Re: Apple changed their documentation at my request but it proves they don't care about privacy

Jon Ribbens <[email protected]>
Newsgroups comp.lang.python,misc.phone.mobile.iphone,comp.mobile.android,alt.internet.wireless,alt.comp.os.windows-10
Organization A noiseless patient Spider
Message-ID <[email protected]>
On 2026-09-05, Maria Sophia <[email protected]> wrote:
> Jon Ribbens wrote:
>>> Anyone who can't answer those queries, can't possibly understand the
>>> issue.
>> 
>> Do you have any intention of letting anyone else know what the issue
>> is?
>
> Hi Jon,
>
> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
> meter or so accuracy, if I want to under the common circumstances which
> I've outlined in this thread (and in others).

Ok. I think BSSID means "MAC address of the WiFi access point".
I don't know what circumstances you can track them, and you don't
seem to have said in this thread.

> I move my router around a lot, and I don't want just anyone being able
> to track all my movements down to a meter accuracy when I do that. Do
> you?

I suppose if someone had reason to target me specifically, and they had
a real-time way of tracking BSSIDs, and for some reason I can't imagine
I was taking a WiFi access point with me, I... oh, wait. In that
circumstance I would not take a WiFi access point with me, for the
same reason I wouldn't have my mobile phone radio enabled, or would not
have a mobile phone with me at all, depending on the threat model.

> You were correct in your prior post to Carlos, when you said (verbatim):
>   "I got the impression they were claiming that their SSID was hidden,
>    which makes it irrelevant as to whether it has "_nomap" at the end
>    of it, but that Apple had somehow discovered and logged it nonetheless.
>    It seems highly implausible."
>
> But, of course, there's more detail (which I provided in my responses).

I saw no response from you to that post. But from what you're saying
in the post I'm replying to now, I wasn't correct - I now think you're
saying that Apple store the BSSIDs of access points of WiFi networks
with hidden SSIDs, because they *don't* know the SSID and therefore
can't tell if it has "_nomap" appended, and so don't exclude it.

I'm not sure what I think about that, and I don't know what any of the
other companies that map SSIDs do in the same situation. I'm not sure
why Apple would store location data of BSSIDs with no visible SSID -
it doesn't seem like it would help the geolocation feature much, since
hiding the SSID is pretty rare.

> I explained it in gory detail, and even provided a link to the research.
> I provided some of the python scripts too (although they're not the point).

You haven't done any of that in this thread so far as I can see.

> We've discussed this ad infinitum on the Apple & Android & Windows ngs in
> the past, although I don't remember how much we brought in Python folks.
>
> What's *new* is Apple told me in my email that there was no way to
> have WPS privacy from Google/Mozilla if I wished to have WPS privacy
> from Apple.

Sorry, what does WPS have to do with it? And why is it a binary option?
A non-hidden SSID with "_nomap" would presumably provide privacy from
all those companies? Or do some of them not support that? Or is having
a non-hidden SSID not acceptable to you? If so, what are the options
for privacy you are referring to?

> It's a catch-22 situation.
> Which would you pick?

I mean I literally do pick a non-hidden SSID without "_nomap" on it,
that I've kept constant for decades. I've never even seen a SSID with
"_nomap" on it. There is no-one I regard as a threat, let alone someone
who would be a threat and who would know my SSID let alone my BSSIDs.

> HINT: If we read the research paper, it's a no brainer which one to pick.

What research paper?
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.