Not everything Apple makes "just works" — at least not as intended, anyway.
Security researchers exploring AirDrop, the iOS and macOS feature that lets users wirelessly share files via WiFi and Bluetooth, reported Wednesday on a flaw they say exposes users' emails and phone numbers. Unless you want every creep on the street to be able to secretly grab your contact info, it's a bit of a nightmare.
The researchers, a team made up of members of the Secure Mobile Networking Lab (SEEMOO)and the Cryptography and Privacy Engineering Group (ENCRYPTO), claim they alerted Apple to the flaw in May of 2019. However, according to them, the company never responded.
"As an attacker, it is possible to learn the phone numbers and email addresses of AirDrop users – even as a complete stranger," reads Tuesday's press release. "All they require is a Wi-Fi-capable device and physical proximity to a target that initiates the discovery process by opening the sharing pane on an iOS or macOS device."
We reached out to Apple to confirm the findings and to ask if indeed it was alerted to the vulnerability in 2019. We received no immediate response.
Notably, this is not the first questionable privacy situation tied to AirDrop. In 2019, researchers discovered that they were able to determine users' phone numbers based on the partial hashes AirDrop sends out. It's not clear if that concern was ever addressed by Apple, especially as the vulnerability disclosed this week appears similar in nature.
"The discovered problems are rooted in Apple's use of hash functions for 'obfuscating' the exchanged phone numbers and email addresses during the [AirDrop] discovery process," explains Tuesday's press release. "However, researchers from TU Darmstadt already showed that hashing fails to provide privacy-preserving contact discovery as so-called hash values can be quickly reversed using simple techniques such as brute-force attacks."
AirDrop is also notorious for its association with digital harassment. Specifically, harassers used the feature for cyber-flashing — wherein a stranger bombards a victim's phone with unwanted photos of a sexual or graphic nature — and sending images associated with white supremacists to people just going about their own business in public.
Tweet may have been deleted
Tweet may have been deleted
Of course, you don't have to deal with any of this.
If you'd rather avoid having your iPhone expose your contact info to creeps and protect yourself from cyber-flashers, you can turn AirDrop off (and disable Bluetooth while you're at it).
SEE ALSO: Apple knows AirTags can be abused and is trying to get ahead of it
It's not a permanent thing — you can always briefly turn AirDrop back on if you need it for some reason — but disabling the feature will provide you with some peace of mind, and hey, that "just works."
文章
6
浏览
34494
获赞
246
People can't get over Trump putting a candy bar on a kid's head dressed as a Minion
Everything was going relatively smoothly for Halloween 2019 at the White House until one kid dressedCraigslist ad seeking attorney for 'difficult client' in D.C. is the ultimate Trump troll
President Donald Trump is currently short on attorney, and since it looks like he's gonna need one (Stephen Miller falls asleep during Trump speech on school shootings
Between frothing about "cosmopolitans" or getting escorted out of CNN by security, it's rare to captPornhub searches for Karen McDougal skyrocket after CNN interview about alleged Trump affair
On Thursday, CNN aired an interview with former Playboy model Karen McDougal, who claims she had a 1This week in politics on Instagram: Breitbart vs. 'Feminist'
Every Tuesday in the run up to the Nov. 3, 2020 election, Mashable will break down the most viral poApple announces $2.5 billion plan to ease California housing crisis
Faced with ever-increasing housing prices, people are leaving San Francisco and the Bay Area, and ApDark Mode on the iPhone can save massive amounts of battery life, test shows
If you're sick of hearing about dark mode on smartphone apps, I hear you. Now that both Android andI shot hoops at the top of a high
I made a few baskets while shooting hoops at the side of a San Francisco high-rise. No, really, takeOnePlus under fire for pre
OnePlus is facing criticism for pre-installing Facebook apps on its newest smartphones—and appRussian trolls on Instagram focus on Joe Biden
As the 2020 election heats up, so, too, do the trolling and interference efforts. And we already knoThe Trump administration is like middle school (with nuclear weapons)
Adolescence can last anywhere from three years to 65 -- at least in the case of the Trump administraHeads up, Mac users: macOS Catalina is now available
The latest version of macOS, dubbed Catalina, is out today, per Apple. It's a free software update j5 ways to charge your new iPhone 12
Apple did the unthinkable with its new iPhone 12: It stopped including a charging brick in the box.Pretend you have the worst job with Facebook's content moderation quiz
If you've ever wanted to cosplay as an underpaid, mentally exhausted, trauma-exposed contract workerToday in optical illusions: There's no need to worry about this corgi
If you do not like to click on links, there's a chance you've worried about this corgi in the past d