it can right the wrongs of the Galaxy Watch FE, however, remains to be seen.


