Re: Surveillance Risk: Apple's WiFi-Based Positioning System

May 29, 2024 Last reply: 2 years ago 67 Replies



>> Surveillance Risk: Apple's WiFi-Based Positioning System
>>
formatting link
>
> Why would Apple design a system so incredibly horrific against privacy?

This is a real "nothing to see here" piece of nonsense. Run for the hills! Lock up your daughters!


BSSID's do not report anything that is a privacy risk. SSID's could contain private data IF the owner added it to the SSID.


Note that some mapping services (such as those used by Google and Apple and others) do collect SSID locations (Lat/Long) which are approximate (but can be narrowed down over time). And thus when Identified can be used as proxy location data. Big deal.


So the huge risk is to "travel routers". Sure. Once upon a time a man with a briefcase stayed at a hotel. Yawn with snooze sauce.


The article also points out some workarounds for people who feel they might be at risk.

Are you saying that only because it was Apple who got caught?

Note that the problem isn't a new problems; what's new is that nobody expected Apple, of all companies, of abusing everyone's privacy.

Let's use the Edward Snowden method to show you don't believe that. Please give me your accurate BSSID of your home router. With that, I can tell you exactly where you live.

Stop trying to change the subject to SSIDs. Stick with the BSSID. If you give me your accurate BSSID, I can tell you exactly where you live.

In fact, that's what the researchers themselves found out.

You seemed to have missed the point of travel routers. They follow you.

Give me the accurate BSSID of your travel router. Not only can I tell you where you live, but I can then follow you around.

That you missed that key point is a bit disconcerting. Maybe you need to read the article again?

Since you didn't seem to understand the implication of "travel routers", you may have missed that they discussed how to use "_nomap" on router SSID's to have the (unique) BSSID removed from Apple's & Google's databases (but not from Microsoft's databases).

Since you did not understand those implications, you probably don't yet know that there are many other databases which don't necessarily honor Google's "_nomap", such as those from WiGle, NetStumbler, Mozilla, etc.

As I said, the problem isn't a new problems; what's new is that nobody expected Apple, of all companies, of throwing privacy under the bus.

What it indicates is Apple advertises privacy - but doesn't understand it.

I'm saying it because it is a non issue and click bait at best.

This does not abuse privacy. If you have a WiFi station broadcasting its B/SSID it is the antithesis of wanting privacy. Your "protection" at that point is strong passwords against intrusion. That's all. And if you travel with a portable access point, there are other ways to "scramble" the BSSID.

But of course, launch off the deep end into the panic a pearl clutching.

This strange idea that B/SSIDs are private is laughable. It's as if these trolls have been hiding under rocks for the past few decades, completely unaware that SSIDs are perfectly visible to anyone nearby.

Yes, because: troll.

You can say privacy is a non issue but doesn't Apple advertise it?

You're apparently not aware that a router's outward-facing BSSID is unique.

Not with a router there isn't. Since you don't know anything about routers, allow me to explain that "MAC cloning" never clones outward facing BSSIDs.

You're denying that a problem exists, but you don't understand the problem.

Apple Location Services vulnerability

formatting link

"This includes your home wifi router, for example. Devices don't gain any access to your router, but they can detect it and consult a database to find out exactly where it is located. The issue could also allow an attacker to work out the location of anyone using a mobile wifi router, such as those in RVs, and travel routers sometimes used by business travellers."

Are you excusing Apple just because Apple got caught doing it?

Are you really saying 9to5Mac is "trolling" Apple by reporting it?

Apple Location Services vulnerability

formatting link

"This includes your home wifi router, for example. Devices don't gain any access to your router, but they can detect it and consult a database to find out exactly where it is located. The issue could also allow an attacker to work out the location of anyone using a mobile wifi router, such as those in RVs, and travel routers sometimes used by business travellers."

Seems pretty real in government, Apple news & cybersecurity news reports.

formatting link
"Researchers from the University of Maryland published their findings, which reveal that an unprivileged attacker can exploit Apple's crowdsourced location tracking system to amass a worldwide database of Wi-Fi access point locations and track devices' movements."

The researchers suggested in their paper that the government again be used to force Apple to implement privacy so this can't be done in the future.

"They also recommend that WPS operators restrict access to their APIs and that governments consider regulating the use of WPS data.

Context: BSSID Privacy: BSSID's are openly broadcast for a reason.

Not an Apple issue.

The silly troll is trying to slant this as an Apple issue.

It's not. At all. It's a public broadcast signal - anyone can record them and where and when they were recorded.

Don't need an Apple device.

Or for that matter, any device.

Just use a database that contains a worldwide listing of known and uploaded BSSID's such as:

formatting link

Every single time you join WiFi you see a list of nearby SSIDs. Are you excusing yourself because you "got caught" doing it? Do you have any idea how ridiculous you sound?

"EERMEGHERD! ThIs Is A pRiVaCy IsSuE! HoW dArE tHeY rEaD sSiDs BeInG bRoAdCaSt By MiLlIoNs Of RoUtErS?!?1!!" - morons everywhere

Next, these smooth brains will try to explain how Apple doing it "Is DiFfErEnT!"... Watch.

You didn't read the paper.

formatting link
They discussed Wigle & Google. And Starlink too. The problem is Apple.

formatting link
"The threat applies even to users that do not own devices for which the WPSes are designed - individuals who own no Apple products, for instance, can have their AP in Apple's WPS merely by having Apple devices come within Wi-Fi transmission range."

You don't know the difference between a unique BSSID & an SSID, do you?

Since even the Apple shills directly blame Apple for this privacy hole, can you find any reference on the Internet that says the problem is NOT Apple?

Even the Apple shills say the privacy hole is an Apple vulnerability due to the way that Apple hands out over 400 responses to each request.

formatting link
"Security researchers report that a key element of Apple Location Services contains what they call a really serious privacy vulnerability"

formatting link
"Researchers at the University of Maryland have discovered a crucial vulnerability in the way Apple¢s location services work"

The supposed "privacy vulnerability stated by the authors of the paper is that a database of WiFi B/SSIDs "enables a remote adversary to query the location of arbitrary BSSIDs".

Yes, you can do that with Wigle as well. Again, routers broadcast their B/SSIDs to the world - everyone can see them, which is why there are numerous databases of them. There's nothing special about Apple in that regard. It's just another database of WiFi SSIDs.

A database of publicly-broadcasted WiFi BSSIDs is not a "privacy hole".

Sure I do. You don't seem to know that your router's BSSID isn't private information.

It's obvious you have no idea what a BSSID is, versus what an SSID is.

Why do you think only Apple has this problem, which, I'm sure you'll deny, but every single cite on the Internet about it directly blames Apple alone.

"In this work, we show that Apple's WPS can be abused to create a privacy threat on a global scale."

formatting link

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required