Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it
arstechnica.com
arstechnica.com
If you had read the article you would have seen that the researchers implemented the same feature without leaking any data using "Private Set Intersections".
If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information.
Reality though - your email and phone number is probably already out there.
I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can - and likely lots more than whatever apple is leaking.
No excuse for apple's idiocy, just some perspective perhaps. You can easily avoid this - I can't remember last time I used share pane in public.
This would be very useful info for marketing campaigns. Automated emails to people that go to specific stores, parks, etc.
Ok? AirDrop doesn't work miles away from people, so if they got your email and phone already through AirDrop, how is having your location such emphasized?
"They can see you, gasp!"
The more trackers you place, the more location data you have on that person. You could literally put thousands around a city at many different stores, gas stations, parks, etc.
Given they found this almost two years ago, I wonder if there is an actual attack or exploit that has been deployed or is this one of those attacks that don’t leave the lab environment?
In some ways it seems having the "Contacts only" mode enabled is almost worse than having it set to everyone. The obvious problem with having it set to everyone though is you can easily get airdropped things by people around you. Which can be a great joke but since it displays preview of image receives can also be used in harmful or abusive ways.