Retail stores use Bluetooth beacons to track customers
nytimes.com
nytimes.com
There are companies offering some basic functions like “wayfinding” so the retailer or mall wants to give wayfinding to the user in their app. Sounds good, in fact it’s cheap, and they will even handle the beacon deployment... hook up sdk to wireshark and find it sending lots of data, some of it comes to me (retailer api) but a metric ton of it is going back to the provider. Being able to see the installed solution in multiple retailers and seeing the app code you start to notice persistence between them... retailer and mall didn’t even ask for this. They just wanted wayfinding.
I did quite a bit of client work here too, specifically around using already existing surveillance camera networks to build user profiles.
At the end of the day the goal is to optimize for the intersection of "what the user wants" and "what we want to sell." So, a low collection system will give bad recommendations and a really good recommendation system will have an immense amount about the user.
Now that I talk with people on the other side of this, it's clear that most don't really care as long as they are getting good suggestions. I had this conversation just a few weeks ago with a young lady and her take was: "It's kind of creepy, but if it gives me good suggestions, I don't really care."
That’s a really weirdly specific issue, and hard to imaging a similar scenario that would affect my life in some equally horrible way.
Am I missing something? Why should I be so afraid of Home Depot or whatever knowing a little bit about me?
They knew this because marketers get near real-time access to prescriptions, hospital admissions and other things.
You should care because your information will be sold or traded, and behaviors can be correlated against medical and other outcomes.
Are you a divorced dad who has moved within 90 days and play daily fantasy sports? I can buy a list that will find you for $250. You are a risk for opioid addiction and may get denied service in the future for medical issues. Or you may attract advertising tailored to get you to gamble or drink more, when you are at your most vulnerable.
I try to maintain a "lite" internet footprint (no facebook, only social media is LinkedIn, I use a VPN when I can) ... it's a little disturbing to think that someone can just purchase my buying history and use it as, essentially, an attack vector to serve me ads or gaslight me into buying stuff I don't really want or need.
Am I'm being naive?
In our case, I found out the marketing list from Enfamil and bought it for my zip code. I complained to the hospitals’ privacy officer and the state regulator and found that everything was legal.
There is a lot of data on the topic...
Prescriptions: https://www.theguardian.com/technology/2017/jan/10/medical-d... Linkage to lifestyle data: https://www.statnews.com/2018/07/18/health-insurers-personal...
In our case, the hospital pharmacy issued drugs to her indicative of a pregnancy. The pharmacy or insurer provides that information in real time to data brokers. The pharmaceutical companies assign quotas and send salespeople for certain drugs. There are other ways for data to get out that we’re not certain of. Perhaps the insurer “anonymizes” and sells subrogation information. Or the lab. In any case, they knew that my wife was admitted to an OB floor of a hospital, but didn’t know the outcome.
It’s not going away. The US government uses these same techniques with companies like Google to combat extremism or terrorist conversions — they actually use factors like this to target potential recruits with counter-information via ads.
Both of those are the wrong venue for complaint on this issue; the hospital privacy officer exist to protect the hospital from liability and will never confirm to an outside party, especially a complaining party, that an act is a violation of the hospital’s legal duty, and the state regulator isn't responsible for enforcing federal law.
The right place for complaint is the federal Department of Health and Human Services Office or Civil Rights, which is actually responsible for enforcing the privacy provisions of HIPAA. Or getting your own attorney.
How the hell was trading individually identifiable hospital admittance and treatment information not a HIPAA violation?
I went to a Norton Hospital Immediate Care Center and paid cash because I didn't have insurance at the time. Because I paid cash, Norton turned all of my contact information over to a company that sells health insurance and gives loans to pay for medical services. They bugged the everlovin' shit out of me with automated phone calls until I decided enough is enough.
The Immediate Care Center denied giving any information out and were shocked this was happening, but Norton central billing knew about it, said they would remove me, but the 3rd party already had my info so it was too late.
The 3rd party were complete assholes, and when I got fired up because I wouldn't give them even MORE personal info to be removed from their call list, they said it was my fault: if I had just called them back and given them the 15-digit code, an agent would have removed me. That's also a lie, because I eventually did try that.
To protect my privacy, I told Norton my phone number had changed, and my new number was 812-555-1212, which is the 812 area code directory assistance number.
They did the same thing to my sister when she paid with cash because her husband had just changed jobs and she didn't have the new insurance info yet.
HIPPA is a joke.
Would you mind sharing more information about how you found that list (esp for a given zip), and how you think they tied that information to an address? My email is in my profile, if you wouldn't mind reaching out.
I don’t have ready access to it now, but it had all sorts of stuff, probably about 150 columns. Stuff ranging from likely medical conditions to car owned, to stores frequently shopped to specific consumer products used.
I imagine it being available and cheaply for sale is also a boon for various financial crimes/fraud.
It's not home depot specifically to be worried about knowing a little about you, but about them not being competent to control that data and everyone's little bit becoming a lot more significant and dangerous when combined.
edit: Also, the same type of information can easily be used later by government. I imagine if Uyghurs were not being specifically targeted by the Chinese government for cultural extermination there would be little trouble in their cultural identity being discernible from certain purchasing profiles. Once they are rounded up into camps, the last 15 years of detailed surveillance about them becomes very troublesome for them.
What will employers find when they use this for background checks? If you regularly buy alcohol a drinks_alcohol flag could be set or a health_indicator could increase.
This is an Unpopular Opinion, but IMHO thats kind of a reasonable stance to take.
I disagree. The recommendation is immediate and apparent to the end-user. The negative potential uses/consequences of all the other data collection are not.
It's funny, but when an unsuspecting person gets a home loan they can't possibly afford pushed on them by a shifty mortgage broker, people here cry bloody murder. But when people ignorantly consent to having their data harvested for the pleasure of better targeted advertising, the tech community happily says "but they asked for it!"
What? I feel like the only topic the tech community gets worked up about that nobody else cares about is digital privacy. There are always people on hacker news condemning a lack of privacy and targeted ads - I'd venture it's the majority of people on this site that feel that way.
Also, point out that you're going to sell that data to anyone who asks, link it to your facebook profile and CC data and people start to get a little uneasy. The reason people tend to view these things as OK, is that they see it as a 2 sided transaction and don't realize the implications of unregulated data. If we had clear laws around data, and consent of use of data like GDPR in the EU, it's a completely reasonable stance to take. (even with GDPR, there's a lot of data in things like tracking beacons and video recognition in public that are difficult to consent too or have data removed . . ..)
A large portion of it was actually focused around security and not product marketing, but the tech is the same.
Reminds me of an old Mac application from PowerPC days that would sense your phone's Bluetooth coming into the room and automatically unlock your computer.
I thought it was pretty cool.
Current Macs have that possibility built-in, but it only works with the Watch.
Maybe built-in to the OS. You can definitely do this with any Bluetooth device and any Mac with both free and paid software.
If the Bluetooth beacon configures itself as a master, and enters inquiry mode, phones that pass nearby will happily respond with their Bluetooth ID (see https://www.bluetooth.org/docman/handlers/downloaddoc.ashx?d..., section 8.4).
You can also do the same with Wifi access points: Phones are constantly broadcasting their MAC address during active scanning for networks. The location from signal strength isn't as good (a Bluetooth beacon can pin you down near the Yoplait yogurt, a Wifi beacon and signal strength measurement just put you in dairy) but it's getting better (worse?). See: https://www.crc.id.au/tracking-people-via-wifi-even-when-not...
I imagine it would not be perfect but would be acceptably easy to use these "anonymous" MAC addresses to connect you to a name and address on a debit card. If your MAC and 20 other people left the store Friday at 2PM, and you and 20 other people went through checkout, and then your MAC and checkout are seen with 20 different people next week it's pretty trivial to identify you.
The cynic in me, though, says that even a minor loss of fidelity in tracking data weighed against the minimal risk and cost of building the spyware makes it worth building both.
Without these trojans the store would have on its hands a major networking infrastructure project. With these trojans, all they have to do is drop a few battery-powered beacons in their venue and store their IDs along with coordinates in a database.
If the beacons increased Wal-Mart's revenue by 1%, the "major networking infrastructure" project could be a $5 billion department, larger than Google's entire R&D operating expenses.
Walmart has been adding cameras on high shrink isles that are almost eye level. At some point they might add even more cameras for "security" that are also used for eye tracking. Think of all the opportunities to optimize product and ad placement.
I thought the name’s embossed on the card, but not on the magstripe/EMV chip data?
Start sentinel — one character (generally '%')
Format code="B" — one character (alpha only)
Primary account number (PAN) — up to 19 characters.
Field Separator — one character (generally '^')
Name — 2 to 26 characters
...https://www.emvlab.org/emvtags/show/t5F20/
There is one store in my neigbourhod where the payment terminals show this field (my full name) on the screen during checkout. I was very surprised when I noticed this the first time.
But apparrently not all card issuers fill the field with correct data. One card, a prepaid Visa from a big fintech, has "N/A" programmed in the field.
Just to reiterate - this was _entirely passive_. I did nothing but enable the Bluetooth presence detection module in Home Assistant on my Raspberry Pi, and over time it built up a detailed log of when nearly all of my neighbors were home or away.
Luckily I was able to quickly turn off tracking of devices that weren't explicitly enabled.
What confuses me, is that I thought iPhones had randomized MAC addresses? In the Home Assistant known_devices.yaml file, you can give aliases to phones based on their MAC address. And my iPhone has never changed it's MAC address, because Home Assistant continues to track it with ease. Not entirely sure how that works.
The good news is that this technology does not tell the AP where you are, only the device knows. However an app on your device could share this information with advertisers.
https://www.crowdconnected.com/blog/testing-wifi-rtt-on-andr...
https://www.theverge.com/2013/12/6/5181302/apple-store-ibeac...
Beacon Technology Arrives in 50 Target Stores (2015)
https://corporate.target.com/article/2015/08/beacon-technolo...
This will probably wreak havoc on traffic counters and other infrastructure that use bluetooth bacons to do things like monitor highway congestion and foot traffic
I actually implemented a nearly identical system for my senior design project, except we targeted the smart home ecosystem. Basic use cases would be automatically turning on/off lights or having a music stream/temperature preference/... follow you as you move throughout your house and enter/leave rooms. All implemented by an app on your phone detecting strategically placed beacons.
They've always done this. I think you have your threat model inverted. Beacons aren't tracking phones around stores.
3rd party SDKs installed in apps are tracking user's indoor location via beacon triangulation and uploading that data. A subtle, but important difference.
It began simply because Apple said "...iBEACON.." and everyone corporate wanted the new buzzword in their portfolio to let people know how hot/hip/tech they were (toys -r- us considered it for awhile) so they could pull the kids away from the internet and back into brick-and-mortar. How can we use these? What are they good for? No one really cared, they just wanted them in the store and we were there to sell them that (at a premium).
In 2015 - indoor location was bogus. Everyone in this forum seems confident that there are multiple ways you can determine location with Wifi (round trip packet time) or bluetooth (RSSI). A cacophony of radio in a catastrophically noisy environment does not work to provide reliable location information.
In fact - it was so bad, that there were a handful of other equally unrealistic solutions being pedaled by everyone from universities to light-bulb manufacturers. One such solution was to profile the accessible space of a building using a phone's compass, and then use the observations from a client device compass to identify how generated patterns correlated to the profile for the building.
The torrent of data you see pouring from your phone to the service via wireshark is real-time sensor data that is being used to feed a service side bayesian / markov-chain / monte carlo / kalman-particle filter / keyword soup monstrosity trying to generate some possible marginal confidence in a probable location. We found that this system was most effective in turning your phone into a pocket warmer, but sold like hot-cakes in a B2B setting wherein the intended end user had absolutely no voice.
Corporate wanted to buy it so they could sell advert-space (pop-up coupons) to affiliates. So we sold them something that worked barely well enough to provide a one-popup demo to potential interested parties. The affiliates bought the magic, corporate paid our company an arbitrarily large quantity of dollars for the service.
A deployment of thousands of coin-cell driven beacons per store, placed within reach of bored youths, maintained by an underpaid associate staff is of only questionable utility.
On a scale of things to worry about, ranging from nuclear holocaust to e. coli in your produce - this ranks a solid -3. In fact, in the 4 years since I've worked in this field I think the only advancement that has been made is that it's harder for third parties to sell because no one can do it well, so why not just do it in-house? It's cheaper and has the same garbage result.
If you think I'm wrong - go do it yourself. All these signals are easily grep-ed within any store (there's no way to make it proprietary), and you can create your own model and out-sell the proprietor. Surprise me. With an actual, viable client-oriented product (and assuming users actually want reliable indoor location) you'll make bundles selling it to the valley. Everyone is trying to do it (even cisco tried for awhile) - no one has.
Michael Kwet has read all the marketing copy, and rewritten it for popular consumption as a product. The insight/value provided by these systems is far more sparse than implied.
The more complex a method is at tracking someone, the less reliable it is.
People fear too much of what can be done with the fancy ways of tracking while overlooking simpler ways that are much more effective.
> These companies take their beacon tracking code and bundle it into a toolkit developers can use. The makers of many popular apps, such as those for news or weather updates, insert these toolkits into their apps. They might be paid by the beacon companies or receive other benefits...
Ban this, full stop, on both ends of this transaction. The Reveal Medias and the scummy app devs using their ~~SDKs~~ trojan horses. At the very least these apps need to be named and shamed, I find this fraudulent and extremely difficult for end users to police.
I have very minor hope that Apple at least will one day shine light on this or ban apps who are not transparent about the data they're sending and to whom, as it doesn't conflict with their business model and they seem to be moving there. For now I have to essentially disable bluetooth when I get out of my car.
It would be naive to point the finger at Facebook listening to you, it would be more accurate to assume its EVERY OTHER app (including FB) gathering data about you and your surroundings - MAYBE ONE IS ACTUALLY LISTENING - but whether any individual app is or isn't, the data brokers have all the data as well as other people like you that have probably reacted to the same external stimulus and can be predicted to be thinking about a certain product around that point in time.
POOF - an ad about that thing you talked about, now on your Facebook feed.
Zuckerberg gets hauled in front of Congress, accurately says "what? no we don't do that", data brokers and software engineers laugh to the bank and let Zuckerberg get crucified for their sins.
It's particularly frustrating given how hard I try to disassociate myself and my family from "data brokers" and then I read another thing like this.
I helped my sister look at a new car an hour away in another town. Back home that evening YouTube was suddenly suggesting new car videos.
Not so much Bluetooth as my own fault for using Google products and tracking but still it was disturbing. I did not search for anything car related myself or for my sister all I did was visit a car dealership.
Not being snarky, genuinely unsure what would need this. You’re definitely right that a single app with permissions and the sdks would be enough.
I work for but don't speak for Fitbit.
It's not even too big of a stretch to realize how many free WordPress frameworks out there collect and sell aggregated site visitor data. I mean... if you're using a free Google Analytics service, do you honestly think they're not doing something with all that access to your site info?
At least, that’s the situation to the best of my knowledge.
They've already banned these SDKs in the kids category. I'm sure the next step is to ban them everywhere.
Adtech industry needs to be torched. GDPR was a step in the right direction, but unfortunately isn't nearly enough (I'd start with more aggressive enforcement of it, though). Something to pressure your politicians for.
As for people using services subsidized by adtech - there's no rule of the universe that says you can either pay everything in cash, or have it free with ads. Those are only two particular business models out of space of many. Getting rid of adtech will only make ad-powered service providers switch to the next best model, hopefully a more ethical one.
The question you're posing is equivalent to "what about all the people who couldn't afford X if providing X wouldn't involve toxic chemicals poisoning their water supply?". Societies around the world consider many business models unacceptable; I'm only pleading that advertising as practiced be added to the list of such unacceptable business models.
What annoys me is that weather is built into both popular phone OSes, so I am not sure why people install ad/tracking apps to get weather information. (What makes me sad is that I really like Weather Underground and subscribed for years... but now their website is super slow and bug-ridden, and I believe it's officially been canceled by their new corporate overlords. So I have no real good way to get "advanced" radar products except via GRLevel3.)
My method delivered.
Imagine if using an app on your iPhone was regarded as more safe than visiting a Web page produced by the same organization, because Apple protected you more than Web standards do. It's a definite technical possibility, and I suppose it might make business sense for Apple.
Malls can then see which stores have highest foot traffic on what days, etc. It's actually one of the things that justifies the expense for huge, expensive free wifi deployments. And it is used to more accurately price locations around malls.
The other alternatives to getting the same kind of data is security camera analytics. Sometimes literally someone just watching footage and taking notes on who they see and what kind of demographics, etc. Which is problematic in it's own right.
If the app’s knowledge of your location provides some service and the user is opting-in, this shouldn’t be a problem (just like I opt-in to provide Google Maps my location).
The keys here are (1) users should be aware that an app knows your location, and (2) User should have the ability to opt-in to providing my location to the app. The mobile operating systems should do a better job of making the user aware and making it very easy to opt in or out.
Maybe an ideal solution would be where (assuming the user opts-in) the OS automatically controls whether an app has the ability to use Bluetooth locationing when the GPS detects that I’m in a certain area. For example, the Target app is prevented from using Bluetooth tracking most of the time, but when my phone GPS sees that I’m in a Target store it automatically enables it while I’m there, and disables it when I leave.
https://www.vice.com/en_us/article/evpz7a/turn-off-wi-fi-and...
Sidenote, it behaves differently if you've enabled airplane mode (or at least so the UI would indicate). In airplane mode, it gives no message and the wifi/bt icon goes transparent. If you're not in airplane mode, the wifi/bt icon goes light gray and it says 'disconnecting <device type> devices until tomorrow' but the radio is still on as your article mentions.
Personally I miss the old behavior where it just turns it off, but I'm often in airplane mode so I get the old behavior anyway and great battery life :P
instead, it should only maintain bluetooth connections to devices already connected (or better yet, trusted), while being invisible to everything else. i know with bluetooth this is technically difficult, if not impossible, but that would be the more customer-friendly implementation.
Anyone know? Occurs to me I could shut wifi fully off when leaving home, and turn bluetooth off with the toggle to still use my devices. Don’t know if that’s useful however.
Used to use airplane mode all the time, but modern convenience became too great.
or maybe it's a feature of the newer devices? my apple devices are older and have bluetooth 4.2 still.
When I turn it off, the bluetooth menu in settings says "new bluetooth connections have been turned off from control center"
The requests we were fielding was for better ability to find things in the store, floor maps for every store with wayfinding, and the ability to use the app to get more contextual info on demand.
For those not completely in the know on beacons: they are broadcast only and it is the apps running in the background on your phone that shuffle off the data on your phone. If you were running a device free of the offending apps, your privacy is fine on that front. The WiFi tracking is a different story though.
Specifically, if I have an app installed, but it's not open in any way (e.g. in iOS I double tap home and swipe up on the app's window to close it) can the app still run any code? Am I safe from these "background" vulnerabilities as long as I aggressively kill apps that I'm not actively using, or is simply having the app installed enough to let it run a certain amount of code on my device?
I can’t speak to Android as it’s been a long time, but iOS is pretty strict about what you can and can’t do in the background. There are certain events that will “wake up” an app, even one that is killed. You’re not necessarily safe if you have a bad app installed and kill it. I usually just recommend avoiding free apps that seem super heavy on ads. Because the ad framework is likely abusive, even if the developer didn’t intend it.
As others have mentioned many of the top wifi brands, Cisco, Aruba, and Meraki (now owned by Cisco) provide this kind of information to clients at their enterprise level.
The reason this doesn't exist for consumers for security at least is that in the use case you described it is hard to tell what MAC address belongs to each device. Even in a neighborhood, you will detect hundreds of macs a day due to mac spoofing that modern phones do.
I didn't know the onboard adapter supported monitor mode, that is ligitmately useful knownledge for me. Thanks, it should be simple to build your own sniffer to just plan around with. Carefull if you are in the EU though, not that it is removely possible to catch a silent sniffer.
Look at some of the filings by Kroger:
https://fccid.io/PBR-SZG3APWC/Users-Manual/Manual-3994818
They are tracking down at the bay level for some items.
You believe that makes a difference?
https://www.zdnet.com/article/ios-11s-control-center-may-say...
I don't see anything wrong with passively tracking people in a store, mall, shopping center, etc., as long as it is used to inform the owners of movement patterns in the area. To use the information to push notifications and determine purchasing habits of people is over the line.
I would like to congratulate Google for such hard work. I mean, CyanogenMod 7 in 2010 could revoke any app permission at the user's will, but you know, computers are difficult
The first time this happens, I'm not going to buy the thing, but I'm going to jump through whatever hoops are necessary to disable this feature on my device. If that doesn't work, I'm going to get another device and then I'm never going to patronize whatever retailer did this.
I suspect eventually this will make people irate and these sorts of things will become opt-in.
I'd be interested in a list of popular apps or SDKs that use beacons -- so I could uninstall them pronto.
It seems somewhat benign, and not very useful, that they know I spent 45 seconds in front of the yogurt section, compared to the average at that time of 28 seconds. Maybe a friend I haven't spoken to for a long time started messaging me. Or maybe I was helping an elderly person get something from the top shelf.
The part about eending ads to your device is FUD, any app that starts doing that without my permission is getting uninstalled straight away.
1) Some random third-party app has to be running on your phone to detect beacons and send the data back... how viable/likely is this actually? It seems like this would only ever effectively detect a tiny percentage of users at best who just happen to have one of the apps open while walking around a store?
2) For an app to detect beacons, don't you have to give permission for the app to use Location Services? I've tried Googling it but can't seem to find a definite answer... I'd be surprised (and saddened) if Apple or Google are allowing apps to detect beacons without explicit location or Bluetooth permissions.
3) If the goal is to track as many users as possible... wouldn't it be far more efficient to look for Wi-Fi devices that are scanning, and identify them by their MAC address? I don't understand what Bluetooth beacons enable that Wi-Fi scanning doesn't.
4) The article lists companies that provide these third-party toolkits... but not a single name of an app that uses them, or what percentage of phones contain an app with them. Since this is the main accusation of the article... I don't understand why they wouldn't provide even a single instance of proof.
I've just seen a lot of very questionable reporting from the NYT in the past on tech/security/privacy, so I'd like to understand better how real this is or not.
They don't have to be running. Here's my understanding (for iOS anyway):
1. Apps have the ability to subscribe to bluetooth callbacks from the OS, which is constantly scanning for them (about once a second, from memory). It will be something like, "wake me up when you detect that beacon with UUID ABCD123 is in range". ABCD123 would be the standard ID of a marketing company's beacons - there could be millions of them.
2. The beacon also have sub-IDs identifying the exact beacon being used. The marketing company will know which are where.
3. Whenever the beacon is in range, the OS pings the app with the data, which decides what to do with it in the same manner as a background data refresh. This could be something useful, like waking up to let you know your suitcase is nearby - but it could also be silently uploading that data to a server.
4. The software to do this is being bundled as a paid SDK in a great many seemingly-unrelated apps, such as weather apps.
5. This behaviour is not counted as location services in the OS, and may or may not be disabled even when bluetooth is "off" on the phone
Corrections welcome but I believe that's roughly what's going on.
I'd greatly appreciate something like Little Snitch on the iPhone so I could see which apps are doing this and delete them with extreme prejudice. Back in reality, I'm glad this is getting attention - at the very least Apple should be providing a list of apps requesting BT access, and indeed any network access over time.
I'm pretty shocked all this can go on in the background without permissions. With Apple adopting such a privacy-conscious stance, I really hope this gets their attention so beacon scanning requires explicit permission in the future (and separate from location services -- my weather app needs to know where I am, but certainly doesn't need to scan for beacons).
This is honestly pretty egregious.
It certainly is. I knew about the mechanics of it but hadn't realised it was being so widely abused. I would like to see Apple come down on this swift and hard.
Third party paid SDKs! Those cunning bastards. AdTech really is the dregs.
It would be trivial to do this if you can get your hands on an iphone with a jailbreakable OS version.
1. Apps can be running in the background. I'd say its more common than you think 2. You need to provide location permissions (either the ACCESS_COARSE_LOCATION or ACCESS_FINE_LOCATION). It seems like every app requests these permissions anyway, so not a red flag just on its own. 3. Something scanning for a WIFI devices has no way (easily) to coorelate those addresses back to a user. With this bluetooth low energy method, the users own phone is the one who reports the detection back to {company}'s servers, so it can pass along any/all other information it has about you. Their location accuracy is also pretty crazy (radius is within centimeters if they've done it well). 4. Bluetooth low energy is actually crazy easy to set up, see here for more... https://developer.android.com/guide/topics/connectivity/blue...
Just a thought.
If ever an entire category of HN posts deserved an instant trip to -4 territory, these ever-present and singularly-unhelpful posts ("Just turn your phone off/leave it in airplane mode/leave it at home/give it up for Lent/sell it on Craigslist/go to Uttar Pradesh and join a Zen monastery") should more than qualify.
Letting scumbags dictate how you live your life -- or how you use your phone -- is never the optimal strategy. Don't turn off. Fight back.
Actually I think a considered and gentle re-looking at one's life is an entirely viable thing to do.
What's so nuts about leaving your smartphone at home, or giving it up completely? Try taking a step back in an attempt to take a cold look at how weird and unbalanced this whole smartphone addiction thing has become. A situation in which, what, 50%+ of any random group of people has head down looking at a screen? A situation in which a family goes out for a meal and spends the time with each member socialising with people in the virtual world but not with each other? A situation in which young girls are self-harming because they're spending 6 hours a day comparing themselves with others online? I live by the sea - a beautiful, wonderful part of the world - but the number of people who simply don't engage with the world they're moving through because of this little square of plastic in their pocket is astounding.
There's nothing blame-y about this - yes, the corporations need a slap at what they're doing with our data and our lives - but we've got individual agency, too.
I'd be curious to hear from anyone who's tried it
You can always detox your phone though. Delete all your third party apps, stay off mobile web and it's a de facto dumb phone with a battery that lasts a day instead of a week like your old razr.
1) Keep a smartphone without a SIM in it at home on wifi for banking / 2FA / etc
2) Move everything social off it. I was never a FB user, but I'm into Twitter and news - so those two got canned, as did Instagram
3) Take work email off it. If you can't, turn off all notifications. If people want you, they'll ring you.
4) Anything you want to do, do it on your desktop - you have way more control here. I use https://heyfocus.com on "hardcore" mode, which blocks Tweetdeck, email, news, HN, whatever so I can actually get work done
5) Have a dumbphone for out-and-about use. It's painful, awful texting, no camera - but it is remarkably liberating to have moments of boredom, moments when you'd normally take a photo but can now just admire the view, moments when you have to actually "ring" someone (I know, this is apparently a thing..)
6) Never let your smartphone into your bedroom, ever
7) Put any gadgets on charge upstairs after 6pm, and leave them there on silent until the morning
It works for me. It hurts, and sometimes I slip (if I have to travel with work, I normally re-sim-ify my smartphone for maps or whatever), but in general I feel more a part of the world I'm supposed to be spending my life in, rather than down a rabbithole of virtual nothingness.
The first and easiest way to try this is simply to leave your phone at home when you go out for a period of time. Redirect calls to your partner if you need - but just try it. There's a Zen saying: "if you don't have 10 minutes to meditate each day, you should meditate for 20 minutes". If it hurts, try it for a longer period of time!
https://www.aerospike.com/blog/silverpush-unifies-people-dev...
Apparently we are all telling anyone around us who cares to listen who we are.
https://techcrunch.com/2017/09/20/target-rolls-out-bluetooth...
Kind of funny that Apple pushing privacy basically helped create this kind of tracking to begin with.
Edit: NYT article mentions other apps selling data to retailers. I think it's time apps start asking permission to use BTLE. No reason a weather app needs that kind of access.
1. Set up a bluetooth beacon in the diary aisle that broadcasts as a connectable (nor not?) device with an "SSID" (or the bluetooth equivelant) that is a known GUID
2. apps on your phone can scan for available bluetooth devices, and see the presence of the GUID, which is enough for them to know you are in the dairy aisle of Store 1234.
if that's right, does this mean disabling bluetooth, or restricting a device's access to scan for devices, will preclude this?
You are right that disabling bluetooth or being aware of what apps your phone has is what is required.
Are there any apps / options that allow for only connecting / responding to a previously connected unless overridden?
1. Pretend it's the 1900s.
Walk into a general store, shopkeeper sees you looking at ammo for 20 minutes and then leave without buying anything. Next time you walk in, he recognizes you and says he'll give you a discount on ammo if you buy in bulk.
This is totally cool, not a violation of privacy, and both parties benefit. win/win
2. Use a computer to do the same exact thing automatically
Rage, pitchforks and proverbial molotov cocktails and people going on privacy diatribes.
What's the difference?
You hear them say, "So their names is John Smith? All right, all right, all right. What is their medical situation? Cancer, you say? Yeah, they're looking at razors right now. They are wearing the new Nike shoes. Just sneezed. Again. They are looking at allergy medication now."...
Then you look around and notice that every person in the store is followed by one of these employees.
You freak out a little bit and leave the store. The next store has the same kind of employees. As soon as you enter, the phone rings. The employee from the previous store calls your new "supervisor". On the phone, you hear a voice describing everything you've just done next-door.
This is what this situation would look like in an imaginary world of 1900s.
I don't believe any of this. Nobody can usurp my free will no matter how much data they have on me. Heck, even if I told them every last piece of private information I knew about me, I doubt they could increase my spending even 1% more than I currently am with all the coupons and targeted advertising and subliminal marketing in the world.
We have a global population that is addicted to their phones. A great deal of their worldview is shaped on a daily basis by a small illuminated screen that fits in the palm of the hand, full of deception and manipulation, which goes well beyond grocery shopping. The phone is an ideal espionage tool since, for most people, it is turned on and broadcasting constantly, and always at its user's side. I mentioned "electronic prison", scaling out from this, in the sense that law-abiding citizens are under constant surveillance, similar to inmates in a prison. We have the ability to move around of course, but we can hardly do so without being watched, which does not equate to actual freedom. The human experience is being overrun by addictive technology that manipulates our will through mechanisms that are totally unknown by the average user. It may seem like hyperbole because its full effects have not yet been understood. It's not like this is the end: this is just where we are today. The intrusion into our lives will only escalate.
2. Use a computer to the the exact thing automatically today. This is just the natural state of the world, nothing to do anything about it, move along.
The Stasi hid cameras in handbags and behind buttons but regimes operating today do not need to operate in such corse ways.
What does bother me is the part where they can get lots of other data and use it to build a profile of me that spans far beyond their store. The fact that this Pulsate company encourages devs to include my email address, for example, seems really invasive, and probably would be illegal under the GDPR?
Merchandising isn’t rocket science. I wonder if there is real roi?
Make no mistake: the purpose of marketing is to maximize information asymmetry. The natural end point is totalitarian: they know everything about you, and you know nothing at all, blindly obeying.
At its best, marketing is a way to let people know the goods and services you have that can make their lives better.
This is marketing at its worst.
I really enjoy this explanation of why targeted advertising is such a horrible thing:
When someone clearly lists the merits of a product without conflict of interest, then that does indeed lets people known what goods and services make their lives better. We have a different word for that - a "review". The purpose of an ad, by definition, is not to inform - the purpose is to persuade. They are opposites.
This is marketing at its real. As practiced.
> I don't think telling people the product you created to serve their need is inherently evil.
Of course it isn't evil, but this is not what marketing is doing - and claiming so amounts to a motte-and-bailey defense of an industry that's rotten to the core and quite openly malicious towards their fellow human beings.
I also think you are being unfair if you say there are zero companies that do marketing right.
And probably most of us, including me, would agree. The problem is when the market is saturated with goods compared to buyers so that more aggressive methods - read: lies and subtle psychological tactics - are used to convince those buyers they need this or that product when they actually don't. Which becomes even more evil when the product is something potentially harmful such as unneeded food, medicines, anything that will be soon thrown away creating more pollution, etc. The problem isn't marketing by itself, but the total disregard for moral issues that can and will make it harmful once overproduction and saturated markets get us to a point where lying is the only way to keep businesses alive.
It is the opposite of what GP is saying here, despite their doomsaying at their own revelation that retailers are listening to the broadcasting device consumers bring onto their property to better understand them.
Yeah, and pay cash before they get rid of it and make us all pay for everything with wechat bucks or whatever.
Location analytics are a built-in feature of many sub-$300 access points.
This is what the ad industry exploiting the fear of missing out [1] looks like when they tout the virtues of "relevant ads". You might draw a comparison with casino marketing to gambling addicts, alcohol to alcoholics, etc -- it's rather slimy.
In reality, I'm not comfortable with the amount of privacy violation getting that targeted ad requires.