• hemmes@lemmy.world
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    1
    ·
    1 year ago

    This is another example of very specific situations in INFOSEC. It’s unlikely that you will become a victim to this key logger attack. And of course the title suggests that Apple’s Find My network is compromised. This is not the case. But it is being utilized, in this instance, against Apple’s rules and regulations.

    The real hack here is that the victim had their keyboard modified or was given a compromised keyboard that broadcasts Bluetooth signals, that are then picked up on the Find My network. It could be transmitted via Cellular, Bluetooth, WiFi, audible sound, monitoring energy differentials, etc. It’s the HMI hardware that’s been compromised. Apple will likely develop updates to their Find My network, but the compromised keyboard could then be modified to use some other service or broadcast methods. Apple fixing the Find My network to recognize bad actors will not prevent this style of attack.

    • shrugal@lemm.ee
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      1 year ago

      I think the main concern is how easy and ubiquitous it is, while also being pretty hard to detect. No other transmission method lends itself so perfectly to this kind of attack.

      And I wouldn’t say it’s that unlikely. Every publicly accessible keyboard could be targeted, like in schools or universities. Buy an identical model to those that are used in the computer room, modify it, switch it out, and wait for people to enter their emails and passwords.

      • hemmes@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        edit-2
        1 year ago

        The potential to abuse Find My to transmit arbitrary data besides just device location was first discovered by Positive Security researchers Fabian Bräunlein and his team over two years ago, but apparently, Apple addressed this problem.

        Not with Apple’s network anymore apparently. But if you read the original PoC from 2021 they said Amazon’s Echo devices have the same potential.

        Ultimately, even the researchers have indicated the slow and unreliable nature of the attack (which now no longer works).

        Small complication: public key validity. Having implemented both the sending and receiving side, I performed a first test by broadcasting and trying to receive a 32 bit value. After a few minutes, I could retrieve 23 out of the 32 bits, each one being unambiguous and with ~100 location reports, but no reports for the remaining 9 bits.

        • shrugal@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          1 year ago

          I just watched a video by a German tech magazine the other day, with Fabian Bräunlein (the original researcher) demonstrating a keylogger using the Find My network. It’s only 3 days old, so I don’t think the main problem is fixed at all.

  • deegeese@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 year ago

    It’s really “Find My Phone” can be used as a sort of ubiquitous low bandwidth whisper network for sending back secrets from hidden devices.

    • ndru@lemmy.world
      link
      fedilink
      English
      arrow-up
      37
      arrow-down
      1
      ·
      edit-2
      1 year ago

      Any platform has vulnerability to exploit to some degree. But this article is about piggybacking on the Find My network to transmit data without actually compromising the network. It’s a clever technique, and worth reading more than the headline.

      • dave@feddit.uk
        link
        fedilink
        English
        arrow-up
        13
        ·
        1 year ago

        It’s very interesting but the article is a rehash of some 2-year-old work by others, and doesn’t really update anything, apart from saying that “apparently, Apple addressed this problem.” with no further clarification. Pretty low effort tbh.

    • ExLisper@linux.community
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      1 year ago

      It’s not malware. They are talking abot physical keyloagger inserted into your keyboard. Real life hack possibility level: 0

    • cynar@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      1 year ago

      It’s not apple being hacked here. The network is just being abused to carry data out. It requires a compromised hardware device e.g. a hacked keyboard. You don’t even need to be using an apple device, it just piggybacks off of any nearby iPhones.