Emulating AirTags to upload arbitrary data via Apple's FindMy network
positive.security
positive.security
> Potential use cases
> While I was mostly just curious about whether it would be possible, I wouldimagine the most common use case to be uploading sensor readings or any data from IoT devices without a broadband modem, SIM card, data plan or Wifi connectivity.
The use case I had in mind is gathering sensor data from boat out in a harbor (away from wifi) that other boats with iPhone-bearing crew pass by frequently. This ESP32 AirTag emulator could send out battery level and bilge pump data any time someone sailed by, without the need for a dedicated modem. Might have to try this out!
Edit: added clarification that all SMTP servers do not only permit Gmail addresses...
Relaying used to be a thing, before spammers and unwillingness to deal with it at the source (boot infected devices, originating AS / IX, .. ) resulted in a choice between a game of whack-a-mole or only accepting gmail¹.
These days, relaying has to be setup on the specific relay server, the originating address needs to permit it (DNS SPF/DKIM/DMARC/whatever), and the relay server will still have a reputational problem with deliverability to unrelated servers, which is problematic even for direct mail, unless you are gmail¹.
¹ usually gmail + varying number of big players
On the other end of the enterpriseyness scale, but still an actual real-world use, there's SD cards attached to homing pigeons [2], in addition to numerous stunts or pranks ala RFC1149.
[1] https://aws.amazon.com/snowball/#Snowball_Data_Transfer
[2] https://www.denverpost.com/2007/06/22/homing-pigeons-get-dow...
I don't have an opinion on what protocol would work best, just that it needs to be localized pretty well to match up with the localization of air quality. My hunch is UWB is a better fit for that.
It might be easier than any of the stuff you described above.
This way you can be away from the sensor and also only have one phone.
A week is about 700 keys to check. For one "lost" device, but as you note Apple are happy for you to buy more than a dozen, and of course you wouldn't be happy if Apple tells you that you must only track one of those.
Apple has no way to know if your check for 7000 keys is, in fact, ten devices for a week, or 7000 unrelated queries, it deliberately doesn't know how to relate the keys to one or more tags.
So while yes, that would mean if you have a long term sensor network Apple could block you using it to move more than a few bytes per hour per Apple ID (Apple IDs are free) if you have a more nefarious motive to move say a kilobyte in an hour or two, once every few weeks, that should work fine.
Because AirTag is designed not to chew battery lifetime on the various Apple devices which are effectively drafted to report they saw an AirTag those devices have no limit on how long they can take to get around to telling Apple what they saw. So Apple does have a "timestamp" but that doesn't tell them when the BLE happened, it just helps them purge their database tables.
Either the site linked or the paper (I can't remember which) has a chart showing that it can take at least hours for some iDevices to be comfortable that it's time to tell Apple. Maybe they're configured not to spend $$$ on mobile Internet and waited until they saw a friendly WiFi AP, maybe they got low on battery and went dormant until charged that evening.
Apple's main "defence" appears to be, as usual, that stuff is designed to be hard to use unless you've given Apple money, thus defending Apple's profitability but not really its customers of course. So a Mac can easily be tricked into doing this stuff (as was done for the article), but you'll need to do a bunch of custom reverse engineering to write a PC app and periodically Apple will casually break it, not because this helps their users but because it protects revenue. I predict some researchers will do that reverse engineering work, Bad Guys will just buy a MacBook.
It wouldn't do much for other uses, like tracking people without their knowledge. A "faked AirTag", could, for example, rotate it's serial number to avoid triggering Apple's "AirTag Found Moving With You" feature. Or the opposite of that. You could stick a fake device on someone's car and trigger the "AirTag Found Moving With You" warning over and over by periodically changing the serial number after the user suppressed the warning for a particular AirTag.
AirPods upgrade firmware automatically, chances are it works in the same way.
Roughly, be in the presence of an iDevice for a certain amount of time under unknown conditions. The advice on the internet is usually something like "leave your AirPods charging and have your phone connected to them when you go to sleep, and they'll probably be updated in the morning".
As far as this method, the IC has thought about this very method for a long time. I’d be surprised if it wasn’t been used in the past.
I wonder what the capacity of the network is before the impact on battery life becomes significant...
I don't really see any realistic density of AirTags that would have any measurable impact on energy use of nearby iPhones.
On Android at least, getting a GPS fix takes many seconds, during which the CPU cannot sleep. For that reason, a default Android phone won't power up the GPS for hours on end sometimes. Yet this find-my feature might require a GPS position every few minutes whenever a new tag is seen. That's a lot of extra power.
Find My on your phone already has to get an approximate location, and it does so fairly frequently (since you can track somewhat realtime).
So having an Air Tag piggy back on the same mechanism won't cost a whole lot in terms of having to power on the geolocation capabilities.
Also, coarse location (cellular and wifi) uses basically no power, and might be good enough for an awful lot of applications.
I guess they can just rate-limit the program that runs in the iPhone, but that still (to me, very naively) would allow a DoS that prevented genuine tags from access.
As mentioned in the OP to know if the tag is genuine a device needs to go to the trouble of receiving the traffic in case it's real, then decrypting (search "ECIES encryption" in OP): so you'd be wasting quite a bit of processing before you reject a fake tag. If they rate limit the decryption - which you'd have to - then you can overwhelm a device on the network by sending out fake packets.
It strikes me you can generate random BLE data that looks like airtag data cheaper than you can verify packets and so in theory one iPhone could overwhelm a minimum of one other; and presumably could overwhelm all others in range (with lower or equal processing power).
They do mention their (the OP's) public keys being rejected.
So, if my analysis is right you can either use all processing on all devices in range, or overwhelm all devices in range of they're rate-limited. The second case is preferable.
I'm interested in why I'm wrong. Can the imaginary fake tags in my analysis be rejected using less power than it takes to make them?
The attack you propose is no more powerful, so probably not worth protecting against.
Suppose they make this, how many would they sell? How many of those customers would have bought an (more expensive, I presume) iPhone if they wouldn’t make it?
They stopped making iPod touch for similar reasons. I doubt adding this feature would attract enough extra buyers to change that.
That's not much, but it has value for industrial machine-to-machine communications. (That's IoT without the hype.) Like commercial air conditioning units. They can send in minimal data ("compressor 1 running, compressor 2 stopped, system OK") to a maintenance service without needing a cellular account or connection to the Internet.
5G is only useful if you need bandwith in an area with very high contention, like a stadium, or you're in an area remote enough that the lower frequencies work but the higher ones don't.
4G might have a larger coverage per cell, but if it isn't able to handle all the devices trying to connect then that means nothing at all.
5G can have comparable coverage, by the way.
Wait, maybe I'm confused, but isn't the point behind rotating serial numbers that the person couldn't just click ignore? But how much sense does that make, if people are routinely ignoring tracking devices glued to their cars instead of finding and disabling them, that seems like... a problem. A tracking device that decides to re-alert you to its presence rather than remain hidden and silent seems like a less dangerous tracking device, rather than the other way around.
And since the communication is one way, there is no encryption (I suppose), so replay-attacks should be possible unless it uses a clock.
Someone could write an app which reads Bluetooth IDs and then transmits them at random times.
Replay attacks may be possible, but we will have to wait to see if the protocol is entirely passive. The iPhone could broadcast a challenge to the AirTag and transmit the signed response and response delay. The delay should be fairly tightly bounded.
The AirTags do have a clock as I understand it, but drift is inevitable, so it wouldn't be a tight bound.
P.S. I know about the beeping, but the speaker can be easily removed.
It's unfortunate that, even though your phone can leave FindMy, it isn't as straightforward as going into Airplane Mode. You certainly can't choose to disable it at certain locations.
Give it a few decades...
For example, the FindMy network would continue to work even in power outage scenarios like parts of the country experienced in Feb 2021.
If you're skeptical, the pricing says it all. Apple could've sold AirTags for $99 each with a $1/mo service fee to use the Find My network. That would've boosted their profit margin on the initial sale and created recurring revenue, while restricting network load.
As it stands, AirTags are $25 each and free to operate, which means that Apple wants them to be ubiquitous — buy 10 or 20 and put them everywhere.
Apple has gotten a lot of mileage on their idea that "the customer is not the product" but this is a turn in the wrong direction. Despite months of claims that AirTags are impregnable, unhackable, etc. the news is just going to get worse.
Counting on lots of people spending $500 on AirTags is probably not a real master plan.
Of course Apple is a massive company, but there is something extremely compelling about precise location tracking. Even if this product isn't successful, I think Apple have propelled a new category of products to the forefront.
Even if they eventually find you innocent, you would have gone through all the headache of the court system anyway.
I'd be much more comfortable with Apple being Privacy, Inc. if they kept their commitment to it, too often it looks like engineers got overrode by marketing. It's v unlikely a privacy engineer signed off on something, with so many side channels, with real world consequences, compromising a billion + iOS devices
I've gathered there's a beep if this is going on for 3 days, but...still not comfy with this. And this isn't a particularly fringe opinion, plenty of comments on the article wondering how to opt out:
The timer is 3 days[1], which observers (Forbes, WaPo) agree is surprisingly unreasonable for this use case. We can infer it was never a serious design consideration.
On Android, decent Bluetooth is a gamble, but scanning will theoretically find one[2].
[1] https://daringfireball.net/linked/2021/04/20/moren-fine-prin... [2] https://lifehacker.com/try-using-a-bluetooth-scanner-app-to-...
I know you can come up with something more substantive than guessing I didn't read the article. To wit, easy quote that backs what I read, and I assume I'm mistaken, given your feedback:
'The details should come as a surprise to everyone because it turns out that ITP could effectively be used for: - information leaks - tracking the user - fingerprinting'