If it's the latter, it might mean that the entire AirTag product line is dead in the water.
If it's the latter, it might mean that the entire AirTag product line is dead in the water.
It appears none of that was ever true and you can register just anything as an AirTag that speaks the right BLE with no secrets required for a world full of iPhones to start tracking them.
So yeah, expect chinese clones to show up within a month, for five dollars each and certainly no speaker included.
Even if it's just for a few days so we can get a sense of what her typical route are so we could know where to look for her other days
But we couldn't find any such GPS device that was anywhere near the pricepoint of an Airtag or Tile unless it came with a really pricey subscription
Those sort of devices are a reasonable choice for mounting in your own vehicle, where you can provide relatively unlimited power (and many of them have the ability to implement engine kill). But you aren’t going to slip one of those into someone’s pocket unobtrusively as you bump into them going past. Or attach it to their car in a car park.
The average consumer, or even 99.9% of consumers, don't care at all.
They want to find their things. AirTags help them find their things. They don't care how it works. End of story.
It's not a popular opinion on HN where everyone wants to understand every technical detail of how every product works, but in the real world it doesn't matter. Consumers buy products to solve problems. That's all.
This problem will need to be addressed though other means than a single company intentionally crippling their own product.
But if your fake airtag rotates through 2000 IDs how do you register them all?
1. you can't track items outside of some distance from you in real-time
2. items marked as lost would need to be sent to a review team inside apple (contractors I imagine) that would then log your information, require you to explain what the item is, and generally make it very cumbersome to get the actual location or history of the location
3. then very likely a neutral 3rd party would have to go to the location to determine if the claim seems to be legitimate, or this is a case of somebody stalking somebody else or something
4. likely would require police getting involved somehow
The idea that people can be vigilante's and track down their own stolen bike is a great idea, but it basically equates to "stalking somebody".. any work-arounds for android users and iphone users will either only work in certain circumstances (what if you only live 1 mile away from the bars downtown -- then now the stalker knows where you live and the device was with you a super short period of time -- maybe 2-5 mins depending upon method of travel)... the only way around this is to block people from being able to get the raw information -- sure the data might be collected, but giving it directly to the customer is both the best and worst thing about this.
Air Tag messages with unknown public keys just get dropped on their server side checks.
So the phones will still relay the beacons to Apple, who can then do things and just reject messages from these fake tags.
(I worked for a Medical Device Company that set all of this up within our supply chain).
that kills the privacy aspect of it, because it also means apple knows about the exact whereabouts of each tag. airtags are specifically designed/marketed so apple can't do that.
No one, including apple, other than a device owner can determine where their device is, or where it has been.
Since the AirTag emits the message, that message would either contain: - a static signature, which could then be copied and mimic'd by imposters (replay attack) - store the private key on the AirTag device, which could then sign the a continuously changing nonce like the current datetime. But this means the private key could then be extracted from one device, and used to sign messages on an imposter device. So unless every device had a separate private key, this method would immediately be compromised as well.
So why doesn't Apple have a unique private key for each device? Well it appears it actually does, and has them constantly changing their private keys. But there appears to be some kind purposely implemented anonymity features that is designed to prevent Apple's servers from associating a ping with ever having to decode the contents, and thus of associating your account/device with the emitted location.
If you build in validation to write to the network ping database that goes "here's a ping with a signature ABC and let's lookup if it's valid, oh it is, that must be from AirTag Bob bought last month with private key XYZ, let's declare this ping valid" then Apple is only a logfile-write-of-this-information away from being able to perfectly stalk everyone who has purchased a device. So instead, the tradeoff they made is they don't keep track / purposely blind themselves to their device-in-circulation keys to truthfully say they actually can't track you. That leaves open the ability of imposter devices to transmit information through the network by creating their own known keys which look indistinguishable from authentic device pings.
Apple likely would go toward batch keys - in addition to being simpler crypto, it doesn't give them the capability to use other mechanisms to potentially correlate location reports.
That said, AirTags work solely within BLE advertisements, which are payload size limited to 31 bytes. Apple is currently using 30 of those bytes.
The state or corporate actor will have those skills.
The common stalker will simply buy them online.
Point for me is that Apple absolutely could do supply chain verification but… for some reason don’t?
> Each advertising packet can carry up to 31 bytes of advertising data payload, along with the basic header information (including Bluetooth device address).
I didn't know about advertising extensions, thanks for the info. Without that I'm not sure if supply chain verification is feasible? I also wonder if there's a significant battery impact to broadcasting more data. I suppose they could overload the device address uuid?
The reason you’ll see different numbers is that not everyone considers the overhead the same. Some count it, some don’t. I do because it just isn’t usable.