news.volyx.in

Turning a Bluetooth device into an Apple AirTag without root privileges (nroottag.github.io)

505 points by layer8 · 522 days ago · 81 comments on HN

Article summary

Researchers have discovered a vulnerability in Apple's Find My network that allows an attacker to turn a Bluetooth device into an AirTag-like tracker without root privileges, enabling location tracking. The attack, called nRootTag, exploits a flaw in the Find My network's use of Bluetooth Low Energy signals. The vulnerability can be used to track devices with Bluetooth capabilities, including laptops, smartphones, and smartwatches. Apple has released patches to fix the vulnerability, but it remains effective as long as there are unpatched iPhones or Apple Watches near the tracked device.

Main themes

  • Bluetooth security
  • Location tracking
  • Apple Find My network
  • Vulnerability exploitation
  • Device tracking
  • Privacy concerns

What commenters say

  • The attack is possible because Apple's Find My network does not validate the public key being broadcast, allowing an attacker to craft a valid FindMy beacon without needing root access to the device.
  • The vulnerability can be exploited by generating a database of public/private key pairs, which can be used to track devices with Bluetooth capabilities.
  • Some commenters argue that the attack is not a significant concern because it requires the device to be compromised with malware, which is a more significant security issue than the tracking vulnerability itself.
  • Others believe that the exploit could be used by advertising SDKs to geolocate users without additional permissions, potentially leading to privacy concerns.
  • The patch released by Apple only fixes the issue for iOS devices, but the attack remains effective as long as there are unpatched iPhones or Apple Watches near the tracked device.
  • Some commenters think that the attack is not a major issue because it can be mitigated by keeping devices updated with the latest security patches and being cautious when installing apps.
  • The exploit highlights the potential risks of using Bluetooth Low Energy signals for location tracking and the need for improved security measures to protect user privacy.
  • The attack's effectiveness is limited by the need for the device to be in range of an iPhone or Apple Watch, which reduces its potential impact.