Re: Apple changed their documentation at my request but it proves they don't care about privacy

Sep 04, 2026 Last reply: 4 hours ago 1 Replies


>>> >>>> Those scripts proved I could collect a list of every single access


>>>> point in Apple's database, just as researchers Eric Rye and Dave
>>>> Levin did, using a simple perl script which proved the results of
>>>> their paper, and which went further to prove that my own
>>>> hidden-broadcast SSIDs were in that database.
>>>
>>> I don’t understand what you’re complaining about, exactly. Your wi-fi
>>> network broadcasts its existence to all and sundry, and yet you feel
>>> upset when somebody collects that information and passes it on. >>
>> I guess it is because the SSID is terminated in _nomap, which is
>> documented as a flag to Apple and others to not store this SSID in their
>> maps. But Apple is/was mapping them all the same.
>
> I got the impression they were claiming that their SSID was hidden,
> which makes it irrelevant as to whether it has "_nomap" at the end
> of it, but that Apple had somehow discovered and logged it nonetheless.
> It seems highly implausible.

Perhaps unless an Apple device was used to connect to it?

This part of the discussion contains 3 very well thought out reflections.

  1. Carlos
  2. John Ribbens
  3. Nuno Silva

Months ago, we wrote a python script that essentially gathered the physical location of every single unique access point BSSID in the world (see sig).

formatting link

All we did was exactly reproduce the results from Levin & Rye in this paper

*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
formatting link
formatting link

There were "posters" who disputed this, particularly on the Apple ngs, but it was clear they were denying only to defend the honor of their God.

They didn't understand a single thing, which is telling when someone denies research papers that no professional would deny, yet Apple posters deny it.

We were able to effectively pick any area of the world that has had an Apple mobile device swing by at some point in time and then we could locate every single BSSID/GPS location in that area, to identify, for non-apartment-style areas the home address, and then, if that router was moved to a new location, instantly, we could locate where they moved it to.

This is in keeping with what the paper claimed, and for Apple posters to deny it (which they did), is not only absurd, but telling in how desperate Apple posters tend to be when it comes to defending their religious God.

To remove doubt, Carlos is correct in his statement above, that every access point I discussed with Apple Maps executives ended with "_nomap".

Therefore, they are not "supposed" to be in the Apple world wide WPS db. And yet, they were.

None of the Apple documentation at that time said that they would be.

Only because of me (and I know this from my emails with Apple), is the cite which I provided saying that even with _nomap, you're still in their db.

Which means, if I didn't have Apple remove it manually (which they did at my insistence), then anyone could instantly track me down to the meter. were I to move my router to another location in the world (by my BSSID).

Apple knows this. They're not stupid.

They're liars. But they're not stupid.

Notice that what Jon Ribbens said is also true, and more telling than what Carlos had mentioned, although both are perfectly accurate assessments. a. The SSID has _nomap b. The SSID broadcast is hidden c. Google refuses to put that in their public WPS database d. Better yet, Google has protections on their public WPS database e. SO does Mozilla (although their database has been deprecated) f. So does everyone... g. Except Apple

Worse, Eric Rye and Dave Levin proved that once the unique BSSID is in the Apple WPS database, anyone in the entire world can track that router, down to the meter, no matter where it is subsequently moved to (and no matter what any subsequent SSID may be), which I also proved in my scripting.

Given Apple posters will stop at nothing to defend their religious God, we wasted umpteen posts proving that, but not one of them ever ran the code.

I did. I simply ran the same python code that was described in the research. And got the same results (I stopped at a fefw hundred thousand, while they went on to gather billions, or at least hundreds of millions, as I recall).

Proof of concept is all I needed to affirm that if I happen to know the BSSID of someone's router (oh, say, an ex wife or a disgruntled employer), I could track that router anywhere in the world, easily, down to the meter.

As for what Nuno Silva said, all we need to do to get our unique BSSID and GPS location into the Apple WPS database, is for an Apple mobile device to be within hearing distance, for only a moment or so, whether or not we have told Apple by the SSID postfix of _nomap, if the broadcast is set to null.

Those who actually understood what I wrote above, which is likely only about one one-hundredth of the people reading this (simply because they have bias that they can't shake), will understand the catch-22 involved.

For data collection... A. Google/Mozilla do privacy one way (i.e, the well-known correct way) B. Apple does it completely differently.

Worse (far worse), for data distribution... A. Google/Mozilla do privacy one way (i.e, with judicious controls) B. Apple does it completely differently (i.e., no controls at all!)

Think about that.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required