Live data from Hacker News

An update on AirTag and unwanted tracking

apple.com

501–508 of 508 posts

Re: An update on AirTag and unwanted tracking

#501

Earlier quoted context omitted.

Apple's "Tracker Detect" Android app wants full network access and precise foreground location permissions. They expect me to consent to having my physical location tracked by Apple in order to avoid having my physical location tracked by someone other than Apple. Unbelievable.

Obviously, the app will need that access privilege to perform its task. Now, you’re in the bind: Do you trust apple to use these privileges on the device only - and not track you - or do you care about being tracked by others. Depends on your risk profile, I’d say.

I'm more concerned about Apple at the moment, I guess we'll see how common AirTag stalking becomes.

Re: An update on AirTag and unwanted tracking

#502
post #347

Earlier quoted context omitted.

The far bigger problem is the airtag itself, which spews unpermissioned tracking data without any consent required.

There is consent. If you don't want the "spewed tracking data", you can disable the Find My Network completely.

Apple has made no attempt at getting consent from whomever the airtag is on. Maybe if you have an iphone it could alert you.

Re: An update on AirTag and unwanted tracking

#503
post #208

Earlier quoted context omitted.

Battery Status API, Ambient Light are the two big Mozilla examples I know, but I suspect the list may be fairly long. I believe they are also against web bluetooth and serial. Apple has some permission stuff that apparently degrades Tile on their platforms IIRC.

There is no reason for any of those to be exposed to the web. For web specs you can't just think "I could do this cool thing", you have to say "what can a random popup ad do with this". Our experience with WebGL shows permission dialogs are a bad experience, and people will also click "yes" to make them go away. Most users report "would you like notifications" from websites as being spam/annoying.

When the only consequence is being tracked, it's mostly fine if people just click yes.

It's generally common knowledge that all sites are tracking you in all ways that they can and any time they ask for a permission it's to spy on you. Users who actually are more concerned with privacy probably will not click every random button.

Which is in itself one bit of trackable information, but that's about it.

Battery status is very useful for kiosk applications. Web Bluetooth is obviously great for all kinds of IoT things.

The more dangerous ones like Bluetooth can require you to explicitly select a target, and most people will notice something is wrong if they see MyBonerBest.io wants to connect to a list that includes their watch and light bulbs.

EU Cookie consent is somewhat changing that all, by training people to click yes on prompts faster than their eyes could even focus on them.

If there is a risk, it's probably more that people click out of reflex than out of not understanding, which can be partly mitigated with improved UI.

Re: An update on AirTag and unwanted tracking

#504

Earlier quoted context omitted.

Airtags were never supposed to be used to track stolen things, but to retrieve lost things. People complaining about airtags being nerfed were misusing them in the first place

> People complaining about airtags being nerfed were misusing them in the first place I sense the "you're holding it wrong" philosophy never really changed at Apple.

That may be the case, but not in this case. AirTags had anti stalking built in from the start and were specifically marketed for lost items over stolen items.

Re: An update on AirTag and unwanted tracking

#505

Earlier quoted context omitted.

>Android users are still vulnerable You misunderstand how airtags work. Airtags can't track an android user. It can only track people with iPhones (and possibly other apple devices).

That's not how Airtags work. From Apple's website: > Your AirTag sends out a secure Bluetooth signal that can be detected by nearby devices in the Find My network. These devices send the location of your AirTag to iCloud — then you can go to the Find My app and see it on a map. Airtags broadcast their ID via bluetooth and then any nearby iPhone with "Find My" enabled will be looking for these signals. If something is…

So just to clarify. The attack is:

You as Android user live in a an apartment block. Your neighbor below has iPhone. Your neighbor keep getting warnings on his phone that unrecognized AirTag is nearby. He can’t find any and doesn’t speak with you about it.

When moving across the city it would be even worse as there is no neighbor that would get the tracking warnings.

Re: An update on AirTag and unwanted tracking

#506

Android users are still vulnerable, and these announcements do nothing to reduce that. All a stalker needs to do, is remove the speaker. To detect a rogue AirTag, an Android owner needs to: 1) know AirTags exist (many obviously don't) 2) go out of their way to install Apple's Android AirTag scanner app (only 100k-500k worldwide have done so according to Google Play stats) 3) manually open the scanner app and scan, si…

>Android users are still vulnerable You misunderstand how airtags work. Airtags can't track an android user. It can only track people with iPhones (and possibly other apple devices).

Most people with Android phones participate in society with everyone else, and don't segregate themselves away from anyone who might have an iPhone.

Re: An update on AirTag and unwanted tracking

#508

Earlier quoted context omitted.

Yeah - I learned the hard way a while back when someone in our household misplaced another key… and found it right after we’d replaced it/paid all that.

fyi, If you ever have to get your locks rekeyed again, ask for a kwikset smartkey cylinder. Its a clever little device that will let you rekey a lock yourself with a new key as long as you still have at least one of the original keys.

Uh, no. See The Lockpicking Lawyers videos on Kwikset Smartkey cylinders, including: https://youtu.be/XqsAFdFsQmQ
Post reply on HN