OR send (handshake) message encrypted with recipients phone number (put through KDF). Anyone knowing the recipient probably could be able to get your phone number, but that seems like an improvement?
OR send (handshake) message encrypted with recipients phone number (put through KDF). Anyone knowing the recipient probably could be able to get your phone number, but that seems like an improvement?
The second approach isn’t how AirDrop works as a product: when you open the Share dialog, you see a list of eligible recipients (either people with open permissions OR you in their contacts list). The recipient is the one doing the identity check, so their phone number isn’t known upfront.
One downside is that it may be make targeted attacks easier (if you can guess the approximate form of someone's email address, you can easily confirm it), but that doesn't seem like much of a leak if you can already guess sufficiently closely. Sending hash(nonce+AppleID+phone number) might be an option, but that feels more limiting.
I would suggest it's because phone number is (should be) device specific, while AppleID's can be shared across devices. But now that I think about it, does anyone know if AirDrop works with iDevices that don't have a SIM? Such as the iPod Touch?
Macs.