News: 1698445813

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Apple Private Wi-Fi hasn't worked for the past three years

(2023/10/28)


Three years after Apple introduced a menu setting called Private Wi-Fi Address, a way to spoof network identifiers called MAC addresses, the privacy protection may finally work as advertised, thanks to a software fix.

"To communicate with a Wi-Fi network, a device must identify itself to the network using a unique network address called a Media Access Control (MAC) address," Apple explains in its [1]documentation .

"If the device always uses the same Wi-Fi MAC address across all networks, network operators and other network observers can more easily relate that address to the device's network activity and location over time. This allows a kind of user tracking or profiling, and it applies to all devices on all Wi-Fi networks."

[2]

Private Wi-Fi Address aims to avoid such tracking by generating a different MAC address for each different Wi-Fi network.

[3]

[4]

But Apple's identifier spoofing feature hasn't functioned properly since it was introduced for iOS 14, iPadOS 14, and watchOS 7 in September 2020 due a bug in mDNSResponder, a process associated with Apple's Bonjour networking protocol.

[5]Apple drops urgent patch against obtuse TriangleDB iPhone malware

[6]Side channel attacks take bite out of Apple silicon with iLeakage exploit

[7]Google - yes, that Google - testing proxy scheme to hide IP addresses for privacy

[8]The problem with Jon Stewart is that Apple appears to have cancelled his show

The bug, CVE-2023-42846, was identified by flaw finders Tommy Mysk and Talal Haj Bakry of Mysk Inc, which also makes various iOS and macOS apps.

"Private Wi-Fi addresses have been useless ever since they were introduced in iOS 14," they [9]said in a Mastodon post on Thursday. "When an iPhone joins a network, it sends multicast requests to discover AirPlay devices in the network. In these requests, iOS sends the device's real Wi-Fi MAC address."

The duo explain that Apple's software replaces the device's actual MAC address in the data link layer with a generated MAC address. But until Apple repaired its code, the software also passed the real MAC address with the decoy in AirPlay discovery requests, even when connected to a VPN.

[10]

Bakry and Mysk determined this by using the [11]Wireshark network protocol analyzer, which revealed that the real MAC address was being sent in the Option Data: field, concatenated with the generated MAC address, as shown in this video.

[12]Youtube Video

Ironically, back in 2015, Apple [13]resumed using mDNSResponder after its intended replacement, a daemon written in C++ called [14]discoveryd that was added a year earlier as part of OS X Yosemite, proved to be more trouble than its C-based predecessor.

[15]

Apple did not respond to a request for comment. The company [16]patched the mDNSResponder bug on Wednesday with the release of iOS 17.1, iPadOS 17.1 and watchOS 10.1.

Users of iOS 16 and iPadOS 16 also received a fix, but those still clinging to iOS 15 did not. ®

Get our [17]Tech Resources



[1] https://support.apple.com/en-us/102509

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2023/10/26/apple_triangledb_exploit/

[6] https://www.theregister.com/2023/10/26/ileakage_apple_exploit/

[7] https://www.theregister.com/2023/10/23/google_ip_proxy/

[8] https://www.theregister.com/2023/10/20/jon_stewart_apple/

[9] https://defcon.social/@mysk/111301686152641593

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.wireshark.org/

[12] https://www.youtube.com/watch?v=T3XABxNogTA

[13] https://daringfireball.net/linked/2015/05/26/discoveryd

[14] https://furbo.org/2015/05/05/discoveryd-clusterfuck/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZTyHaPoHVB3ddjWN@GgeIwAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://support.apple.com/en-us/HT213982

[17] https://whitepapers.theregister.com/



Nobody apparently cared?

Gene Cash

So it took 3 years for someone to whip out Wireshark and ask "does this really work?"

"Note that nobody reads every post in linux-kernel. In fact, nobody who
expects to have time left over to actually do any real kernel work will
read even half. Except Alan Cox, but he's actually not human, but about
a thousand gnomes working in under-ground caves in Swansea. None of the
individual gnomes read all the postings either, they just work together
really well."

- Linus Torvalds