Apple ignored warnings that AirDrop had a vulnerability that China learned to exploit

emorphy

Posts: 64   +0
Staff
Facepalm: China isn't exactly a standard-bearer for human rights and individual privacy, so being able to grab AirDrop users' contact information is worrisome. Apple was warned its service was vulnerable years ago, but did nothing about it.

In 2019, researchers at Germany's Technical University of Darmstadt discovered that Apple's AirDrop wireless sharing function had vulnerabilities that allowed an attacker to hack the phone numbers and email addresses of the AirDrop users using a Wi-Fi-capable device and being in close proximity to a target. Then it becomes just a matter of opening the sharing pane on an iOS or macOS device and grabbing that information. The researchers warned Apple of the vulnerability back then, but the company did nothing. Two years later the same group proposed a fix for the problem, but again Apple made no moves to fix the flaw.

Now the consequences of Apple's inaction have become clear, or at least public for the first time: Beijing judicial authorities recently announced police were able to track down people who used the service to send "inappropriate information" to passersby in the Beijing subway with the help of the Chinese tech firm Wangshendongjian Technology.

Some background about the way AirDrop works is useful in understanding what happened next. AirDrop is a proprietary Apple protocol that lets you share files directly but wirelessly with other Apple users that are nearby. AirDrop works even when both users are offline, using a combination of Bluetooth and peer-to-peer Wi-Fi for fast, simple, local wireless sharing.

Users open themselves to the vulnerability through AirDrop's "Contacts only" mode, where you tell AirDrop to only accept a message from users already in your own contact list. The Darmstadt researchers found that the two ends of an AirDrop connection that determines whether these two people consider each other a contact uses network packets that don't properly protect the privacy of the contact data.

And indeed Wangshendongjian Technology was able to circumvent the hash values related to the sender's device name, email address and mobile phone number by creating a rainbow table of mobile phone numbers and email accounts, which converted the cipher text into original text and locked the sender's mobile phone number and email account.

Which is exactly what the researchers from TU Darmstadt warned would happen: namely, that AirDrop's hashing fails to provide privacy-preserving contact discovery as hash values can be quickly reversed using simple techniques such as brute-force attacks.

The news that China has figured out how to hack AirDrop has reverberated across Capitol Hill and among humanitarian rights activists. Florida Senator Marco Rubio, the leading Republican on the Senate Intelligence Committee, called on Apple to "be held accountable for failing to safeguard its users against such blatant security breaches. "This breach is just another way for Beijing to target any Apple user it perceives to be an opponent." Benjamin Ismail, campaign and advocacy director of Greatfire.org, which monitors internet censorship in China, said it is "imperative that Apple is transparent about their response to these developments."

Apple, meanwhile, has not answered multiple media inquiries about the matter.

Permalink to story.

 
"Facepalm: China isn't exactly a standard-bearer for human rights and individual privacy, so being able to grab AirDrop users' contact information is worrisome."

But " the five eyes" or US PRISM program is ? when are we gonna stop pretending that in 2024 people actually have rights (when it comes to online).

Everything is monitored, especially phones and IOT devices.
 
"Facepalm: China isn't exactly a standard-bearer for human rights and individual privacy, so being able to grab AirDrop users' contact information is worrisome."

But " the five eyes" or US PRISM program is ? when are we gonna stop pretending that in 2024 people actually have rights (when it comes to online).

Everything is monitored, especially phones and IOT devices.
This is classic Whataboutism, straight out of the communist playbook.
 
It would be viable to have privacy and "digital shielding" if we didn't have terrorists and all types of criminals navigating these virtual waters.
 
At this point, I wouldn't be surprised if the CCP "persuaded" Apple to ignore it. They already bend the knee to them, and we know that a lot of Apple's privacy PR can be pretty shallow.
Also, it's not like big companies like this face actual consequences outside of China (beyond a slap on the wrist). It would've just been another calculated cost of doing business...
 
"Facepalm: China isn't exactly a standard-bearer for human rights and individual privacy, so being able to grab AirDrop users' contact information is worrisome."

But " the five eyes" or US PRISM program is ? when are we gonna stop pretending that in 2024 people actually have rights (when it comes to online).

Everything is monitored, especially phones and IOT devices.
True, but who would you rather have your data? That's what makes this story different.
 
"Facepalm: China isn't exactly a standard-bearer for human rights and individual privacy, so being able to grab AirDrop users' contact information is worrisome."

But " the five eyes" or US PRISM program is ? when are we gonna stop pretending that in 2024 people actually have rights (when it comes to online).

Everything is monitored, especially phones and IOT devices.
The difference is that the US doesn't throw you in jail for talking about the government.
 
There's a fine line between "Whataboutism" and pointing out blatant hypocrisy. The Five Eyes have done this exact same thing. Five Eyes intelligence agencies used the "grey boxes" from Israel that used unpublished exploits in iOS to break their encryption and bypass passcode locks.
You are comparing apples to oranges, the comparison is so bad that it hurts my liver to have to explain. One side is using these security exploits to protect itself from the millions of terrorists surrounding it; China, on the other hand, is the dictatorship that supports all other dictatorships, nullifying the effect of sanctions on obscure countries like Russia, Iran, North Korea and other smaller dictatorships in Africa. It is a monster with tentacles that is spreading rapidly and growing stronger thanks to these weak Western leaders and their demagoguery over the decades.
 
You are comparing apples to oranges, the comparison is so bad that it hurts my liver to have to explain. One side is using these security exploits to protect itself from the millions of terrorists surrounding it; China, on the other hand, is the dictatorship that supports all other dictatorships, nullifying the effect of sanctions on obscure countries like Russia, Iran, North Korea and other smaller dictatorships in Africa. It is a monster with tentacles that is spreading rapidly and growing stronger thanks to these weak Western leaders and their demagoguery over the decades.
Noted: violating civil liberties is perfectly acceptable if you label everyone who opposes you the "bad men". Wait, isnt that what china does? Hmmm.....

I will admit, your comment is refreshing, its like being back in 2006 where people are desperate to justify the never ending wars in the sand of the middle east. And, of course, simply saying there are millions of "bad men" that justify such a massive invasion of privacy on those who are not affiliated with those bad men is hilariously tone deaf.

Remember: A group that uses unpublished exploits to spy on its own citizens is criticizing another government for doing the same thing. If you think the five eyes are not spying on, or always looking for ways to suppress, their own citizens, and you wish to blatantly ignore everything revealed to us via people like Snowden about things like PRISM, then that would make you no better then the influences bought and paid for by china to promote chinese views on youtube. The only difference is the side you wish to shill for.
The difference is that the US doesn't throw you in jail for talking about the government.
Not YET*. Those who oppose the current regime are looked upon with hatred and contempt by those in power, and polarization is only growing. And we are the only five eyes country with such freedom. New zealand, australia, canada, and ESPECIALLY the UK have shown they are absolutely willing to go after those who criticize the government. Given how influenced australia is by chinese interests it's especially damning that their group is the one angry that china did something like this.
 
Noted: violating civil liberties is perfectly acceptable if you label everyone who opposes you the "bad men". Wait, isnt that what china does? Hmmm.....

I will admit, your comment is refreshing, its like being back in 2006 where people are desperate to justify the never ending wars in the sand of the middle east. And, of course, simply saying there are millions of "bad men" that justify such a massive invasion of privacy on those who are not affiliated with those bad men is hilariously tone deaf.

Remember: A group that uses unpublished exploits to spy on its own citizens is criticizing another government for doing the same thing. If you think the five eyes are not spying on, or always looking for ways to suppress, their own citizens, and you wish to blatantly ignore everything revealed to us via people like Snowden about things like PRISM, then that would make you no better then the influences bought and paid for by china to promote chinese views on youtube. The only difference is the side you wish to shill for.
Not YET*. Those who oppose the current regime are looked upon with hatred and contempt by those in power, and polarization is only growing. And we are the only five eyes country with such freedom. New zealand, australia, canada, and ESPECIALLY the UK have shown they are absolutely willing to go after those who criticize the government. Given how influenced australia is by chinese interests it's especially damning that their group is the one angry that china did something like this.
Is that big pile of generic tantrum arguments the best you could think of? Is there a parallel universe where supporting 90% of the dictatorships and terrorists on the planet doesn't make you the bad guy?

I hope you know that in the real world there are much bigger concerns than the government looking at the adult website you are on. If you're not involved in illegal stuff, I wouldn't be worried about this nonsense, there's a real danger growing and pointing all its guns at the West.
 
Apple users won't believe it , and even if they do , they will soon forget it.
Eg someone at the moment is claiming no terrorist activities or wars during the reign. It's complete hogwash .
But people will soon be telling you that it's true

It really is amazing how powerful , gaslighting , telling complete lies ( Eg perfect call) , blaming others of the crimes you do
Apple never makes mistakes , it's users do , we don't get viruses , hacked , and celebs don't get their icloud media files stolen
Apple dies not profile you and try to make advertising money off you

So many people believe those complete lies

Not only will apple charge you , it spies on you , all your photos , your health data from your watch , it wants to control 100% your life and clip every ticket
That's why I prefer googles messy spying if just mostly wants advert revenue . Apple want everything in a nasty vicious targeted way
Get kids hooked on cheap Ipads

Just like META who already track me , even though I have never had a farcebook account . You have a unique apple ID and profile - they know when you cheat on your partner if you have and Iwatch etc
 
Is that big pile of generic tantrum arguments the best you could think of? Is there a parallel universe where supporting 90% of the dictatorships and terrorists on the planet doesn't make you the bad guy?

I hope you know that in the real world there are much bigger concerns than the government looking at the adult website you are on. If you're not involved in illegal stuff, I wouldn't be worried about this nonsense, there's a real danger growing and pointing all its guns at the West.

Would you like me to list all the terrorists, terrorist groups, dictatorships and autocrats that Uncle Sam (+some minions) has supported and currently supports? I have many experiences in this regard in the history of my country, more so over the last 65+ years.

Have you ever wondered why most of the planet despises this little group that calls itself "the West"? Do you think it's for sport or because one day they got up on the wrong side of the bed? Have you ever wondered the why of those "millions of terrorists surrounding it". no?
 
Would you like me to list all the terrorists, terrorist groups, dictatorships and autocrats that Uncle Sam (+some minions) has supported and currently supports? I have many experiences in this regard in the history of my country, more so over the last 65+ years.

Have you ever wondered why most of the planet despises this little group that calls itself "the West"? Do you think it's for sport or because one day they got up on the wrong side of the bed? Have you ever wondered the why of those "millions of terrorists surrounding it". no?
Let's look for justifications in how many centuries ago. What century do you live in? I live today with today's problems, and today's people. If I lived in the past, I would be saying "let's destroy Germany, Japan" and others responsible for the great world wars and millions of deaths.

There have never been and never will be more nations with destructive power and terrorist and autocratic tendencies like today; Russia, China, Iran and North Korea. My liver hurts seeing people like you, juggling to defend terrorists who tell people to blow themselves up and kill as many as possible.

You mean, besides being the scum of the planet who enslaves and oppresses their own people, dragging them down into poverty under the banner "it's all the fault of the evil West, let's destroy it"?

If the west is so evil, why haven't we attacked with full force to decimate these groups that openly threaten us? Have you ever stopped to think that we could.
 
Let's look for justifications in how many centuries ago. What century do you live in? I live today with today's problems, and today's people. If I lived in the past, I would be saying "let's destroy Germany, Japan" and others responsible for the great world wars and millions of deaths.

There have never been and never will be more nations with destructive power and terrorist and autocratic tendencies like today; Russia, China, Iran and North Korea. My liver hurts seeing people like you, juggling to defend terrorists who tell people to blow themselves up and kill as many as possible.

You mean, besides being the scum of the planet who enslaves and oppresses their own people, dragging them down into poverty under the banner "it's all the fault of the evil West, let's destroy it"?

If the west is so evil, why haven't we attacked with full force to decimate these groups that openly threaten us? Have you ever stopped to think that we could.
I´m not talking centuries ago, I´m talking just last decades, or the very last year.
Just a small example, remember that "who shelters a terrorist" thing by Bush...?
The rest of what you write is just a sample of the level of effect of mental enemas, of extreme hypocrisy, egocentricity, hegemony, already carrying it in the blood. I think you should see the annual reports of trends and opinions worldwide. 3/4 of the planet will have some reason to have the opinions they do. And right now they are being given more reasons.
That "west" have been attacking directly or indirectly a good part of the planet, even more the last three decades.
But whatever, your opinion matters little to me, as little as mine will matter to you.
You can eat your liver all you want, it won't change the fact
 
Last edited:
I´m not talking centuries ago, I´m talking just last decades, or the very last year.
Just a small example, remember that "who shelters a terrorist" thing...
The rest of what you write is just a sample of the level of effect of mental enemas, of extreme hypocrisy, egocentricity, hegemony, already carrying it in the blood. I think you should see the annual reports of trends and opinions worldwide. 3/4 of the planet will have some reason to have the opinions they do. And right now they are being given more reasons.
That "west" have been attacking directly or indirectly a good part of the planet, even more the last three decades.
But whatever, your opinion matters little to me, as little as mine will matter to you.
You can eat your liver all you want, it won't change the fact
You have no arguments beyond generic posts and analogies like "If I stole, I can justify it by pointing to the thief who robbed me 50 years ago", there is not a single line in this post that nullifies what I said, because the truth cannot be countered with juggling words.

Terrorism cannot be justified, there is no valid opinion that supports these groups, if you support these people it is good to be at least outside of Western countries and their allies. I don't give a crap what people think, if it's 20% or 90%, whatever, wrong will continue to be wrong. Right will continue to be right.

China will continue to support the largest terrorist groups in the history of humanity and their pet dictatorships. They must be laughing to see that there are still those who defend it.
 
You have no arguments beyond generic posts and analogies like "If I stole, I can justify it by pointing to the thief who robbed me 50 years ago", there is not a single line in this post that nullifies what I said, because the truth cannot be countered with juggling words.

Terrorism cannot be justified, there is no valid opinion that supports these groups, if you support these people it is good to be at least outside of Western countries and their allies. I don't give a crap what people think, if it's 20% or 90%, whatever, wrong will continue to be wrong. Right will continue to be right.

China will continue to support the largest terrorist groups in the history of humanity and their pet dictatorships. They must be laughing to see that there are still those who defend it.
...and this answer is one more example of being blinded...[shrug] ... well... bye
 
Apple and China are now best friends. What do you expect?

For all you hardcore Apple fans, your "Apples" are now made in China.

And thanks to the West's outsource to Asia for "cheap producing costs but still sell as though as it is made in the US of A" policy, China has now learnt the tech used by these western companies, and let know their compatriots to produce even better products, by copying the same tech.

So, yeah, now the Huawei is actually on par or even better value than iBones.

Too bad, the US of A banned Huawei, because these are the same or better products than Apple stuff. Or maybe, that's what the US government was paid by the Tim Cook's gang to maintain that status.

**Just bought the large popcorn pack from an "Asian" cinema franchise, to read all the flames expected soon** --chomp-chomp--
 
Last edited:
You have no arguments beyond generic posts and analogies like "If I stole, I can justify it by pointing to the thief who robbed me 50 years ago", there is not a single line in this post that nullifies what I said, because the truth cannot be countered with juggling words.

Terrorism cannot be justified, there is no valid opinion that supports these groups, if you support these people it is good to be at least outside of Western countries and their allies. I don't give a crap what people think, if it's 20% or 90%, whatever, wrong will continue to be wrong. Right will continue to be right.

China will continue to support the largest terrorist groups in the history of humanity and their pet dictatorships. They must be laughing to see that there are still those who defend it.
Well, luckily China is falling apart and their military sucks. The People's Liberation Army isn't actually part of the CCP and it's gotten to the point where ranking members of the PLA have been stealing so much money that they're finding water replacing fuel in missiles.

On another note, I used to criticize Isreal but Palestine lost all of my sympathy when 1200 people, almost all civilians, were killed.

But the middle east has been like this since before the United States was even a country. Frankly, most of this started in the 600AD before Europe even looks close to what it does now but nobody knows that since our education system sucks now. Even if it didn't, I don't think anyone would even care anyway.
 
Umm... None of them? I'm pretty sure I don't want my data to be in hand of CPP, or 5 eyes, 9 eyes, 14 eyes, or whatever that will most likely use it to monitor me.
First word in my reply was "True" was it not? Again, the topic is China getting your data...
 
Back