Hacker News new | ask | show | jobs
by RIMR 2565 days ago
Okay, so this would make it insanely easy to stalk any iPhone user.

1. Get BLE tracking tags, and register them with Find My.

2. Covertly attach the BLE tracking tags to things your target owns (backpacks, cars, bikes, etc).

3. You constantly get updates on your tags locations via their iPhone and other iOS devices near the BLE tag(s). This gives you their approximate location and movement history, facilitated primarily through their own iPhone and data plan.

4 comments

The only "BLE tracking tags" reported to use Find My are Apple devices, and if you can attach an Apple device to something your target owns, there are many means you can use other than Find My to track them.

I mean, if you can accomplish step 2, you don't need Apple at all.

They are widely expected to introduce such tags later this year.
Wouldn't this be already possible (and a lot cheaper) using something like Tile?
Yes, except you'd need to get your target to install the Tile app and use it frequently enough that it keeps background location privs.

If Apple does come out with a cheap Tile-type device with a then this could be a legit concern. If you hid one in a person's belongings then you'd get hits from their phone- and turning it off wouldn't work, because random passersby would report their location as well.

This could even be better (worse) than spy-gear standalone GPS trackers because the battery would last for a very long time.

What I understood the parent to mean would be to buy and register a Tile yourself, then hide that on your victim.

Using the same type of "mesh network" Apple mentioned, other users you can track that Tile for you: https://youtu.be/WG7BdW7iFzo?t=58

(I'm not familiar enough with Tile to know if that feature is continuous, but I wouldn't be surprised if a competitor does).

<ahem> It must already be reasonably well along in development for it to be showing up in iOS builds.

[0] https://www.macrumors.com/2019/06/04/apple-tile-item-tracker...

One of the fundamental rules of security is that if your adversary has physical access, it's over. This sounds like that but with extra steps. If somebody has access to your equipment and am able to attach arbitrary items to your bag, then it could be any tracker (Tile, cheap GPS tracker, iPhone, etc.), then of course it's over from a security perspective.
I have no idea how the FindMy BLE system works, but i strongly suspect that the cheaperst compatible "tag" you will find will be an iPhone. Might get a tad expensive to do this...
Assuming the newest ipod touches will work with this, $200 is the cheapest you could do this with in terms of using an iOS device (not that i'm suggesting this is a great option. As pointed out by the other second-level comments, you could just use tile or a real gps tracker without needing iOS).
The potential of low cost tags is in the first paragraph, and an overview of how the system would work is in the second. My takeaway is that you will be able to use something far cheaper than an iPhone.
Cheap ble tags do NOT use fancy rotated private keys or anything of the like. At best they use BLE privacy mode. That is as private as the spec gets.

Source: worked on Bluetooth for years