3 ms·
AirDrop never was hacked. It uses bluetooth and wifi to auth/search/transfer. It doesn’t require any existing network so it works in the desert or in the middle
by supreme_berry 5y ago
AirDrop never was hacked. It uses bluetooth and wifi to auth/search/transfer. It doesn’t require any existing network so it works in the desert or in the middle of the ocean.
- fragmede 5y agoThat's slicing it rather finely. After transfer is complete, the host device opens the transferred data. When combined with CVE-2016-4657 on an unpatched device, they allow an attacker to gain control of the victim's device after they accept the airdrop. We can call that a Webkit vulnerability instead of Airdrop (because it is), but end of the day, Airdrop is another route for attackers to gain access to your system. You can choose to enable it if you deem it useful enough, but it would be naive to blindly believe "it's fine". Now, the victim has to accept the Airdrop payload, and Airdrop has limited range, so it's not as scary as the Pegasus iMessage exploit which was totally remote, but I wouldn't bet my life on the Airdrop code having zero bugs.
- jamesgeck0 5y agoAirDrop has had several vulnerabilities. Some of them were reported by the same group of security researchers who developed OpenDrop. ADWL, the underlying protocol, had a zero-day that allowed pwning every iOS device in radio range with no user interaction. https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-click-radio-proximity.html https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-c...
- nojito 5y agoWere any of them actively exploited?