Apple AirDrop shares more than files
informatik.tu-darmstadt.de
informatik.tu-darmstadt.de
The latter is more serious imo, because those attributes live on your file system basically for ever, and they're preserved when transferring to another compatible file system or even when archived in a zip file. The meta-data can ride along with the files to completely unrelated systems even years after the fact. So if you AirDrop some files to your computer and then zip them up, anyone you send that zip to (a journalist, a public file-hosting site, w/e) will have your full legal name to go with them.
Even sharing your name through the interface seems questionable -- the fact that you and another person have each other's phone numbers is not necessarily an indication that you want to share your real names with each other. (Though i guess someone could usually find it out anyway if they already had your phone number.)
I reported this to Apple, but i don't think they care. Seems like it's by design.
1. Airdrop an item to your Mac.
2. Run 'mdls [file]' to see associated metadata
3. Copy the file, run 'mdls [file]' again - open it locally or even in a macOS VM - you'll see that your name and phone name is copied with the file!
https://eforensicsmag.com/airdrop-forensics-by-kinga-kieczko...
It lists 2 vulnerabilities: Sender Leakage and Receiver leakage. The files are not at risk, its your phone number and apple ID.
Or alternatively, Maybe rename to: Apple AirDrop reveals mobile number and email
> The discovered problems are rooted in Apple's use of hash functions for “obfuscating” the exchanged phone numbers and email addresses during the discovery process. However, researchers from TU Darmstadt already showed that hashing fails to provide privacy-preserving contact discovery as so-called hash values can be quickly reversed using simple techniques such as brute-force attacks.
The post that they then linked to is about how, by hashing random phone numbers, you can effectively de-anonymise users of popular messaging apps.
So you'd need to be in physical proximity to the person, and what you're getting is details like your phone number which aren't especially private anyway (they literally need to be given to people to be of any use). It's far from the dragnet-level issue facing Signal & Whatsapp and others.
I don't know, but that doesn't seem like an especially serious issue to me. It seems just like a research group trying to make some hype for themselves.
Proximity doesn’t mean I would like to share my phone number. Seems like an unlikely attack day-to-day, but one with definite privacy and personal safety concerns.
1: https://qz.com/1660460/hong-kong-protesters-use-airdrop-to-b...
I mean sure, I'm not saying there's no issue here. But it certainly isn't 'huge' either.
The FBI had certain groups under watch but didn't act on it. For a variety of reasons. This continues today - the FedEx shooter was well known to law enforcement but wasn't acted on. Instead of talking about how we can solve that problem, the media and people probably like you screech about restricting rights of everyone else (gun control?) instead :p
> A global pandemic occurred and we had no plan, PPE or ventilator supply and could not mobilize our infrastructure to respond.
We built massive temporary hospitals in NYC, sent a floating hospital up to NYC and instead of using those for the elderly, the NY governor sent the infected elderly back to nursing homes where the most vulnerable are. They also sent non-elderly to nursing homes too. There at least was some reporting about a violent 30 something homeless guy sent to a nursing home that assaulted elderly residents but it was pretty minimal and blew over quickly. There were mobilized responses - they were incompetent mobilizations. But why talk about that - maybe because most of disproportionate nursing home death rates happened predominantly in blue states? God forbid someone draw attention to that! Quick - more handwaving about "lack of mobilization" is needed!
Ventilators - we produced thousands of emergency ventilators that sat in warehouses waiting for a crises that never materialized. Then as we got more experience we learned ventilators actually make things worse and it's better to just change people's resting position. However those facts are not nearly as sexy or politically expedient as being able to blame the other side for lacking to produce something, so we still have people fixating on the non-existent ventilator crises to again deflect from other incompetence and also justify further "fixes".
> Thousands descended on the Capitol building and took selfies during a violent overthrow attempt and the FBI has no idea who the majority of them were, depending on internet tips to identify them.
lol - and the most preposterous propaganda of the year award. Entire city blocks repeatedly burning down over the summer during "mostly peaceful protests" and one incident started WHILE TRUMP WAS STILL SPEAKING is the end of western democracy as we know it. Yup. Trump lead. So violent that there were no fires. No statues toppled. No walls or paintings spray painted. All things that routinely happed in many American cities over and over for over a year but was hand waved off.
Indeed, the vast majority of people "insurrecting" were walking between the velvet ropes taking pictures, smiling, chatting with the capital police. Several videos show the same capital police holding the doors open for them - but it was a violent insurrection.
You see I watched most of it live from various streamers as it happened. I didn't just watch the carefully crafted media narrative. Yes there were some bad actors, but the cognitive dissonance and utterly disproportional response between what happened in those four hours vs. the entire year before is off the charts. If that was a violent insurrection and what happened over the summer were just mostly peaceful protests then we have gotten to levels of absurd gaslighting that even Orwell couldn't have imagined.
>The state is far less organized and competent than you think if the US is any indication.
Thank you for providing the biggest reason socialized medicine is an utterly ridiculous and downright scary proposition. Given your other positions this is a refreshingly frank take.
Yes, not being able to apprehend people before they break the law is a real inconvenience.
Whaaaat the fuck.
Once you know the phone number, you would then be able to track an iOS device's location if it's in "contacts only" discoverability mode for AirDrop, right?
Makes me wonder how sparse phone numbers would have to be to make spam impractical. Would people use long virtual numbers? Imagine if your friends had your 64 digit phone number, and you would know it was a non spam inbound caller.
Or even better, TOFU, like a Signal call. Or just a Signal data channel over LTE.
un- is a prefix for adjectives, not verbs.
e.g.
Bob decrypted the message and set it to Alice as unencrypted plain-text.
Unlisted numbers are less prone to robo-calling, but most phone companies charge a fee for delisting a number.
To me, that means that if I was going to attack someone using this exploit, I would need to sit there all day until someone used AirDrop to send something and then I'd need to make sure to have my attack planned out in advance so that I could then use that information to do something useful.
The chances of that actually happening to some detriment are so small, in my eyes.
If a brute-force requires multiple 500 watt GPUs in order to brute force in real time, I'd like to know. This is vastly different than if it can be done on a laptop's GPU.
If hashes can be cracked later offline with 100% certainty, I'd like to know, since a malicious device can just collect hashes simply by traveling around a city.
But if the brute forced hashes need to be confirmed with the other AirDrop device in real time, else you don't know which of dozens, hundreds, or thousands of results you might get, then this is mostly a non-issue.
Does the article they published about that which they link to not provide enough details? In that news release they referenced, they say "However, the research team shows that with new and optimized attack strategies, the low entropy of phone numbers enables attackers to deduce corresponding phone numbers from cryptographic hashes within milliseconds."
I'm not sure if I'm misunderstanding what you're asking, or if you just didn't notice that they provide the info you want fairly easily and succinctly already.
[0]: https://googleprojectzero.blogspot.com/2020/12/an-ios-zero-c...
Cool. Security research is important.
> The research team developed a solution that could replace the flawed AirDrop.
Wait, what? Nobody will want to install some third-party tool over this.
EDIT: I just found snapdrop [1], but haven't given it a try yet.
Research links:
https://hexway.io/research/apple-bleee/
https://arxiv.org/pdf/1904.10600.pdf
https://www.usenix.org/system/files/sec19fall_stute_prepub.p...
Your email and phone number may be less secret than these folks claim .
But aside from this overhype interesting work.
No question should be fixed - but compared to the rce s Apple has had (which do get fixed quickly) this is relatively lower risk
This seems like a very plausible scenario and most users would not expect and would not want everyone in the restaurant to be able to see their email and phone number.
The person you replied to literally said this should be fixed. I agree with them that this is nowhere near as serious as issues Apple has had before, since the attack requires physical proximity and the use of the share pane. Even then, it doesn’t give the attacker RCE privileges or anything similarly world shaking.
Should Apple fix it? Again, absolutely. No one has said otherwise.
Nothing is 100% secure, so the relative risk posed by vulnerabilities can only really be assessed with a threat model. In most threat models, this is nowhere near as bad as their “GOTO Fail” bug or any number of others over the years.
I think celebrities and VIPs are essentially the only ones whose threat models would actually be impacted by this vulnerability in a plausible way.
… and do not use all of the other options for getting data from people in close proximity such as cameras or microcell sites. If your threat model goes far enough that this matters you should be more worried about all of the other options. I would be more worried about a Bluetooth, WiFi, or cellular exploit given the history.
(No, this is not saying that Apple shouldn’t improve this - only that it doesn’t seem like a huge change in the amount of risk you’re exposed to)
This exploit requires that they already know who you are and where you live and where you go get coffee. They have to send a physical attacker to stalk your coffee shop. They have to have this equipment to run the impersonation exercise - and then wait until you are picking up coffee and airdropping something.
And after all this they get your email and phone number? So they know all these details about you but can't be bothered to use true people search or ANY of the data brokers or any of the giant data leaks to look this up?
Apple is selling a CONSUMER device. If your threat model is this elaborate, stick your phone in a faraday cage and leave it at home, someone could just grab it out of your hand at the coffee shop and be likely to get a lot more data.
So yes, it's a risk - but on the scale of risks including just being straight mugged and your phone stolen, it seems somewhat lower?
https://www.forbes.com/sites/kateoflahertyuk/2019/01/07/thes...
https://techcrunch.com/2020/08/31/apple-notarized-mac-malwar...
Pretty much every post on HN is filled with comment like this. Clearly their reputation amongst developers has suffered.
At what point do you start to accept that the store might just be a monopoly control gateway and revenue source?
Apple has approximately 150,000 employees in total, but more than 1,000,000,000 customers, and more than 23,000,000 registered developers.
Of course a few things will be missed and found by customers. Given the numbers it looks like they are doing a pretty good job.
It makes no sense to imagine that they are deliberately allowing apps into the store.
How long would this take?
I mean, is the person's iPhone going to respond to all 10 billion possible domestic US phone numbers in the, what, 3-10 seconds they have their share sheet open? Not to mention the far larger space of e-mail addresses, ultimately limited by whatever the hash length is?
Unless the AirDrop protocol is permitting the validation of many millions of hashes per second (presumably requiring 100mbps+ speed), this doesn't appear to be even remotely a viable attack method in practice, no?
- mass record all these requests
- offline, recover the phone numbers or email addresses
⇒ you know who was where, when.
The target has to open the sharing pane on their phone while the attacker is in proximity.
That probably effectively stops "mass" attacks.
(The contact exposure is in support of a setting for AirDrop to work with Everyone, Contacts Only, or No one.)
While it's certainly a bit concerning, it's pretty unlikely to be a practical attack, particularly since all it does is get you the user's contact list. It doesn't sound like there's any way of using it to exfiltrate other information, and though the article doesn't touch on this (that I saw) I'd be surprised if the attack was fast enough to just gulp down all your contacts in the couple of seconds most people have their share sheets open.
It’s not even that - all it gets is the phone number associated with your personal contact card.
No, with the share sheet open, the attacker can simply record the hashes of phone numbers that are being broadcasted. And then crack the hashes off-line at any time, which is easy since there are at max 999-999-9999 hashes.
Assuming that's meant to represent 10 digits, it's not sufficient. My phone number is one longer than that (11 digits). If you drop the 0 prefix and use +44 instead, that'll be 12 digits (or 13 if you include the + but you could specify that as always present.)
(A minor nit since it only increases the search space 10x or 100x which probably doesn't make a huge impact?)
"As an attacker, it is possible to learn the phone numbers and email addresses of AirDrop users – even as a complete stranger. All they require is a Wi-Fi-capable device and physical proximity to a target that initiates the discovery process by opening the sharing pane on an iOS or macOS device."Isn't analyzing severity one of the most interesting, and critical, parts of discussing a potential vulnerability?
https://github.com/hexway/apple_bleee/tree/master/hash2phone
the choice is reduced to "how much information do i want my personal communicator to be leaking" (and somewhat "to whom")
they do. but yea, there stance is no as belivable.