Live data from Hacker News

Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

arstechnica.com

11–14 of 14 posts

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#11

not much they can do? they could remove the feature, or why not just require some one-time iCloud handshake to happen to exchange anonymous identifiers once you confirm the contact? might gimp the feature somewhat but still, something can be done for a feature where air dropping to randos is just a cool party trick

> not much they can do?

If you had read the article you would have seen that the researchers implemented the same feature without leaking any data using "Private Set Intersections".

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#12

Earlier quoted context omitted.

It's not just email and phone. It's email and phone and location . This would be very useful info for marketing campaigns. Automated emails to people that go to specific stores, parks, etc.

> and location . Ok? AirDrop doesn't work miles away from people, so if they got your email and phone already through AirDrop, how is having your location such emphasized? "They can see you, gasp!"

It shouldn't be too hard to understand...

The more trackers you place, the more location data you have on that person. You could literally put thousands around a city at many different stores, gas stations, parks, etc.

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#13

Earlier quoted context omitted.

> and location . Ok? AirDrop doesn't work miles away from people, so if they got your email and phone already through AirDrop, how is having your location such emphasized? "They can see you, gasp!"

It shouldn't be too hard to understand... The more trackers you place, the more location data you have on that person. You could literally put thousands around a city at many different stores, gas stations, parks, etc.

The article is sparse on how they implemented. Do you need a Mac/iPhone or can this thing run on very cheap hardware that can be deployed at scale?

Given they found this almost two years ago, I wonder if there is an actual attack or exploit that has been deployed or is this one of those attacks that don’t leave the lab environment?

Re: Apple’s AirDrop leaks users’ PII, and there’s not much they can do about it

#14
post #3

What a bogus headline. If you don't want to try to sync with others publically, don't airdrop in a place where you think someone is waiting to steal your information. Reality though - your email and phone number is probably already out there. I'm waiting for the headline - thieves who grab the phone you stick out in front of you while you walk / sit / eat / drink / ride bus / ride train - may get PII. They really can…

Unfortunately while you shouldn't try to sync with others publically is a good theory, in the current implementation just opening the share sheet to share via messages or some other app will trigger AirDrop discovery. So you'd need to actively turn the feature off.

In some ways it seems having the "Contacts only" mode enabled is almost worse than having it set to everyone. The obvious problem with having it set to everyone though is you can easily get airdropped things by people around you. Which can be a great joke but since it displays preview of image receives can also be used in harmful or abusive ways.

Post reply on HN