Germany: Ex-spy chief arrested for espionage
Germany has arrested a former spy chief on charges of espionage. The arrest highlights ongoing concerns about intelligence security in the country. (dw.com)
This explains how iChat AV on older Macs (Leopard/Snow Leopard) can be made to perform audio/video calls again by recreating Apple's long-defunct SNATMAP service. iChat originally fetched configuration.apple.com/configurations/macosx/ichat/1/snatmap.txt to learn an SNATMAP UDP endpoint, then used that server on UDP port 5678 to discover each peer's public IP/port so peers could establish an RTP connection through NAT. Modern redirects to HTTPS break the old TLS stack, so iChat falls back to exchanging private LAN addresses and calls fail. Using packet captures and an LLM to reverse-engineer the protocol, a simple spec was produced: 16-byte UDP request/response packets containing a type (1=request, 2=response), nonce, and IP/port fields; the server returns the caller's external IP and port. A small Python SNATMAP implementation was written from that spec.
The recreated service was validated in a lab built from two NATed OpenWrt VMs and two Macs behind them, with an ejabberd XMPP server and lighttpd serving snatmap.txt. Practical deployment steps are provided: host configuration.apple.com to a server running snatmap and serve /configurations/macosx/ichat/1/snatmap.txt containing snatmap://YOUR_SERVER_IP:5678, ensure your router preserves source ports (enable in pfSense/OPNsense), or use the author's public server by adding "157.230.2.213 configuration.apple.com" to /etc/hosts. Logitech USB webcams (eg. C920) work, spec and source code are linked for self-hosting.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Germany has arrested a former spy chief on charges of espionage. The arrest highlights ongoing concerns about intelligence security in the country. (dw.com)
The German military intelligence agency MAD has implemented an AI system to screen Bundeswehr applicants for right-wing extremism by analyzing their online activities. Tens of thousands of applicants have been examined, with a small number filtered out due to extremist content. (news.osna.fm)
UK MPs are calling for an investigation into the treatment of whistleblower Simon Andriesz, who died in Thailand last month. Andriesz had exposed links between US Commerce Secretary Howard Lutnick and Jeffrey Epstein, raising concerns about retaliation by financial regulators. (bbc.co.uk)
Anojan Sivarasa, a Sri Lankan migrant worker in Saudi Arabia, faces the death penalty for a Facebook comment deemed blasphemous against Islam. Diplomatic efforts and public petitions are underway to seek clemency, but his fate remains uncertain. (bbc.co.uk)
Apple is testing code in Safari to track when Google promotes Chrome or the Google app to users and how they respond. This may be part of efforts to address regulatory scrutiny over browser competition and user choice. (9to5mac.com)
Decompiling complex software like AAA games shows that almost any binary can be reverse-engineered, threatening software secrecy. This signals the decline of closed-source models and the rise of open source dominance. (twitter.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.