1) Some random third-party app has to be running on your phone to detect beacons and send the data back... how viable/likely is this actually? It seems like this would only ever effectively detect a tiny percentage of users at best who just happen to have one of the apps open while walking around a store?
2) For an app to detect beacons, don't you have to give permission for the app to use Location Services? I've tried Googling it but can't seem to find a definite answer... I'd be surprised (and saddened) if Apple or Google are allowing apps to detect beacons without explicit location or Bluetooth permissions.
3) If the goal is to track as many users as possible... wouldn't it be far more efficient to look for Wi-Fi devices that are scanning, and identify them by their MAC address? I don't understand what Bluetooth beacons enable that Wi-Fi scanning doesn't.
4) The article lists companies that provide these third-party toolkits... but not a single name of an app that uses them, or what percentage of phones contain an app with them. Since this is the main accusation of the article... I don't understand why they wouldn't provide even a single instance of proof.
I've just seen a lot of very questionable reporting from the NYT in the past on tech/security/privacy, so I'd like to understand better how real this is or not.