Not everything Apple makes "just works" — at least not as intended,Watch Online Crush Movie (2010) anyway.
Security researchers exploring AirDrop, the iOS and macOS feature that lets users wirelessly share files via WiFi and Bluetooth, reported Wednesday on a flaw they say exposes users' emails and phone numbers. Unless you want every creep on the street to be able to secretly grab your contact info, it's a bit of a nightmare.
The researchers, a team made up of members of the Secure Mobile Networking Lab (SEEMOO)and the Cryptography and Privacy Engineering Group (ENCRYPTO), claim they alerted Apple to the flaw in May of 2019. However, according to them, the company never responded.
"As an attacker, it is possible to learn the phone numbers and email addresses of AirDrop users – even as a complete stranger," reads Tuesday's press release. "All they require is a Wi-Fi-capable device and physical proximity to a target that initiates the discovery process by opening the sharing pane on an iOS or macOS device."
We reached out to Apple to confirm the findings and to ask if indeed it was alerted to the vulnerability in 2019. We received no immediate response.
Notably, this is not the first questionable privacy situation tied to AirDrop. In 2019, researchers discovered that they were able to determine users' phone numbers based on the partial hashes AirDrop sends out. It's not clear if that concern was ever addressed by Apple, especially as the vulnerability disclosed this week appears similar in nature.
"The discovered problems are rooted in Apple's use of hash functions for 'obfuscating' the exchanged phone numbers and email addresses during the [AirDrop] discovery process," explains Tuesday's press release. "However, researchers from TU Darmstadt already showed that hashing fails to provide privacy-preserving contact discovery as so-called hash values can be quickly reversed using simple techniques such as brute-force attacks."
AirDrop is also notorious for its association with digital harassment. Specifically, harassers used the feature for cyber-flashing — wherein a stranger bombards a victim's phone with unwanted photos of a sexual or graphic nature — and sending images associated with white supremacists to people just going about their own business in public.
This Tweet is currently unavailable. It might be loading or has been removed.
This Tweet is currently unavailable. It might be loading or has been removed.
Of course, you don't have to deal with any of this.
If you'd rather avoid having your iPhone expose your contact info to creeps and protect yourself from cyber-flashers, you can turn AirDrop off (and disable Bluetooth while you're at it).
SEE ALSO: Apple knows AirTags can be abused and is trying to get ahead of it
It's not a permanent thing — you can always briefly turn AirDrop back on if you need it for some reason — but disabling the feature will provide you with some peace of mind, and hey, that "just works."
Topics Apple Cybersecurity Privacy
Mark Zuckerberg responds to Charlottesville, criticizes neoDid Sam Tarly just become one of the most powerful men on 'Game of Thrones'?How tech can stand up to racism and bigotryWe finally have a shipping date for Andy Rubin's Essential phoneTexts between Uber's Travis Kalanick and Anthony Levandowski are juicy'Game of Thrones' fan has an epic theory about what's in store for BronnThe HBO hackers just hit us with the biggest dump yet10,000 impounded bikes look like abstract artChinese state media just released a terribly racist video mocking IndiansCharlottesville comes together for a candlelight vigil'Mission: Impossible 6' shoot paused while Tom Cruise recoversBiggest theater chain to $9.99Android phones could copy the iPhone 8's biggest expected featureBusiness media startup Cheddar adds radio to its growing TV operationBehold, the LG V30 in all its gloryNielsen is bringing its data and analysis expertise to esportsInstagram just added nested comment threads to postsNielsen is bringing its data and analysis expertise to esportsFancy smart locks marketed to Airbnb hosts permanently broken by software updateInstagram just added nested comment threads to posts July was one of Earth's warmest months in 137 years, NASA finds Nokia wants you to be less selfie and more 'bothie' with its new flagship phone Uber's never Gang steals 20 tonnes of Nutella and other chocolate goodies White nationalists are flocking to genetic ancestry tests. Some don’t like what they find. Why Apple's not going to sell an OLED TV 7 best burns from Martin Shkreli's jury selection process Guess who's back: Daniel Craig confirms return as James Bond The internet gives film titles totally British makeovers and it's absolutely brilliant Fancy smart locks marketed to Airbnb hosts permanently broken by software update Do you watch movies? MoviePass's new deal is unreal and you should sign up today Business media startup Cheddar adds radio to its growing TV operation Ron Howard's Han Solo movie might feature the Death Star Anderson Cooper breaks down exactly why Trump's press conference should bother you Mic is laying off staff and pivoting to video, a move all too familiar in digital media 'The Defenders' review roundup: It's good, give or take an Iron Fist 'Overwatch' deathmatch was a mistake Behold, the LG V30 in all its glory 'Game of Thrones' fan shares impressively detailed theory about Jaime and Cersei Google protests called off after organizers blame Trump's newest scapegoat
2.9386s , 8224.796875 kb
Copyright © 2025 Powered by 【Watch Online Crush Movie (2010)】,Charm Information Network