Live data from Hacker News

Emulating AirTags to upload arbitrary data via Apple's FindMy network

positive.security

31–40 of 132 posts

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#31

does apple provide a way to opt out of the FindMy network?

Disabling it, won't you also lose the notification that someone is tracking you (like Android users) ?

P.S. I know about the beeping, but the speaker can be easily removed.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#32
As there's a limit of 16 AirTags per Apple ID, and each AirTag's keys rotate every 15 minutes, presumably Apple can detect if anyone is abusing the system by sending more than 16 different "messages" per 15 minutes. They can't detect this when the fake airtags are sending, but can detect it from stored message timestamps when you query. If they start to see this being abused a lot, they can then block Apple IDs. To avoid Apple being able to see this, you probably need to either use multiple Apple IDs, or send less than 16 bits per 15 minutes.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#33
post #3

Would be cool if Apple released a iPod touch with pager functionality that works thru find my network. Where you can send / receive short messages (even with 15 min delays).

Cool, but I don’t see it being viable, commercially.

Suppose they make this, how many would they sell? How many of those customers would have bought an (more expensive, I presume) iPhone if they wouldn’t make it?

They stopped making iPod touch for similar reasons. I doubt adding this feature would attract enough extra buyers to change that.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#34

Does this fall within Apple's policy of fair use? Would be great if there were an officially supported (paid) API for this, the technology and potential use cases are great. I'm afraid hooking something like this up to my Apple ID will get me banned somehow.

On Wikipedia it says that Find My is enabled for certain third-party accessories [0], so you could probably join if you wanted.

[0]: https://en.wikipedia.org/wiki/Find_My

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#35
post #14

Hilarious. This is exactly what Amazon Sidewalk intends to be. Apple has fallen ass backwards into an IoT killer app, but just don’t know it yet...

Sidewalk's bandwidth and latency is a little better than this, though.

Sidewalk also has the advantage of mostly being home internet connection instead of metered wireless plans

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#36

Does this fall within Apple's policy of fair use? Would be great if there were an officially supported (paid) API for this, the technology and potential use cases are great. I'm afraid hooking something like this up to my Apple ID will get me banned somehow.

You are using other users' (mobile) bandwidth to do the transmission, and apples server resources to brute force/ddos request the data on the other side. I can't see them condoning this at all and simple not responding negatively to it could encourage this misuse. I would expect that kind of response from Apple.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#37
post #14

Earlier quoted context omitted.

Sidewalk's bandwidth and latency is a little better than this, though.

Sidewalk also has the advantage of mostly being home internet connection instead of metered wireless plans

I’m probably on some sort of wifi on my phone like 90% of the time.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#39

This could have been an immensely powerful covert communications channel for field operators of military and intelligence services

It feels like Apple's ability to fix this is somewhat limited, since they can't change anything about Airtags that have already been produced.

Re: Emulating AirTags to upload arbitrary data via Apple's FindMy network

#40

This is starting to remind me of when Intelligent Tracker Prevention(tm) was released and instead was a super cookie leaking history. http://blog.lukaszolejnik.com/curious-case-of-privacy-vulner... I'd be much more comfortable with Apple being Privacy, Inc. if they kept their commitment to it, too often it looks like engineers got overrode by marketing. It's v unlikely a privacy engineer signed off on something, with…

You only read the title, didn't you?

Not constructive :( Getting downvoted through the floor on Apple comments for the first couple hours is a time-honored HN tradition at this point, but I'm hoping you can help us break that habit: a big contributor is aggressive comments like this that assume an agenda.

I know you can come up with something more substantive than guessing I didn't read the article. To wit, easy quote that backs what I read, and I assume I'm mistaken, given your feedback:

'The details should come as a surprise to everyone because it turns out that ITP could effectively be used for: - information leaks - tracking the user - fingerprinting'

Post reply on HN