Re: Apple changed their documentation at my request but it proves they don't care about privacy
Maria Sophia <[email protected]>
| Newsgroups | comp.lang.python,misc.phone.mobile.iphone,comp.mobile.android,alt.internet.wireless,alt.comp.os.windows-10 |
|---|---|
| Organization | BWH Usenet Archive (https://usenet.blueworldhosting.com) |
| Message-ID | <[email protected]> |
Jon Ribbens wrote:
>> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
>> meter or so accuracy, if I want to under the common circumstances which
>> I've outlined in this thread (and in others).
>
> Ok. I think BSSID means "MAC address of the WiFi access point".
> I don't know what circumstances you can track them, and you don't
> seem to have said in this thread.
Hi Jon,
Thanks for your questions as it shows you're trying to understand this.
Your questions are all good questions, from someone who is encountering
this issue for the first time in their lives, but let's be clear that an
entire course in networking for privacy is beyond my personal skill sets.
If you don't know what a BSSID is by now then it will take too much work
here to explain it "fully" to you. Suffice to say it's like a vehicle
identification number on a car. It goes everywhere the router goes.
Every access point has a unique BSSID that stays with the router forever.
(Yes, I know in extremely expensive routers, not home routers, that the
BSSID can be changed, and yes, I know, in those extremely rare situations,
the BSSID may actually not be unique, but only one out of a million people
know those facts, so suffice to say for this thread the BSSID is unique).
The Apple trolls absurdly claimed that changing the SSID changes the BSSID,
but the fact remains the BSSID remains the same no matter what the SSID is.
>> I move my router around a lot, and I don't want just anyone being able
>> to track all my movements down to a meter accuracy when I do that. Do
>> you?
>
> I suppose if someone had reason to target me specifically, and they had
> a real-time way of tracking BSSIDs, and for some reason I can't imagine
> I was taking a WiFi access point with me, I... oh, wait. In that
> circumstance I would not take a WiFi access point with me, for the
> same reason I wouldn't have my mobile phone radio enabled, or would not
> have a mobile phone with me at all, depending on the threat model.
Read the paper which we referenced multiple times in this thread so that I
don't have to re-hash over and over again how mass surveillance is possible
with the Apple WPS database design.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Anyone who can run a python script (which I will provide to them upon
request) can track anyone in the world who moves from one place to another
(and who happens to take their router with them to their new location).
Nobody disputes that fact, which is what the paper itself explained.
I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
It doesn't bother you that I can track the movements of billions of people
if they happen to move from one locale to another using the same router?
You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?
That's 1/2 the point of this thread.
1. Apple is doing NOTHING about it (as described in the paper)
2. So anyone in the world can track the movements of billions of routers
2. Worse, Apple isn't honoring the established meaning of the hidden
broadcast (which even Google honors, by way of stark contrast).
So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
>> You were correct in your prior post to Carlos, when you said (verbatim):
>> "I got the impression they were claiming that their SSID was hidden,
>> which makes it irrelevant as to whether it has "_nomap" at the end
>> of it, but that Apple had somehow discovered and logged it nonetheless.
>> It seems highly implausible."
>>
>> But, of course, there's more detail (which I provided in my responses).
>
> I saw no response from you to that post. But from what you're saying
> in the post I'm replying to now, I wasn't correct - I now think you're
> saying that Apple store the BSSIDs of access points of WiFi networks
> with hidden SSIDs, because they *don't* know the SSID and therefore
> can't tell if it has "_nomap" appended, and so don't exclude it.
There are two fundamental issues, only one of which is in this paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
I've summarized what's in that paper likely a half dozen times in this
thread, and I've added a second issue that is not discussed in that paper.
I've talked that second issue over with security professionals like Brain
Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
To summarize complex issues in a few simple sentences, they might be:
1. Apple allows anyone on the world to track the movements of everyone
in the world (if they take their router with them when they move).
2. Apple puts zero controls on that tracking by anyone, of everyone.
3. In addition, Apple does not respect the known meaning of a hidden
broadcast, and worse, Apple *refuses* to honor what even Google does.
4. Anyone can prove these statements are true on a Windows PC running
Python using the scripts I have provided for that express purpose.
> I'm not sure what I think about that, and I don't know what any of the
> other companies that map SSIDs do in the same situation. I'm not sure
> why Apple would store location data of BSSIDs with no visible SSID -
> it doesn't seem like it would help the geolocation feature much, since
> hiding the SSID is pretty rare.
Remember the Apple trolls posted to this thread that changing the SSID
would solve the issue, but the main issue is about the BSSID, not the SSID.
a. The BSSId is unique (see above for rare exceptions).
b. The GPS location is also unique
c. The SSID only plays a role tangentially, and as such is a minor player
Assume, for an analogous purpose that a flock camera allowed anyone in the
world to track everyone in the world, not only by the license plate (which
can be changed) but by the VIN number, which cannot be changed.
Then assume Flock knows this, but refuses to add any security whatsoever.
a. Worse, assume all the other camera outfits DO add security.
b. Not only that, the other camera outfits add lookup protection.
That's a decent analogy of what's going on that is more easily understood.
>
>> I explained it in gory detail, and even provided a link to the research.
>> I provided some of the python scripts too (although they're not the point).
>
> You haven't done any of that in this thread so far as I can see.
Did you read the paper?
What does that paper say?
Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?
I've explained both perhaps a half dozen times in this thread.
Explaining another half dozen times won't help until you do the above.
It's unfair of you to claim I haven't provided you an entire courese in
basic networking, when you didn't even click on the links we provided.
>> We've discussed this ad infinitum on the Apple & Android & Windows ngs in
>> the past, although I don't remember how much we brought in Python folks.
>>
>> What's *new* is Apple told me in my email that there was no way to
>> have WPS privacy from Google/Mozilla if I wished to have WPS privacy
>> from Apple.
>
> Sorry, what does WPS have to do with it? And why is it a binary option?
> A non-hidden SSID with "_nomap" would presumably provide privacy from
> all those companies? Or do some of them not support that? Or is having
> a non-hidden SSID not acceptable to you? If so, what are the options
> for privacy you are referring to?
Wrong WPS.
Read the paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
>> It's a catch-22 situation.
>> Which would you pick?
>
> I mean I literally do pick a non-hidden SSID without "_nomap" on it,
> that I've kept constant for decades. I've never even seen a SSID with
> "_nomap" on it. There is no-one I regard as a threat, let alone someone
> who would be a threat and who would know my SSID let alone my BSSIDs.
What you need to think about is what the paper explains about the SSID.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Then, you need to consider what happens when that SSID broadcast is hidden.
Only one out of a million people (or so) has thought about those two things
(but it goes further since now you need to consider what Google/Apple do).
Google does one thing (which, surprisingly, is the right thing to do).
Apple does the opposite (and, not surprisingly, refuses to change it).
If you don't follow the trail from your router to some guy in Russia who is
tracking the movements of everyone in the world, you can't understand it.
Read the paper (which explains half the issues brought up here).
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
>> HINT: If we read the research paper, it's a no brainer which one to pick.
>
> What research paper?
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
--
Most people can only parrot what clever marketing told them to believe.