3 ms·
It seems to me that this attack leaves a very easy to detect signature of several tags that were seen only once by the same device. To counter being detected, a
by air7 5y ago
It seems to me that this attack leaves a very easy to detect signature of several tags that were seen only once by the same device. To counter being detected, an attacker would need to fake other readings of the same single-use "tags" by other devices. This is somewhat similar to the detecting fake spam accounts in social networks. It's a cat-and-mouse game, but it seems that in this case the cat has the upper hand unless the mice are willing to put in a lot of effort to fake "realness", which might make the attack not feasible.
- adhesive_wombat 5y agoNot that hard, but no longer trivially done by just buying the inevitable stealth AirTag clones. Step one: Set up one of these with a known sequence of keys: either preloaded or a derivation function (to allow it to run continuously). Plant it on your victim. Step two: set up another one with the same key sequence, but delay it (or advance it), so that the same keys are presented, but on a delay. Plant this one in a public place with lots of iPhones, ideally moving around like on a bus or train. Now, the keys won't be unique any more. With a bit more thought, you can probably figure a way to make it even less obvious (the decoy tags rotate faster and reuse old keys on a cycle, perhaps, so they keep pinging up and obscuring the single real one). A lot more effort than a buy and forget device, for sure. Figuring out a strategy to counter such an attack would be a fascinating game of real life tower defense, if not for the fact that if you fail, people get harmed. Still seems mad to me that the tags aren't also rocking some kind of secure enclave so that they can, say, cryptographically sign off as genuine. Crypto chips are (perhaps literally if you own the silicon anyway) ten a penny. Even without the security implications, seems like leaving money on the table to me, which is unlike Apple.