Exercise 3: The "Everyone for 10 Minutes" Risk — Possible Solution ==================================================================== THE SPECIFIC RISK ------------------------------ Per this chapter, setting AirDrop visibility to Everyone is reasonable while actively receiving one specific file, but leaving it set that way afterward means anyone nearby with a compatible Apple device can send an unsolicited AirDrop request to your device, without your prior consent to being reachable by strangers at all. WHY IT'S BOTH A TECHNICAL AND A SOCIAL-ENGINEERING RISK ------------------------------ Technically, it widens the device's reachability surface to any nearby stranger rather than only known contacts. But the chapter frames the more immediate real-world risk as social engineering: an unwanted or malicious file, or an inappropriate image, sent to a stranger's device in a public place, relies not on exploiting a software vulnerability but simply on the fact that the device is left open to receiving unsolicited content from anyone nearby - a people-facing risk rather than a purely technical one. THE FIX ------------------------------ Set AirDrop back to Contacts Only or Off immediately after the specific transfer that required Everyone is complete, rather than leaving it on indefinitely as a matter of convenience. WHY THIS WORKS AS AN ANSWER ------------------------------ It correctly explains that the risk stems from remaining reachable by any nearby stranger rather than a specific technical exploit, correctly frames the social-engineering angle (unwanted/inappropriate content sent by a stranger) as distinct from a purely technical vulnerability, and gives the chapter's own recommended fix (returning to Contacts Only or Off promptly).