Beware of Apple device spoofing and password trickery with this $70 device

A security researcher at Def Con used a custom-made device consisting of a Raspberry Pi Zero 2 W, two antennas, a Linux-compatible Bluetooth adapter, and a portable battery to spoof an Apple device and trigger pop-up messages on nearby iPhones, prompting users to connect their Apple ID or share a password with a nearby Apple TV. The researcher aimed to raise awareness about the need to turn off Bluetooth in the iPhone settings rather than using the quick-access Control Center. While the contraption did not collect any data, it could potentially trick users into transferring their passwords. Apple's Bluetooth low energy protocol has known flaws that leak device and behavioral data to nearby listeners, but the researcher believes Apple won't address these issues as they may be intentional for the seamless functioning of watches and headphones.
- This $70 device can spoof an Apple device and trick you into sharing your password TechCrunch
- If the choice is Fort Knox security or AirPods, I know which one I'm choosing 9to5Mac
- Stop using Control Center on your iPhone to disable Bluetooth and Wi-Fi — here's why Tom's Guide
- Don't use Control Center to turn off Bluetooth on iPhone Android Authority
- A cheap Bluetooth transmitter can spoof some iPhone notifications AppleInsider
Reading Insights
0
9
3 min
vs 4 min read
80%
689 → 136 words
Want the full story? Read the original article
Read on TechCrunch