Re: Apple changed their documentation at my request but it proves they don't care about privacy

Maria Sophia <[email protected]>
Newsgroups comp.lang.python,misc.phone.mobile.iphone,comp.mobile.android,alt.internet.wireless,alt.comp.os.windows-10
Organization BWH Usenet Archive (https://usenet.blueworldhosting.com)
Message-ID <[email protected]>
Jon Ribbens wrote:
>> If you don't know what a BSSID is by now then it will take too much work
>> here to explain it "fully" to you. Suffice to say it's like a vehicle
>> identification number on a car. It goes everywhere the router goes.
> 
> Well, yes, it's the MAC address, like I already said.

Hi Jon,

To your credit, you are the first person who has responded, who has shown
that he actually *read* the paper before trying to respond intelligently.

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

That's good. 
Nobody else even bothered to click on the link, before responding.

Hence, everyone else simply parroted their stone-age knowledge level.
You, at least, did *read* the paper, which I congratulate you for doing.

But you did not *understand* what the paper said by the BSSID.
See below where you completely whooshed on which BSSID is what matters.

I must be careful here not to fault you like I fault the Apple trolls,
because I think you are sincerely trying to understand the problem set.

So I simply caution you, as I did Lawrence & Andy, all of whom I respect
for acumen, that you have to follow the trail of the *router* AP BSSID.

You can not "randomize the BSSID" of the router AP (except in the most
expensive commercial routers, which are not the topic of this thread).

Think very deeply about that simple fact before responding, as the crux of
the problem is no different than a governmment-issued identification
number.

You can't easily change your unique government-issued ID number just as you
can't easily change the router-issued BSSID of your home router AP.

Think about that the same way the paper presented the mass surveillance.
 1. I wrote a Python script that ran on Windows 10 that guessed at a set
    of random government-issued identification numbers, e.g., 123.45.6789
 2. Within minutes, I had a hit on a random government ID, which came
    back with a GPS location and 400 nearby government IDs and locations.
 3. Then, I ran another Python script on Windows 10 that extended that, 
    taking the furthest-away governemtn ID/location pair, and did it again.
 4. Within an hour, I had thousands of government IDs and locations.
    (the researchers gathered billions, as I recall, but I stopped there.)

Now that I have every government-issued ID and GPS location in the world in
my 2TB database (which we calculated would be the size it would have been), 
what is the paper saying about "mass surveillance" possibilities?

HINT: I can track the future location of every one of those billions of
government ID/GPS location pairs, without any restrictions on my scripts!

Want to prove that?
What's your home router BSSID?

I will not only tell you exactly where that router is located (I even wrote
the Python code to give me a dot on an OSM map for your location) but I can
trivially easily forever track that router's location forever, without any
restrictions on my part (which is the point of the paper, after all).

That's what the paper says.
I went further (i.e., to hidden broadcast issues).

But that alone is what the paper says you can do, and I proved it, and I
supplied the python scripts (and will supply them to anyone who asks me).

>>> I suppose if someone had reason to target me specifically, and they had
>>> a real-time way of tracking BSSIDs, and for some reason I can't imagine
>>> I was taking a WiFi access point with me, I... oh, wait. In that
>>> circumstance I would not take a WiFi access point with me, for the
>>> same reason I wouldn't have my mobile phone radio enabled, or would not
>>> have a mobile phone with me at all, depending on the threat model.
>>
>> Read the paper which we referenced multiple times in this thread so that I
>> don't have to re-hash over and over again how mass surveillance is possible
>> with the Apple WPS database design. 
> 
> You hadn't referenced it at the time I wrote my post, or at least
> by the time you wrote the post I was responding to.
> 
> It mostly seems to be an attack against people who don't realise
> they are targets, or are not thinking about the implications - c.f.
> soldiers who upload their daily runs to public web sites thus
> revealing if/where they are deployed.

It's not "an attack" so much as explaining, with examples, of why we should
care that mass surveillance is so easy with the Apple WPS implementation.

The soldier part is just an example.
I have a more potent example.

Give me your MAC address of your home router AP.

Not only can I instantly tell you where that reouter is, but I can tell you
the location and BSSID of the nearest 400 routers to your location.

We proved that in the Python scripts I had provided and had run on WIn10.
Test me.

Give me your BSSID.

Note: I don't expect you to do it, which alone proves the point.

>>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> Anyone who can run a python script (which I will provide to them upon
>> request) can track anyone in the world who moves from one place to another
>> (and who happens to take their router with them to their new location).
>>
>> Nobody disputes that fact, which is what the paper itself explained.
>> I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
>>
>> It doesn't bother you that I can track the movements of billions of people
>> if they happen to move from one locale to another using the same router?
> 
> As I say that's a pretty unusual thing to do (travelling with a router).
> Google's API does seem more sensible though (give it MAC addresses, it
> tells you where you probably are, rather than giving you the recorded
> individual locations of all those MAC addresses).

I think your claim that it's "pretty unusual" for people to take their
router with them when they move from one apartment to another is skewed.

If I ask 100 people who recently moved, do you really think it would be
only 1 or 2 people who took their home router with them when they moved?

> 
>> You think this tracking isn't happenging asa we speak?
>> You think Apple is doing something about it?
>>
>> That's 1/2 the point of this thread.
>>  1. Apple is doing NOTHING about it (as described in the paper)
> 
> Have you, er, read the paper? It says Apple *is* doing things about it
> (page 14, section 10 paragraph 3).

See my first response to you in this post, where I want to be careful to
not chastise you for misunderstanding what that paragraph actually says.

You can NOT randomize the MAC address of the router AP, Jon.

Sure, for expensive commercial routers, with thousands of access points,
they can randomize their MAC addresses, but it's not on most home routers.

To be clear, it is on some (expensive) home routers. 
I am well aware of that. 

But we're talking about surveilling the masses, not the people who actually
know how networking works (which nobody on this thread so far has shown).

>>  2. So anyone in the world can track the movements of billions of routers
>>  2. Worse, Apple isn't honoring the established meaning of the hidden
>>     broadcast (which even Google honors, by way of stark contrast).
> 
> This is the bit I keep asking about and you keep not responding.
> Is your actual/main complaint that Apple is storing BSSIDs that
> correspond to hidden SSIDs? And you're saying only Apple do this,
> not Google etc?

First off, I don't have a complaint. That's absurd. I have facts.
This entire thread is people disputing those facts, without ever even
bothering to read the links which were provided for them to read.

The absurdity of this thread is nobody has read or understood the links
which were provided, and yet, they ask me (repeatedly) to explain them.

Why can nobody understand the point that Eric & Dave made in this paper?
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

Why can nobody understand what's different about what Apple documented?
 <https://support.apple.com/en-ie/102515>

Why can nobody undestqand the concept inherent in a hidden-broadcast?
 <https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html>
    "The BSSID of the Wifi network. 
     Hidden Wifi networks must not be collected."

Why is it that I feel it's trivial to understand that 1+1=2 when everyone
else is trying to claim that I need to explain why 1+2=2 when, if they
simply read (and understood) what I've explained, they would understand?

Can *nobody* actually read those references except me, and understand them?

> 
>> So much for Apple "cares about your privacy" bullshit, huh?
>> It's shocking that google cares about privacy more than Apple does.
> 
> Apple cares about the privacy of *its customers*.

I realize you're trying to understand these concepts so I have to be
careful when I point out that this affects every single person in the world
who owns a router (and company, but let's restrict this to just people).

The issues are exactly the same no matter what company made that router.

>> There are two fundamental issues, only one of which is in this paper.
>>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> I've summarized what's in that paper likely a half dozen times in this
>> thread, and I've added a second issue that is not discussed in that paper.
>>
>> I've talked that second issue over with security professionals like Brain
>> Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
>>
>> To summarize complex issues in a few simple sentences, they might be:
>>  1. Apple allows anyone on the world to track the movements of everyone
>>     in the world (if they take their router with them when they move).
>>  2. Apple puts zero controls on that tracking by anyone, of everyone.
> 
> I imagine the issue here is that if they change their API then older
> devices that are no longer receiving updates will stop being able to do
> wifi-positioning.

The issue is clearly obvious that the Apple WPS design is flawed.

I have dozens of emails from Apple, all of which show that they *know* that
their design is flawed. 

They're simply trying to protect themselves legally with me by having their
emails redirected to their lawyers, who are whom I was responding with.

They *know* what they're doing is wrong.

>>  3. In addition, Apple does not respect the known meaning of a hidden
>>     broadcast, and worse, Apple *refuses* to honor what even Google does.
>>  4. Anyone can prove these statements are true on a Windows PC running
>>     Python using the scripts I have provided for that express purpose.
>>
>>> I'm not sure what I think about that, and I don't know what any of the
>>> other companies that map SSIDs do in the same situation. I'm not sure
>>> why Apple would store location data of BSSIDs with no visible SSID -
>>> it doesn't seem like it would help the geolocation feature much, since
>>> hiding the SSID is pretty rare.
>>
>> Remember the Apple trolls posted to this thread that changing the SSID
>> would solve the issue, but the main issue is about the BSSID, not the SSID.
>>   a. The BSSId is unique (see above for rare exceptions).
>>   b. The GPS location is also unique
>>   c. The SSID only plays a role tangentially, and as such is a minor player
> 
> The "Apple trolls" are presumably correct inasmuch as if you change the
> SSID to end in "_nomap" then it solves the issue.

No it does not. Did you read any of the Mozilla references?
Simply *collecting* the BSSID is the starting point.

The problem exists no matter what the SSID is.

>>>> I explained it in gory detail, and even provided a link to the research.
>>>> I provided some of the python scripts too (although they're not the
>>>> point).
>>> 
>>> You haven't done any of that in this thread so far as I can see.
>>
>> Did you read the paper?
>> What does that paper say?
> 
> You hadn't linked the paper at the time I wrote my post.
> The paper doesn't quite say what you're claiming, I think,
> although I see your general point (or at least, the paper's
> authors' general point).

I appreciate that you're the only person in this thread who has ever shown
any indication that you actually clicked on the link, so I must be careful
to let you know that I understand that you went to that trouble to "try" to
understand what the paper actually said.

Remember, I go further than what the paper said, because the paper didn't
discuss hidden broadcast implications, but do keep in mind I wrote the
scripts so I can track any router AP anywhere in the world myself, just as
the paper claimed I could.

With my congratulations to you and with my appreciation that you are the
only one who has shown they have read the paper, I must point out that I
think you misunderstood which BSSID the paper is talking about.

For most home routers, the owner has no way of changing the AP BSSID.

>> Do you know what a hidden broadcast SSID is?
>> What is the purpose of a hidden broadcast in your opinion?
> 
> To waste power in client devices, as far as I can see, since it
> means they have to be constantly pinging for the network rather
> than just connecting to it when they see the SSID broadcast.

No. Every mobile device has the on/off ability to NOT autoconnect.

Privacy never was something that everyone could understand, but let's hope
the people on this ng have the capacity to understand the complexities.

> So in some senses it makes the user tracking problem *much worse*,
> since it means the attacker can hang around public places watching
> for client devices (which, unlike access points, tend to move around
> with the user) that are pinging for the attack target's hidden SSID.

That's why you set the mobile device to NOT autoconnect after all.

Remember, privacy doesn't mean you don't have to understand networking.
 
> Hang around a diner near Langley, Virginia, watching for people
> carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"...

I'm very happy you understand networking at that level, Jon.

This is an extremely well known phenomenon, which has been the topic of
discussion in numerous hackers' conferences, where the presenter puts on
the projector screen the names and locations of all such requests.

Anyone who doesn't understand what we're conversing about, can't really add
value to the conversation, so I'm glad you know it at that level.

>> I've explained both perhaps a half dozen times in this thread.
>> Explaining another half dozen times won't help until you do the above.
> 
> I'm starting to think that by "this thread" you don't mean "the set
> of Usenet articles referenced in the References headers" and are
> including other historic threads...

All the python scripts I wrote I put into the public domain so you're
welcome to ask for any of those scripts, which I posted to these ngs.

>> Google does one thing (which, surprisingly, is the right thing to do).
>> Apple does the opposite (and, not surprisingly, refuses to change it).
> 
> I think you are still failing to explain what those two things are,
> and I'm getting tired of guessing. If you are claiming the paper
> describes this difference, please say where. If it doesn't, please
> just say what it is.

Again, I have to first say that I appreciate that you read the paper, and I
presume you read the Mozilla documentation I presented, and I presume you
also read the Apple documentation which the Apple lawyers wrote after my
discussions with them way back in December of last year (public knowledge).

The paper shows that Apple's WPS implementation is highly flawed.

If you've ever tried Google's WPS implementation, you'll see that it's not.
Nor is Mozilla's MLS implementation (now deprecated).

This is known public information that I have to assume you already know, as
it would take me a while to write the Python scripts to query Google's
implementation, which also requires a key which is well known data.

SO, while I do appreciate that you're 'trying' to understand, to have me
document what Google has already documented, would be a waste of energy.

It's absurd for anyone to dispute what I say without actually looking up
the extremely well known fact that the Google lookup requires not only a
key from Google but also it's limited in what it outputs, and also it's
limited in how many lookups you can do in a certain time period.

Apple's WPS lookup is not.
That's why they wrote that paper, after all... :)
-- 
What is disconcerting is nobody seems to look anything up even as everyone
in the world knows what I'm explaining in this thread, over & over again.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.