Live data from Hacker News

Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

arstechnica.com

1–10 of 14 posts

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#2
Pavel Zhovner, creator of Flipper[1] had this cool post [2] in June 2020 on how he used Apple AirDrop for automated dating and fun. It included the phone number recovery component as well.

1 - https://flipperzero.one/

2 - https://m.habr.com/ru/company/ruvds/blog/505384/

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#3
What a bogus headline.

If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information.

Reality though - your email and phone number is probably already out there.

I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can - and likely lots more than whatever apple is leaking.

No excuse for apple's idiocy, just some perspective perhaps. You can easily avoid this - I can't remember last time I used share pane in public.

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#4
post #2

Pavel Zhovner, creator of Flipper[1] had this cool post [2] in June 2020 on how he used Apple AirDrop for automated dating and fun. It included the phone number recovery component as well. 1 - https://flipperzero.one/ 2 - https://m.habr.com/ru/company/ruvds/blog/505384/

I wonder if doing this would be illegal in the US, a-la Aaron Swartz.

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#6
post #3

What a bogus headline. If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information. Reality though - your email and phone number is probably already out there. I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can…

It's not just email and phone. It's email and phone and location.

This would be very useful info for marketing campaigns. Automated emails to people that go to specific stores, parks, etc.

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#7
post #3

What a bogus headline. If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information. Reality though - your email and phone number is probably already out there. I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can…

It's not just email and phone. It's email and phone and location . This would be very useful info for marketing campaigns. Automated emails to people that go to specific stores, parks, etc.

The number of people transferring files in public is so limited that it would be much more simple to buy the marketing data for everyone in a given city.

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#8
post #3

What a bogus headline. If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information. Reality though - your email and phone number is probably already out there. I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can…

It's not just email and phone. It's email and phone and location . This would be very useful info for marketing campaigns. Automated emails to people that go to specific stores, parks, etc.

> and location.

Ok? AirDrop doesn't work miles away from people, so if they got your email and phone already through AirDrop, how is having your location such emphasized?

"They can see you, gasp!"

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#9
post #2

Pavel Zhovner, creator of Flipper[1] had this cool post [2] in June 2020 on how he used Apple AirDrop for automated dating and fun. It included the phone number recovery component as well. 1 - https://flipperzero.one/ 2 - https://m.habr.com/ru/company/ruvds/blog/505384/

I wonder if doing this would be illegal in the US, a-la Aaron Swartz.

I don't know what the criminal threshold for stalking and harassment is. But unlike Zhovner and yourself, I know what the normative threshold is (tip: it's DON'T THE FUCK).

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#10
not much they can do? they could remove the feature, or why not just require some one-time iCloud handshake to happen to exchange anonymous identifiers once you confirm the contact? might gimp the feature somewhat but still, something can be done for a feature where air dropping to randos is just a cool party trick
Post reply on HN