Affiliation:
1. Univ Lyon , INSA Lyon, Inria, CITI, F- 69621 Villeurbanne, France
2. Univ Lyon , INSA Lyon , Inria, CITI, F- 69621 Villeurbanne, France
Abstract
Abstract
Apple Continuity protocols are the underlying network component of Apple Continuity services which allow seamless nearby applications such as activity and file transfer, device pairing and sharing a network connection. Those protocols rely on Bluetooth Low Energy (BLE) to exchange information between devices: Apple Continuity messages are embedded in the pay-load of BLE advertisement packets that are periodically broadcasted by devices. Recently, Martin et al. identified [1] a number of privacy issues associated with Apple Continuity protocols; we show that this was just the tip of the iceberg and that Apple Continuity protocols leak a wide range of personal information.
In this work, we present a thorough reverse engineering of Apple Continuity protocols that we use to uncover a collection of privacy leaks. We introduce new artifacts, including identifiers, counters and battery levels, that can be used for passive tracking, and describe a novel active tracking attack based on Handoff messages. Beyond tracking issues, we shed light on severe privacy flaws. First, in addition to the trivial exposure of device characteristics and status, we found that HomeKit accessories betray human activities in a smarthome. Then, we demonstrate that AirDrop and Nearby Action protocols can be leveraged by passive observers to recover e-mail addresses and phone numbers of users. Finally, we exploit passive observations on the advertising traffic to infer Siri voice commands of a user.
Reference51 articles.
1. [1] Jeremy Martin, Douglas Alpuche, Kristina Bodeman, Lamont Brown, Ellis Fenske, Lucas Foppe, Travis Mayberry, Erik Rye, Brandon Sipes, and Sam Teplov. Handoff All Your Privacy – A Review of Apple’s Bluetooth Low Energy Continuity Protocol. Proceedings on Privacy Enhancing Technologies, 2019(4):34–53, 2019.
2. [2] Google. Nearby. URL https://developers.google.com/nearby/. Accessed: 2019-05-25.
3. [3] Microsoft. Microsoft Connected Devices Platform Protocol Version 3. 2019. URL https://docs.microsoft.com/enus/openspecs/windows_protocols/ms-cdp/f5a15c56-ac3a-48f9-8c51-07b2eadbe9b4. Accessed: 2019-05-25.
4. [4] Apple. All your devices. One seamless experience.. URL https://www.apple.com/macos/continuity/. Accessed: 2019-05-25.
5. [5] Apple. MFi Program.. URL https://developer.apple.com/programs/mfi/. Accessed: 2019-05-25.
Cited by
18 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献