USENIX Security2019Top-tier venue
A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link
Milan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich, David Kreitschmann, Guevara Noubir, Matthias Hollick
Abstract
Apple Wireless Direct Link (AWDL) is a key protocol in Apple's ecosystem used by over one billion iOS and macOS devices for device-to-device communications. AWDL is a proprietary extension of the IEEE 802.11 (Wi-Fi) standard and integrates with Bluetooth Low Energy (BLE) for providing services such as Apple AirDrop. We conduct the first security and privacy analysis of AWDL and its integration with BLE. We uncover several security and privacy vulnerabilities ranging from design flaws to implementation bugs leading to a man-in-the-middle (MitM) attack enabling stealthy modification of files transmitted via AirDrop, denial-of-service (DoS) attacks preventing communication, privacy leaks that enable user identification and long-term tracking undermining MAC address randomization, and DoS attacks enabling targeted or simultaneous crashing of all neighboring devices. The flaws span across AirDrop's BLE discovery mechanism, AWDL synchronization, UI design, and Wi-Fi driver implementation. Our analysis is based on a combination of reverse engineering of protocols and code supported by analyzing patents. We provide proof-of-concept implementations and demonstrate that the attacks can be mounted using a low-cost ($20) micro:bit device and an off-the-shelf Wi-Fi card. We propose practical and effective countermeasures. While Apple was able to issue a fix for a DoS attack vulnerability after our responsible disclosure, the other security and privacy vulnerabilities require the redesign of some of their services.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 132052eb-c644-44a6-aae3-cc6304daeaadCited by top-tier papers17
- PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDropAlexander Heinrich, Matthias Hollick, Thomas Schneider, Milan Stute et al.USENIX Security 2021 · 32 citations
- Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-FiMilan Stute, Alexander Heinrich, Jannik Lorenz, Matthias HollickUSENIX Security 2021 · 31 citations
- Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege EscalationJiska Classen, Francesco Gringoli, Michael Hermann, Matthias HollickS&P 2022 · 16 citations
- When Good Becomes Evil: Tracking Bluetooth Low Energy Devices via Allowlist-based Side Channel and Its CountermeasureYue Zhang, Zhiqiang LinCCS 2022 · 12 citations
- Linking Bluetooth LE & Classic and Implications for Privacy-Preserving Bluetooth-Based ProtocolsNorbert Ludant, Tien Dang Vo-Huu, Sashank Narain, Guevara NoubirS&P 2021 · 11 citations
Builds on8
- Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2Mathy Vanhoef, Frank PiessensCCS 2017 · 437 citations
- Synthesizing Plausible Privacy-Preserving Location TracesVincent Bindschaedler, Reza ShokriS&P 2016 · 193 citations
- Inferring User Routes and Locations Using Zero-Permission Mobile SensorsSashank Narain, Triet D. Vo-Huu, Kenneth Block, Guevara NoubirS&P 2016 · 149 citations
- Tracking Mobile Web Users Through Motion Sensors: Attacks and DefensesAnupam Das, Nikita Borisov, Matthew CaesarNDSS 2016 · 145 citations
- Protecting Privacy of BLE Device UsersKassem Fawaz, Kyu-Han Kim, Kang G. ShinUSENIX Security 2016 · 111 citations
Related papers
- Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConfXiaolong Bai, Luyi Xing, Nan Zhang, XiaoFeng Wang et al.S&P 2016 · 33 citations
- Surveilling the Masses with Wi-Fi-Based Positioning SystemsErik C. Rye, Dave LevinS&P 2024 · 5 citations
- Snatcher: Apple Find My Network Exposes Your Lost Devices To StrangersZhenyu Ren, Yanbo Zhang, Boya Liu, Mo LiCCS 2026
- Tracking You from a Thousand Miles Away! Turning a Bluetooth Device into an Apple AirTag Without Root PrivilegesJunming Chen, Xiaoyue Ma, Lannan Luo, Qiang ZengUSENIX Security 2025
- WCDCAnalyzer: Scalable Security Analysis of Wi-Fi Certified Device Connectivity ProtocolsZilin Shen, Imtiaz Karim, Elisa BertinoNDSS 2026
