<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Joseph Crawford - Latest Comments in Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.disqus.com/</link><description></description><atom:link href="https://josephcrawford.disqus.com/scary_isight_trick_joseph_crawford/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Thu, 24 Jan 2008 00:08:03 -0000</lastBuildDate><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575438</link><description>&lt;p&gt;hi my name is giovanni and my highschool has distrubited laptops to all of its students i was wondering if u could put this hack on my myspace for me because i cant do it on my own we dont have the dev. toolz please email me and let me know how u feel about this..&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Giovanni</dc:creator><pubDate>Thu, 24 Jan 2008 00:08:03 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575439</link><description>&lt;p&gt;It looks to me like Leopard has fixed this so it can no longer be used... bummer it was cool while it lasted lol.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Tue, 20 Nov 2007 18:52:25 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575440</link><description>&lt;p&gt;I have fixed the video :)&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Fri, 28 Sep 2007 15:15:40 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575436</link><description>&lt;p&gt;Yea my site got messed up and I didn't notice this was not working, I will have to get this working again.  Thanks for pointing this out.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Wed, 18 Apr 2007 21:48:08 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575437</link><description>&lt;p&gt;I now notice that the iSight pictue does not show up (Running Safari on my MacBook and iSight is not in use).&lt;/p&gt;&lt;p&gt;Perhaps the 10.4.9 update corrected this "security flaw"?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jay</dc:creator><pubDate>Wed, 18 Apr 2007 16:23:41 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575435</link><description>&lt;p&gt;Hello,&lt;/p&gt;&lt;p&gt;Honestly I would not be your best bet for advice here, maybe someone else who has commented on this post could help out.&lt;/p&gt;&lt;p&gt;Although it just looks to me like they are showing their video locally (could do it with iChat even) and screen casting it so that it is captured inline with what they are doing.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Sun, 14 Jan 2007 23:54:24 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575434</link><description>&lt;p&gt;Joseph,&lt;/p&gt;&lt;p&gt;I'm looking for a way to show a small, borderless live video window to use in screencasting. The idea is to record the presenter while he is demonstrating software. Here is rough example:&lt;/p&gt;&lt;p&gt;&lt;a href="http://mediacast.sun.com/share/lou/RSS_Demo.mov" rel="nofollow noopener" target="_blank" title="http://mediacast.sun.com/share/lou/RSS_Demo.mov"&gt;http://mediacast.sun.com/sh...&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Would you know how to do this without using a clunky Quicktime preview window?&lt;/p&gt;&lt;p&gt;Thanks&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Lou Ordorica</dc:creator><pubDate>Sun, 14 Jan 2007 18:44:14 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575433</link><description>&lt;p&gt;Thanks for all of the comments guys, I appreciate the feedback&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Fri, 12 Jan 2007 08:04:22 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575432</link><description>&lt;p&gt;I found this info very interesting and useful. Thanx a lot.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Leo</dc:creator><pubDate>Mon, 18 Dec 2006 05:26:39 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575431</link><description>&lt;p&gt;Are there any patches that allow this to work with 10.3.9? Any ideas?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Booperkit</dc:creator><pubDate>Thu, 14 Dec 2006 11:53:14 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575430</link><description>&lt;p&gt;What do you want to turn off?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Mon, 04 Dec 2006 13:20:40 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575429</link><description>&lt;p&gt;And how do you turn it OFF ?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Fanoo</dc:creator><pubDate>Mon, 04 Dec 2006 13:09:08 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575428</link><description>&lt;p&gt;Judging by the number of posters that find this scary, I think that one can safely conclude that this trick could be used to "Socially Engineer" an exploit. For example, someone could be convinced that you have video of them doing something embarrassing and that leads to blackmail.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Security is Not Just Technolog</dc:creator><pubDate>Wed, 15 Nov 2006 07:17:41 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575427</link><description>&lt;p&gt;The only scary thing about this is that it is a picture of me.  Whoa! who is that big fat bald guy?  Oh its me!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Bill Mead</dc:creator><pubDate>Tue, 14 Nov 2006 23:17:05 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575426</link><description>&lt;p&gt;Murdoch,&lt;/p&gt;&lt;p&gt;Except that's not what's happening, because that's not what this does. And if what you said were happening, it would be ridiculously easy to see outbound network connections being made, whether by wired, wireless, or any mechanism. That can't be hidden.&lt;/p&gt;&lt;p&gt;This trick CANNOT BE USED REMOTELY, BY ANYONE.&lt;/p&gt;&lt;p&gt;Dave Schroeder&lt;br&gt;das@doit.wisc.edu&lt;br&gt;&lt;a href="http://das.doit.wisc.edu/" rel="nofollow noopener" target="_blank" title="http://das.doit.wisc.edu/"&gt;http://das.doit.wisc.edu/&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guest</dc:creator><pubDate>Tue, 14 Nov 2006 17:59:27 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575425</link><description>&lt;p&gt;It's weird that I see this now here for the first time, 'cause I just had a dream 2 or 3 days ago that Apple was actually working for some secret agency like the CIA. And all the macs had an iSight now so they could spy on people cause they had access to all of them through some software available only to them. :(&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Murdoch</dc:creator><pubDate>Tue, 14 Nov 2006 13:46:17 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575424</link><description>&lt;p&gt;Check out this version, which also uses your microphone: &lt;a href="http://www.uccs.edu/~cbrewer/gigo_files/ab0273a8deaa53e2de475736042cd62b-14.html" rel="nofollow noopener" target="_blank" title="http://www.uccs.edu/~cbrewer/gigo_files/ab0273a8deaa53e2de475736042cd62b-14.html"&gt;http://www.uccs.edu/~cbrewe...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Godrifle</dc:creator><pubDate>Tue, 14 Nov 2006 09:54:53 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575423</link><description>&lt;p&gt;Jules,&lt;/p&gt;&lt;p&gt;That wouldn't be possible since there's no way to use this remotely.&lt;/p&gt;&lt;p&gt;You could, however, instruct the person to take their own picture with their iSight (e.g., with Photobooth) or other camera and upload it...&lt;/p&gt;&lt;p&gt;There no special way to "use" this in the way you describe just because it happens to be in a web page. I want to make this clear, because if people think that what you describe is possible, then there are ways to abuse it. (See my previous messages.)&lt;/p&gt;&lt;p&gt;Dave Schroeder&lt;br&gt;das@doit.wisc.edu&lt;br&gt;&lt;a href="http://das.doit.wisc.edu/" rel="nofollow noopener" target="_blank" title="http://das.doit.wisc.edu/"&gt;http://das.doit.wisc.edu/&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guest</dc:creator><pubDate>Tue, 14 Nov 2006 09:49:02 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575422</link><description>&lt;p&gt;Wow, you can display a local feed from an isight. So what.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Peter Morgan</dc:creator><pubDate>Tue, 14 Nov 2006 08:14:44 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575421</link><description>&lt;p&gt;That's not scary. This iSight Trick is scary:&lt;/p&gt;&lt;p&gt;&lt;a href="http://funwithstuff.com/blog/2006/11/got-mac-inspired-by-joseph-crawfords.html" rel="nofollow noopener" target="_blank" title="http://funwithstuff.com/blog/2006/11/got-mac-inspired-by-joseph-crawfords.html"&gt;http://funwithstuff.com/blo...&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Iain Anderson</dc:creator><pubDate>Tue, 14 Nov 2006 07:08:11 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575420</link><description>&lt;p&gt;A piece of tape is enough to disable it!!!&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">GillesB</dc:creator><pubDate>Tue, 14 Nov 2006 06:31:44 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575419</link><description>&lt;p&gt;Awesome !!&lt;br&gt;Would be cool to have the possibility to take a snapshot so this trick could be use, for example, on user registration : user could add a picture to his account.&lt;br&gt;Just show the user face, then user click on "take a photo" then the photo is uploaded and added to his account , in his prefs.&lt;/p&gt;&lt;p&gt;Cool stuff !&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Jules</dc:creator><pubDate>Tue, 14 Nov 2006 06:23:23 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575418</link><description>&lt;p&gt;Huh.....I have an iSight but it doesn't work. I see no picture, and my iSight is still off.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Crazybitch</dc:creator><pubDate>Tue, 14 Nov 2006 05:43:54 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575417</link><description>&lt;p&gt;Dave,&lt;/p&gt;&lt;p&gt;Thanks for explaining that.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Joseph Crawford</dc:creator><pubDate>Mon, 13 Nov 2006 16:59:21 -0000</pubDate></item><item><title>Re: Scary iSight Trick | Joseph Crawford</title><link>http://josephcrawford.com/2006/11/11/scary-isight-trick/#comment-3575416</link><description>&lt;p&gt;Rich,&lt;/p&gt;&lt;p&gt;You are correct that, if anything, this is a reminder that cameras without physical shutters, or the fact that cameras cannot be physically disabled or omitted in the latest iterations of Apple's products. It's also a reminder that if a machine were compromised, an attacker could potentially have control over the camera (as well as anything else), which could cause a variety of problems for secured environments (not to mention personal ones ;-).&lt;/p&gt;&lt;p&gt;But to be clear, this particular demonstration doesn't make such a compromise easier or possible. It merely serves as a reminder that such a compromise, in which an attacker had full remote control over the machine and could do anything with it anyway, could also use the camera.&lt;/p&gt;&lt;p&gt;Joseph,&lt;/p&gt;&lt;p&gt;As far as screenshots are concerned, a screenshot would still have to be taken, and then uploaded somewhere. Again, that is not possible unless it would be via some other mechanism of compromise. It's important to understand that this Quartz-Composer-in-QuickTime-embedded-in-a-web-page trick doesn't make any possible exploit that could take advantage of this easier.&lt;/p&gt;&lt;p&gt;Now, if there was some remote exploit where an attacker could take a screenshot of a web page and upload or capture it somewhere (which currently doesn't exist and I don't see how would be possible, but seems to be what a lot of people are saying), then, yes, this could be interesting. But the point is, some other MAJOR exploit is required to take advantage of this in any way. And if someone already had access to your machine in that way and wanted to use your camera, they're not going to trick you into going to a web page with a Quartz Composer movie in it - they're just going to use your camera. ;-)&lt;/p&gt;&lt;p&gt;The reason why this is "scary" is because you're seeing yourself on a "web page". But in reality all that's happening is you're seeing a QuickTime movie that happens to have an action to display a locally attached iSight that is embedded in a web page. There is no inherent security risk, real or perceived, from even turning on your iSight in this fashion. A security risk would imply and require that it could be used for something improper or without your knowledge, and it cannot.&lt;/p&gt;&lt;p&gt;Saying that it "turns on your iSight without your permission" is like saying that a web page is displaying text "without your permission." There is going to be this strong urge for people to say, "But...but...it's a *camera*! This *has* to be bad somehow!" But in reality, it's not. It's just a nifty trick with no security implications, which is why it's been around for so long, and even Apple itself has demonstrated how this could be done. It's the idea of seeing yourself unexpectedly on a "web page" that's startling.&lt;/p&gt;&lt;p&gt;Now, I will fully agree that iSights and Apple's integrated cameras should have physical shutters or the ability to be physically disabled and/or omitted completely from orders (particularly for government/military applications), but that is another issue altogether.&lt;/p&gt;&lt;p&gt;Also, using this trick to turn on someone's iSight might be a neat trick, but it's somewhat disconcerting. While it may be rude, as long as one understands the technical details of what is actually occurring, that's all that it is: rude. But definitely not a security risk.&lt;/p&gt;&lt;p&gt;Regards,&lt;/p&gt;&lt;p&gt;Dave Schroeder&lt;br&gt;das@doit.wisc.edu&lt;br&gt;&lt;a href="http://das.doit.wisc.edu/" rel="nofollow noopener" target="_blank" title="http://das.doit.wisc.edu/"&gt;http://das.doit.wisc.edu/&lt;/a&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Guest</dc:creator><pubDate>Mon, 13 Nov 2006 16:54:18 -0000</pubDate></item></channel></rss>