Khoury News
Don’t want stalkers tracking your AirTag? These researchers built a cheap, effective solution.
Meet AirCatch: a cheap-to-build, easy-to-use device that sniffs out hidden trackers by mapping the hardware imperfections that hackers struggle to erase.
Tag-based tracking devices like Apple’s AirTag, Samsung SmartTags, and Google Find My tags are intended for tracking items like luggage, keys, and wallets. But in the wrong hands, these devices can be used to stalk unwitting victims.
“Current anti-stalking protections assume that tracking devices will follow safety protocols as designed. Our work shows that an attacker can exploit that assumption to make those protections ineffective,” Northeastern cybersecurity PhD student Swadeep says.
Khoury Professor Guevara Noubir and Swadeep collaborated with Abhishek Kumar Mishra and Mathieu Cunche at Inria, a computer science research institute in France, to develop a device called AirCatch that disrupts attackers’ latest trick for slipping by modern detection systems.
“These AirTags typically broadcast a cryptographic public keys. The devices next to you pick up these keys, encrypt their own location, and upload it to Apple’s servers,” Noubir explains. “So when you want to find your device, you know what to look for on Apple’s server, you download it, and decrypt to estimate your tag’s location.”
The problem is that if this cryptographic public key never changes, it could be used by adversaries sniffing wireless transmissions to track a user. Whenever they saw a certain public key, they would know that a certain tag was around. Apple gets around this by changing an AirTag’s identifying information every 15 minutes.
But that’s not the only cryptographic key that needs to be changed frequently. The Bluetooth MAC address of these devices also needs to change synchronously with the key; otherwise, broadcast messages could be linked to devices.
Only if the item is lost or away from the owner does the device switch into a mode that gives off persistent identifying information, which allows a user to detect that there is a neighboring AirTag traveling with them (potentially tracking them), while still enabling the owner of the AirTag to find and recover the item.

This means that when an attacker slips a tracker into someone’s bag or attaches it to their car without their knowing, the device should give off persistent identifying information, which would enable the victim’s smartphone to notice that a device is travelling with them. But attackers avoid detection by hacking the tags and rotating identifying information every 15 minutes, or less, even when the tag is away from the attacker.
AirCatch offers a new way of detecting hidden devices even when their identifying information is constantly changing. The system combines a cheap-to-build software-defined radio (SDR) — a small device for picking up radio signals — with a powerful algorithm that identifies Bluetooth devices based on identifying information that can’t be easily changed.
“When you transmit anything, there are characteristics at the physical layer that are not controllable the way they are at the software level. Identifying these characteristics is called fingerprinting,” Noubir says.
Radio frequency fingerprinting (RFF) works by identifying hardware-level imperfections that are unintentionally embedded in the device’s transmitted signal.
“As long as the device works, the manufacturer doesn’t really care about imperfections. Ideally you want to make it neat, but as long as the receiver gets the information and decodes these bits correctly, minute imperfections don’t matter that much from a communications perspective,” Noubir explains.
These imperfections are idiosyncratic and, when carefully mapped, can create a unique identifying fingerprint for a device that even a hacker would have trouble changing.
Noubir was inspired by his own past research in Wi-Fi and cellular security to look for a device’s RFF. More than 10 years later, the technique still proves effective.

Part of the novelty of this research is the development of a small SDR device called BLE Phaysr, which picks up radio signals. BLE Phaysr can be built cheaply compared to similar devices, which cost hundreds or even thousands of dollars.
“If you’re worried about people tracking you, you can build this thing for $10,” Noubir says. “It has a USB-C; you can just plug it into your phone.”
Because effective tracking devices must be usable in crowded spaces with many similar Bluetooth signals, the researchers stress tested AirCatch in airports, on the subway, walking around Boston, and while driving.
“We moved with a tracking device and the BLE Phaysr. We needed to make sure that we could detect all of the devices that were with us without having any false positives,” Noubir explains. “Our research showed no false positives and about a 97% detection rate.”
Even with such successful results, Noubir is already thinking about the limitations of this work and how an attacker might get around this form of detection.
“One thing an adversary could do is transmit very rarely,” Noubir posits. “If they transmit once an hour, then it’s very hard to detect. With just one transmission, you don’t have enough samples to really be quite certain, then your false positives will become much larger. They could also build new devices that can change the imperfection that we’re fingerprinting. They could change not only the data, but they could also obfuscate features at the physical level.”
As for the future of AirCatch, Noubir says he can imagine the device being easily manufactured and sold on Amazon, but he also knows that many people are unaware of the dangers presented by tag-based tracking devices and they may not seek out the means to protect themselves from this threat.
Until people learn to take their digital privacy more seriously, researchers like Noubir, Swadeep, and their Inria colleagues will continue to work to outsmart attackers who are always devising ways to circumvent the latest security practices.
In the meantime, the researchers have submitted their paper for publication at an upcoming privacy symposium.
The Khoury Network: Be in the know
Subscribe now to our monthly newsletter for the latest stories and achievements of our students and faculty