Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

Security researcher gets Linux device to receive Apple Find My location data

A 22-year-old researcher known as Zerotistic succeeded in enrolling a Linux machine on Apple’s Find My network and extracting live location information shared with his Apple account.

The young security analyst, operating under the handle Zerotistic, discovered a method to register a non-Apple computer with Apple’s Find My service by exploiting the GrandSlam authentication protocol and submitting a specially formatted PKCS#10 request signed with a 2048-bit RSA key using SHA-1. Apple responded with an IDS certificate, allowing the Linux system to appear as a legitimate Find My participant after it subscribed to six required sub-services and presented appropriate APNs credentials.

Once enrolled, the researcher sent a SubscribeAndFetch command, prompting a friend’s Apple device to push an encrypted location payload to the Linux host. He then wrote a script to unwrap Apple’s messaging envelope, extract the shared location key, and decrypt the data, revealing real-time coordinates, timestamps and accuracy metrics. The entire process took less than a week of development. Apple has not yet commented on the discovery.

Why it matters

It shows that Apple’s Find My network can be accessed from non-Apple hardware, raising potential privacy concerns.

In this story

Find MyLinuxlocation dataApple Push Notification servicecertificate signing requestprivacysecurity research
Get the beta ↗