3 ms·
The claimed threat vector is loss of anonyminity. There is no anonyminity designed into AirDrop, and nowhere in Apple's documentation do I see the claim for it.
by groovybits 7y ago
The claimed threat vector is loss of anonyminity. There is no anonyminity designed into AirDrop, and nowhere in Apple's documentation do I see the claim for it.
You iCloud account is your identity. When you choose to share things directly from your phone, you are choosing to share that identity. How else can another iPhone verify you?
There is no information leak. This is a clickbait title combined with a 'Well, duh' moment.
- bri3d 7y agoThere’s a difference between disclosing “I am phone XYZ and I want to AirDrop” and “here is my phone number.” I would call that an information disclosure. With that said I agree with you that it’s an intuitive and non-serious disclosure, but it appears some disagree.
- eridius 7y agoExcept it's not "here is my phone number", it's "if you know my phone number you can tell it's me".
- Thorrez 7y agoIt's functionally the same, because attackers can brute force all phone numbers to reverse the hash.
- heroic 7y agoSo basically someone trying to call all phone numbers and identify your number, when it rings falls in the same category?
- Thorrez 7y agoNo, calling a number is expensive. It takes time, processing power, a phone plan, etc. It also alerts the victim, as well as your phone provider who will likely shut you down. Calculating a hash is cheap, a single GPU can calculate 5 billion sha256 hashes/second.
- eridius 7y agoI just looked up Apple's Security White Paper and it explains that the Bluetooth LE signal only includes a "short identity hash", and then the receiving device responds with its own identity info, and then the sending device establishes a peer-to-peer WiFi connection and sends its "long identity hash", which the receiver then uses to confirm that it knows the recipient before responding with its own "long identity hash". Which it to say, it sounds like you only get partial information about the sender prior to identifying yourself and establishing a direct connection. So you cannot passively identify the exact phone number of an unknown sender. The "short identity hash" itself it says is "created based on the email addresses and phone numbers associated with the user’s Apple ID", though I have to assume that it's independently hashing each piece of info because if you hash the whole set, then the receiver would have to know the whole set, which would be a problem (my device knows more email addresses for me than any of my friends do).
- Thorrez 7y agoInteresting. Looking at the code, it uses the first 3 bytes of the sha256 hash. That's 24 bits of entropy, or 16777216 possibilities. So if you know the area code, you can find the full phone number with decent probability. https://github.com/hexway/apple_bleee/blob/master/hash2phone/hashmap_gen.py https://github.com/hexway/apple_bleee/blob/master/hash2phone...