Why AirDrop keeps getting restricted in China and Hong Kong

AirDrop's defining feature is that it moves files phone-to-phone over Bluetooth and Wi-Fi without touching a server, which is also what made it an organizing tool during Hong Kong's 2019 protests. Strangers used it to hand pro-democracy material to passers-by, including visitors from the mainland, with nothing to subpoena afterward. That fact has shaped policy ever since.

AirDrop is Apple's built-in feature for sending files directly between nearby Apple devices over Bluetooth and Wi-Fi, with nothing uploaded to a server and no account required. It briefly became a tool of political organizing during Hong Kong's 2019 protests, and has been a target of Chinese government restriction ever since:

  • Open, everyone-visible receiving now times out after 10 minutes in China
  • Beijing claims to have partially traced anonymous senders
  • New rules require file-sharing tools to register with regulators
  • Hong Kong's national security law extends the same scrutiny locally

What's actually happened, in order

Apple was first to move. Weeks before mainland anti-lockdown protests in late 2022, an iOS update quietly changed AirDrop for users in China: instead of staying open to "Everyone" indefinitely, that setting now reverts to contacts-only after ten minutes. Apple didn't frame it as a protest response, but the timing was hard to read any other way. The change shipped to China only; everywhere else, AirDrop kept its old behavior.

Then Beijing went further on the technical side. In January 2024, Beijing's Justice Bureau said forensic experts had found a way to partially reverse AirDrop's encryption, enough, they claimed, to recover the phone numbers and email addresses tied to a sender's Apple ID from device logs, specifically to identify people who had AirDropped "inappropriate" material in public places like subway stations. Apple has not confirmed a vulnerability on its end, and independent verification of the claim is limited, but the announcement itself was the point: don't assume anonymous, offline sharing stays anonymous.

Regulation followed the same year. The Cyberspace Administration of China proposed rules requiring offline file-sharing tools, the category AirDrop sits in alongside similar Android features, to pass a security review and register their service details before operating, giving authorities a route to require identity information from providers. Hong Kong's national security law already reaches communication and assembly more broadly than the mainland framework, so the territory sits downstream of that same posture. The practical assumption for anyone there is that proximity-based sharing is a monitored channel now, not an anonymous one.

Why this is bigger than one protest tactic

The mechanism Hong Kong organizers relied on, trusted and ephemeral peer-to-peer transfer with no server in the middle, is the same mechanism plenty of ordinary users and IT admins want for entirely unremarkable reasons. Handing a contractor a file without putting it in a cloud folder, moving photos off a phone on a network you don't control, or sharing something at a conference where you'd rather not broadcast to "Everyone" and have no idea who's listening are all the same problem. AirDrop being reachable, loggable, and increasingly regulated in some jurisdictions is a reason to think about what you actually need from a transfer tool: staying off a cloud server, or reaching someone regardless of what device they're carrying.

DropCopy is built for the first case: free, local, encrypted transfer directly between your own Mac, iPhone and iPad over Wi-Fi, no cloud upload and no account required, and it works in situations where AirDrop is flaky about discovering older or non-Apple-adjacent hardware. It's an Apple-device tool the same way AirDrop is, so it doesn't solve reaching a Windows or Android user on its own. For that, DropCopy adds Secure Remote Send: the file is encrypted on your Mac before it ever leaves, and the recipient, on any device on any platform, just opens a link in their browser to download it, no install and no account needed on their end. The decryption key travels only in the URL fragment, the part after the #, which browsers never transmit to a server, so the relay carrying the file can't read it either. Links expire after 30 minutes. You're trusting a link and a 30-minute window instead of physical closeness, a different shape of privacy than AirDrop's proximity model, but one that doesn't depend on one vendor's region-specific throttling of who can discover whom.

Frequently asked questions

Is AirDrop banned in Hong Kong?

No. AirDrop itself isn't banned. What's changed is the regulatory and technical environment around it: Apple limits open, everyone-visible receiving to ten minutes on Chinese devices, Beijing has claimed a method for tracing senders, and mainland rules increasingly require file-sharing tools to register and undergo security review. Hong Kong operates under a national security law that gives authorities broad reach over communications generally.

Does AirDrop being encrypted mean it's anonymous?

Encryption protects the contents of a transfer in transit, but it doesn't by itself guarantee the sender's identity is unrecoverable. China's claimed forensic method targeted device logs rather than breaking the encryption outright, a distinction that matters technically even though the practical result, for anyone relying on anonymity, is the same.

What's a good alternative to AirDrop when the recipient isn't on Apple hardware?

AirDrop only works device-to-device within Apple's ecosystem. DropCopy's free local transfer has the same limitation and covers Mac, iPhone and iPad, but its Secure Remote Send feature sends an encrypted link that opens in any browser on any platform, which is the more common everyday version of this problem: getting a file to someone on Windows or Android without an account on either end.

Does using a local file-transfer tool make me anonymous on a monitored network?

No. Any tool is visible to whoever controls or monitors the network it runs on, and that's true of AirDrop, DropCopy's local transfer, or anything else. Staying local avoids sending your file through a third-party server, but it doesn't make the transfer invisible to network-level monitoring. Get DropCopy for Mac and iOS.

Share this article