Projection. Both are broadcast by the router which makes them both public information.
Wrong, Arlen. Wigle.net and other databases also let you look up routers by SSID and BSSID.
Projection. Both are broadcast by the router which makes them both public information.
Wrong, Arlen. Wigle.net and other databases also let you look up routers by SSID and BSSID.
No you can't.
It's obvious you have no idea what the problem is, especially since every cite on the Internet directly blames Apple and Apple alone for this flaw.
"In this work, we show that Apple's WPS can be abused to create a privacy threat on a global scale."
What is obvious you don't understand, besides what a BSSID is, is that every cite on the Internet blames Apple alone - and that's because how Apple implemented the lookup (for example, by allowing an infinite number of lookups without any checks whatsoever and then, to make it worse, by reporting over 400 nearby BSSID's when you look up just one).
Apple Location Services vulnerability
Why do you think only Apple has this problem, which, I'm sure you'll deny, but every single cite on the Internet about it directly blames Apple alone.
Every cite on the net blames Apple and Apple alone for this privacy flaw.
The fact that he pointed it out as SSID rather than BSSID shows JR knows precisely what the difference is.
The latter is usually obfuscated from the user as not esp. useful to users. Though it is in the clear and clearly visible with a deeper look and/or with scanning tools available for pretty much every OS.
Every excuse you make for Apple's flawed implementation shows you do not understand that it's Apple's flawed implementation alone that is to blame.
"researchers at the University of Maryland have discovered a crucial vulnerability in the way Apple's location services work"
"The researchers discovered an oddity in the way Apple's WPS works"
It's obvious that Jolly Roger doesn't know the difference between an SSID and a BSSID because it was clear that the problem isn't in the SSID at all.
It was Apple's suggested workaround that involved an SSID - nothing else. The problem is all about the way Apple handles the BSSID.
It's obvious that neither of you understand the difference in the least. Only Apple has this vulnerability.
Neither of you shows any understanding that the WAN-facing BSSID is unique to the router and unchangeable in almost all routers, and that a router's location is unique to your exact location, and that a travel router's WAN-facing BSSID, in particular, follows you around everywhere you go.
Neither of you shows any indication you understand that the LAN-facing MAC cloning has absolutely no effect on the WAN-facing BSSID of most routers.
As a result of your lack of understanding, you didn't even read any of teh cites, every one of which clearly says the problem is unique to Apple's implementation alone - as only Apple hands out the nearest 400 BSSIDs.
Only Apple has this vulnerability.
Only Apple has this vulnerability.
It's actually the root of it which you would know if you knew at all what it going on. I'll explain this as to a child to give you a fighting chance.
When an a device such as a phone detects a WiFi access point it gets all sorts of interesting information.
The device (phone) user usually is only interested in the latter - he picks from whatever is available to access the WiFi - if it is password access, then of course he'll need that too.
The actual working connection does not use the SSID - it uses the BSSID. (You can refer to it is as the MAC or Wi-Fi address if that helps you connect all these big people ideas - although they often/usually the same they don't have to be the same...).
Most devices will display the BSSID if the user wants to delve into it. On most phones this would be shown as the MAC or Wi-Fi address. Or of course, once can use one of many tools to display same.
Thus - in JR's earlier reply - he was being quite clear about what he was replying to and did so correctly.
Apple trigger word got ya huh?
Yes, you can.
Nope, sorry.
Arlen acts like this is some sort of secret information, when the reality is the definitions of BSSIDs and SSIDs is common knowledge. Arlen clearly doesn't understand how WiFi works, yet he's claiming everyone else is dumb.
Of course it is. It's broadcast by routers. It's public information. There is no "privacy violation" inherent in looking at publicly broadcast information.
It's obvious *you* don't understand how WiFi works. BSSIDs and SSIDs are broadcast by WiFi routers and have been since WiFi was created. There is no "privacy violation" in looking at information that is broadcast to the public.
Irrelevant. It is broadcast to the world. No privacy issue here.
There is no excuse. WiFi routers broadcast their SSIDs as well as their BSSIDs to the world. That's how WiFi works, you ignorant troll.
This is all elementary. Arlen pretends it's top-secret information that nobody but he knows to feed his superiority complex due to his insecurities. He has to pretend he's better than everyone else because deep down, he knows he's a loser troll with nothing constructive to do with his time on Earth.
It's clear you don't understand the issue when you and Jolly Roger are the only people in the world who say it's not specifically an Apple issue.
Projection, it is *you* who don't understand the ramifications - or how WiFi access points work.
What Arlen refrained from quoting is that this "crucial difference" is simply that with Apple's database, searches yield more results of access points that are near the queried B/SSID. What he also isn't acknowledging is that when you search for a B/SSID on Wigle.net's map, you also see all nearby access points right there on a handy visual map.
Nothing Arlen can say changes the FACT (little Arlen loves that word) those IDs are still broadcast to the public by those WiFi access points.
that you are gullible. A click bait drive victim.
you don't understand the issue when you and Jolly Roger are the
The "general" case is that it is absolutely not an Apple issue. SSID/BSSID's are OPENLY AND LOUDLY BROADCAST WORLDIWDE IN THE BILLIONS.
THESE WAVES ARE PENETRATING YOUR HEAD RIGHT NOW.
DESPITE THE 6 LAYERS OF ALUMINUM PAPER OVER YOUR HEAD.
The specific case is "Apple do things differently than (say) Google or someone else". Well .... frick -- who'd a thunk different people do things differently. BRING BACK COMMUNISM AND DO IT FROM CENTRAL CONTROL!
Keep beating on that. What you're missing (big picture) is that these people are using words like "crucial" and this is causing neurons to fire brightly in your head. There is nothing important happening - it's just happening differently. The contrast is being exploited because the trigger words cause you to go bananas and that is good to get articles seen and linked and copied when there is little of consequence actually happening.
Alan Browne wrote on Thu, 30 May 2024 19:18:55 -0400 :
The fact is you're defending Apple's holes, to the death, no matter what.
Every desperate excuse you make for the flaws in Apple's implementation show you not understand what only Apple does that's different here.
Worse, you were not aware the outward facing MAC address cannot be cloned (in almost all routers and particularly in the tested travel routers).
And you were not aware that the SSID is meaningless for this exploit, other than the workaround that Apple suggested (of appending _nomac to the SSID).
Furthermore, you're still not aware that a "hidden broadcast" has been a feature of nearly every router since the dawn of Wi-Fi, where the mere act of clicking that checkbox prevents the BSSID from being *uploaded* to the Google and Apple and Mozilla and Wigle databases, by default. (See notes in the sig, given the Apple religious zealots don't understand this issue).
While you're frantically desperate to fabricate excuses for Apple's vulnerabilities, you don't ever show any understanding of them.
Notes in the sig given Apple religious zealots don't understand anything.
-- Note 1: The hidden broadcast won't hide the BSSID from a seasoned attacker (such as a Google or Apple transit vehicle - depending on how its code is written); but the mere act of hiding the SSID broadcast packet has been proven to prevent the normal users' device (i.e., mobile phones) from uploading your BSSID using the typical software that we are speaking about
Note 2: Since the Apple religious zealots act only out of franctic desperation to make excuses for all Apple's vulnerabilities, it should be noted that an intelligent person knows the difference between the upload of the BSSID (which is a first-order issue) vs the deletion of the BSSID from the Internet databases (which requires second-order software processing).
Note 3: There's no way the Apple religious zealots will understand the two notes above, but for the intelligent people reading this thread, it should be noted that if you do hide your broadcast packets, then you often might want to set your client (such as a phone) to "remember" and "reconnect"; but this has other issues - where the Apple zealots won't understand but you might understand that the "remember" is fine (unless you're worried about your phone being stolen) but the "automatic reconnect" should be turned off because that setting causes the phone to seek out the named AP.
Jolly Roger wrote on 30 May 2024 21:33:55 GMT :
That sentence proves beyond any doubt that these ignorant uneducated Apple religious zealots have absolutely no understanding of how broadcasts work.
Their only desperate goal is to defend Apple's flaws to the death.
See technical notes in the sig since adults understand what they do not.
-- Note 1: The hidden broadcast won't hide the BSSID from a seasoned attacker (such as a Google or Apple tracking vehicle - depending on how its code is written); but the mere act of hiding the SSID broadcast packet has been proven to prevent the normal users' device (i.e., mobile phones) from uploading your BSSID using the typical software that we are speaking about.
Note 2: Since the Apple religious zealots act only out of franctic desperation to make excuses for all Apple's vulnerabilities, it should be noted that an intelligent person knows the difference between the upload of the BSSID (which is a first-order issue) vs the deletion of the BSSID from the Internet databases (which requires second-order software processing).
Note 3: There's no way the Apple religious zealots will understand the two notes above, but for the intelligent people reading this thread, it should be noted that if you do hide your broadcast packets, then you often might want to set your client (such as a phone) to "remember" and "reconnect"; but this has other issues - where the Apple zealots won't understand but you might understand that the "remember" is fine (unless you're worried about your phone being stolen) but the "automatic reconnect" should be turned off because that setting causes the phone to seek out the named AP.
Jolly Roger wrote on 30 May 2024 21:33:55 GMT :
That sentence proves beyond any doubt that these ignorant uneducated Apple religious zealots have absolutely no understanding of how broadcasts work.
Their only desperate goal is to defend Apple's flaws to the death.
See technical notes in the sig since adults understand what they do not.
-- Note 1: The hidden broadcast won't hide the BSSID from a seasoned attacker (such as a Google or Apple tracking vehicle - depending on how its code is written); but the mere act of hiding the SSID broadcast packet has been proven to prevent the normal users' device (i.e., mobile phones) from uploading your BSSID using the typical software that we are speaking about.
Note 2: Since the Apple religious zealots act only out of franctic desperation to make excuses for all Apple's vulnerabilities, it should be noted that an intelligent person knows the difference between the upload of the BSSID (which is a first-order issue) vs the deletion of the BSSID from the Internet databases (which requires second-order software processing).
Note 3: There's no way the Apple religious zealots will understand the two notes above, but for the intelligent people reading this thread, it should be noted that if you do hide your broadcast packets, then you often might want to set your client (such as a phone) to "remember" and "reconnect"; but this has other issues - where the Apple zealots won't understand but adults might understand that the "remember" is fine (unless you're worried about your phone being stolen) but the "automatic reconnect" should be turned off because that setting causes the phone to seek out the named AP.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required