Alexander Heinrich

dblp:248/1693 · DBLP profile ↗
← Back
14ranked-venue papers
6as first author
13since 2021 · last 2025
0000-0002-1150-1922ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 6 first-author · 12 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Starshields for iOS: Navigating the Security Cosmos in Satellite Communication
Jiska Classen, Alexander Heinrich, Fabian Portner, Felix Rohrbach, Matthias Hollick
NDSS2
2025 WatchWitch: Interoperability, Privacy, and Autonomy for the Apple Watch
abstract
Smartwatches such as the Apple Watch collect vast amounts of intimate health and fitness data as we wear them. Users have little choice regarding how this data is processed: The Apple Watch can only be used with Apple's iPhones, using their software and their cloud services. We are the first to publicly reverse-engineer the watch's wireless protocols, which led to discovering multiple security issues in Apple's proprietary implementation. With WatchWitch, our custom Android reimplementation, we break out of Apple's walled garden-demonstrating practical interoperability with enhanced privacy controls and data autonomy. We thus pave the way for more consumer choice in the smartwatch ecosystem, offering users more control over their devices.
Nils Rollshausen, Alexander Heinrich, Matthias Hollick, Jiska Classen
Proc. Priv. Enhancing Technol.2
2024 Poster: Leveraging Apple's Find My Network for Large-Scale Distributed Sensing
abstract
Find My is a crowd-sourced network of hundreds of millions of Apple devices that use Bluetooth Low Energy (BLE) to detect and track the location of items. We explore the limits and opportunities of using this proprietary network for large-scale distributed sensing. The key idea is to let low-cost sensing devices emit specially crafted BLE advertisements that trick nearby Apple devices into generating location reports that carry arbitrary sensor data, which can then be retrieved from the Apple servers. This paper reports on our ongoing work to reverse engineer the Find My system and to design a protocol for the efficient and reliable collection of data from sensing devices via the Find My network. Preliminary results from real-world experiments demonstrate the feasibility of our approach and a several-fold performance improvement compared with the state of the art.
Max Granzow, Alexander Heinrich, Matthias Hollick, Marco Zimmerling
MobiSys2
2024 Please Unstalk Me: Understanding Stalking with Bluetooth Trackers and Democratizing Anti-Stalking Protection
abstract
While designed to locate lost items, Bluetooth trackers are increasingly exploited for malign purposes, such as unwanted location tracking. This study probes deeper into this issue, focusing on the widespread use of these devices for stalking. Following a dual approach, we analyzed user data from a widely used tracking detection app (over 200,000 active installations) and conducted a comprehensive online survey (N=5,253). Our data analysis reveals a significant prevalence of trackers from major brands such as Apple, Tile, and Samsung. The user data also shows that the app sends about 1,400 alarms daily for unwanted tracking. Survey insights reveal that 44.28% of stalking victims had been subjected to location tracking, with cars emerging as the most common hideout for misused trackers, followed by backpacks and purses. These findings underscore the urgency for more robust solutions. Despite ongoing efforts by manufacturers and researchers, the misuse of Bluetooth trackers remains a significant concern. We advocate for developing more effective tracking detection mechanisms integrated into smartphones by default and creating supportive measures for individuals without smartphone access.
Alexander Heinrich, Leon Janzen, Matthias Hollick
Proc. Priv. Enhancing Technol.1
2022 Ghost Peak: Practical Distance Reduction Attacks Against HRP UWB Ranging
Patrick Leu, Giovanni Camurati, Alexander Heinrich, Marc Röschlin, Claudio Anliker, Matthias Hollick, Srdjan Capkun, Jiska Classen
USENIX Security Symposium3
2022 OpenHaystack Mobile - Tracking Custom Find My Accessories on Smartphones
abstract
In 2021 OpenHaystack on macOS was the first step into liberating Apple's Find My technology to be integrated into any Bluetooth-capable device. By using custom firmware for microchips like the ESP32, it was possible to build custom trackable accessories similar to an Apple AirTag in size and functionality.
Lukas Burg, Max Granzow, Alexander Heinrich, Matthias Hollick
WISEC3
2022 Evil Never Sleeps: When Wireless Malware Stays On after Turning Off iPhones
abstract
When an iPhone is turned off, most wireless chips stay on. For instance, upon user-initiated shutdown, the iPhone remains locatable via the Find My network. If the battery runs low, the iPhone shuts down automatically and enters a power reserve mode. Yet, users can still access credit cards, student passes, and other items in their Wallet. We analyze how Apple implements these standalone wireless features, working while iOS is not running, and determine their security boundaries. On recent iPhones, Bluetooth, Near Field Communication (NFC), and Ultra-wideband (UWB) keep running after power off, and all three wireless chips have direct access to the secure element. As a practical example what this means to security, we demonstrate the possibility to load malware onto a Bluetooth chip that is executed while the iPhone is off.
Jiska Classen, Alexander Heinrich, Robert Reith, Matthias Hollick
WISEC2
2022 AirGuard - Protecting Android Users from Stalking Attacks by Apple Find My Devices
abstract
Finder networks in general, and Apple's Find My network in particular, can pose a grave threat to users' privacy and even health if these networks are abused for stalking. Apple's release of the AirTag-a very affordable tracker covered by the nearly ubiquitous Find My network-amplified this issue. While Apple provides a stalking detection feature within its ecosystem, billions of Android users are still left in the dark. Apple recently released the Android app "Tracker Detect," which does not deliver a convincing feature set for stalking protection. We reverse engineer Apple's tracking protection in iOS and discuss its features regarding stalking detection. We design "AirGuard" and release it as an Android app to protect against abuse by Apple tracking devices. We compare the performance of our solution with the Apple-provided one in iOS and study the use of AirGuard in the wild over multiple weeks using data contributed by tens of thousands of active users.
Alexander Heinrich, Niklas Bittner, Matthias Hollick
WISEC1
2021 PrivateDrop: Practical Privacy-Preserving Authentication for Apple AirDrop
Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert
USENIX Security Symposium1
2021 Disrupting Continuity of Apple's Wireless Ecosystem Security: New Tracking, DoS, and MitM Attacks on iOS and macOS Through Bluetooth Low Energy, AWDL, and Wi-Fi
Milan Stute, Alexander Heinrich, Jannik Lorenz, Matthias Hollick
USENIX Security Symposium2
2021 AirCollect: efficiently recovering hashed phone numbers leaked via Apple AirDrop
abstract
Apple's file-sharing service AirDrop leaks phone numbers and email addresses by exchanging vulnerable hash values of the user's own contact identifiers during the authentication handshake with nearby devices. In a paper presented at USENIX Security'21, we theoretically describe two attacks to exploit these vulnerabilities and propose "PrivateDrop" as a privacy-preserving drop-in replacement for Apple's AirDrop protocol based on private set intersection.
Alexander Heinrich, Matthias Hollick, Thomas Schneider 0003, Milan Stute, Christian Weinert
WISEC1
2021 OpenHaystack: a framework for tracking personal bluetooth devices via Apple's massive find my network
abstract
OpenHaystack is an open-source framework for locating personal Bluetooth devices using Apple's Find My Network. A user can integrate it into Bluetooth-capable devices, such as notebooks, or create custom tracking accessories that can be attached to personal items (key rings, backpacks, etc.). We provide firmware images for the Nordic nRF5 chips and the ESP32. We show that they consume little energy and run from a single coin cell for a year. Our macOS application can locate personal accessories. Finally, we make both application and firmware available on GitHub.
Alexander Heinrich, Milan Stute, Matthias Hollick
WISEC1
2021 Who Can Find My Devices? Security and Privacy of Apple's Crowd-Sourced Bluetooth Location Tracking System
abstract
Abstract Overnight, Apple has turned its hundreds-of-million-device ecosystem into the world’s largest crowd-sourced location tracking network called o~ine finding (OF). OF leverages online finder devices to detect the presence of missing o~ine devices using Bluetooth and report an approximate location back to the owner via the Internet. While OF is not the first system of its kind, it is the first to commit to strong privacy goals. In particular, OF aims to ensure finder anonymity, prevent tracking of owner devices, and confidentiality of location reports. This paper presents the first comprehensive security and privacy analysis of OF. To this end, we recover the specifications of the closed-source OF protocols by means of reverse engineering. We experimentally show that unauthorized access to the location reports allows for accurate device tracking and retrieving a user’s top locations with an error in the order of 10 meters in urban areas. While we find that OF’s design achieves its privacy goals, we discover two distinct design and implementation flaws that can lead to a location correlation attack and unauthorized access to the location history of the past seven days, which could deanonymize users. Apple has partially addressed the issues following our responsible disclosure. Finally, we make our research artifacts publicly available.
Alexander Heinrich, Milan Stute, Tim Kornhuber, Matthias Hollick
Proc. Priv. Enhancing Technol.1
2019 A Billion Open Interfaces for Eve and Mallory: MitM, DoS, and Tracking Attacks on iOS and macOS Through Apple Wireless Direct Link
Milan Stute, Sashank Narain, Alex Mariotto, Alexander Heinrich, David Kreitschmann, Guevara Noubir, Matthias Hollick
USENIX Security Symposium4