Hacker News new | ask | show | jobs
by dexter0 2049 days ago
It's not clear from the tweet and video: How is his exfiltrator piggybacking on an excluded Apple process? Is nsurlsessiond in the exclude list?
1 comments

I don't think the video was intended to explain the technique. It's likely that Wardle is privately reporting the details to Apple Product Security.