Find You: Building a stealth AirTag clone
positive.security
positive.security
If it's the latter, it might mean that the entire AirTag product line is dead in the water.
Air Tag messages with unknown public keys just get dropped on their server side checks.
So the phones will still relay the beacons to Apple, who can then do things and just reject messages from these fake tags.
(I worked for a Medical Device Company that set all of this up within our supply chain).
that kills the privacy aspect of it, because it also means apple knows about the exact whereabouts of each tag. airtags are specifically designed/marketed so apple can't do that.
No one, including apple, other than a device owner can determine where their device is, or where it has been.
Since the AirTag emits the message, that message would either contain: - a static signature, which could then be copied and mimic'd by imposters (replay attack) - store the private key on the AirTag device, which could then sign the a continuously changing nonce like the current datetime. But this means the private key could then be extracted from one device, and used to sign messages on an imposter device. So unless every device had a separate private key, this method would immediately be compromised as well.
So why doesn't Apple have a unique private key for each device? Well it appears it actually does, and has them constantly changing their private keys. But there appears to be some kind purposely implemented anonymity features that is designed to prevent Apple's servers from associating a ping with ever having to decode the contents, and thus of associating your account/device with the emitted location.
If you build in validation to write to the network ping database that goes "here's a ping with a signature ABC and let's lookup if it's valid, oh it is, that must be from AirTag Bob bought last month with private key XYZ, let's declare this ping valid" then Apple is only a logfile-write-of-this-information away from being able to perfectly stalk everyone who has purchased a device. So instead, the tradeoff they made is they don't keep track / purposely blind themselves to their device-in-circulation keys to truthfully say they actually can't track you. That leaves open the ability of imposter devices to transmit information through the network by creating their own known keys which look indistinguishable from authentic device pings.
Apple likely would go toward batch keys - in addition to being simpler crypto, it doesn't give them the capability to use other mechanisms to potentially correlate location reports.
That said, AirTags work solely within BLE advertisements, which are payload size limited to 31 bytes. Apple is currently using 30 of those bytes.
The state or corporate actor will have those skills.
The common stalker will simply buy them online.
But if your fake airtag rotates through 2000 IDs how do you register them all?
1. you can't track items outside of some distance from you in real-time
2. items marked as lost would need to be sent to a review team inside apple (contractors I imagine) that would then log your information, require you to explain what the item is, and generally make it very cumbersome to get the actual location or history of the location
3. then very likely a neutral 3rd party would have to go to the location to determine if the claim seems to be legitimate, or this is a case of somebody stalking somebody else or something
4. likely would require police getting involved somehow
The idea that people can be vigilante's and track down their own stolen bike is a great idea, but it basically equates to "stalking somebody".. any work-arounds for android users and iphone users will either only work in certain circumstances (what if you only live 1 mile away from the bars downtown -- then now the stalker knows where you live and the device was with you a super short period of time -- maybe 2-5 mins depending upon method of travel)... the only way around this is to block people from being able to get the raw information -- sure the data might be collected, but giving it directly to the customer is both the best and worst thing about this.
It appears none of that was ever true and you can register just anything as an AirTag that speaks the right BLE with no secrets required for a world full of iPhones to start tracking them.
So yeah, expect chinese clones to show up within a month, for five dollars each and certainly no speaker included.
Even if it's just for a few days so we can get a sense of what her typical route are so we could know where to look for her other days
But we couldn't find any such GPS device that was anywhere near the pricepoint of an Airtag or Tile unless it came with a really pricey subscription
Those sort of devices are a reasonable choice for mounting in your own vehicle, where you can provide relatively unlimited power (and many of them have the ability to implement engine kill). But you aren’t going to slip one of those into someone’s pocket unobtrusively as you bump into them going past. Or attach it to their car in a car park.
Point for me is that Apple absolutely could do supply chain verification but… for some reason don’t?
> Each advertising packet can carry up to 31 bytes of advertising data payload, along with the basic header information (including Bluetooth device address).
I didn't know about advertising extensions, thanks for the info. Without that I'm not sure if supply chain verification is feasible? I also wonder if there's a significant battery impact to broadcasting more data. I suppose they could overload the device address uuid?
The reason you’ll see different numbers is that not everyone considers the overhead the same. Some count it, some don’t. I do because it just isn’t usable.
The average consumer, or even 99.9% of consumers, don't care at all.
They want to find their things. AirTags help them find their things. They don't care how it works. End of story.
It's not a popular opinion on HN where everyone wants to understand every technical detail of how every product works, but in the real world it doesn't matter. Consumers buy products to solve problems. That's all.
This problem will need to be addressed though other means than a single company intentionally crippling their own product.
Sure you can use it to find your lost keys in your own house and maybe have it warn you when you've been separated from your AirTag, but that's about it.
The problem is not the airtag, it’s the find my network. Anything that can be tracked through the find my network can be used for malicious purposes. It is apple’s USP but also its achilles heel.
Tile, for example, actually works the exact same way. If you fully loose your tile connected to your keys you can put it into a "lost" mode [1] which will then notify you and gps locate it just like an airtag if someone with the tile app is near your tile. But you are correct, the big difference here will be how many devices have tile installed vs iphones.
[1] https://www.thetileapp.com/en-us/how-it-works (search: 'Tile Network')
On the bright side, the end result of this is that AirTags will be safer for everyone, and competitors with tracking products not designed for secret spying will be forced to step up their privacy games.
It's kinda dumb that our cabin has a 'smart' meter on a meshnetwork, but there's no way for me to remotely turn-on a heater 4h before I arrive without a $10+/month subscription.
Maybe one day I can offline order a book and it just shows up because the on-line devices nearby (or are likely to show up nearby) can drop it off wirelessly.
A traffic light won't be needing its own internet subscription or private physical network to beam up a picture of the intersection or status.
If you exclude the time to dev the software, design the PCB, and assemble the tracker then you can knock up a NB-IOT module + GPS module + Microcontroller & supporting parts (to tie the two modules together) for about $30-$35 in small quantities, keep your data usage low and you can throw in a pre-paid IOT-NB sim for about $15.
EDIT: Its not gonna be as small as a AirTag, But if you wanted to tag something like a car you could get it into a small enough box to easily hide under it.
EDIT The 2nd: Throw in a movement detector, keep everything asleep unless its moved, before firing up the GPS/modem write your code so not to power up the GPS/Modem up unless a certain time as passed since the last known location fix, when you do fire up the GPS compare the location to the last known location so you only need to phone home if the distance as changed by a certain amount and you could get a decent battery life.
(not that I've thought about this...)
Pretty much no regular stalker is going to design and build their own GPS+cellular tracker. Even if someone were to do that and then sell them online, the barrier to finding and buying those are still probably going to be higher than getting an AirTag. And the battery won't last anywhere near as long as well. And also consider that the software running on it, as well as the cloud service that lets you check the location, doesn't just magically appear either. Someone has to build and host that as well. Even a lower-tech solution that just emails a location report every few minutes still requires work to build.
Yes, it's absolutely possible, and not super difficult, to track someone using a GPS+cellular device. But it feels really disingenuous to claim that tracking people was just as easy to do for your average stalker pre-AirTags.
Oh yeah, Was just pointing out that the pricing of such things is dropping like flies.
> Pretty much no regular stalker is going to design and build their own GPS+cellular tracker.
Agreed, again was just pointing out the pricing of parts.
> Yes, it's absolutely possible, and not super difficult, to track someone using a GPS+cellular device. But it feels really disingenuous to claim that tracking people was just as easy to do for your average stalker pre-AirTags.
I don't think I did claim that. I wasn't trying to claim that. Maybe thats just the limitation of using text.
They're on Amazon, for $50-150 [0]. The first result for "GPS tracker" I found has 10 days of battery life, which is a fair negative, but you can do a lot to someone if you follow them for 10 days.
[0]: https://smile.amazon.com/LandAirSea-Waterproof-Magnetic-Pers...
Prepaid sim. US (and many other countries) does not have mandatory registration for SIM cards. See: https://www.gsma.com/publicpolicy/wp-content/uploads/2013/11...
Compare that to the difficulty of tracking down where a commodity BLE antenna and battery pack were sold.
>Compare that to the difficulty of tracking down where a commodity BLE antenna and battery pack were sold.
The ESP (or whatever BLE chipset was used) probably will have a mac address burned in, which is essentially an IMEI. You'll have a hard time getting anything from that, because the aliexpress supply chain that supplied the GSM GPS tracker keeps records and/or responds to US subpoena as well as the aliexpress supply chain that supplied the airtag clone.
>If the SIM was prepaid, the network operator will have a pretty good idea of where it was sold (by tying the SIM number to a wholesale lot number), and that would give police a narrow pool of suspects (whoever bought a prepaid SIM from that seller while the wholesale lot was on their shelves) to work from.
It was sold from a mobile phone kiosk at a mall
>what payment method is used for service
voucher purchased at the same store, both paid with cash
>If anyone bought a prepaid SIM with cash, they may have been caught on security camera doing so.
the purchase/activation of the sim occurred a month or two ago, outside of the retention range of the surveillance footage. even if the footage exists, all you'd see is a masked (thanks covid!) 5'8" white possibly hispanic male, wearing a hoodie and jeans.
>> what payment method is used for service
> voucher purchased at the same store, both paid with cash
>> If anyone bought a prepaid SIM with cash, they may have been caught on security camera doing so.
> the purchase/activation of the sim occurred a month or two ago, outside of the retention range of the surveillance footage. even if the footage exists, all you'd see is a masked (thanks covid!) 5'8" white possibly hispanic male, wearing a hoodie and jeans.
That's so much op sec that you wouldn't have to do to exploit the Find My protocol! And let's hope the mall didn't change their retention interval and that the same 5'8" white male didn't do something stupid like buy something with a credit card on the same trip or park in the mall parking lot.
2. the same mechanism that makes it easy to build stalking devices for, also makes it convenient to use as a lost key finder. I'm not going to attach a GPS tracker and buy a sim card for my keys/bag, but I will buy a $30 airtag.
So, unlike GPS trackers or competing Bluetooth trackers, AirTags can do two things:
* Last for a very long time on a small battery, no recharging required.
* Reliably report location anywhere in the world that an ordinary person is likely to be.
What happens inside buildings when the phone doesn't have a fix? Does it store the tag's key and sends it as soon as it gets gps data?
Your phone takes it's last position from GPS, refines it with RSSI of nearby WiFi networks and then you add in the broadband stuff they have to localize the tag further.
Yes of course. That's how these phones are supposed to work. I don't have time to micromanage my devices. As long as I get a day of usage, why would I bother?
Absolutely, yes.
> What happens inside buildings when the phone doesn't have a fix?
Have you never used your phone inside a building before? It still has a very good idea of your location, it doesn't rely solely on GPS signals.
It's almost like it's on purpose.
Imagine building a tracking system where your only way to avoid being a victim is to have everyone agree to not participate.
Step one: Set up one of these with a known sequence of keys: either preloaded or a derivation function (to allow it to run continuously). Plant it on your victim.
Step two: set up another one with the same key sequence, but delay it (or advance it), so that the same keys are presented, but on a delay. Plant this one in a public place with lots of iPhones, ideally moving around like on a bus or train.
Now, the keys won't be unique any more. With a bit more thought, you can probably figure a way to make it even less obvious (the decoy tags rotate faster and reuse old keys on a cycle, perhaps, so they keep pinging up and obscuring the single real one).
A lot more effort than a buy and forget device, for sure.
Figuring out a strategy to counter such an attack would be a fascinating game of real life tower defense, if not for the fact that if you fail, people get harmed.
Still seems mad to me that the tags aren't also rocking some kind of secure enclave so that they can, say, cryptographically sign off as genuine. Crypto chips are (perhaps literally if you own the silicon anyway) ten a penny. Even without the security implications, seems like leaving money on the table to me, which is unlike Apple.
> While OpenHaystack-based AirTag clones are not paired with an Apple ID, the retrieval of location reports requires authentication. Such an account however can be created anonymously using an email address without any identity/KYC-verification.
> The OpenHaystack team currently even considers running a server that proxies those location report requests, which in the future might take away the need to create an account oneself.
Imagine a clone. They use the apple network for free, while white-labeling it. They could create accounts with their own emails and IPs, and forward the data to users.
Wait, I'm not liking this so much anymore.
cool.
The barrier to entry would be a lot higher though, as all that's needed here is 'microcontroller with Bluetooth'. And that really makes it dangerously easy.
I think gp included the lorawan for that purpose. No SIM required.
I honestly have no idea how widespread LoRaWAN is, but I would be very surprised if it came anywhere close to the coverage you can achieve using Apple users carrying your uplinks around unwittingly. (Especially if you are attempting to track an Apple user.)
But most importantly, I doubt you could build a LoRaWAN tracker as compactly as an AirTag. A beacon would use significantly less electricity and therefore require a smaller battery.
Below is one of the smallest LoRaWAN modems on the market, which by itself is marginally bigger than an AirTag. Now add batteries, GPS, antennas, and an SoC to drive the whole thing.
https://www.murata.com/en-eu/news/connectivitymodule/lpwa/20...
- using a cellular modem requires a high capacity battery
- if you hide a tracker well, it probably won't have a good GPS reception
Apple's BLE-based network solves both of these problems.
The example third party AirTag clone described on the linked page is powered by a full size USB power bank.
It could easily be optimized for power and size. Sure, it will have to use more power than a vanilla airtag, because it's doing (slightly) more, but not enough to make a significant difference.
Problem is: 1. Precise location of tracked object, now
This is actually one problem and Apple didn't solve it very well, airtag doesn't work in real-time. You only get updates when there are people near object that uses iphone.
Ok? In practice, this is most of the time. In most reasonable use cases (i.e. excluding the Sahara desert or some remote mountain).
An AirTag might help me find my keys if they fall out of my pocket in a restaurant restroom. A cellular-based tracker won't because (1) it will be out of battery, and (2) it won't have a GPS signal.