conv.

All stories
TechQuiet 42h · day 3

iOS 27 quietly adds an API letting apps ask if you're being scammed

Apple's new Impersonation Risk Detection flags suspicious money transfers or password changes, but ships off by default and buried in settings.

What to know

  • Impersonation Risk Detection uses interaction patterns, timing, context and sensor data — not Photos, Messages, or Mail content — to flag possible scam activity to supporting apps.
  • The system only returns a single word (Unknown/Medium/High); iOS itself does not freeze transfers, block changes, or show alerts — apps decide what to do with the flag.
  • It's unclear which apps currently support the feature.
  • The feature is off by default and buried about four taps deep behind a toggle labeled 'Share with App Developers,' drawing criticism for poor discoverability.

Apple iOS 27 developerArin Waichulis 9to5Mac Security Bite columnistAAKL Infosec commenter (@infosec.exchange)

iOS 27 quietly adds an API letting apps ask if you're being scammed
9to5mac.com

How it unfolded 2 developments, newest first · click a bar or a number to jump articlesposts

Peak 4 pieces in one hour at Sep 21, 10 AM; 7 pieces over 3 days (4 articles · 3 posts) Sep 21, 10 AM — 4 pieces · 2 articles · 2 posts — Mastodon 3, Newswires 1Sep 21, 11 AM — quietSep 21, 12 PM — quietSep 21, 1 PM — quietSep 21, 2 PM — quietSep 21, 3 PM — quietSep 21, 4 PM — quietSep 21, 5 PM — quietSep 21, 6 PM — 1 piece · 1 article — Newswires 1Sep 21, 7 PM — quietSep 21, 8 PM — quietSep 21, 9 PM — quietSep 21, 10 PM — quietSep 21, 11 PM — quietSep 22, 12 AM — quietSep 22, 1 AM — quietSep 22, 2 AM — quietSep 22, 3 AM — quietSep 22, 4 AM — quietSep 22, 5 AM — quietSep 22, 6 AM — quietSep 22, 7 AM — quietSep 22, 8 AM — 1 piece · 1 article — Newswires 1Sep 22, 9 AM — 1 piece · 1 post — Mastodon 1Sep 22, 10 AM — quietSep 22, 11 AM — quietSep 22, 12 PM — quietSep 22, 1 PM — quietSep 22, 2 PM — quietSep 22, 3 PM — quietSep 22, 4 PM — quietSep 22, 5 PM — quietSep 22, 6 PM — quietSep 22, 7 PM — quietSep 22, 8 PM — quietSep 22, 9 PM — quietSep 22, 10 PM — quietSep 22, 11 PM — quietYesterday, 12 AM — quietYesterday, 1 AM — quietYesterday, 2 AM — quietYesterday, 3 AM — quietYesterday, 4 AM — quietYesterday, 5 AM — quietYesterday, 6 AM — quietYesterday, 7 AM — quietYesterday, 8 AM — quietYesterday, 9 AM — quietYesterday, 10 AM — quietYesterday, 11 AM — quietYesterday, 12 PM — quietYesterday, 1 PM — quietYesterday, 2 PM — quietYesterday, 3 PM — quietYesterday, 4 PM — quietYesterday, 5 PM — quietYesterday, 6 PM — quietYesterday, 7 PM — quietYesterday, 8 PM — quietYesterday, 9 PM — quietYesterday, 10 PM — quietYesterday, 11 PM — quietToday, 12 AM — quietToday, 1 AM — quietToday, 2 AM — quietToday, 3 AM — quiet 1–2
Sep 22yesterdaynow · 4:44 AM ET
  1. 2

    Infosec commenter questions feature's transparency and scope

    A commenter on the 9to5Mac Mastodon post welcomed the concept but questioned what data the feature actually examines and how much depends on individual app developers acting on the risk flag.

    “Not sure what to make of this. On the surface, this is a great feature.”
    — AAKL@infosec.exchange
    • AAKL@infosec.exchange

      Not sure what to make of this. On the surface, this is a great feature. But the app you're using would have to support such a feature. Then, there's the part about how the feature "doesn’t look at content in Photos, Messages, or Mail for context." Where does it look then? 🤔. And lastly, it depends on what the app does with the resulting red…

      AAKL@infosec.exchangeMastodon2d agoview on Mastodon ↗
  2. 1

    Columnist criticizes default-off, buried toggle

    9to5Mac's Arin Waichulis argues the feature is shipped off by default and hidden roughly four taps deep in Privacy and Security settings behind a toggle labeled 'Share with App Developers,' meaning the people most likely to need it won't find it.

    “My gripe is that Apple shipped the feature off by default, about four taps deep in Privacy and Security within iOS 27 Settings, behind a toggle labeled “Share with App Developers,” which sounds like something you would want to avoid.”
    — Arin Waichulis
    1. first by Mastodon, 2d ago · also 9to5Mac

      1 more headline
  3. background

    9to5Mac details how Impersonation Risk Detection works — The Security Bite column explains that supporting apps can query iOS for a risk read on actions like payments or password resets, receiving only 'Unknown,' 'Medium,' or 'High' without access to message, photo, or mail content.

  4. background

    Apple releases iOS 27 with new security features — Apple officially rolled out iOS 27 to all users, including a batch of new security features after what the author called a lackluster iOS 26 on that front.