Re: Apple changed their documentation at my request but it proves they don't care about privacy
Maria Sophia <[email protected]>
| Newsgroups | comp.lang.python,misc.phone.mobile.iphone,comp.mobile.android,alt.internet.wireless,alt.comp.os.windows-10 |
|---|---|
| Organization | BWH Usenet Archive (https://usenet.blueworldhosting.com) |
| Message-ID | <[email protected]> |
Carlos E.R. wrote: >>>> 1. Apple are storing the location of "hidden" WiFi Access Points. >>>> (My opinion: low priority.) >>> >>> Only Apple? >> >> I think that is what Maria is saying, and I have no information to the >> contrary. >> >>>> Allegedly: Apple are adhering to this exclusion, but are not also >>>> excluding BSSIDs which are not broadcasting any SSID at all (i.e. >>>> "hidden" networks). Other organisations (e.g. Google) do exclude such >>>> "hidden" networks. >>> >>> And if it is hidden they would not see if the SSID ends in _nomap. >>> >>> But is there a consensus that hidden SSIDs should not be listed? In >>> writing? Maybe there is such a consensus now. >> >> To me it's fairly intuitive that if someone has taken the unusual step >> of explicitly marking their network as "hidden", then its location >> should not be included in these databases - especially given the fact >> that the "_nomap" SSID method doesn't work for "hidden" networks. >> >>> Related: What did Arlen (aka Maria) achieve? That Apple agreed to >>> remove all hidden and _nomap entries, or that they removed only his >>> entry? >> >> My impression is that as a result of Maria's communications with them, >> Apple updated their documentation to note that "hidden" networks are >> still listed in their database, and removed Maria's own BSSID(s) from >> the database. > > AH! Understood. Hi Jon & Carlos, The two of you show potential in being able to understand the problem set. Below are a few very important details that you don't know yet. You're pretty far ahead of everyone else though. Vert far ahead, in fact, in terms of understanding the problem set. Everyone else is in the stone age, but you're in the modern era. So this is just listing a few more important details you need to know. I appreciate that Jon Ribbens not only reproduced my own horror when I found my own BSSID in Apple's database (and in no other databases!), but that he explained correctly to Carlos that only Apple does this. While every one of us likely has the same stone-age knowledge of Wi-Fi networking, the information in this thread is new to almost all of you. It was even new to me, last December, when, much to my horror, after I read this paper, I found my own hidden-broadcast BSSID/GPS pairs in Apple's db! *Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975> I was horrified! The instant I read that paper, I did what almost all of us would do, which is I ran the code to see if what the researches said was true. It was true! I was shocked. As Jon has said elsewhere in this thread, what Apple does is "highly implausible" Especially for a company that claims "we value your privacy" But the facts are shown, in this thread, easily reproduced as Jon and I have done so, that no application of our stone-age wireless networking prepares us for the shock that Apple ignores all common privacy conventions. Shockingly, even Google respects the hidden-broadcast BSSID. And those who know me know I don't congratulate Google easily. But to Jon in particular, and Lawrence, and maybe also Andy, what you don't suspect most likely, is HOW the hidden-broadcast is handled by Apple/Google. What almost nobody will know unless they researched it with the security professionals, as I have done so, is they handle it different. Mozilla is documented to say they won't even COLLECT it. a. Let alone save it on the device. Let alone upload it to a cloud db. b. Let alone Likewise, Android devices never even *see* it (Winston's absurd denial to that fact being brought out as this is the point of me explaining that Winston's stone-age understanding is two or three decades old). If Android devices can't even *see* it, they don't collect it, save it on device, upload it, store it in a database (or even cull it from the database), nor can they let anyone in the world see it as it's not there. Only Apple does it the way Apple does it. Not only does Apple see it, but they collect it. a. They save it on device. b. They upload it to the cloud c. They do not cull it (even though the SSID ends with _nomap! Worse. unlike Google/Mozilla and everyone else we know of, Apple does not protect it from being tracked by anyone in the world. That's pretty bad. Is it not? -- When I write a thread, it's about something important most people can't even fathom, so it takes intelligence to understand the topic.