Not everything Apple makes "just works" — at least not as intended, anyway.
Security researchers exploring AirDrop, the iOS and macOS feature that lets users wirelessly share files via WiFi and Bluetooth, reported Wednesday on a flaw they say exposes users' emails and phone numbers. Unless you want every creep on the street to be able to secretly grab your contact info, it's a bit of a nightmare.
The researchers, a team made up of members of the Secure Mobile Networking Lab (SEEMOO)and the Cryptography and Privacy Engineering Group (ENCRYPTO), claim they alerted Apple to the flaw in May of 2019. However, according to them, the company never responded.
"As an attacker, it is possible to learn the phone numbers and email addresses of AirDrop users – even as a complete stranger," reads Tuesday's press release. "All they require is a Wi-Fi-capable device and physical proximity to a target that initiates the discovery process by opening the sharing pane on an iOS or macOS device."
We reached out to Apple to confirm the findings and to ask if indeed it was alerted to the vulnerability in 2019. We received no immediate response.
Notably, this is not the first questionable privacy situation tied to AirDrop. In 2019, researchers discovered that they were able to determine users' phone numbers based on the partial hashes AirDrop sends out. It's not clear if that concern was ever addressed by Apple, especially as the vulnerability disclosed this week appears similar in nature.
"The discovered problems are rooted in Apple's use of hash functions for 'obfuscating' the exchanged phone numbers and email addresses during the [AirDrop] discovery process," explains Tuesday's press release. "However, researchers from TU Darmstadt already showed that hashing fails to provide privacy-preserving contact discovery as so-called hash values can be quickly reversed using simple techniques such as brute-force attacks."
AirDrop is also notorious for its association with digital harassment. Specifically, harassers used the feature for cyber-flashing — wherein a stranger bombards a victim's phone with unwanted photos of a sexual or graphic nature — and sending images associated with white supremacists to people just going about their own business in public.
Tweet may have been deleted
Tweet may have been deleted
Of course, you don't have to deal with any of this.
If you'd rather avoid having your iPhone expose your contact info to creeps and protect yourself from cyber-flashers, you can turn AirDrop off (and disable Bluetooth while you're at it).
SEE ALSO: Apple knows AirTags can be abused and is trying to get ahead of it
It's not a permanent thing — you can always briefly turn AirDrop back on if you need it for some reason — but disabling the feature will provide you with some peace of mind, and hey, that "just works."
文章
5664
浏览
949
获赞
9
Instagram's 'Pinned Comments' feature is now available to everyone
If you're trying to inject some positivity into your Instagram posts, the new Pinned Comments featurBest kitchen deal: Save 50% on the Vitamix Ascent A2500 blender today only at Best Buy
SAVE 50%:The Vitamix Ascent A2500 blender is on sale for just $299.99 at Best Buy, down from the staBest ice cream maker deal: Ninja Creami Deluxe deal
SAVE $33: As of today, July 22, the Ninja Creami Deluxe ice cream maker is on sale at Amazon for $21General Motors' Ultra Cruise takes on Tesla's Autopilot FSD
General Motors' hands-free driving assistance is leveling up with Ultra Cruise.The advanced drivingHere's why everyone's mad about Kylie Jenner's new walnut scrub
Kylie Jenner announced her new skincare line, Kylie Skin, on Tuesday. The collection includes six prEarly Prime Day outdoor deals: Save on Coleman, YETI, and more
UPDATE: Jul. 15, 2024, 6:22 p.m. EDT Save up to 50% on tents, sleeping bags, and more ahead of PrimeHalo Infinite PC Graphics Benchmark
Today we're taking a look at Halo Infinite's graphics performance by testing over 30 Nvidia and AMDTesla wipes Cybertruck details from its website following delay into 2022
Elon Musk's meme truck is starting to feel even more like a goof than ever.Tesla's appears to have rMom faceswaps her kid with Thomas the Tank Engine, and it's incredibly cursed
Faceswaps are inherently pretty terrifying. Who thought this was a good idea? The proportions neverGrindr adds grunt notification for US Open
The US Open is underway and everyone is living their Challengersdream (watching tennis and yelling "Apple's mixed reality headset might require an iPhone to work
Apple is coming for Facebook's Oculus and Snapchat's Spectacles with a mixed reality headset of itsHow to get followers on Twitter
It's the age-old social media question: How do I get more followers on Twitter?The truth is, there iGoogle Assistant can now use your voice to verify purchases
Making purchases with your voice is convenient, but it's far from secure. Google is attempting to ch9 Olympians to follow on TikTok during the 2024 Paris Olympics
Olympians aren't just competing for medals in Paris; some of them are competing for our screen timeSwedish pole vaulter Mondo Duplantis breaks his world record — and the internet
Armond "Mondo" Duplantis has officially set the bar higher than anyone else in the world. The Swedis