Re: Apple changed their documentation at my request but it proves they don't care about privacy

Maria Sophia <[email protected]>
Newsgroups comp.lang.python,misc.phone.mobile.iphone,comp.mobile.android,alt.internet.wireless,alt.comp.os.windows-10
Organization BWH Usenet Archive (https://usenet.blueworldhosting.com)
Message-ID <[email protected]>
Carlos E.R. wrote:
>>>> 1. Apple are storing the location of "hidden" WiFi Access Points.
>>>>      (My opinion: low priority.)
>>>
>>> Only Apple?
>> 
>> I think that is what Maria is saying, and I have no information to the
>> contrary.
>> 
>>>> Allegedly: Apple are adhering to this exclusion, but are not also
>>>> excluding BSSIDs which are not broadcasting any SSID at all (i.e.
>>>> "hidden" networks). Other organisations (e.g. Google) do exclude such
>>>> "hidden" networks.
>>>
>>> And if it is hidden they would not see if the SSID ends in _nomap.
>>>
>>> But is there a consensus that hidden SSIDs should not be listed? In
>>> writing? Maybe there is such a consensus now.
>> 
>> To me it's fairly intuitive that if someone has taken the unusual step
>> of explicitly marking their network as "hidden", then its location
>> should not be included in these databases - especially given the fact
>> that the "_nomap" SSID method doesn't work for "hidden" networks.
>> 
>>> Related: What did Arlen (aka Maria) achieve? That Apple agreed to
>>> remove all hidden and _nomap entries, or that they removed only his
>>> entry?
>> 
>> My impression is that as a result of Maria's communications with them,
>> Apple updated their documentation to note that "hidden" networks are
>> still listed in their database, and removed Maria's own BSSID(s) from
>> the database.
> 
> AH! Understood.

Hi Jon & Carlos,

The two of you show potential in being able to understand the problem set.
Below are a few very important details that you don't know yet.

You're pretty far ahead of everyone else though.
Vert far ahead, in fact, in terms of understanding the problem set.

Everyone else is in the stone age, but you're in the modern era.
So this is just listing a few more important details you need to know.

I appreciate that Jon Ribbens not only reproduced my own horror when I
found my own BSSID in Apple's database (and in no other databases!), but
that he explained correctly to Carlos that only Apple does this.

While every one of us likely has the same stone-age knowledge of Wi-Fi
networking, the information in this thread is new to almost all of you.

It was even new to me, last December, when, much to my horror, after I read
this paper, I found my own hidden-broadcast BSSID/GPS pairs in Apple's db!
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

I was horrified!

The instant I read that paper, I did what almost all of us would do, which
is I ran the code to see if what the researches said was true.

It was true!
I was shocked.

As Jon has said elsewhere in this thread, what Apple does is 
  "highly implausible"

Especially for a company that claims
  "we value your privacy"

But the facts are shown, in this thread, easily reproduced as Jon and I
have done so, that no application of our stone-age wireless networking
prepares us for the shock that Apple ignores all common privacy
conventions.

Shockingly, even Google respects the hidden-broadcast BSSID.
And those who know me know I don't congratulate Google easily.

But to Jon in particular, and Lawrence, and maybe also Andy, what you don't
suspect most likely, is HOW the hidden-broadcast is handled by
Apple/Google.

What almost nobody will know unless they researched it with the security
professionals, as I have done so, is they handle it different.

Mozilla is documented to say they won't even COLLECT it.
 a. Let alone save it on the device. Let alone upload it to a cloud db.
 b. Let alone 

Likewise, Android devices never even *see* it (Winston's absurd denial to
that fact being brought out as this is the point of me explaining that
Winston's stone-age understanding is two or three decades old).

If Android devices can't even *see* it, they don't collect it, save it on
device, upload it, store it in a database (or even cull it from the
database), nor can they let anyone in the world see it as it's not there.

Only Apple does it the way Apple does it.

Not only does Apple see it, but they collect it. 
 a. They save it on device.
 b. They upload it to the cloud
 c. They do not cull it (even though the SSID ends with _nomap!

Worse. unlike Google/Mozilla and everyone else we know of, 
Apple does not protect it from being tracked by anyone in the world.

That's pretty bad.
Is it not?
-- 
When I write a thread, it's about something important most people 
can't even fathom, so it takes intelligence to understand the topic.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.