Airtag clones can sidestep Apple anti-stalker tech
- Reference: 1645528494
- News link: https://www.theregister.co.uk/2022/02/22/apple_airtags_protections_bypass/
- Source link:
Source code for the clones were published online by Berlin-based infosec startup Positive Security (not to be confused with [1]US-sanctioned cybersecurity outfit Positive Technologies ), which said its tags "successfully tracked an iPhone user... for over five days without triggering a tracking notification."
The user consented, added Positive's Fabian Bräunlein in a [2]blog post explaining his findings.
[3]
"In particular," said Bräunlein, "Apple needs to incorporate non-genuine AirTags into their threat model, thus implementing security and anti-stalking features into the Find My protocol and ecosystem instead of in the AirTag itself, which can run modified firmware or not be an AirTag at all."
[4]
[5]
The findings suggest that Apple's claims of the Find My protocol being "built with privacy in mind" fall short of the mark, with Positive Security spoofing the protocol by having an open-source device broadcast "2,000 preloaded public keys" as a way of fooling some anti-stalking protections.
The proof-of-concept device was kept with a volunteer user for five days, during which time it did not show on Apple's Tracker Detect app – while "location reports for the broadcasted public keys were uploaded and could be retrieved."
[6]
Airtags, originally conceived as a way of keeping track of luggage and similar portable items through Apple's Find My app, have been abused by stalkers in the past. Miscreants would drop Airtags into victims' bags or attach them to cars and then use the Find My app to view their precise locations.
[7]Anti-stalking protections were hastily introduced by Apple recently; Airtags are supposed to sound an audible alarm and also send notifications to nearby iPhones announcing their presence.
This doesn't work with non-Apple phones, although Apple released an Android app capable of picking up these broadcasts. The BBC described Airtags last month as [8]"a perfect tool for stalking."
[9]Apple tweaks AirTags to be less useful for stalkers, thieves
[10]Unpatched flaw 'weaponises' Apple AirTags to turn them into the phisherman's friend
[11]Apple's Find My network can be abused to leak secrets to the outside world via passing devices
[12]Apple extends Find My support to third-party vendors including Belkin, Dutch bike maker VanMoof, and Chipolo
In a 10 February [13]statement Apple declared it was tightening up privacy protections in Airtags, adding "we condemn in the strongest possible terms any malicious use of our products."
Airtag spoofing has also spawned an open source project called OpenHaystack, which is described on its GitHub page as "an application that allows you to create your own accessories that are tracked by Apple's Find My network."
[14]
While the use cases presented by the project's creators (Technical University of Darmstadt) are benign, the Find My protocol (which operates over Bluetooth Low Energy) appears straightforward for unofficial devices to piggyback off.
It is unclear if Apple will look at the Find My protocol itself rather than tinkering around the edges with the proprietary devices it deploys to use that protocol. We've asked Apple for comment. ®
Get our [15]Tech Resources
[1] https://www.theregister.com/2021/04/16/positive_technologies_us_sanctions_groundless/
[2] https://positive.security/blog/find-you
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YhUWvJQNUBQ14IrzuTe1eQAAAEU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhUWvJQNUBQ14IrzuTe1eQAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhUWvJQNUBQ14IrzuTe1eQAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YhUWvJQNUBQ14IrzuTe1eQAAAEU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2022/02/11/apple_airtags_stalking/
[8] https://www.bbc.co.uk/news/technology-60004257
[9] https://www.theregister.com/2022/02/11/apple_airtags_stalking/
[10] https://www.theregister.com/2021/09/29/weaponised_apple_airtags/
[11] https://www.theregister.com/2021/05/12/apples_find_network/
[12] https://www.theregister.com/2021/04/08/apple_extends_find_my_support/
[13] https://www.theregister.com/2022/02/11/apple_airtags_stalking/
[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YhUWvJQNUBQ14IrzuTe1eQAAAEU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[15] https://whitepapers.theregister.com/
"we condemn in the strongest possible terms any malicious use of our products."
Even though we have created a product that specifically allows for stalking without any serious safeguards.
Shame on you for taking advantage of it.
Come on Apple, you goofed. Own up to it, retire the product and think of a better version.
Re: "we condemn in the strongest possible terms any malicious use of our products."
Apple take responsibility for a mistake? Sorry mate, wrong house.
Re: "we condemn in the strongest possible terms any malicious use of our products."
" Come on Apple, you goofed. Own up to it, retire the product and think of a better version. "
Why is it Apple's fault that people are dicks?
Come on God, you goofed. Own up to it, retire the product and think of a better version.
Re: "we condemn in the strongest possible terms any malicious use of our products."
Come on God, you goofed. Own up to it, retire the product and think of a better version.
I think God is well aware of that, and is now working on a much less ambitious project ...
Re: "we condemn in the strongest possible terms any malicious use of our products."
It's not Apple's fault that people are dicks. It's Apple's fault that, despite knowing that people are dicks, they made a product with no effective safeguards against abuse by said dicks.
Re: "we condemn in the strongest possible terms any malicious use of our products."
> It's not Apple's fault that people are dicks. It's Apple's fault that,
You're holding looking at it wrong. The way to look at it is:
Positive Security have found a bug in Apple's implementation of Airtags and the Find My prototcol. But instead of disclosing that vulnerability responsibly they decide to publish the code on Github and give every wannabee stalker a head-start.
Well done.
Re: "we condemn in the strongest possible terms any malicious use of our products."
God found the world in a dumpster. See oglaf a few weeks ago:
https://www.oglaf.com/strongly-discouraged/
(be aware this one is marginally sfw, most of the others are definitely not!)
I find his Send-My far more interesting
IMHO his [1]Send-my idea is creepier by some distance.
[1] https://github.com/positive-security/send-my
Re: I find his Send-My far more interesting
There are no use cases I can think of, like bugging, remote surveillance, network snooping that could be enabled by Send-My.
The whole find-my network thing seems badly thought through/implemented. Can people not use the historic approach; lose keys or other important item, go through pain of sorting it out*, make a point of not misplacing important stuff for the remainder of life.
* rediscovery of lost item may occur after this point.
Re: I find his Send-My far more interesting
My other half finally managed to spend her Apple Store gift voucher by buying 4 airtags.
She has 3 I have 1 ,
1 on her car keys
1 on dog collar
1 on a travel bag
1 on my car keys
the dog did a runner the other week when i was out walking, i can't track her tags so i had to call her for her to check her phone to see where the dog was. In the end someone had heard me calling and brought the dog back for me. The app showed the dog was in the opposite direction to where he was found. I assume it was the last location it had pinged its location to apple via my phone.
I had put a tile tag on him previously & we could both see that from our own accounts within our family account.
I don't understand why we can't permit others to see where our tags are. Family & friends permanently share their locations with us from their idevices i don't see why airtags can't be the same
https://www.macrumors.com/2021/05/04/airtag-uses-disappointed-family-sharing/
Re: I find his Send-My far more interesting
She has 3 I have 1 ,
1 on her car keys
1 on dog collar
1 on a travel bag
1 on my car keys
the dog did a runner the other week when i was out walking, i can't track her tags so i had to call her for her to check her phone to see where the dog was. In the end someone had heard me calling and brought the dog back for me. The app showed the dog was in the opposite direction to where he was found. I assume it was the last location it had pinged its location to apple via my phone.
I’m somewhat relieved that you have a dog and not sharing just a little too much information about your life.
I also feel your pain about the dog, I’ve lost my folks dog whilst out walking him. This was horrific because another dog nearby had recently been hit by a car after being let off the lead in that field.. There was a hole in the hedgerow that it managed to squeeze through and despite the driver slamming on the brakes still sent it flying a few feet. Fortunately it wasn’t injured at all according to the vet and ours came back after a few minutes carrying a large stick.
Its the story of the Internet
Most of the problems we have with security all boil down to the single notion that "nobody would ever do that" back in the early days of protocol design. It was the true Age of Innocence.
It was also 40 years ago in a very different communications environment.
Now any design should include the possibility of misuse and spoofing as a key parameter. This doesn't necessarily mean tying up the protocol in a welter of key infrastructure hacks -- they're useful but they're really a Band-Aid trying to stop a hemorrhage -- but at least put basic security into it if the information it carries has a private content. Put simply -- "We should know better".
Re: Its the story of the Internet
"Now any design should include the possibility of misuse and spoofing as a key parameter. This doesn't necessarily mean tying up the protocol in a welter of key infrastructure hacks -- they're useful but they're really a Band-Aid trying to stop a hemorrhage -- but at least put basic security into it if the information it carries has a private content. Put simply -- "We should know better"."
Thing is, just about ANYTHING can be abused if someone demented enough thinks hard enough. Quite simply, we just can't have nice things.
No
Not creepy at all