Security researcher gets Linux device to receive Apple Find My location data
A 22-year-old researcher known as Zerotistic succeeded in enrolling a Linux machine on Apple’s Find My network and extracting live location information shared with his Apple account.
The young security analyst, operating under the handle Zerotistic, discovered a method to register a non-Apple computer with Apple’s Find My service by exploiting the GrandSlam authentication protocol and submitting a specially formatted PKCS#10 request signed with a 2048-bit RSA key using SHA-1. Apple responded with an IDS certificate, allowing the Linux system to appear as a legitimate Find My participant after it subscribed to six required sub-services and presented appropriate APNs credentials.
Once enrolled, the researcher sent a SubscribeAndFetch command, prompting a friend’s Apple device to push an encrypted location payload to the Linux host. He then wrote a script to unwrap Apple’s messaging envelope, extract the shared location key, and decrypt the data, revealing real-time coordinates, timestamps and accuracy metrics. The entire process took less than a week of development. Apple has not yet commented on the discovery.
Why it matters
It shows that Apple’s Find My network can be accessed from non-Apple hardware, raising potential privacy concerns.
In this story
