EN
Back to the archive

The archive · Consumer Apps · Product decision · 2026

Mysk's Loupe shows iPhone users the no-permission data their apps silently read

A free, open-source iOS app that lists every signal your installed apps can read without a prompt — 548 HN points, 1.5k GitHub stars, and macOS next.

Mysk

The betGive people a hands-on tour of fingerprint signals their phones leak without permission, free and open source.Live

What the business is

Loupe — an open-source iOS/iPadOS app that reads the same public API values any installed app can read and displays them raw, as a fingerprinting surface.

How it started

Mysk, an independent mobile-security research team, had spent years publishing findings on how iOS apps pass device signals to trackers — but findings read as abstract. They turned the findings into a hands-on tour: an app that reads the values itself and shows a user, raw, what their phone gives away.

What happened

Loupe shipped open source (MIT) in June 2026, iOS/iPadOS first with a mostly finished macOS port; the README credits AI coding tools for writing 'almost entirely' the app; press coverage (Digital Trends, Mezha, gigazine) and the 2026-06-20 HN thread (548 points, 246 comments) followed.

How it ended up

As of 2026-09-02 Loupe is free and MIT-licensed with 1.5k GitHub stars; no paid tier — its return is reach and credibility for Mysk's research, plus pressure on platforms to close the leaks it documents.

Background

Mysk, an independent security-research team known for probing how iOS apps pass device signals to advertisers, kept publishing findings that read as abstract. Their counter-move was literal: ship an app that reads the same public iOS APIs every installed app can call — the installed-apps list, device-creation timestamp, pasteboard change counters, storage UUID, keychain persistence — and show a user exactly what their iPhone hands over without ever asking.

Loupe is open source (MIT), iOS/iPadOS first with a mostly finished macOS port, and it is deliberately small and honest: values are displayed raw, nothing is uploaded or hashed, and the README credits AI coding tools with writing 'almost entirely' the app. That candor shaped the reception — the Hacker News launch thread (2026-06-20) ran to 246 comments, most appreciative, and coverage from Digital Trends, Mezha and gigazine followed within weeks.

Loupe's model is indirect. It is the tangible artifact behind Mysk's research: the fingerprinting surface it documents is the same one regulators and platforms are starting to eye, and each user who runs it has felt the leak on their own device.

What has to be true

  • Demonstration beats documentation for security claims: watching your own pasteboard counter or device-creation date changes a reader's belief in a way a findings report cannot.
  • Permissionless-by-design keeps the argument intact: because Loupe calls only APIs any app may call, every reading doubles as evidence that the leak needs no permission prompt.
  • Radical transparency is the brand: no telemetry, raw values, AI-credited code — the app models the honesty the team argues the industry lacks.

What can be applied

For a security claim, the strongest proof is the reader's own device: an app that shows me what my phone leaks convinces more than any report, and open-sourcing the proof is what makes it believable.

Aftermath

As of 2026-09-02, Loupe is free and MIT-licensed with 1.5k GitHub stars and the macOS port 'mostly complete'. Mysk continues to publish iOS-privacy research picked up by outlets like TechRadar and 9to5Mac, and Loupe serves as the reproducible artifact behind its claims. There is no paid tier: the tool's return is reach and credibility for the research brand, and each leak it documents stays demonstrable on a reader's own phone.

Sources

spotted an error? The archive wants to know.

Your turn

You just read one. Describe what you are building, and see who is betting on the same thing.

Free account · 3 free questions · no card

Related cases