Is it private when you're screaming it on the street corner for everyone to hear? If we're talking about vocal utterances, the law says "no".
It's... disappointing that the addition of a computer to a activity makes people lose sight of the similarities between that activity and very similar ones that have long-settled legal treatment.
Edit: To drive the point home: There are many jurisdictions that require you to affix your street number to the exterior of the building in which you live using numerals that are sufficiently large to be read clearly from across the street. Noone would honestly make the claim that the data provided by those numerals is in any way private information, and that broadcasting your street number to everyone who was walking or driving by is in any way a breach of privacy. :)
FWIW despite what our modern religion emphasizes, the Nazis were hardly the only ones to track prisoners with tattooed numbers
The useful parallel is the general inventorying and tracking of people. Luckily we don't have the rest of totalitarianism (yet), but this cornerstone is well laid due to naive designers.
BTW you were the one who brought up the subject of Nazis.
Every router I've ever seen has a pretty clear setup option for creating a hidden network. I agree that defaults are powerful, but they don't make it any less "willing," they merely expose people's indifference.
I'm making a general point about identifiers and protocols. The same thing applies to client MACs, which are obviously being used to track phone users with wifi on. Obviously MAC addresses can be cycled, but that takes active diligence. If the protocol had simply been designed to eschew and hide such identifiers in the first place, the entire issue wouldn't even exist.
I've never heard of this, and have family that served in the Pacific during WWII. I'm also having difficulty discovering any sources that mention the practice, let alone reliable ones.
AFAIK, it was never policy of the Allied forces to tattoo anything on captured POWs. I would be very surprised if captured Axis soldiers were not given some sort of uniform, unique tracking number.
Hidden networks are even less private, because then every client device has to probe repeatedly to see if the network is there.
So. How would you design a system to permit associated or unassociated stations to passively determine whether or not they were in range of a given AP? Remember that unassociated stations may never have ever interacted with the AP in question before this moment.
If the AP and client possess a shared secret (as in WPA2), then there's no reason for a third party to be able to deduce any identifying information.
Okay. How would you design a system to permit associated or unassociated stations to passively determine whether or not they were in range of a given AP? Remember that human-friendly names for a given AP are almost certain to collide.
Simple protocol: The AP and client have shared secret K (similar to the present WPA2 key). We define the identity of a network as this secret key. The AP can change "BSSID" every hour, while broadcasting [BSSID, Hash(BSSID, K)]. An interested client runs through their database of known private networks, checking if the broadcaster is any they know.
This obviously has a number of shortcomings (eg our attacker is also known to groom people into uploading K to their silos), but it should illustrate the concept.
That solves the problem for clients that have connected to that AP before. [0]
How do you propose to solve the problem for clients that have never interacted with that AP before?
[0] It probably actually doesn't, but I won't distract you with why at the moment. :)
Okay, I'm a little confused, please bear with me.
Are you designing two half systems, one of which periodically changes BSSID but provides no other anonymity protection, and the other which hashes the BSSID with the WPA2 PSK?
Or are you designing one system with a rotating BSSID that transmits -in cleartext- the BSSID and the hashed BSSID?
It's obviously impossible to have a publicly-available network that hides its existence to the public (while a private network can obviously hide its existence to the public completely), so each problem will obviously have different ideal solutions.
It's the merging and the details of the same that's the complicated bit, and the only thing worth talking about in this sub-thread.
You made the assertion that the "the committees designing [wireless communications] protocols don't think [that things screamed on the street corner are public data]". [0] This is simply not true. The folks who designed 802.11 had to make several key-management-complexity/computational-power/ease-of-use tradeoffs.
> ...while a private network can obviously hide its existence to the public completely...
Not if it's a relatively-high-performance radio network operating in a relatively tiny slice of spectrum, [1] it can't.
[0] https://news.ycombinator.com/item?id=10950276
[1] As 802.11b/g/n does
A high-bandwith radio transmitter obviously gives its presence up, but that doesn't mean it needs to identify itself. Of course the FCC likes transmitters to do this, but that too is an anti-feature with respect to public-use spectrum.
There were obviously tradeoffs involved for 802.11, which is how we got WEP. I'd just be surprised if having a (semi-)fixed MAC address was ever questioned, given that it's the basis for 802.3 and leaking some associated identity is basically a forgone conclusion in today's world of license plates, etc. But with the obvious effects of mechanized tracking and aggregation, it really shouldn't be. So I stand by my assertion that the designers would have benefited from a perspective where being pushed to do the equivalent of continually shouting/showing one's identity is a very bad thing.
Yes, it is, if the screaming is between you and another person and not addressed at the public.
> If we're talking about vocal utterances, the law says "no"
Actually the law says "yes". At least in all the countries in which secrecy of telecommunications laws are in place. The general outline has been laid out by the ITU and the paraphrased rule is, that it is strictly forbidden to listen to communications to which one is not the intended communications partner and the signal is not addressed at the public. It's debateable if a SSID beacon is a public broadcast or not. But at least from most user's point of view their intention is not broadcasting to the general public if they set up an encrypted 802.11 access point.
CPC 632 disagrees with you. California is a two-party consent state when it comes to recording of conversations, but it does not require consent of both of the communicating parties if "...the parties to the communication may reasonably expect that the communication may be overheard or recorded." [0]
I expect that you'd be hard-pressed to find a judge who would buy your theory that someone screaming out in public on the street corner would not reasonably expect that their communication might be overheard... regardless of to whom they were addressing their screams.
> Actually the law says "yes". At least in all the countries in which secrecy of telecommunications laws are in place. ... The general outline has been laid out by the ITU...
AFAIK, telecommunications law does not cover shouting-with-one's-vocal-cords-without-electronic-assistance-in-public. Do you have court decisions or rulings (that were not later overturned) that say otherwise?
[0] http://codes.findlaw.com/ca/penal-code/pen-sect-632.html