Show HN: Howmanypeoplearearound – Use wifi to calculate number of people around
github.com
github.com
For example, an important piece of data to pharmaceutical companies is which doctors are linked to prescriptions. Some states have rules against disclosing this information. If a company were to monitor target doctor's offices and pharmacies then the distribution data could provide clear indications of who is writing what prescriptions. Would this be a problem? To the degree that prescription filling discloses a health condition that a person considers private, the use of associational wifi monitoring might be seen as a privacy violation.
If this is seen as a problem, what could be done? In a sense, I think that the better solution is on the client/protocol side rather than attempting to enforce some "don't sniff" rule. Given the practicalities of updating clients, something on the rules side would have to be done, although I doubt it would be as effective as a speed bump.
[1] http://www.pewinternet.org/fact-sheet/mobile/
[2] https://twitter.com/conradhackett/status/701798230619590656
I guess you can determine how many people are around you, that have a phone and it's switched on, with the wifi on as well (I personally turn off everything when it's not being used, mostly for battery reasons on this old clunker).
I'm open to suggestions to distinguish routers from mobile phones! Perhaps something like monitoring how "static" a mac address is (i.e. routers should never move and would be much less dynamic than signals from phones).
[1] https://www.comscore.com/Insights/Rankings/comScore-Reports-...
> Specify WiFi adapter (use ifconfig to determine): wlp4s0
> [==================================================] 100% 0s left
> Found no signals, are you sure wlp4s0 supports monitor mode?
Do I need to run airmon first?
Also people think ur a hacker. Heh.
I remember they got into hot water a few years ago when their mapping cars were going around and monitoring wifi data in range.
Do you know if collecting MAC addresses is illegal in UK? In US there is a statue against "intercepting electronic information" [2] but I'm not sure it applies because I don't know whether the MAC address is "electronic information".
There is some precedent, as Google got in trouble for sniffing packets, but they were actually definitely capturing information (emails/passwords) on un-encrypted networks. [3] In any case, I put a warning on the README.
[1] https://github.com/schollz/howmanypeoplearearound/issues/4
The UK act applies mostly to trying to gain unathorized access to a computer system or network. If you put up your own wifi network and simply listen to your own interface's traffic, and other people access your network without your authorization, it's actually those devices connecting to your network that would be legally suspect - but intent matters, so the device accidentally connecting means they're not breaking the law.
In the US, sniffing the portion of a network which you do not own or operate is considered illegal wiretapping (or at least, it was at one time; I haven't looked into the most recent court cases). But if you own the network (your network interface in managed mode is basically your own AP), you can sniff it.
Your LICENSE should probably explicitly mention that this tool is for research purposes, that you provide no warranty whatsoever, and that anyone using it should follow all local, state, and federal laws at all times.