Re: New vulnerability in Apple's positioning service allows troop movements to be tracked

Oscar Mayer <[email protected]> Fri, 31 May 2024 14:57:15 -0400
Newsgroups misc.phone.mobile.iphone,comp.sys.mac.system,alt.comp.networking.routers,alt.comp.os.windows-10
Organization A noiseless patient Spider
Message-ID <[email protected]>
> TheRegister reports Apple is throwing UK residents' privacy under the bus.
> https://www.theregister.com/2024/05/23/apple_wifi_positioning_system/
> 
>   "The threat applies even to users that do not own devices for which the
> WPSes are designed - individuals who own no Apple products, for instance,
> can have their AP in Apple's WPS merely by having Apple devices come within
> Wi-Fi transmission range."
> 
> Here's the paper.
> https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf

Here's more information about Apple's privacy flaw which affects everyone.

 [https://9to5mac.com/2024/05/24/apple-location-services-vulnerability/]
 "There is one crucial difference between the way in which
  Apple and Google devices carry out this task
  and that's exactly where the privacy issue arises."

[https://www.macworld.com/article/2343297/apple-wi-fi-network-wps-vulnerability-location-services-leak.html]
  "Researchers have discovered a crucial vulnerability in the way 
   only Apple's location services work"

[https://www.govinfosecurity.com/surveillance-risk-apples-wifi-based-positioning-system-a-25330]
 "The attack risk stems from Apple's WiFi-based Positioning System, or WPS"

 [https://9to5mac.com/2024/05/24/apple-location-services-vulnerability/]
 "We need to understand Apple devices figure out locations differently"

[https://securityboulevard.com/2024/05/apple-wi-fi-location-privacy-richixbw/]
 "An unrestricted Apple API endpoint allows for easy tracking."


[https://cybernews.com/privacy/apple-beams-wifi-location-data-privacy-risk/]
 "Anyone can exploit Apple's flawed WiFi-based positioning system (WPS)*

 [https://arxiv.org/abs/2405.14975]
  "In this work, we show that Apple's flawed WPS can too easily be abused"