Apple's AirDrop is Mika Muroi Archivesundeniably convenient for sending photos, videos, links, and more between iPhones, iPads, and Macs. But there's one thing you probably didn't know AirDrop's sharing: part of your phone number, which in the wrong hands, could be used to recover your full digits.
Security researchers at Hexway (via Ars Technica) have discovered a "flaw" in AirDrop that can used to obtain unsuspecting iPhone users' phone numbers using software installed on a laptop and a Bluetooth and WiFi adapter to sniff them out.
Because of the way AirDrop works — it uses Bluetooth LE (Low Energy) to create a peer-to-peer WiFi network between devices for sharing — it broadcasts partial hashesof an iPhone user's phone number in order establish the device as a sending/receiving contact when sending a file.
SEE ALSO: 9 hidden iOS 13 features you need to know aboutMore serious is if you use Apple's WiFi password sharing feature, you're exposing hashed parts of your phone number, but also your Apple ID and email address.
Now, although AirDrop's only beaming partial hashes – a.k.a. some numbers and letters that have been scrambled (Hexway says only the "first 3 bytes of the hashes" are broadcast) — the researchers concluded that there's "enough to identify your phone number" if somebody really wanted to do it.
The researchers shared one scenario in which a hacker could secretly sniff out iPhone users' phone numbers:
- Create a database of SHA256(phone_number):phone_number for their region; e.g., for Los Angeles it’s: (+1-213-xxx-xxxx, +1-310-xxx-xxxx, +1-323-xxx-xxxx, +1-424-xxx-xxxx, +1-562-xxx-xxxx, +1-626-xxx-xxxx, +1-747-xxx-xxxx, +1-818-xxx-xxxx, +1-818-xxx-xxxx)
- Run a special script on the laptop and take a subway train
- When somebody attempts to use AirDrop, get the sender’s phone number hash
- Recover the phone number from the hash
- Contact the user in iMessage; the name can be obtained using TrueCaller or from the device name, as it often contains a name, e.g., John’s iPhone).
Errata Security CEO Rob Graham confirmed to Ars Technica Hexway's software, shared to GitHub, does indeed work. "It’s not too bad, but it’s still kind of creepy that people can get the status information, and getting the phone number is bad."
Scary as this "flaw" appears, it's very unlikely anyone will go through these lengths to recover your phone number. Hexway's researchers even admit that the partially-shared — and we can't stress this enough — information is a necessity to how AirDrop works.
"This behavior is more a feature of the work of the ecosystem than vulnerability," reports Hexway. The researchers further explained that they've "detected this behavior in the iOS versions starting from 10.3.1 (including iOS 13 beta)."
Scary as this "flaw" appears, it's very unlikely anyone will go through these lengths to recover your phone number.
Older iPhones, pre-iPhone 6S, however, appear to be safe based on their findings.
"Old devices (like all before iPhone 6s) are not sending Bluetooth LE messages continuously even if they have updated OS version," reports Hexway. "They send only limited number of messages (for example when you navigate to the Wi-Fi settings menu) probably Apple does that to save battery power on an old devices."
So, how can you stop potential snoopers from sniffing your Bluetooth information out? Turn off Bluetooth. Yes, that means you won't be able to connect AirPods or an Apple Watch to your iPhone, but if that's what will help you sleep at night, then it's the only option.
We've reached out to Apple for comment on Hexway's security findings and will update this story if we receive a response.
Topics Apple Cybersecurity iPhone Privacy
Disney's 'Mulan' gets a liveAmazon launches Inspire as it looks to become a major player in education techRobots ruin the fun of 'Where's Waldo?' with facial recognition: WatchDozens of Las Vegas slots suddenly failed during a hacker conventionDisney's 'Mulan' gets a liveApple's Group FaceTime won't arrive with iOS 12 and macOS MojaveSupreme Court strikes down controversial Texas abortion lawsWoman finds parents' old love letters and reduces the internet to tearsTwitter suspends Proud Boys and Gavin McInnes before Unite the RightYou'll tolerate being annoyed by this gloriously cute toy instrumentColin Kaepernick and Donald Trump weigh in as NFL anthem protests continue in preseasonLena Dunham sticks up for Taylor Swift after Kanye West's 'Famous' videoHere's a bracket game to determine the best fictional boyfriendsPresident Trump signs NDAA, banning government use of ZTE and Huawei technologyThis 'Game of Thrones' theory about Tyrion just got some compelling new evidenceFirst photos of Kiernan Shipka as Sabrina the teenage witch: PhotosDisney's 'Mulan' gets a liveSoccer player scores brilliantly odd goal, follows it up with an even better tweetWhat to know about NASA's Parker Solar Probe mission to the sunHere's what more than 400 electric guitars trying to break a world record sounds like 13 blunt and sweary Christmas cards for your greatest frenemy 8 Thanksgiving comedy episodes you need to rewatch this holiday Tamagotchis are making a comeback to your smartphone in 2018 Gawker killer Peter Thiel may try to buy what's left of Gawker Sneaking treats into the movies? Here's a clever trick This 'Game of Thrones' casting news could hint at a Season 8 storyline Here's how to contact your reps in support of net neutrality Christmas at the Wizarding World of Harry Potter is fittingly magical A roasted turkey's NYC travel diary Apple will launch a new iPhone SE in 2018, report says With little else to rely on, refugees turn to Twitter to detail harsh treatment 'Old Man's Journey' is a touching game about family and forgiveness History of gaming's most pervasive meme: Skyrim's 'arrow in the knee' J.K. Rowling shuts down article calling Meghan Markle 'unsuitable' with 1 hashtag Koch brothers help Meredith buy Time magazine Bitcoin hits record high, breaks $9,000 over Thanksgiving weekend Samsung allegedly plans to unveil new Galaxy S smartphones at CES 'House of Cards' production hiatus draws on in Spacey aftermath Pakistan reportedly blocks Twitter, Facebook, and YouTube amid protest crackdowns Someone help Chrissy Teigen get her lost Nintendo Switch back
1.67s , 10130.015625 kb
Copyright © 2025 Powered by 【Mika Muroi Archives】,Information Information Network