Apple Private Wi-Fi hasn't worked for the past three years
(2023/10/28)
- Reference: 1698445813
- News link: https://www.theregister.co.uk/2023/10/27/apple_private_wifi_fixed/
- Source link:
Three years after Apple introduced a menu setting called Private Wi-Fi Address, a way to spoof network identifiers called MAC addresses, the privacy protection may finally work as advertised, thanks to a software fix.
"To communicate with a Wi-Fi network, a device must identify itself to the network using a unique network address called a Media Access Control (MAC) address," Apple explains in its [1]documentation .
"If the device always uses the same Wi-Fi MAC address across all networks, network operators and other network observers can more easily relate that address to the device's network activity and location over time. This allows a kind of user tracking or profiling, and it applies to all devices on all Wi-Fi networks."
[2]
Private Wi-Fi Address aims to avoid such tracking by generating a different MAC address for each different Wi-Fi network.
[3]
[4]
But Apple's identifier spoofing feature hasn't functioned properly since it was introduced for iOS 14, iPadOS 14, and watchOS 7 in September 2020 due a bug in mDNSResponder, a process associated with Apple's Bonjour networking protocol.
[5]Apple drops urgent patch against obtuse TriangleDB iPhone malware
[6]Side channel attacks take bite out of Apple silicon with iLeakage exploit
[7]Google - yes, that Google - testing proxy scheme to hide IP addresses for privacy
[8]The problem with Jon Stewart is that Apple appears to have cancelled his show
The bug, CVE-2023-42846, was identified by flaw finders Tommy Mysk and Talal Haj Bakry of Mysk Inc, which also makes various iOS and macOS apps.
"Private Wi-Fi addresses have been useless ever since they were introduced in iOS 14," they [9]said in a Mastodon post on Thursday. "When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network. In these requests, iOS sends the device's real Wi-Fi MAC address."
The duo explain that Apple's software replaces the device's actual MAC address in the data link layer with a generated MAC address. But until Apple repaired its code, the software also passed the real MAC address with the decoy in AirPlay discovery requests, even when connected to a VPN.
[10]
Bakry and Mysk determined this by using the [11]Wireshark network protocol analyzer, which revealed that the real MAC address was being sent in the Option Data: field, concatenated with the generated MAC address, as shown in this video.
[12]Youtube Video
Ironically, back in 2015, Apple [13]resumed using mDNSResponder after its intended replacement, a daemon written in C++ called [14]discoveryd that was added a year earlier as part of OS X Yosemite, proved to be more trouble than its C-based predecessor.
[15]
Apple did not respond to a request for comment. The company [16]patched the mDNSResponder bug on Wednesday with the release of iOS 17.1, iPadOS 17.1 and watchOS 10.1.
Users of iOS 16 and iPadOS 16 also received a fix, but those still clinging to iOS 15 did not. ®
Get our [17]Tech Resources
[1] https://support.apple.com/en-us/102509
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/10/26/apple_triangledb_exploit/
[6] https://www.theregister.com/2023/10/26/ileakage_apple_exploit/
[7] https://www.theregister.com/2023/10/23/google_ip_proxy/
[8] https://www.theregister.com/2023/10/20/jon_stewart_apple/
[9] https://defcon.social/@mysk/111301686152641593
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.wireshark.org/
[12] https://www.youtube.com/watch?v=T3XABxNogTA
[13] https://daringfireball.net/linked/2015/05/26/discoveryd
[14] https://furbo.org/2015/05/05/discoveryd-clusterfuck/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://support.apple.com/en-us/HT213982
[17] https://whitepapers.theregister.com/
"To communicate with a Wi-Fi network, a device must identify itself to the network using a unique network address called a Media Access Control (MAC) address," Apple explains in its [1]documentation .
"If the device always uses the same Wi-Fi MAC address across all networks, network operators and other network observers can more easily relate that address to the device's network activity and location over time. This allows a kind of user tracking or profiling, and it applies to all devices on all Wi-Fi networks."
[2]
Private Wi-Fi Address aims to avoid such tracking by generating a different MAC address for each different Wi-Fi network.
[3]
[4]
But Apple's identifier spoofing feature hasn't functioned properly since it was introduced for iOS 14, iPadOS 14, and watchOS 7 in September 2020 due a bug in mDNSResponder, a process associated with Apple's Bonjour networking protocol.
[5]Apple drops urgent patch against obtuse TriangleDB iPhone malware
[6]Side channel attacks take bite out of Apple silicon with iLeakage exploit
[7]Google - yes, that Google - testing proxy scheme to hide IP addresses for privacy
[8]The problem with Jon Stewart is that Apple appears to have cancelled his show
The bug, CVE-2023-42846, was identified by flaw finders Tommy Mysk and Talal Haj Bakry of Mysk Inc, which also makes various iOS and macOS apps.
"Private Wi-Fi addresses have been useless ever since they were introduced in iOS 14," they [9]said in a Mastodon post on Thursday. "When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network. In these requests, iOS sends the device's real Wi-Fi MAC address."
The duo explain that Apple's software replaces the device's actual MAC address in the data link layer with a generated MAC address. But until Apple repaired its code, the software also passed the real MAC address with the decoy in AirPlay discovery requests, even when connected to a VPN.
[10]
Bakry and Mysk determined this by using the [11]Wireshark network protocol analyzer, which revealed that the real MAC address was being sent in the Option Data: field, concatenated with the generated MAC address, as shown in this video.
[12]Youtube Video
Ironically, back in 2015, Apple [13]resumed using mDNSResponder after its intended replacement, a daemon written in C++ called [14]discoveryd that was added a year earlier as part of OS X Yosemite, proved to be more trouble than its C-based predecessor.
[15]
Apple did not respond to a request for comment. The company [16]patched the mDNSResponder bug on Wednesday with the release of iOS 17.1, iPadOS 17.1 and watchOS 10.1.
Users of iOS 16 and iPadOS 16 also received a fix, but those still clinging to iOS 15 did not. ®
Get our [17]Tech Resources
[1] https://support.apple.com/en-us/102509
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2023/10/26/apple_triangledb_exploit/
[6] https://www.theregister.com/2023/10/26/ileakage_apple_exploit/
[7] https://www.theregister.com/2023/10/23/google_ip_proxy/
[8] https://www.theregister.com/2023/10/20/jon_stewart_apple/
[9] https://defcon.social/@mysk/111301686152641593
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://www.wireshark.org/
[12] https://www.youtube.com/watch?v=T3XABxNogTA
[13] https://daringfireball.net/linked/2015/05/26/discoveryd
[14] https://furbo.org/2015/05/05/discoveryd-clusterfuck/
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://support.apple.com/en-us/HT213982
[17] https://whitepapers.theregister.com/
Nobody apparently cared?
So it took 3 years for someone to whip out Wireshark and ask "does this really work?"