LIVE · cybersecurity feed
Live wire
security

Researcher tricks Apple’s Find My into sharing location data with Linux

Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget

zeroday.news ·

A security researcher has successfully enrolled a Linux device into Apple's Find My network, enabling it to receive live location data from individuals who had previously shared their location with the associated Apple account. This development allows a non-Apple device to access a feature typically restricted to Apple hardware.

The researcher, known as "Zerotistic," is 22 years old and spent less than a week developing the technique. It is important to note that this method does not allow arbitrary retrieval of any Apple user's location; rather, it facilitates the reception of location data from users who have already consented to share their whereabouts with the owner of the Apple account linked to the Linux device.

The process involved several intricate steps to convince Apple's systems that the Linux machine was a legitimate device capable of receiving location data via Apple's Push Notification service (APNs). First, Zerotistic obtained an identity delegate through Apple's standard GrandSlam authentication protocol. This delegate was then used to craft a custom certificate signing request (CSR) in the PKCS#10 format, utilizing a 2048-bit RSA key signed with SHA-1. This CSR was then sent to Apple's `authenticateDS` profile-enrollment endpoint, which the researcher speculates is a legacy endpoint due to its requirement for older cryptographic standards and XML encoding.

Upon Apple signing the CSR, the Linux device received an Apple Identity Services (IDS) device certificate, linking it to the researcher's Apple account. However, further steps were necessary to enable Find My functionality. The researcher discovered that a Find My registration request required the device to subscribe to six specific subservices, declare its supported encryption types, and provide public keys for Apple's device-to-device messaging format. This request also needed to be signed using both the IDS certificate and an APNs certificate obtained during the initial network setup.

Once these conditions were met, the Linux machine was enrolled and capable of receiving location data via a persistent binary TLS connection to Apple's private APNs servers. Unlike a new Apple device, this registration did not automatically retrieve existing shared location data. To address this, Zerotistic issued a `SubscribeAndFetch` request, which prompted the friend's device to push an encrypted location key to the newly registered Linux device.

The final challenge was decrypting and interpreting the location data received from Apple's SearchParty service. This required a custom Linux script to unwrap Apple's messaging envelope, extract the shared location key, and decrypt the Find My location data, which includes coordinates, timestamps, and accuracy information. Once developed, the script could continuously fetch and decode subsequent location reports for the established location share.

Apple has not yet responded to inquiries regarding this research or any potential plans to address the implications of a non-Apple device accessing this functionality.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.