6 ms·
One explanation is that Apple has sat on this for 2 years, knowing this is a serious security bug. Another explanation is that they just don't think it's that s
by scotchmi_st 5y ago
One explanation is that Apple has sat on this for 2 years, knowing this is a serious security bug. Another explanation is that they just don't think it's that serious. The article states-
> The discovered problems are rooted in Apple's use of hash functions for “obfuscating” the exchanged phone numbers and email addresses during the discovery process. However, researchers from TU Darmstadt already showed that hashing fails to provide privacy-preserving contact discovery as so-called hash values can be quickly reversed using simple techniques such as brute-force attacks.
The post that they then linked to is about how, by hashing random phone numbers, you can effectively de-anonymise users of popular messaging apps.
So you'd need to be in physical proximity to the person, and what you're getting is details like your phone number which aren't especially private anyway (they literally need to be given to people to be of any use). It's far from the dragnet-level issue facing Signal & Whatsapp and others.
I don't know, but that doesn't seem like an especially serious issue to me. It seems just like a research group trying to make some hype for themselves.
- deleted 5y ago[deleted]
- ryanwhitney 5y agoNot sure how much is required to brute force these, but AirDrop has been used in notably sensitive situations like the Hong Kong protests[1], where I’m sure anonymity was assumed. Proximity doesn’t mean I would like to share my phone number. Seems like an unlikely attack day-to-day, but one with definite privacy and personal safety concerns. 1: https://qz.com/1660460/hong-kong-protesters-use-airdrop-to-breach-chinas-firewall/ https://qz.com/1660460/hong-kong-protesters-use-airdrop-to-b...
- scotchmi_st 5y agoIf the state where you live wants to know if you've been at a protest, they have more efficient ways of figuring that out than sending someone out to walk around, trying to collect AirDrop IDs. That should be the least of your worries. I mean sure, I'm not saying there's no issue here. But it certainly isn't 'huge' either.
- Apocryphon 5y agoIt sounds like a metadata situation where collecting AirDrop IDs is another piece of the puzzle that helps build a complete data profile of individuals. It may not be a huge issue, but it’s certainly not a small one.
- eptcyka 5y agoIf I turn off my phones LTE radio, and wear face coverings, how exactly would a state track me? Its said that Apple tries to randomize MACs of all the radios as much practically possible. What's the spin here?
- philsnow 5y agoIf I were seriously trying to avoid tracking, you can bet my phone would have its very own tin foil hat. I don't trust "airplane mode" to not still have some radio active, but I trust physics.
- lozf 5y ago"Gait DNA" and / or WiFi / Bluetooth perhaps?
- eptcyka 5y agoApple allegedly tries it's hardest to randomize bluetooth and WiFi MACs.
- hansel_der 5y agobluetooth mac addr is NOT randomized as of IOS 14.4.2
- ramphastidae 5y agoCitation needed. The state is far less organized and competent than you think if the US is any indication. Planes were flown into skyscrapers and government facilities and we had zero defenses in place. A global pandemic occurred and we had no plan, PPE or ventilator supply and could not mobilize our infrastructure to respond. Thousands descended on the Capitol building and took selfies during a violent overthrow attempt and the FBI has no idea who the majority of them were, depending on internet tips to identify them.
- deleted 5y ago[deleted]
- jdsully 5y agoIn the old days they used to print giant books of these "phone numbers" and drop them on your neighbours porches. Odd how things that were common are now security risks.
- macintux 5y agoIn the old days phone numbers were not used for authentication.
- hansel_der 5y agonor were they carried on person and linked to a government id
- prutschman 5y agoAnd in the old days you could get your number unlisted if you didn't want it published.
- angry_octet 5y agoIn Australia you have to pay extra for this feature, like $3/month, and extra for caller ID blocking, but cell numbers get unlisted status for free. I haven't had a landline for a decade. Is this still the case in the US?(https://www.motherjones.com/kevin-drum/2010/08/unlisted-phone-number-scam/ https://www.motherjones.com/kevin-drum/2010/08/unlisted-phon...) Makes me wonder how sparse phone numbers would have to be to make spam impractical. Would people use long virtual numbers? Imagine if your friends had your 64 digit phone number, and you would know it was a non spam inbound caller. Or even better, TOFU, like a Signal call. Or just a Signal data channel over LTE.
- dingaling 5y agodelisted un- is a prefix for adjectives, not verbs. e.g. Bob decrypted the message and set it to Alice as unencrypted plain-text. Unlisted numbers are less prone to robo-calling, but most phone companies charge a fee for delisting a number.
- lxgr 5y ago> So you'd need to be in physical proximity to the person, and what you're getting is details like your phone number which aren't especially private anyway Once you know the phone number, you would then be able to track an iOS device's location if it's in "contacts only" discoverability mode for AirDrop, right?
- dkonofalski 5y agoNot unless the device in question also has your number listed in its contacts.
- willyt 5y agoDepends how easy this is to do on the fly. Lots of people thinking about it like it's a spy thriller. But could a creep with a laptop use it to harvest phone numbers from random school girls that they like the look of in starbucks? Not sure I would like my kids to experience this.
- dannyw 5y agoYes, I believe so.
- dkonofalski 5y agoThat's what I thought too since the AirDrop protocol, as mentioned in the article, doesn't even share any of that hashed info unless a user opens the share sheet to initiate an AirDrop transfer. To me, that means that if I was going to attack someone using this exploit, I would need to sit there all day until someone used AirDrop to send something and then I'd need to make sure to have my attack planned out in advance so that I could then use that information to do something useful. The chances of that actually happening to some detriment are so small, in my eyes.