Live data from Hacker News

An update on AirTag and unwanted tracking

apple.com

31–40 of 508 posts

Re: An update on AirTag and unwanted tracking

#31
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

You're both right; it's an interesting question. Something that can't be used maliciously is probably not useful for much of anything at all. OTOH, when the potential for harm is far greater than the potential for good, as it arguably is here, that calls for extra discretion on the part of the developers.

Re: An update on AirTag and unwanted tracking

#32
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

Meanwhile, you can get a cheap GPS tracker for the price of an AirTag or two…

Re: An update on AirTag and unwanted tracking

#33
post #25
post #21

Earlier quoted context omitted.

TBH sharing keys is a nightmare even without airTags. Honestly recommend each spouse gets their own key to each vehicle. Once my wife had her keys stolen and we made do for a year sharing my car key and it was hell (because both of us prefer the EV to the minivan). I don't track keys but I track my wallet and my wife does not need or ever ask for that.

Luckily keys are on the way out. Between a August Smart Lock and a Tesla I haven’t carried keys in years and I don’t miss that nightmare.

How are fobs different in this scenario?

Re: An update on AirTag and unwanted tracking

#34
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

I think that a key issue in this case isn't just that Apple made a device that could be used for tracking - after all, you could engineer or buy a different tracking device from a number of vendors - but that its feasibility was massively increased due to a unique Apple asset - its network of iDevices. That is, Apple released a product that was uniquely good at tracking people due to an Apple-specific asset.

Slightly less, but still very importantly, there's the fact that by design you can't see if someone is tracking you unless you buy another Apple product, which wasn't an intrinsic engineering limitation, but just a choice that Apple made for their own profit.

Re: An update on AirTag and unwanted tracking

#35
post #8

Earlier quoted context omitted.

There is an Android app which allows Android users to see the same notifications.

Yea, but philosophically, you shouldn't have to opt in (to opt out) - if I don't want to any part of apple's ecosystem, this forces me to actively opt out.

What about Tile and other AirTag competitors? None of them even have an app to alert you to unwanted trackers at all.

Re: An update on AirTag and unwanted tracking

#36
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

I don't think all bases can be covered, certainly. But neither do I think Apple has been doing a good job of even trying to do a good job of it, at least recently.

Apple clearly put some thought into how the product would be misused, and added some features for that - but then appears to have not bothered having actual (simulated malicious) users test those features to see how they'd bypass them. Things like "removing the speaker" seem oddly trivial, yet there's no indication Apple even thought through that situation. It wouldn't be too difficult to design something in which the deliberate disabling of the speaker rendered the device useless after a few days, yet would be unlikely to trip in normal use. They're pretty well sealed.

"Red teaming" something like this in the early design phases is often useful to be able to figure out how to mitigate these sorts of attacks, and Apple, far too often lately, seems to be in a "...they did what? No, they can't have... we didn't think they'd... ugh, OK, let's add something to support that..." mode.

And if they don't have family sharing support, as seems to be the case from the other comments here, it clearly means they weren't tested with any sort of realistic use case, because "Oh, yeah, my wife's keys in her purse keep making my phone go off when we're driving together" seems a common use case to discover in testing.

I don't think a company should be responsible for all malicious uses, but when those uses seem utterly trivial to manage (remove speaker, your tracking target uses Android and like almost all Android users hasn't downloaded Apple's app to check for AirTags following them), I think they've missed something really important in the design phase.

Re: An update on AirTag and unwanted tracking

#37
post #25

Earlier quoted context omitted.

Luckily keys are on the way out. Between a August Smart Lock and a Tesla I haven’t carried keys in years and I don’t miss that nightmare.

How are fobs different in this scenario?

You can drive your Tesla using your smartphone app or other devices.

Re: An update on AirTag and unwanted tracking

#38

Earlier quoted context omitted.

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

Meanwhile, you can get a cheap GPS tracker for the price of an AirTag or two…

And if you want it to report out, it has to have an active cell plan, and the power consumption is rather radically higher than "years on a button cell," so the device is bigger, it needs a clear enough view of the sky to get a GPS signal, etc. They're an awful lot less useful and less discreet. Again, not impossible by any means, but certainly quite a bit less convenient than an AirTag with a removed speaker.

Re: An update on AirTag and unwanted tracking

#39

Earlier quoted context omitted.

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

You're both right; it's an interesting question. Something that can't be used maliciously is probably not useful for much of anything at all. OTOH, when the potential for harm is far greater than the potential for good, as it arguably is here, that calls for extra discretion on the part of the developers.

> as it arguably is here

That may be understating it a bit. I honestly can't decide which is greater.

Airtags as-is are nerfed for non-technical reasons as to make them more or less useless to me, despite their ability to be incredibly useful.

For example:

Due to the nag/anti-stalking alerts I can't put them on dog collars due to day-care visits. No way for others to whitelist a tag on their phone, or any way to silence it.

Same goes now for the car. It's annoying to just toss one in each trunk in case of theft or whatnot, since the cars are shared.

The privacy concerns have more or less turned this product into something of a very narrow usage band - aside from a personal bookbag or whatnot I don't see many other realistic uses at this time. Not useful for hiding in my power tools, etc. etc.

I had pretty high hopes for these for some peace of mind (dogs), and I live in a high crime area so being able to track my expensive items has proven useful in the past. I was excited about expanding on this use until they started crippling them.

Re: An update on AirTag and unwanted tracking

#40
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

AirTags shipped with anti-abuse features on day one, no other product provides any anti-abuse features whatsoever.

The speaker could be defeated, but the anti tracking stuff cannot be stopped without breaking the basic functionality.

If you’re demanding that companies must go to great length to avoid abuse of their products why aren’t you demanding the same from tile? Why not the myriad gps trackers on Amazon? It’s not unreasonable to demand that Amazon ensures every such tracker they sell has speakers and anti abuse features.

Post reply on HN