Beware of Apple device spoofing and password trickery with this $70 device

1 min read
Source: TechCrunch
Beware of Apple device spoofing and password trickery with this $70 device
Photo: TechCrunch
TL;DR Summary

A security researcher at Def Con used a custom-made device consisting of a Raspberry Pi Zero 2 W, two antennas, a Linux-compatible Bluetooth adapter, and a portable battery to spoof an Apple device and trigger pop-up messages on nearby iPhones, prompting users to connect their Apple ID or share a password with a nearby Apple TV. The researcher aimed to raise awareness about the need to turn off Bluetooth in the iPhone settings rather than using the quick-access Control Center. While the contraption did not collect any data, it could potentially trick users into transferring their passwords. Apple's Bluetooth low energy protocol has known flaws that leak device and behavioral data to nearby listeners, but the researcher believes Apple won't address these issues as they may be intentional for the seamless functioning of watches and headphones.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

3 min

vs 4 min read

Condensed

80%

689136 words

Want the full story? Read the original article

Read on TechCrunch