Apple bleee. Everyone knows what’s on your iPhone (2020)
hexway.io
hexway.io
You can get personally identifiable info from an iPhone pretty easily given the methods described
Edit - it's 3 years old I'm guessing they have made some changes since
Neither does the author, seemingly: "This behavior is more a feature of the work of the ecosystem than vulnerability."
Especially:
> Broadband BLE requests contain your data, namely, SHA256 hashes of your phone number, AppleID, and email. Only the first 3 bytes of the hashes are sent, but that's enough to identify your phone number
Is that a viable way of accessing someone’s phone number in 2023?
That being said, Apple does have modes which disable these features for people who are worried, including their Lockdown Mode: https://support.apple.com/en-by/guide/personal-safety/ipsd5b...
It's wild that this hash isn't salted.
Your phone will probably broadcast its hash in that scenario too.
Or am I misunderstanding something?
Oooookay. I'll show myself out.
/s
Security should not be implemented by anyone who is not a subject matter.
It's a subject where it's easy to sound informed while being completely wrong.
I'm of the opinion this should be a development interview question.
"How would you implement {security solution} from scratch" -- The only acceptable answer being refusal.
Take this with a grain of salt though, I did not test the speed claim myself.
Do you salt all the phone numbers with the same salt? Do you send out the salt and expect phones to respond with the salted hashes (in which case, how does this achieve anything?). Do you salt based on geographic location? (Again...) Do you make every phone use the same salt and try to hide it?