5 ms·
As far as I know, dissidents would hang around major population area (i.e, subway station) and allow for anonymous users to connect to them to transfer files. T
by fma 3y ago
As far as I know, dissidents would hang around major population area (i.e, subway station) and allow for anonymous users to connect to them to transfer files. This security issue would allow the Chinese government to track them.
However, also as far as I know...although VPNs are banned in China, there are ways to get them. I'd wonder how much do dissidents use Airdrop in this manner if they can access the global Internet anonymously. Given mass surveillance in China, I'm sure the Chinese government can track "oh this airdrop sender appears every time this person is in this station".
I also hope that Apple adopts an open source protocol for AirDrop not just for cross platform compatibility, but auditable security. Android has its own "Nearby Share". If Apple doesn't want to get in trouble for "fixing" this, they can easily adopt a cross platform compatible protocol that just happens to also fix this.
- vyrotek 3y agoIs this sort of sharing big enough to warrant dedicated and open-source devices just to do this? A sort-of glorified USB Drive with a sharing protocol and nothing else. You walk around and it just syncs up with things around you. Something that looks like an original iPod with a screen and folders of files. I don't know anything about the AirDrop or NearbyShare protocols, but I wonder if they can be implemented in such a device? All the recently announced dedicated AI devices make me think people might be into it.
- samstave 3y agoThis would be a really cool way to secretly do intel "dead-drops" where you just need to walk by a certain place at a certain time to receive your dead-drop/
- brk 3y agoIt’s already a thing for dead drop data exchange. Has been for about 20 years now. First with ad-hoc WiFi networks.
- hattmall 3y agoWay longer than that too. Transmitting encrypted data packets over radio waves was a thing during the cold war. Tune in to a certain frequency at a certain time, of course you must be in range too, record the packet then go back and decrypt it.
- bombcar 3y agohttps://en.m.wikipedia.org/wiki/Numbers_station https://en.m.wikipedia.org/wiki/Numbers_station still exist and there’s basically nothing you can do to trace recipients.
- mdhb 3y agoA lot has changed since then but they had techniques to identify the listeners as early as the 50s https://en.m.wikipedia.org/wiki/Operation_RAFTER https://en.m.wikipedia.org/wiki/Operation_RAFTER Having said that there isn’t really anything special about this particular technique of using numbers stations. It’s just a part of the same trick to pass along information via an open channel without having to give away what the message is about or who the intended audience is supposed to be. Taking out an ad in the classifieds section of a newspaper is ultimately the same trick just with a much lower bandwidth to transmit anything useful beyond a simple signal.
- wiml 3y agoI think some of the offline-first chat/social networks will work this way - briar? serval?
- simplyluke 3y agoIf you haven’t seen it before you might find the pirate box interesting. No longer exists and definitely a relic of the era of piracy/crypto from a decade+ back. https://en.m.wikipedia.org/wiki/PirateBox https://en.m.wikipedia.org/wiki/PirateBox
- lxgr 3y agoThis would be great, and I'd be really happy to see it. One (definitely not insurmountable) problem that would exist in such a federated and open system is credential authentication: Currently, Apple signs your email address and phone number (hash) so that you can't impersonate somebody's trusted contacts and send unwanted material to them without their consent, which has been a problem for Apple in the past. That's supposedly also why they have removed the "allow all AirDrop senders" option in favor of one that times out after 10 minutes. There would either have to be a federated alternative to that, or the open source system would have to drop sender authentication; then you could only receive AirDrops while your device is in "allow all senders" mode.
- olliej 3y agoHow would federation solve this problem? The reason there's anything in the airdrop protocol that can be converted to a person is to allow your device to say who is sending it if you know their identity already, and/or to filter the messages if you don't. The whole point of this activity was that people did not care, nor want to care, about who was sending payloads. In such an environment the solution is no identity at all, not federation of identity. If you do try to do this simply because of "federation", all china does it use the same federation system to get the user information (because the whole point here is china was monitoring local bluetooth info, so some nebulous application of federation dust doesn't magically resolve anything). The problem here is that people were using a system is not anonymous by design (there is a deterministic relationship between the underlying account and the hash by published design), and that relationship is necessary for basic functionality. A hindsight being 50/50 step could have been to use a password hashing function, but airdrop has existed long enough at this point for me to assume that the iterative systems would have relatively low iteration counts, and mobile hardware probably can't afford the resources to make every airdrop also perform memory bounding steps.
- lxgr 3y ago> How would federation solve this problem? I'm not saying that federation solves the anonymity problem, I'm just saying that the current implementation includes Apple as a trust anchor for email address and phone number verification and issuance of corresponding certificates. My point is that in order to enable an open cross-platform solution, there would have to be some alternative mechanism to that. What they could add is a sender-side option that makes sending completely anonymously. This would be possible without any change on the receiver side, but would require recipients to enable "allow all senders" mode.
- bobobob420 3y agoMany people use vpn openly in china for business and gaming. Its sort of allowed. Source : my Chinese mates
- samstave 3y agoThis is not a snarky comment: It wouldnt be surprising if VPN use will be tied to a social credit score, if not already?
- hattmall 3y agoYeah maybe, but people give the CCP way more credit than is due. They are a much more hands on and brutalist group than technocratic overlords. Many of their initiatives sound powerful and wizardly but most are implemented poorly if at all. At the end of the day they are almost entirely reliant on a monopolistic hierarchy of physical violence and in person observations.
- samstave 3y agoYeah - the CCP is getting good at online Social PR. Especially from what they have been learning about generating viral from tiktok (the ADHD Dopamine Addicts in the growing adolescent brain is a gold mine).... But one interesting thing I noticed on tiktok and reddit r/artisanvideos and others for example - is these agrarian-crafty-chipster videos. Like the soft music, the beautiful landscapes, the cute dog in the background and all the nice, clean village-esque looking surrounding as some master craftsman makes bamboo mats, or tofu, or paper etc... They look highly polished PR videos that one might see at an amusement park showing the "simple but accomplished life in china - look how elegantly crafty these simple folk are" -- However - that doesn't mean they aren't making incredibly authoritarian tools disguised as benefits for society. and AI will engulf their tool set and accelerate. Just make sure to leave some bread, circuses and sex to distract the frogs from the temp in the cauldron.
- ehhthing 3y agoUU Booster, which is the service I currently use for gaming is operated by NetEase, which is a giant in the Chinese online gaming space. It's fully legal, no issues whatsoever. Also you can get roaming SIM cards or even eSIMs, which connect to APNs overseas. You can also get Alibaba Cloud private networking connection between a region inside of China and a region outside. They use private lines so there's no GFW involved. My understanding is that you need an international real name verified account to do this, but after that you basically have an uncensored line that's also much more stable than connections that have to go through the GFW. I know of a US company that uses this to connect their Chinese workers to their central office, and again it's fully legal once you get an ICP license.
- spullara 3y agoAt Yahoo we built a thing called "meatspace" that would do this with wifi MAC addresses but legal stopped it as you could identify people and their locations back in time as soon as you associated them. Some other companies did this for retail tracking. That caused apple to periodically change the MAC address.
- hulitu 3y ago> This security issue would allow the Chinese government to track them Thank god that only the Chinese do it. Imagine what the reaction will be if someone finds out that the US or the Canadian or the UK government does it. /s
- godelski 3y ago> I also hope that Apple adopts an open source protocol for AirDrop not just for cross platform compatibility There was a user who pitched the idea of an airdrop like thing to Signal awhile back, specifically stating that it could be used for organization, but it didn't seem to get much traction and looks like they got in a little scuffle with the mods. Sounds like it would be a useful thing given the other security around Signal and the fact that it is cross platform. https://community.signalusers.org/t/signal-airdrop/ https://community.signalusers.org/t/signal-airdrop/