Comment on Apple 'Find My' network can be abused to steal keylogged passwords

<- View Parent
hemmes@lemmy.world ⁨10⁩ ⁨months⁩ ago

The potential to abuse Find My to transmit arbitrary data besides just device location was first discovered by Positive Security researchers Fabian Bräunlein and his team over two years ago, but apparently, Apple addressed this problem.

Not with Apple’s network anymore apparently. But if you read the original PoC from 2021 they said Amazon’s Echo devices have the same potential.

Ultimately even the researches indicate the slow and unreliable nature of the attack (which no longer works).

Small complication: public key validity. Having implemented both the sending and receiving side, I performed a first test by broadcasting and trying to receive a 32 bit value. After a few minutes, I could retrieve 23 out of the 32 bits, each one being unambiguous and with ~100 location reports, but no reports for the remaining 9 bits.

source
Sort:hotnewtop