Apple’s ‘Find My’ Network Exploited via Bluetooth
#1
Information 
Quote:Apple’s “Find My device” function for helping people track their iOS and macOS devices can be exploited to transfer data to and from random passing devices without using the internet, a security researcher has demonstrated.
 
Security researcher Fabian Bräunlein with Positive Security developed a proof of concept, using a microcontroller and a custom MacOS app, that can broadcast data from one device to another via Bluetooth Low Energy (BLE). Once connected to the internet, the receiving device can then forward the data to an attacker-controlled Apple iCloud server.
 
Bräunlein called the method “Send My,” and posited several use cases for the method — including the benign building of a network for internet-of-things (IoT) sensors, or as way to deplete people’s mobile-data plans over time.
 
The misuse of Find My in this way seems nearly impossible for Apple to prevent, he said, given that the capability is “inherent to the privacy and security-focused design of the Find My offline finding system,” Bräunlein observed.
Quote:Full technical details are available in the researcher’s blog post, published this week.

Read more: Apple’s 'Find My' Network Exploited via Bluetooth | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.0.5 / 19.0.7 Update
Changes in 19.0.7 ...harlan4096 — 05:52
AnyDesk 9.5.8 for Windows
AnyDesk 9.5.8 for ...harlan4096 — 05:50
Notepad++ v8.8.3
Notepad++ v8.8.3 s...harlan4096 — 05:49
Intel releases new Arc PRO graphics driv...
Intel’s new GPU dr...harlan4096 — 05:48
Microsoft caused and fixed a WSUS Synchr...
Reports about prob...harlan4096 — 05:47

[-]
Birthdays
Today's Birthdays
avatar (49)WillieVot
Upcoming Birthdays
avatar (45)RidgeDimb
avatar (36)ipumaqar
avatar (50)tanliorsPeri
avatar (42)lapedDow
avatar (48)rituabew
avatar (36)omyjul
avatar (40)papedDow
avatar (49)ArnoldFum
avatar (37)yfaza
avatar (48)Kevensi
avatar (38)boineDon
avatar (39)Grompelbawn
avatar (40)vkseogaF
avatar (36)usogy
avatar (39)ywixazok
avatar (37)ixoqe
avatar (35)pa.OpenTran

[-]
Online Staff
There are no staff members currently online.

>