How does Google know where I am?
security.stackexchange.com
security.stackexchange.com
Android searches for access points even when wifi is turned off. If anyone (with GPS enabled) uses that wifi with any google services the bssid will end up in their database. Also if the google car has been nearby it has recorded the presence of the wifi access point at that location [1].
Before you freak out: Apple and Microsoft also use access point information for positioning, although not as successfully.
[1] https://googleblog.blogspot.se/2010/05/wifi-data-collection-...
Who would really need that sort of information? I understand how this can be useful at the mall but I think I can find my way around my own house thank you.
I don't know the answer to that question, but I have a guess at the answer to another question: "is it okay for a private company to create a geodatabase of SSID strings that were freely and willingly broadcast via radio?"
I think the answer is "yes". Ten, fifteen years ago, if there were an HN story about how I, owner of a small business you've never heard of, created a database of SSIDs that are broadcast and tagged them with lat/longs, I'd bet money it would make the top of the front page. Bonus points if I included an API and threw the thing up on github.
Fine, it's evil, append "_nomap" to your SSID string. That's fine for stopping Google, but it won't stop "owner of small business you've never heard of". Don't broad SSIDs, but then (IIRC) one can still obtain the MAC address.
But in the end, if a radio broadcasts something then one has little recourse when receivers use that broadcast in ways you didn't intend. The analogy crumbles under a little scrutiny, but it's similar to FM broadcasters complain about geodatabases of FM towers because the intent of the broadcaster was to allow you to listen to drive-time hyenas, not use it for location services.
Additionally, I don't buy that to begin with, at least not as it concerns the majority. Where do folks think those other SSIDs (even if they don't call them that) in their list of networks come from?
minimum standards of knowledge required for the citizens
Do you know how the electricity in your wall works? What about the plumbing under your house? Would you be able to fix those things on your own?Using your analogy it would be sufficient for a person to know how to handle electricity coming from your wall or the plumbing under your house safely. And generally people do know how to do that.
Everyone who is regularly using WiFi networks knows that he/she can see the names of other WiFi networks in their vicinity. Therefore people using WiFi generally do know that this information is publicly broadcasted and available to be collected by anyone interested in doing so.
No one believes that he is the only person being able to somehow magically see the name of his neighbours WiFi.
http://qz.com/333313/milliions-of-facebook-users-have-no-ide...
Frankly I don't care for the matter at hand about the perception and understanding of the Internet that people from a different culture might have just as I do not care about the Saudi perspective on women's and LGBT rights. We are discussing here what should be the standard in our societies.
The level of IMO required knowledge I'm talking about here is to know e.g. that water in your faucet is distributed through the building via water pipes, and electricity comes through cables that are inside walls. Even this basic knowledge allows one to infer quite a lot.
This should be opt-in by default in sane universe, not opt-out.
OTOH, to the extent this is not true, its ISPs and router manufacturers who are at fault.
Broadcasting is, inherently, sharing location with everyone with a receiver.
> Who the fuck do they think they are?
People with receivers (see above.)
I don't know what to tell you other than "I don't like the way I feel about this" is not the basis of good policy.
If they don’t want to be seen, they can just stop broadcasting their face and wear a burqa, right?
There is a huge difference between "publicly available in every case seperately" and "publicly indexable".
EDIT: Instead of downvoting, please leave a comment instead – do you disagree because you believe there’s a fundamental difference between gigahertz and terahertz light waves? Or is there another reason you disagree?
There is no such established pattern where we can reasonably assume that a company collecting SSIDs will usually do this to act in a criminal way.
By the way I didn't down vote you, but I think this is the "common sense" reason why people reject your position.
You can't publicly index newspaper articles that are already decades old and irrelevant, you can't publicly index photos of buildings, you can't publicly index the names of people even.
Every of these things requires written approval of everyone listed, be it StreetView, the application of the Right to be Forgotten, or collecting WiFi SSIDs.
So the question is: why does everything require approval, except for SSIDs?
The possibilities of human behavior are infinite. We don't need to and can't enumerate all possible bad behaviors as illegal. Thus the civil court system.
On the second thought, I think there's some law against publishing images of people without their consent in some circumstances. I'm not clear on exactly what is allowed, but I know that TV broadcasters post notices in places that they are filming.
A restraining order is issued for either actually illegal activity, or for activity whose legal status is in dispute, and which would irreparably negatively impact a party in the case in which it that status was in dispute, or for activity which might straddle the line of legality but which is related to a broader pattern of activity which was found to be illegal.
Its not done for specifically legal activity.
> The possibilities of human behavior are infinite. We don't need and can't enumerate all possible bad behaviors as illegal. Thus the civil court system.
The civil court system is for addressing things which are illegal -- violations of the law -- but which are not violation of criminal law. The civil court system applies those things prohibited in civil law, it does not substitute for having laws to determine what is prohibited.
The subset of restraining orders (sometimes called "protective" orders) you are thinking of are available when something illegal has been done, and relate to patterns of activity related to that illegal thing. For California, there are several kinds [0] of such orders:
(1) Domestic Violence Restraining Order: available if someone close to you in specific ways defined in law has abused you in specific ways defined in law as acts of domestic violence.
(2) Elder or Dependent Adult Abuse Restraining Order: available if you are elderly or disabled and have been a victim of certain kinds of abuse.
(3) Civil Harassment Restraining Order: available if you are being harassed or stalked, etc., by someone not close enough to be covered by a domestic violence restraining order.
(4) Workplace Violence Restraining Order: available to an employer to protect an employee that has been a victim of stalking, harassment, violence, or serious threats.
Now, yes, they sometimes cover acts which would not otherwise be illegal, but they actual require something illegal to have happened as their basis (a temporary restraining order can be issued on the claim that such a thing has occurred, and a permanent restraining order only after a hearing to determine that.)
Or putting video surveillance up in public spaces. Also illegal, even for the government.
Or whatever.
Collect the router mac and BSSID? Possibly justifiable. That's like making a map where phone numbers are, physically.
But collecting the SSID?
Looking at the wifi list, I see "Meier family WiFi" and "Meier WiFi upper floor: Finn & Jan" (that's their children, having both the room on the upper floor, and family protection filters enabled for that WiFi).
I see WiFi names that are identifiable, somes that have a little poetry in them, others named as the favourite football club of their owners.
That's creative work and PII.
How is that illegal? That's called a map.
Appealing to child stalking as a way to emotionally charge your argument about radio reception is a disingenuous tactic for this conversation. What's more, people who actually work to promote and secure a safer environment for kids don't need people like you constantly exacerbating parental paranoia with a constant back chatter stranger danger.
Please refrain from emotionally manipulative rhetoric.
Or anything else that's that personal.
The point isn't about what is collected, but that this type of broad data collection exists in the first place.
Let's recap: not eventhe government can do video surveillance of public places, streetview became opt in, the phone book is opt in.
But Google collects SSIDs?
Collecting only the router mac or BSSID might possibly be justifiable, because it's just a map of technical data, but collecting a string where people but creative works in, or names, or jokes?
I've seen families where the WiFi for the first floor had another name than that for the ground floor — specifically, the names of their two children, whose room was on first floor.
Collecting such PII can be problematic.
No. That's not my job to arbitrarily re-interpret what you said to give you a free pass for your disingenuous rhetoric.
> Let's recap: not eventhe government can do video surveillance of public places, streetview became opt in, the phone book is opt in.
The government CAN do video surveillance though. Both our governments do it. What varies is how its deployed and who has access.
> Collecting only the router mac or BSSID might possibly be justifiable, because it's just a map of technical data, but collecting a string where people but creative works in, or names, or jokes?
Look, responsibility has to be exercised in all forms of data collection. But it's also the case that the light that shines out of your house is subject to public interpretation. Standing nude in your window facing a crowded street CAN be illegal in both our countries, as could placing a sign that says threatening things to passerbys. The trigger conditions for this vary between our countries, but they exist in both cases.
> Collecting such PII can be problematic.
COLLECTING PII is seldom the problem. Storing it or promptly and thoroughly deleting it is the challenge. You might argue that you shouldn't have collected it in the first place, and maybe that's true. But given the modern world where we have a rapidly expanding frontier of data analytics, it's actually difficult for real (re: not rhetorical trashbag arguments on HackerNews) people. Often times it's not obvious what PII is until later.
For example, there are people who claim that transactional data can be "anonymized". Do not believe these people; it is nearly impossible to anonymize transactional data. Even mixing users and attempting to delocalize vendor strings will not fix the problems.
But they literally can not at any point ever do it. Video surveillance of public space is a crime, even for the police, government, or security agencies, and it does not happen.
> COLLECTING PII is seldom the problem. Storing it or promptly and thoroughly deleting it is the challenge. You might argue that you shouldn't have collected it in the first place, and maybe that's true. But given the modern world where we have a rapidly expanding frontier of data analytics, it's actually difficult for real (re: not rhetorical trashbag arguments on HackerNews) people. Often times it's not obvious what PII is until later.
The law literally makes that a crime. You have to stop collection of PII, not just delete it at any later point.
Surveillance of public environments via the private security systems is how your government (and ours really) accomplishes this "legally."
> The law literally makes that a crime. You have to stop collection of PII, not just delete it at any later point.
The law's definition of PII in your country is woefully out of date. Same in mine.
I wouldn't be surprised if there were in fact laws against this kind of public surveillance behavior in some jurisdictions in the United States.
=> https://www.reddit.com/r/privacy/comments/3g3xyu/for_wifi_ms...
That would be very not ok if it would happen with wifi off. I turn my wifi off to save the battery, and it wouldn't do much if it was still looking for broadcasts.
It's very different from when you hit "scan" and are actively sending broadcast packets on every frequency and waiting for the wifi routers to (actively) answer. Which really only happens when you pull down the list of nearby hotspots.
This simply isn't true. You'll be using power to demodulate at a minimum. You'll also be using energy to ammplify the incoming signals and a variety of other things.
Listening is actually one of the more power-intensive things a radio does, because it tends to be active more of the time than transmitting does. For many radios power consumption is the same whether transmitting or receiving.
This, is not right.
Nexus 5X, Android 7.0
Sending/receiving data over wifi takes roughly ~8x less power than sending/receiving data over cell.
If you want to save battery you need to turn off data entirely not turn off wifi. Turning off wifi ultimately costs you battery.
How did you arrive at this 8x figure? I don't think this is correct at all. See:
http://people.cs.umass.edu/~arun/papers/TailEnder.pdf
Additionally power efficiency is related to distance from the cell tower which is generally much further away than a wifi access point.
> Our measurements (Section 3) confirm that the transmission energy consumed by WiFi is significantly smaller than both 3G and GSM, especially for large transfer sizes.
Also that's 3G, not LTE which is what most everyone is using nowadays.
Of course Google does its usual, making it inconvenient. When you enable that setting wifi location is completely disabled and many apps which use finer location will trigger a popup to enable it back in order to get a better location.
They do this with any setting that benefits them. For example if you don't allow Google to store your historical location Maps won't remember any locations searched. As if it was impossible to maps store that details locally sigh.
For those wondering, I believe the setting is Settings => Location => => Scanning (in the the vertical dots menu in the upper right) => Wi-Fi scanning (on my Nexus 5 running Android 6.0.1, anyway.)
Is that supposed to comfort one, or make one freak out even more? The usage to mean the former is very.. peculiar, and the usage of the phrase "freak out" rather than, say, "before you are concerned about this and move to change it", does make it seem like that was the intended usage.
https://location.services.mozilla.com/map
Mozilla exchanges the cell location data with the OpenCellID project. Mozilla's cell database is available for download here:
https://location.services.mozilla.com/downloads
For privacy reasons, the Wi-Fi and Bluetooth databases are not currently downloadable, but they can be queried through a web service API:
If you want "privacy" turn off the location services, or your phone, if you want privacy don't take your phone with you.
That said this isn't some "conspiracy" Google actually states when you enable background location services that this will be on all the time even when GPS and the wireless network are explicitly disabled, IIRC even in airplane mode the location background service can be operational without violating FCC regulations.
Orientation/heading from a phone's gyroscope/compass can be pretty reasonable, but most mems accelerometers are pretty much crap for dead reckoning use when loosely attached to a person. I could definitely see some interesting ideas with cell tower position data + heading + pedometer estimation getting merged, but I have a hard time believing that works in practice.
Given a known starting point, or a known point in general this increases both the speed and accuracy of identifying your location considerably even outdoors.
I'm specifically curious about evidence for a commercial smartphone that can track you to room-level accuracy using only IMU + GPS. (Add in wifi or other RF triangulation and it's clearly a solved problem.) In practice with a cell-phone GPS receiver and IMU only, attached to a person it is a hard problem to track a path to within a few meters. Trying to use accelerometer data to get position information over more than fractions of a second in that situation is... tricky.
It is also used for indoor navigation, Google had quite a few talks about this this one is from Google I/O 2013 https://www.youtube.com/watch?v=oLOUXNEcAJk (click to https://youtu.be/oLOUXNEcAJk?t=1985 if you want to see the break down).
There were a few better/more technical talks from 2010 and a few more recent ones that I'm trying to find again.
On android this is exposed through the Fused Sensor Location provider https://developers.google.com/android/reference/com/google/a....
"Fused Location Provider: Get highly accurate location information (latitude and longitude) based on combined signals from the device GPS and sensors."
And the 2nd 2013 talk https://youtu.be/Bte_GHuxUGc?t=400
However the last I heard, powering the gyro + accelerometer constantly was a prohibitive drain on the battery and the relatively low grade sensors used in smartphones made the positional drift rate high enough to be problematic, so I'm pretty sure that the original poster above is misinformed. I'm not aware of any smartphones that use inertial dead reckoning to augment their positioning.
Then skip https://youtu.be/Bte_GHuxUGc?t=700 to for the deep dive :)
You can still do location "manually" by either using GPS or sensor data using the Android framework.
P.S.
I'm pretty sure that iOS has the same thing, I also know that there are a few startups that want to push their own location provider service including sensor based tracking, I've played around with pathsense their location API was faster and considerably* more accurate than Google's https://pathsense.com
*As far as jitter goes, if you are talking about accuracy only to the point of "is jim at the juicebar on the corner of Main St. and 8th.?" they both work pretty much the same.
https://www.reddit.com/r/privacy/comments/3g3xyu/for_wifi_ms....
Your house is also visible in Street View, for precisely the same reason: It transmits electromagnetic waves that are visible from public roads.
And slightly less scary.
In other countries you can ask Google to blur your house.
Why aren't you helping your neighbors?
This guy said he does this in a bunch of cities, driving around the geographic area of the USA where I work in. Very interesting to learn about.
Edit: I am not located anywhere near where Google has an office, so for him to stop by was interesting by itself.
Edit 2: grammar.
It should be possible to reconstruct google's BSSID database, right?
To my knowledge this Google trick was first discovered by the researcher Samy Kamkar (https://samy.pl/mapxss), though the tool no longer works.
When the tool used to work, I tested it using my home router address and it accurately located me. Then, I moved to another house, and the location remained being my old home. Then, after a couple of weeks, it got updated.
I think in the final product the resulting location is not only based off one WiFi address. It might try to crossvalidate using the multiple addresses you can see.
> Something you didn't mention: when a Google-car goes around taking pictures for StreetView it also maps the location and all wifi networks name. So taking a new router with a new network name from a different ISP might work, but only until they come near your house to update their pictures... > - Bakuriu
I am not sure how this makes me feel :-|
https://www.reddit.com/r/privacy/comments/3g3xyu/for_wifi_ms...
"_optout" only gets you out of Microsoft's WiFi sharing of open networks, which allows other computers to automatically connect to your network. To opt out of Microsoft's location tracking of your router's location, you need to go to https://www.windowsphone.com/en-us/support/location-block-li... and input your MAC address (BSSID). Microsoft uses the MAC address instead of WiFi name (SSID), because supposedly they don't collect WiFi names at all due to privacy concerns.
[0]https://www.reddit.com/r/privacy/comments/3g3xyu/for_wifi_ms...
Or maybe we as society do already have reasonable limits where "publicly available" is not equivalent to "publicly indexable".
The types of radiation that you're comparing have two very important differences that influence people's expectations: First, they're blocked by very different sets of substances. Second, we've got a detector for one of those ranges built into our heads. I don't think it's reasonable to treat the two segments of the spectrum in the same way.
I expect vehicles to drive by my home. I expect people in those vehicles to have wifi devices that can see the broadcasts from my AP. I expect their devices to capture that data, possibly store it, and possibly transmit it to another device. I think it's unreasonable to assume that someone won't do that. I don't have a strong argument for how capturing and publicly indexing that information is harmful to me.
Video surveillance of public space is illegal, not even the government can do that.
At least here in Germany.
When a modern phone connects to a non-hidden wifi access point for the first time, it remembers it can connect to that and passively listens for it to announce it's self in future.
When a modern phone connects to a hidden wifi access point for the first time, it remembers that it can connect to that access point, and also that it wont receive any announcements about it's presence in future. So how does it auto-connect in future? By constantly shouting "ARE YOU THERE HIDDEN ACCESS POINT NAMED FOO?". Making you even easier to track.
OK, it's only open wifi data that can be accessed by anybody (nearby), but still "I am not sure how this makes me feel"
Neither has Wi-Fi.