How does Apple privately find offline devices?
blog.cryptographyengineering.com
blog.cryptographyengineering.com
I lost my phone like a dufus about a two weeks ago. Battery died and I had no idea where it was. When I pulled the my google location history, it was too coarse to tell me anything other than 'at your house'. However, I was able to pull the raw data from google and post process it by time stamp into a series of rasters that were fine enough for me to see that the phone was definitely in the bedroom/ bathroom area. After processing my data, finding my phone took all of a minute.
See I wasn't sure if I lost it in the couch in the living room, the office, or the bedroom. This got me within a few feet.
Is that something Google's not doing with the data, but could? (E.g. they don't because their maps don't show most houses precisely enough or whatever, so it wouldn't be useful?)
Or is it relying on the fact that you are triangulating or similar from the known exact position of your WiFi routers or similar down to the inch, and Google doesn't have any way of knowing that?
By the way, I'm pretty sure I've seen that Google's advertising targeting is only allowed to use "neighborhood level" location, which is designed to be coarse enough to not allow specifying individual people.
- it is opt in,
- it can be deleted by me
- is not given to anyone else
For all my trashing of Google lately (check my comment history) I actually expect and belive them to defend my raw data in a way that few others are able to. It all boils down to incentives:
- as long as they keep the data between them and me they can sell targeted ads again and again. If the data leaks then others can skip the middle man.
- as long as they keep their reputation as nice guys that is an immense advantage.
Now this might of course be changing, so everyone should consider if they personally trust this arrangement going for the future:
- it seems some part of the organization is tightening the screws around the Chrome team to squeeze out more revenue.
- of the data is available there is always the risk of attacks both cyber attacks as well as legal attacks.
>In going through a set of privacy popups put out in May by Facebook, Google, and Microsoft, the researchers found that the first two especially feature “dark patterns, techniques and features of interface design mean to manipulate users…used to nudge users towards privacy intrusive options.”
https://techcrunch.com/2018/06/27/study-calls-out-dark-patte...
Maybe it is not clear but I was talking about location history.
At least I think I had to opt in to that at some point.
For example:
>Ways that Google tricks users into sharing location
Android users are pushed through a variety of techniques:
Deceptive click-flow: The click-flow when setting up an Android device pushes users into enabling “Location History” without being aware of it.
Hidden default settings: When setting up a Google account, the Web & App activity settings are hidden behind extra clicks and enabled by default..
Misleading and unbalanced information: Users are not given sufficient information when presented with choices, and are misled about what data is collected and how it is used. Information about location data being used for advertising, for example, is hidden away behind extra clicks.
Repeated nudging: Users are repeatedly asked to turn on “Location History” when using different Google services even if they decided against this feature when setting up their phone.
Bundling of services and lack of granular choices: If the user wants features such as Google Assistant and photos sorted by location, Google turns on invasive location tracking.
https://www.forbrukerradet.no/side/google-manipulates-users-...
More alarmingly, when users attempted to turn off location tracking:
>In a wonderfully clear example of “dark patterns” designed to mislead users and retain control over their data, Google continues tracking your location even when you turn off Location History and are told that “the places you go are no longer stored.” Google says it tells users, but its disclosure is the bare minimum and users are discouraged from further interference with data collection.
https://techcrunch.com/2018/08/13/google-keeps-a-history-of-...
I'm pretty sure they've both been caught with their hands in the cookie jar doing things they swore they never would.
If it's happened time and time again, it should be easy to pull up a source, right?
When Google bought the advertising network DoubleClick in 2007, Google founder Sergey Brin said that privacy would be the company’s “number one priority when we contemplate new kinds of advertising products.”
https://www.propublica.org/article/google-has-quietly-droppe...
https://www.theguardian.com/technology/2018/nov/14/google-be...
https://www.edweek.org/ew/articles/2014/03/13/26google.h33.h...
"While the allegations by the plaintiffs are explosive, it’s the sworn declarations of Google representatives in response to their claims that have truly raised the eyebrows of observers and privacy experts. Contrary to the company’s earlier public statements, Google representatives acknowledged in a September motion to dismiss the plaintiffs’ request for class certification that the company’s consumer-privacy policy applies to Apps for Education users. Thus, Google argues, it has students’ (and other Apps for Education users’) consent to scan and process their emails."
"In November, Kyle C. Wong, a lawyer representing Google, also argued in a formal declaration submitted to the court in opposition to the plaintiffs’ motion for class certification that the company’s data-mining practices are widely known, and that the plaintiffs’ complaints that the scanning and processing of their emails was done secretly are thus invalid. Mr. Wong cited extensive media coverage about Google’s data mining of Gmail consumer users’
>Mr. Wong’s inclusion of the following reference to the disclosure provided to students at the University of Alaska particularly caught the attention of privacy advocates: The University of Alaska (“UA”) has a “Google Mail FAQs,” which asks, “I hear that Google reads my email. Is this true?” The answer states, “They do not ‘read’ your email per se. For use in targeted advertising on their other sites, if your email is not encrypted, software (not a person) does scan your email and compile keywords for advertising. For example, if the software looks at 100 emails and identifies the word ‘Doritos’ or ‘camping’ 50 times, they will use that data for advertising on their other sites.” “The fact that Google put this in their declaration means we take it as true,” said Ms. Barnes of the privacy watchdog group EPIC. Google’s sworn court statements reveal that the company has violated student trust by using students’ education records for profit.”
https://www.washingtonpost.com/news/grade-point/wp/2016/02/0...
https://www.eff.org/press/releases/google-deceptively-tracks...
This isn’t a controversial point, it’s well observed.
[1] sometimes outside if they think they can argue it to be a novel situation
Their only goal is the make money - by definition. It is not that people assume that they are evil - just that they will follow on things that will earn them money.
Reminds me of Superjail, which is an uber-maximum security jail inside a volcano, that is itself inside a second volcano
By my data, do you mean data from Google Android Device Configuration Service?
If you're logged into Chrome or GSuite tools from desktop locations, I just wonder how useful the data from those other products would be, if it even has location data.
I'm downloading my data archive to check it out...
So although the numerical precision is pretty high, the actual accuracy is pretty low, I think I pulled all the points from 2am-6pm in the final time stamp to figure out where the phone was.
This took about 20 minutes to hack together, and I found the phone in 10 minutes of looking in the 'right' spot. My phone had fallen behind the bedside stand and found a way to balance itself between the bed and the baseboards. The bed post is ~phone width, so even looking, you just couldnt see it.
That being said, I work in the geospatial sciences doing geospatial data processing, so 20 minutes for me may not be 20 minutes for some one else.
Yeah, I have these moments too. Could be a good disinfectant for keys, I guess.
My car got broken into and my iPad nicked. I was able to locate that, however, the cops here in NZ were really unhelpful.
They said the GPS location wouldn't be sufficient for a search warrant as they have had many cases of false positives.
I said I would give the ssid and ip address of their wifi network, even then they wouldn't agree for a raid.
It was only when the thief (who was a minor) took the pic of his family member, which I then furnished to the police (via iCloud), they could do something.
Wondering what good is technology, if the law takes a while to catchup, well at least here in NZ.
Smaller crimes like bicycle theft or small electronics are basically "who cares" to the police. Many police departments don't even do bicycle registrations anymore.
Even car theft has sort of fallen to insurance companies to take care of. A lot of people just want a police report to turn in to insurance so they can get a new car.
I don't know about serious crimes. Are people more often caught with lots of data and the erosion of privacy?
But yeah, that does mean a lot of petty crime goes unpunished. Stealing a bike here has become normalized - as in, "my bike got stolen, I need to get home so I'll just steal another". Mind you that's only possible with shoddy locks.
Because many more people are affected by minor crime than major crime. In the UK, where the police's funding has been reduced significantly, it's next to impossible to get them to do anything for burglary and minor thefts (although they're quite reactive if you say something impolitic on Twitter).
because of
> Stealing a bike here has become normalized - as in, "my bike got stolen, I need to get home so I'll just steal another"
There's three options:
1. We abolish ownership
2. Everyone is responsible for protecting his own stuff, resorting to vigilante justice if he finds the thief after the fact
3. The taxes we pay fund police and courts to bring justice.
Option 1 is a version of socialism, option 2 is anarchy, that only leaves us option 3 if we want capitalism.
All your options assume a perfectly rational world. The world we have now is not one of those 3 options, but it exists. Things are often internally contradictory.
Services like Uber are interesting because they essentially strive to eleminate ownership by eleminating the thing to be owned.
The local politicians are apparently very liberal about their views on police (do not support), so they keep the pay as low as possible. All the police have to live outside the community and commute to work the area since it is unaffordable for them to live here.
I’m actually surprised they serve as well as they do under the circumstances.
https://www.seattle.gov/police/police-jobs/salary-and-benefi...
https://splinternews.com/how-an-internet-mapping-glitch-turn...
Is trespassing to retrieve stolen property still trespassing?
The story goes that a man wakes up in the middle of the night to the sound of burglars looting his garage. Given the occurences of aggravated robberies in SA at the time, often involving guns, he didn't want to confront the miscreants himself, and so called his local police department.
Apparently since no actual violence had been done at this point, the police-person to whom he was speaking claimed that they had no free units to come and attend, and that they'd send a car round in the morning to collect evidence. At this point the call ended.
The man who was being burgled was understandably unimpressed with this, thought about what he could do, and then rang the police back.
"Don't worry about the burglars here. I shot them." he says.
Within minutes his house is surrounded by police cars, and the burglars are under arrest.
The commander of the responding officers says to the man "I thought you said you shot them?"
The man replies "I thought you said you had no units free?"
An active shooting incident would certainly reshuffle the prio list...
It was being pinged in a gang prone area, I wouldn't have done it anyway.
If an Apple device is constantly emitting a BLE beacon code that can't effectively be changed in any way by a thief...
...then unless a thief keeps the device in their basement and never has anybody visit, your stolen device will almost certainly be detected sooner or later, and then you just call the police?
Even if the thief has sold it by that point and disappeared, if local law means the stolen good reverts to you, then people would quickly learn never to purchase any phone there's even a chance of having been suspiciously acquired.
Am I missing something here?
So yup, sounds like they’ve either resorted to stripping them for parts or selling them whole (and still firmware-locked) to innocent buyers in places where you’d have practically no legal recourse — who then become victims to the theft as well, ironically. And by then, of course, you’ve likely had a new phone for long enough to not lose much sleep over it.
https://krebsonsecurity.com/2017/03/if-your-iphone-is-stolen...
Emergency contacts (accessible while the phone is locked) + Facebook?
Guessing here but maybe using "emergency call" and another phone to get the caller ID?
For phones, how often is this really an issue? Sure, this is useful for the Tile type "dumb" devices... but if my phone has no cell or data service... it's probably because the battery is dead.
Again complete speculation, I have zero clue if the current hardware is even capable of doing this.
They could probably use a cut down derivative of the W2 chip used in AirPods with the audio codec etc. removed. I’m guessing phone batteries reach a point where they’re still storing energy but can’t provide enough current to safely boot the whole phone. The BLE chip could sip on the remainder of the battery for a long time.
* I lost the phone hiking somewhere with no signal
* I lost the phone / it was stolen while in airplane mode
* I lost the phone while traveling abroad without any local service
This finding service will work for wifi-only ipads, wifi-only apple watches, and macbooks in addition to the likely tracking tokens.
Try it. Wrap your phone in tinfoil then call it. It will still ring.
It's harder than it looks to make a Faraday cage.
Either way once you remove the phone from sight, the suspicion is probably over. The only next step is to kill the signal.
1) The iPhone will be considered the "master" (aka BLE Central device)
2) All of your devices that you enroll in your "find my" service will be required to sending out a periodic BLE beacon or a similar bluetooth packet (BLE peripheral device)
3) The iPhone will periodically listen for BLE beacons and upon receiving that beacon it has 3 options:
->option 1, save the time/location when it saw that beacon
->option 2, scan the device with a BLE "scan request" operation which asks the device to provide more information -- it provides the "scan response" packet which can and often is different from the main advertisement packet
->option 3, connect to the device and query further information like your macbook battery level and maybe other info
For option 1, the iPhone never needs to send a packet ever and will simply have its BLE RX radio stage on listening for advertisement packets -- which are sent in clear text for anybody to listen to. The RX stage is listening periodically and works on a statistical basis where if the beacon side is transmitting very rarely then you can easily miss the beacon.
So.. what you should take away from this is that highly likely Apple will only allow the iPhone to be the master and all of your other devices will be periodically sending out beacons. So if you have this enabled and you walk around with your iPad Pro and your iPhone together and people sniff bluetooth packets, they can track when you walk down the sidewalk past you every day. For example if you live near a busy street in New York or something, start sniffing for bluetooth packets and you'll find tons of stuff. Tons.. most of it is random bluetooth headphones, but pretty soon it will be iPad Pro's.
It could have an X-hour "deadman timer" after which if it still hasn't successfully phoned home and been told it's not lost, it starts pinging?
It would be useful for those.
https://www.milwaukeetool.com/OneKey
Basically anyone who runs the Milwaukee One Key app will watch for signals from tools and other devices with the One Key transmitter and upload the location. So if your tool is stolen and comes within range of someone running the One Key app the location should get uploaded.
I would imagine something along the lines of TOTP would provide a better mechanism here. There would be no need to scan a whole list of pseudonyms, and the BLE would rotate the identifier it transmits frequently. The lassie device can include GPS timestamps when it reports the device to apple.
I have not seen this before. Trying to wrap my brain around how this works. In terms of ECC I thought public and private were a single pair. Can anyone explain what is going on with public key randomization?
https://github.com/bitcoin/bips/blob/master/bip-0032.mediawi...
It is also easy to solve this simply using ECC and ECDH. I just wrote a scheme on the board in the office. It might have slightly larger data payload than the deterministic wallets approach.
If you asked me to implement "randomized public keys" I would generate a master key pair (MPUB and MPRIV). Then, I would combine MPRIV and a random value N in a one-way function to make a new key K. I would use K as effectively a "random public key" and use it as if it was MPUB (the one-way function would have to output a K that is in the same format / usable like MPUB). I would distribute N along with K, as N is useless without MPRIV.
I have no idea if that is how they did it but that's what comes to mind.
Couldn't "random value N" just be a nonce that only Apple knows?
As with anything public + blockchain it had all the Cryptoeconomics incentives problems you would expect and I never solved them.
Finding a lost device has much lower stakes than proving an alibi in court so I see how this model would work.
The threat I'm thinking of is some organisation that is able to crack the private key at some point in the future and therefore able to work out where you have been in the past.
Of course, the phone's location in the recent past is exactly what this system is designed to produce. Would it be possible to rekey the connection on a regular/opportunistic basis?
As for the tracking: I really like the idea. However, in my country finding your device isn't the issue, it is getting it back that's the problem. Police won't go and enter the particular house were your device is.
I would like 100% passive bluetooth. (and wifi, and nfc)
The idea would be yes -- connect to bluetooth headphones or your car. Connect to wifi in your home. Allow NFC transactions on command.
But no, don't promiscuously advertise your device. Don't look up every bluetooth beacon you encounter or crowdsource every wifi access point.
Many people disable Wifi when they're not planning to be actively connected to a network. Even ignoring the privacy benefits, it can improve battery.
I'll add my voice that this is nice, and I appreciate Apple's approach and privacy improvements, but I'd kind of like to be able to turn Bluetooth on and off the same way I can with WiFi.
I want most connections on my phone (with a couple of small exceptions) to be user-initiated only.
In a recent iOS update, it turns on automatically again; you can only disable it "until tomorrow". Not sure if that's until midnight, until "morning", but it doesn't seem to be "for 24 hours".
- hidden ssid access point - your phone will broadcast unique data looking for it (initially the ap must listen and respond)
- regular named ssid access point - your phone can passively listen for the name and join if it is available. (initially the phone must listen and respond)
That said, I don't know if apple NFC works that way. Apple can use NFC to read nearby NFC tags, and possibly become an NFC tag, but I don't know if it can respond in a static way without power.
Lassie's help needs to have some limits otherwise it may quickly drain batteries or mobile plans especially in roaming.
Sending the locations from these pings likewise also uses negligible battery, as Apple already coalesces timers and network traffic like push notifications.
I don't understand the mentality where people think Apple would have announced this without doing any testing on its battery life impact.
iPhone's have about at 10X larger batter than that. So iPhones can do this for ~20-30 years if configured correctly.
[0] https://www.wired.com/story/apple-find-my-cryptography-bluet...
1. Get BLE tracking tags, and register them with Find My.
2. Covertly attach the BLE tracking tags to things your target owns (backpacks, cars, bikes, etc).
3. You constantly get updates on your tags locations via their iPhone and other iOS devices near the BLE tag(s). This gives you their approximate location and movement history, facilitated primarily through their own iPhone and data plan.
I mean, if you can accomplish step 2, you don't need Apple at all.
If Apple does come out with a cheap Tile-type device with a then this could be a legit concern. If you hid one in a person's belongings then you'd get hits from their phone- and turning it off wouldn't work, because random passersby would report their location as well.
This could even be better (worse) than spy-gear standalone GPS trackers because the battery would last for a very long time.
Using the same type of "mesh network" Apple mentioned, other users you can track that Tile for you: https://youtu.be/WG7BdW7iFzo?t=58
(I'm not familiar enough with Tile to know if that feature is continuous, but I wouldn't be surprised if a competitor does).
[0] https://www.macrumors.com/2019/06/04/apple-tile-item-tracker...
Source: worked on Bluetooth for years
But that does nothing to protect your privacy against Apple.
I already have to make sure that I disable WiFi and Bluetooth when I enter commercial establishments. Now I have to stop using Bluetooth whenever I leave my house?
If you're talking about apps on your phone tracking you by looking at nearby wifi networks, then Apple also fixes that in iOS 13.
In addition, I believe apps that use ibeacon technology can respond to specific ibeacons. But I think your phone can become a beacon.
I suspect (but am not certain) that if your phone is running app XYZ it can talk to other phones running XYZ through the XYZ registered beacons (if location services are on for app XYZ).
Also, just for an interesting example of where some of this stuff can go... The target app will change the price of an item if it finds you are in a store (search "target app price switch").
``` iOS uses a randomized Media Access Control (MAC) address when conducting Wi-Fi scans while it isn’t associated with a Wi-Fi network. These scans could be performed in order to find and connect a preferred Wi-Fi network or to assist Location Services for apps that use geofences, such as location-based reminders or fixing a location in Apple Maps. Note that Wi-Fi scans that happen while trying to connect to a preferred Wi-Fi network aren’t randomized.
.... [continues with all the cases] ```
The short answer is because it makes me feel better.
The long answer is that it prevents tracking my movements within a store. Stores appear to be increasingly installing and using such trackers, and I do not wish to be tracked.
Not being able to be identified personally, or to be identified as the same person who was there last week or that I also went into other stores isn't sufficient to me.
WiFi can be used to track most people's phones because they'll have personally identifiable networks they're set to auto-connect to. Randomizing the Mac address is not enough to prevent tracking in that scenario.
Unless Apple has some way to guard against this that I've never heard of? But I don't think they do.
JohnFen's root comment is totally wrong (Apple is encrypting your location so even they can't read it), but on the WiFi side of things this seems spot on to me. Turn your WiFi off when you leave your house.
I use one labled ‘Car’ that turns off wifi, enables cellular data and BLT for the stereo and terminates after it ensures my (non-DNS) VPN is on. The other, ‘Home’ turns off cellular data and BLT, wifi on and again ensures my VPN is still active.
Also if you’ve got anything newer than a iPhone 6, you can 3D touch the settings icon to a pop-up menu to Bluetooth, Wi-Fi, Cellular Data and the Battery sub-menus. From there it’s an extra tap or two to disable stuff completely.
Formatting is likely terrible, I mobile-phoned this in..
Absolutely not true. This is E2EE. This is the whole point of the article.
Buy a Nokia, perhaps?