[Resource Topic] 2021/481: PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop

Welcome to the resource topic for 2021/481

Title:
PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop

Authors: Alexander Heinrich, Matthias Hollick, Thomas Schneider, Milan Stute, Christian Weinert

Abstract:

Apple’s offline file-sharing service AirDrop is integrated into more than 1.5 billion end-user devices worldwide. We discovered two design flaws in the underlying protocol that allow attackers to learn the phone numbers and email addresses of both sender and receiver devices. As a remediation, we study the applicability of private set intersection (PSI) to mutual authentication, which is similar to contact discovery in mobile messengers. We propose a novel optimized PSI-based protocol called PrivateDrop that addresses the specific challenges of offline resource-constrained operation and integrates seamlessly into the current AirDrop protocol stack. Using our native PrivateDrop implementation for iOS and macOS, we experimentally demonstrate that PrivateDrop preserves AirDrop’s exemplary user experience with an authentication delay well below one second. We responsibly disclosed our findings to Apple and open-sourced our PrivateDrop implementation.

ePrint: https://eprint.iacr.org/2021/481

See all topics related to this paper.

Feel free to post resources that are related to this paper below.

Example resources include: implementations, explanation materials, talks, slides, links to previous discussions on other websites.

For more information, see the rules for Resource Topics .