Live data from Hacker News

OpenDrop: An Open Source AirDrop Implementation

github.com

71–80 of 231 posts

Re: OpenDrop: An Open Source AirDrop Implementation

#71
post #7
post #3

I wish we had something like AirDrop to work between android and iOS devices.

iMessage too. It's insane to me that this is still a problem.

I like that here in Turkey every single person uses WhatsApp. I recently switched from iOS to Android and haven't realized I lost iMessage.

Re: OpenDrop: An Open Source AirDrop Implementation

#75

Could this technology be used to create a "shadow" internet/network/messaging service where devices connect and communicate directly with each other. This way governments can't just block internet access or services during demonstrations.

For what it’s worth, I have been able to get the Yggdrasil Network (https://yggdrasil-network.github.io) to peer over AWDL, allowing nearby Macs to mesh without even being connected to the same Wi-Fi network, or any network at all.

It’s not perfect - there are trade offs, like how the wireless performance is reduced somewhat when AWDL is active due to channel hopping and how AWDL expects a single node to play the role of clock sync source. It’s also not very well tested yet.

However, it works and in theory it allows an infrastructure-free IPv6 mesh network to be built ad-hoc.

Re: OpenDrop: An Open Source AirDrop Implementation

#76
post #5

Earlier quoted context omitted.

Knowing Apple, such an effort would likely be destroyed by an army of lawyers the moment you bring out an app that provides such features. The Apple ecosystem is very closed and Apple will fight tooth and nail to keep it that way. Removing vendor lock-in would, after all, allow users to try switching to another brand without an enormous amount of hassle.

Apple's open-source mDNS/DNS-SD implementation mDNSResponder underlies Android's NSD API, so I could one day see seamless interoperability over Wi-Fi Aware being a thing. I wouldn't bet on it happening, but given Windows (which ships with an mDNS/DNS-SD stack) and Android will be doing it before too long, I wouldn't be surprised to see Apple join the party.

Incidentally, Wi-Fi Aware is based heavily on AWDL but the Wi-Fi Alliance made a number of breaking protocol changes in the Wi-Fi Aware standard. This isn’t exactly Apple’s fault - it could have been interoperable.

Re: OpenDrop: An Open Source AirDrop Implementation

#77
post #60
post #35

Interestingly the article on the bottom links to a Usenix 2019 (held Aug 14 - 16) paper with the title "A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link" Abstract: "Apple Wireless Direct Link (AWDL) is a key protocol in Apple's ecosystem used by over one billion iOS and macOS devices for device-to-device communications. AWDL is a propri…

I can’t hep but think that these seemingly numerous security flaws are a product of proprietary software development. There is the old “many eyes” idea for software bugs, but even on a standards level. Did Apple not send out an RFC? Isn’t this type of architectural level screw up exactly what you want to avoid with an RFC? I’m glad Apple are taking the privacy issue to heart, but for every inch we’ve won in privacy,…

The “many eyes” hypothesis is routinely debunked when severe security bugs are found in things like the Linux kernel that have been there for years. The same is true for standards that end up being fundamentally broken at later dates. In the end software and hardware is so overly complicated that we cannot currently build secure systems.

Re: OpenDrop: An Open Source AirDrop Implementation

#78

Earlier quoted context omitted.

Absolutely, but I can ask a bit more nuanced question. In any society, there is state-"friendly" communication and state-"unfriendly" communication. Also there are state-"essential" communications like state-propoganda [1]. Is it possible to build communication networks that allow for secure and anonymous state-unfriendly communication, such that trivially jamming it also jams state-friendly and state-essential commu…

I don't believe so. I think the state would be comfortable denying phone and wifi usage to protesters congregating in public places, and the state has plenty of 'state-essential' communication mediums like loudhailers, billboards, riot police beating their truncheons against their shields etc, to fall back on. That air-drop does work in the Hong Kong protests really just says that the state wasn't really prepared, bu…

> I think the state would be comfortable denying phone and wifi usage to protesters congregating in public places

I don't entirely agree. It's a resource tradeoff scenario where the state has to expend political-capital (because they are also blocking people living nearby) to prevent the protestors from communicating. In fact, the protestors in Hong Kong have been protesting in different neighborhoods so non-protestors can see first hand the brutality of the state.

I agree with your larger point though that communication jamming is probably a minor point right now in the Chinese state's gameplan for dealing with these protests.

Re: OpenDrop: An Open Source AirDrop Implementation

#79

I wonder if it's more reliable than Apple's own implementation for MacOs. It used to be rock solid – and between iOS devices it still is – but between Macs I regularly have to switch both to "Search for an older Mac" to make them see each other, with no explanation why.

I found that the macos firewall is to blame.

Re: OpenDrop: An Open Source AirDrop Implementation

#80
post #60

Earlier quoted context omitted.

I can’t hep but think that these seemingly numerous security flaws are a product of proprietary software development. There is the old “many eyes” idea for software bugs, but even on a standards level. Did Apple not send out an RFC? Isn’t this type of architectural level screw up exactly what you want to avoid with an RFC? I’m glad Apple are taking the privacy issue to heart, but for every inch we’ve won in privacy,…

The “many eyes” hypothesis is routinely debunked when severe security bugs are found in things like the Linux kernel that have been there for years. The same is true for standards that end up being fundamentally broken at later dates. In the end software and hardware is so overly complicated that we cannot currently build secure systems.

I don't think it's as easy as saying "measles exists therefore vaccines don't work." Do you have actual studies on this that you can cite?
Post reply on HN