Live data from Hacker News

An update on AirTag and unwanted tracking

apple.com

51–60 of 508 posts

Re: An update on AirTag and unwanted tracking

#51

Are airtags still useful for eg. tracking a stolen bike? Or will it now alert the thief within minutes that the bike contains a tracker?

There are details not exposed outside of NDA, but my suspicion is that there is a requirement that MAC rotation happen more slowly, like every 15 minutes, and it is a bluetooth MAC and the actual GPS/cell based 'movement' which together trigger an alert.

If a bike's Find My support randomized its MAC on every broadcast, it may very well not be possible to tell that it is not a new device each time. That might not be allowed per the licensing agreement, and that might be something that Apple has heuristics to detect and alert on.

Re: An update on AirTag and unwanted tracking

#53
post #8

Earlier quoted context omitted.

There is an Android app which allows Android users to see the same notifications.

Does it also conveniently increase the coverage of the network?

Nope, that requires their magic low power networking chip thing

Re: An update on AirTag and unwanted tracking

#54
post #41
post #37

Earlier quoted context omitted.

You can drive your Tesla using your smartphone app or other devices.

unless if their servers go down, in which case you can't unlock your car

Or the cellular network goes down, which happens about once a year during a bad winter storm.

Re: An update on AirTag and unwanted tracking

#55
post #40
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

AirTags shipped with anti-abuse features on day one, no other product provides any anti-abuse features whatsoever. The speaker could be defeated, but the anti tracking stuff cannot be stopped without breaking the basic functionality. If you’re demanding that companies must go to great length to avoid abuse of their products why aren’t you demanding the same from tile? Why not the myriad gps trackers on Amazon? It’s n…

> It’s not unreasonable to demand that Amazon ensures every such tracker they sell has speakers and anti abuse features.

I agree, however, this thread is about Apple's AirTag devices, and complaining about Amazon's incredibly vile sales practices seems at least somewhat off topic for it.

Re: An update on AirTag and unwanted tracking

#56
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

I think you’re completely misunderstanding the threat model here.

First the reality: Malicious actors interested in, e.g., tracking other people or other people’s things without their knowledge or consent, have many other options. To defeat them, an Apple product just needs to be somewhat less convenient/useful/cost-effective than some of the many other options.

Second, the perception: Apple needs to convince their customers and potential customers that they care and they’ll do something when there’s an issue.

As released, they pretty much had number one covered, though improvements are always good. So they are mostly working on number two… it’s good when there are actual improvements, but that’s not the main point.

Re: An update on AirTag and unwanted tracking

#57
post #36

Earlier quoted context omitted.

To what extent is any hardware manufacturer responsible for malicious usage of their product in your opinion? Surely you don't believe that all bases can be covered no matter how simple the product prior to launch. I credit Apple for making a best effort at launch and continuing security and support for much longer than the industry standard in their products. But realistically there is no way to launch something fla…

I don't think all bases can be covered, certainly. But neither do I think Apple has been doing a good job of even trying to do a good job of it, at least recently. Apple clearly put some thought into how the product would be misused, and added some features for that - but then appears to have not bothered having actual (simulated malicious) users test those features to see how they'd bypass them. Things like "removin…

Making AirTags safe is fundamentally impossible, a bit like trying to make a knife impossible to hurt yourself with.

For example:

> deliberate disabling of the speaker rendered the device useless after a few days

That only kicks the can. Now people will silence the speaker from outside, for example by covering the whole AirTags in superglue and foam to muffle all vibrations.

Re: An update on AirTag and unwanted tracking

#58
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

I've said this in other threads, but I'm probably done buying AirTags, because the anti-stalking features, that I assume you're aware of, are so annoying, that I don't want to add any more to my life.

When I get in my car with my wife, we both get a notification that an AirTag is following us, because my wife is potentially stalking me with her purse and keys. I can silence this notification for only one day. I can't disable it, because that's what a stalkers or abusive boyfriend would do. They randomly beep and boop to notify me that they exist, and I'm being stalked, and to put my phone near the offending AirTag so I can see the serial and last four digits of the owners phone number.

If someone were actually stalking me, I probably wouldn't notice.

I think the whole concept is almost doomed, if you're to be satisfied. The purpose of an AirTag is to track a thing. The desire of a stalker is to track a thing. I don't think these two identical problem spaces can exist together, in some harmonious way, that would satisfy people with your concerns, without constant annoyance. Just imagine if these were more popular and you did something crazy like, got on a bus, or went on a plane, walked any reasonable distance down a street with someone in your proximity.

I would love to hear a solutions that doesn't result in constant notifications. I also think it's completely silly to say "We'll we just have to restrict location track of anything, because there are bad people out there. Period." If the metric is to stop all the bad, then technology needs a huge lobotomy!

Re: An update on AirTag and unwanted tracking

#59
post #18

> ...and we condemn in the strongest possible terms any malicious use of our products. Then subject them to malicious users before releasing them to see what sort of ideas they can come up with in a few days, and mitigate those before general release. Go schedule a room at Defcon, give people AirTags, and see what they do. If they neutralized your mitigations in an hour, well... other people can figure that out too.…

Have any of the AirTag stalking mitigations actually been defeated by hackers? Besides physically removing the speaker.

The “an AirTag is traveling with you” alerts haven’t been defeated as far as I can tell. Apple tweaked some of the time periods after launch but the core technical mitigations are the same.

I agree the current situation is non-ideal, but it’s not clear to me this is from a lack of sufficient pre-release pentesting.

Re: An update on AirTag and unwanted tracking

#60
post #45

Earlier quoted context omitted.

Being able to share AirTags via a family iCloud account seems to be a pretty commonly requested feature. It does seem a little silly that I can track every device attached to the account but not AirTags.

I suspect they are working on it, but the crypto is privacy-preserving enough to make centralized authorization management hard. Specifically, you get a cryptographic secret when you pair the key, it broadcasts as a bluetooth beacon with encrypted messages based on that secret and current time, that get reported up to an Apple service. When you want to see your accessories, your device will compute the encrypted mess…

sorry I didn't mean the MAC address but rather an HMAC-based key derivation. I suspect they rotate MAC addresses every half hour or so, but the broadcast itself is encrypted such that you can't tell two belong to the same AirTag without knowing the secret.

I might have a secret key for the AirTag, and the encrypted messages derive a new key each day based on the current date, then encrypt a check-in message based on the current time.

If I share the secret key, its permanent access until a hardware reset of the AirTag. If I want to share "for a while", I just share a bag of those derived keys for the date range. The UX might represent it as not having a date range, and my devices which know the secret just periodically share out the derived keys when online to give out keys, and effectively make it so that any revocation of permission takes a week.

The other option is for me to be able to share enough information with Apple's servers that (on permission change) it blocks the AirTag web service query itself. That won't help you with any shared secrets allowing someone to detect its the same tag even after MAC rotation.

Post reply on HN