Re: Surveillance Risk: Apple's WiFi-Based Positioning System

May 29, 2024 Last reply: 2 years ago 67 Replies

Jolly Roger wrote on 30 May 2024 21:36:46 GMT :

And yet, it's not.

Which proves beyond question what you Apple zealots don't understand.

*All you wish to do is defend Apple's vulnerabilities to the death.*

See technical proof in the sig proving sheer ignorance of the zealots.

-- Note 1: The hidden broadcast won't hide the BSSID from a seasoned attacker (such as a Google or Apple tracking vehicle - depending on how its code is written); but the mere act of hiding the SSID broadcast packet has been proven to prevent the normal users' device (i.e., mobile phones) from uploading your BSSID using the typical software that we are speaking about.

Note 2: Since the Apple religious zealots act only out of franctic desperation to make excuses for all Apple's vulnerabilities, it should be noted that an intelligent person knows the difference between the upload of the BSSID (which is a first-order issue) vs the deletion of the BSSID from the Internet databases (which requires second-order software processing).

Note 3: There's no way the Apple religious zealots will understand the two notes above, but for the intelligent people reading this thread, it should be noted that if you do hide your broadcast packets, then you often might want to set your client (such as a phone) to "remember" and "reconnect"; but this has other issues - where the Apple zealots won't understand but adults might understand that the "remember" is fine (unless you're worried about your phone being stolen) but the "automatic reconnect" should be turned off because that setting causes the phone to seek out the named AP.

Jolly Roger wrote on 30 May 2024 21:37:35 GMT :

If I'm ignorant and you know so much about how broadcasts work, why does nothing you have ever said show any indication of how they actually work?

Note 1: While almost every router has an option to hide the broadcast packets, that hidden broadcast setting won't prevent a seasoned attacker (such as a Google or Apple tracking vehicle - depending on how its code is written) from pulling the packets out of a netstumbler/wireshark wardriving scan, but the mere act of purposefully hiding the SSID broadcast packet has been proven to prevent the normal users' device (i.e., mobile phones) from uploading your BSSID using the typical software that we are speaking about.

Note 2: Since the Apple religious zealots act only out of franctic desperation to make excuses for all Apple's vulnerabilities, it should be noted that an intelligent person knows the difference between the upload of the BSSID (which is a first-order issue) vs the deletion of the BSSID from the Internet databases (which requires second-order software processing).

Note 3: There's no way the Apple religious zealots will understand the two notes above, but for the intelligent people reading this thread, it should be noted that if you do hide your broadcast packets, then you often might want to set your client (such as a phone) to "remember" and "reconnect"; but this has other issues - where the Apple zealots won't understand but adults might understand that the "remember" is fine (unless you're worried about your phone being stolen) but the "automatic reconnect" should be turned off because that setting causes the phone to seek out the named AP.

*Or is it that your only goal is to defend Apple's flaws, to the death?*

Every government, security researcher and even Apple centric publication reported the problem is the specific way that only Apple has implemented the vulnerability. Not Google. Not Wigle. Not Mozilla. Only Apple.

formatting link
"Researchers have discovered a crucial vulnerability in the way only Apple's location services work"
formatting link
"The attack risk stems from Apple's WiFi-based Positioning System, or WPS"
formatting link
"We need to understand Apple devices figure out locations differently"
formatting link
"An unrestricted Apple API endpoint allows for easy tracking."
formatting link
"Anyone can exploit Apple's flawed WiFi-based positioning system (WPS)*
formatting link
"In this work, we show that Apple's flawed WPS can too easily be abused"

You're the one making excuse after excuse for Apple's flawed coding.

Every government, security researcher and even Apple centric publication reported the problem is the specific vulnerable way that only Apple alone has chosen to implement their location services without ever testing it.

Not Google. Not Wigle. Not Mozilla. Only Apple.

formatting link
"Researchers have discovered a crucial vulnerability in the way only Apple's location services work"

formatting link
"The attack risk stems from Apple's WiFi-based Positioning System, or WPS"
formatting link
"We need to understand Apple devices figure out locations differently"
formatting link
"An unrestricted Apple API endpoint allows for easy tracking."
formatting link
"Anyone can exploit Apple's flawed WiFi-based positioning system (WPS)*
formatting link
"In this work, we show that Apple's flawed WPS can too easily be abused"

Nobody but you denies what even Apple doesn't deny.

Why do you do that?

formatting link
"There is one crucial difference between the way in which Apple and Google devices carry out this task and that's exactly where the privacy issue arises."
formatting link
"Researchers have discovered a crucial vulnerability in the way only Apple's location services work"
formatting link
"The attack risk stems from Apple's WiFi-based Positioning System, or WPS"
formatting link
"We need to understand Apple devices figure out locations differently"
formatting link
"An unrestricted Apple API endpoint allows for easy tracking."
formatting link
"Anyone can exploit Apple's flawed WiFi-based positioning system (WPS)*
formatting link
"In this work, we show that Apple's flawed WPS can too easily be abused"

Why do you deny what nobody but you denies (not even Apple denies it)?

I'm not defending what Apple do. What Apple do is their choice and it is no more harmful than what others do. It's different. That's all.

But you do you: desperately misinform and spread BS

Completely irrelevant. But play all you want.

You're clearly not following.

Not only understand it, have reliable knowledge that hardly anyone uses it.

You're really grasping.

I did leave out that the SSID can be muted. But that is not at all relevant to the discussion.

It is only you throwing more distraction at things to try (desperately) to score points.

There is a rock out there missing what should be under it. Go back.

Your wording shows you're searching the web and employing the results badly.

Seasoned attacker? A CHILD can get at the BSSID when the SSID is hidden, you fool.

Your new trigger word is "vulnerability". It is not the big boogie man you desperately are painting it to be.

By your reaction if you heard of a shoplifter at a local store you'd be screaming for protection against murderers.

It's not flawed. It's doing as designed. Do keep up.

Yes it is. That's why it's called a "WAN-facing BSSID", numbskull.

He very clearly knows very little about how WiFi actually works. Dunning-Kruger in full effect.

Nothing you can say will ever change the FACT (you love misusing that word) that anyone can pull up wigle.net, search for any WiFi router, and see the BSSID of it and every router around it on a neat little map. According to you this is a YUGE "vulnerability" - it's not. It's just public information made accessible by an API and service, which is exactly what Apple's service is. And the fact that you don't know this says all we need to know about you. Cry harder, little Arlen. Your troll is going nowhere.

Nobody but you trolls the Apple newsgroups all day every day like their miserable lives depend on it. You are a sad, little loser, Arlen.

You wouldn't know a fact if it slapped you in the face, little Arlen.

And we know this because they so very often have done.

:-)

Jolly Roger wrote on 31 May 2024 20:18:42 GMT :

And yet, I've provided almost a dozen cites of fact, Jolly Roger.

All you did was brazenly deny every fact about Apple that you hate.

Not only is that a lot of facts that you hate about Apple, but even Apple does not disagree with the fact that their WPS implementation is flawed.

I've studied you strange Apple religious fundamentalists, to conclude you are herd animals - with no adult capacity to make your own choices.

Hence, *you defend Apple, to the death* no matter what.

Even when Apple itself admits to the fact that these flaws are serious.

Alan Browne wrote on Fri, 31 May 2024 15:12:41 -0400 :

And yet, no other company except Apple has this huge privacy vulnerability.

formatting link
The attack risk stems from Apple's WiFi-based Positioning System, aka WPS

And yet, I'm quoting the cites and all you're doing is denying all facts.

formatting link
Researchers have discovered a crucial vulnerability in the way only Apple's location services work - no other platforms have it.

It's obvious that neither you, nor Jolly Roger, has any understanding of why this huge Apple-only vulnerability is caused by Apple & Apple alone.

formatting link
The threat applies even to users that do not own devices for which Apple's WPS was designed. Individuals who own no Apple products, for instance, can have their AP in Apple's WPS merely by having Apple's flawed and highly insecure devices come within Wi-Fi range"

You're the one defending Apple's privacy holes to the death, not me.

formatting link
There is one crucial difference between the competent way in which Apple and Google devices carry out this task and how Apple alone chose to implement it and that's exactly where the privacy issue arises.

Heh heh heh... it's clear you've never even heard of a BSSID in your life, and now you're claiming you know more than Apple does about this problem by saying it's not caused by the way Apple handles the database queries.

formatting link
Apple's unrestricted WPS API endpoint is why this flaw is so serious

It's no longer shocking that you Apple religious fundamentalists are making excuses for what even Apple hasn't denied is a flaw caused only by Apple.

formatting link
"Anyone can exploit Apple's flawed WiFi-based positioning system (WPS)*

And yet, I'm the one who is supplying cites for every single fact I speak.

formatting link
"In this work, we show that Apple's flawed WPS can too easily be abused"

All you're doing is defending all of Apple's privacy flaws, to the death.

Jolly Roger wrote on 31 May 2024 20:12:41 GMT :

Heh heh heh...

And yet, it's obvious you knew *none* of what I just explained to you.

There's a reason I've concluded you Apple religious fundamentalists are a. of low IQ b. hence, completely uneducated c. which explains why you're always so ignorant

You knew *none* of those first order and second order ameliorations.

*Your only goal is to defend Apple, to the death.*

Alan Browne wrote on Fri, 31 May 2024 15:17:59 -0400 :

Heh heh heh... not only did you know none of what I wrote, but I have entire privacy tutorials on the net saying what I said above.

The only goal you have is to deny every fact you hate about Apple products.

It's no longer shocking Apple religious zealots still don't understand the difference between first-order vs second-order BSSID privacy ameliorations.

Your main goal here is to make excuses for Apple's privacy vulnerabilities.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required