Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
If you enable that, you can save locations, so that, for example, you can "favorite" your home and your office for easy access.
If you disable activity tracking, you can't save anything.
Those two are totally unrelated, and you're still using Google Maps through your Google account, so there are 0 technical reasons they couldn't just persist your saved locations in the Google Cloud.
They just don't do it to force you to let them track your location.
It shows some respect that you don't want focus on your actual geography but I also do stuff like look at real life places to see how well it matched with my initial imagination.
I have no skin in this game - I have however been a very satisfied https://wego.here.com/ user since they were Nokia Maps back in 2012.
If you just want to look at the map you can say no.
I just opened up Google Maps on my Android 10 device with activity tracking off. They've changed the UI, now it's sneakier. I can set them and there's a faint gray text underneath that says, and I quote:
"Personal places will be used across Google products, for personalized recommendations, and for more useful ads."
Dark Pattern to the ten thousandth power.
They're literally turning my input of my home and work address as an implicit consent to enable activity tracking (!!!)
Again, there are absolutely 0 technical reasons why the two have to be related. Software of all kinds from the beginning of time has had "saved"/"favorite"/"starred" functionality, without ad tracking related to it.
The ones you mention are put in lists and you have to navigate to them, about 3 screens.
There's no technical reason why the highest UI real-estate values "Home" and "Work" couldn't be saved independently of the ad settings.
The final straw for me was when I disabled location services for Google Play Services[1] and the Gmail app, of all things, started nagging me about Google Play Services not having location data. Every time I opened it. Why the fuck does a mail client need location data so badly it has to nag you on every startup?
Oh wait, it doesn't. It's just their most popular app and so the premier spot for a nag screen.
My life's been de-Googled (apart from the odd video on YouTube) since the start of 2018 and my skin feels so much less crawly.
[1] You know, after they pushed all app developers to stop using the GPS APIs and instead get location through Google Play Services, so that you had to 'consent' to Google Play Services getting your location data if you wanted ANYTHING to be able to use location data?
Oh absolutely.
But to play devil's advocate, your wifi device is basically an always broadcasting radio antenna that rarely moves or changes. And SSIDs are broadcast by design.
It's a digital landmark.
I bet there are a lot of other companies other than google using it too. And even if you used google's opt out, they're not going to care. So opting out is pretty pointless anyway. So while it feels invasive because we lack a sensory organ for radio, your router is constantly broadcasting (advertising?) itself as a part of normal operations. SSIDs aren't private information. It's more akin to an amateur radio callsign, except you can change it at will.
And since they're no consistent convention for naming your wifi there are probably 10,000 "FBI surveillance van"s. The only useful data to an outsider is location.
This was going to be utilized by someone, and probably already is by the NSA. So google doing it is no big surprise.
Again, devil's advocate here, but SSIDs are broadcast on purpose. Sacrificing security for convenience as always when people are involved.
The wiki definition seems to me to fit.
> Surveillance is the monitoring of behavior, activities, or information for the purpose of information gathering, influencing, managing or directing.
Perhaps people are comfortable with google using their publically available SSIDs so their android phones get better location info?
Otherwise people could abusively de-register SSIDs by doing the same sort of scanning Google is doing to improve location services, or have to force a user to authenticate and "claim" an SSID, which is much more intrusive.
(disclosure: googler, but not in any way associated with any of this)
And yes, Google could incentivize people to register in some way. One thing you'll notice is that the most valuable companies in the world seem incredibly reliant on free labor: They take for free what other companies used to pay for or pay staff to create or gather themselves.
Would you feel comfortable with your name, address and MAC + SSID of your wireless AP(s) being registered in a public database and the onus on you to keep that registration information up to date every time you changed the SSID or swapped in something with a different MAC address?
I'm not sure I would be.
The ethics around Google's behavior aside - this is a tricky problem to solve.
Edit: Why the downvotes? I'd really like for people that disagree to engage and tell me where I am either wrong or not arguing in good faith. If you believe this is a Google specific problem or somehow an easy problem to solve under the current FCC regulatory regime I'd be happy to hear about it.
Just add the suffix "_optin" to your SSDI and you're opted in.
This is what they're currently requiring for the opt-out, I can't see why the same solution can't be used for opt-in...
Taking it to a bit of a silly extreme - what happens when 100 different companies want to use public SSID data? 100 different opt-in codes? 1 code for all? What if I want to allow 5 companies out of that 100 to use that data and exclude the other 95?
If two companies use different suffixes, that makes it impossible to opt out of both.
Edit: The only reason this isn't already an issue is because Microsoft made their opt-out work anywhere in the SSID
For comparison, take a look at 802.11y, which operates in the 3.6Ghz band, a "lightly" licensed part of the radio spectrum. Before you can set up 802.11y stations you must first register with the FCC (or whatever the equivalent in your country is called) and receive a license, and all your stations must be identifiable (you are not free to choose your SSID). That is already far too much for consumer devices (802.11y is meant for WISPs; it has better propagation characteristics than the unlicensed bands and you are allowed to transmit at higher power), and that is a "lightly" regulated radio band. Typical regulations e.g. the bands used by cell phones require far more coordination with governments -- more paperwork, more money, and many more rules about permissible operations.
Finally, for what it's worth, nobody has ever had to pay anyone for ISM band operations, including just recording transmissions on the band. In fact, if you are using wifi, you have been monitoring and analyzing nearby wifi transmissions this whole time without ever paying anyone -- that is part of the wifi standard. Just connecting to a wifi network means your device is monitoring transmissions from other people. So here is a final bit of snark for you: HOW DARE YOU USE WIFI WITHOUT PAYING YOUR NEIGHBORS?!?!?!?!?!
2. I have APs that do collect and store data about nearby wifi stations and transmission patterns as part of a system that improved wireless throughput.
3. What difference does it make if it is being stored?
If it's just nearby ones then that's much less of a problem.
> 3. What difference does it make if it is being stored?
Imagine saying that about someone else's telephone call...
Listening out for interference is not at all the same as siphoning up information.
You seem to be saying that if an AP stores information about other "nearby" APs there is no problem. What if I am operating thousands of APs across a broad geographic region using a centrally managed AP controller? That is a common practice for large organizations and that is exactly the setting where you see APs collecting and storing information about other wifi stations. Is that not a large enough scale to be a concern? I have to wonder at what point you are drawing the line here. What is an unacceptable scale?
> It is no different from a database of street addresses and corresponding GPS coordinates.
The locations of streets are public records.
> There is no reasonable expectation of privacy for SSIDs or wifi beacons -- everyone knows they can see their neighbor's SSIDs.
Being able to see your neighbor is very different from being able to see everyone's neighbor.
I do not see how SSIDs are in different in any meaningful way. We are literally talking about building a map -- a map that includes the locations of SSIDs, to be used as a kind of landmark, no different from a map that includes other landmarks (e.g. "the house with the red siding") that could conceivably be used to help a person identify their position on the map. There is zero expectation of privacy for SSIDs, just like there is zero expectation of privacy for the exterior of your home.
Is there any specific objection beyond, "This is happening at a large scale?"
If you don't want to be tracked by Google, don't use their software.
Now, if you're having a hard time avoiding their software because it's become a de-facto standard that's a separate problem. The bottom line is that we shouldn't be in a position where we don't have a choice not to use software from Google (or Apple, or Microsoft, etc). As long as these companies are in a position to offer software that can't reasonably be avoided, you should expect them to optimize these offerings at the expense of their users.
I don't have to use their free browser, their free smartphone OS or even their search engine, but they will still freeload on my Wi-Fi for location tracking and will record my router location without consent, and the only way to opt-out is appending a stupid _nomap to the end of my ID.
You don't want anyone to monitor your wifi network? Either don't use wifi, or switch to a band that will not propagate beyond your home (60 ghz).
Listening and putting it in a massive database along with other sensitive data, such as location, are two completely different things, though.
Repeating what I said in other comment: What Google is doing is a cool hack and might be fully legit, but it's foolish to claim there's no potential privacy issues in it.
Wifi is convenient because it is unlicensed and loosely regulated. The price of that convenience is that you have no particular claim to privacy with your wifi transmissions, and everyone knows it -- that is why we encrypt the contents of those transmissions. Building a database of AP locations is not a privacy issue at all -- it is no different from building a database of landmarks (or publishing a travel guide with a list of landmarks in various towns), or for that matter, creating a map by gathering information about roads/buildings/etc.
It's not just Google doing it - see https://wigle.net/ with over 10B observations. So your privacy would be at risk even if Google didn't collect SSID/location information.
Fundamentally, asking people not to do something has never been a security measure that's worked. You need to implement some tangible, real protections. We already have those in the case of SSIDs, namely, the SSID and AP information aren't accessible to an app without location permissions in modern operating systems.
You’re right that it’s technically public, just like the license plate on a vehicle. However, there is still a privacy expectation that all of that localized data won’t be pulled into a massive database for correlation.
It’s beyond the SSID, using your logic, it would also be fine if Google observed all of the client frames to track the locations of users that don’t use Google services. Randomized MACs aren’t usually used for home WiFi so this is completely feasible and well within your “privacy” framework.
This argument “don’t use google” or “don’t use Facebook” is very frustrating because others make this decision for me. If only it was possible to not use these services.
Not to do it.
Hide your IP address behind Tor. Transmit identical information as a significant group of people. Don’t store information from websites.
The issue is that degrades the web in ways unrelated to tracking.
And so many sites, and CDNs treat those as hostile by default, and some outright refuse service. It's infuriating as a mere VPN user.
I know that's the reason we classed all traffic from those sources as suspicious unless they were willing to log in.
But it's not just that is it? If you log in to a google site from that publicly broadcast BSSID, you will get tracked by association, even if you have your location tracking turned off.
I wouldn't bet against Google being capable of exfiltrating BSSIDs via their broad swathe of 'Google Services' most Android devices are running (and probably most iOS devices too).
Both have location privacy controls that govern that, and there's no particular reason to believe they ignore them.
(And Apple might be too, but they've got different motivations and incentives around iOS user privacy that Google for Android users...)
Turning WiFi SSIDs in to location data doesn't track people directly, but it does enable the mass surveillance of people's devices, and that's something that's quite reasonable to opt out of.
cite?
Apple is also collecting & phoning home all SSIDs with a GPS location that they come across, for example. So is Mozilla for that matter, and Mozilla also uses the same _nomap suffix as Google does ( https://location.services.mozilla.com/optout ). It's how browsers on laptops are able to get a location, which is also true on again both Apple & Microsoft devices as well.
So no, Google can't just opt to not do this at all. Not if they want to be competitive. The entire ecosystem could collectively decide to not build an SSID location database at all, but since SSIDs are not identifying this is going to be a struggle to justify.
Google knows practically every SSID location in the developed world. Now your Android phone browsing and mapping every SSID it sees as you move about is a reliable "Location mapping" of the user even though they may have no GPS or have it disabled.
You can map a person's movement through cities/towns just based on the SSIDs their device(s) saw as they moved about.
The issue here is having control over when your phone looks up your location, not the existence of a database that makes it work.
I just don't see why this is a problem when apps can't even access your SSID without a location permission.
If you want everyone to have that data publicly then have your government do it...
I'd think it similar to a journalist reporting on a story. Its public, butthe value they add is private
https://www.theatlantic.com/technology/archive/2012/05/googl...
It seems like it should fall under a regulation similar to photographs. You can take photos of me in a public place and do whatever you want with them until you're using my likeness in a commercial capacity... then you need to ask me first. Opt-out isn't enough, it needs to be opt-in. If that doesn't work for your business then too bad.
In the end, asking people to please not snoop on you never has and never will be a security measure that works. You need something tangible to protect your privacy, so as to make it virtually impossible.
We already have this. Every modern mobile OS gates the SSID API behind location permissions.
Given such protections, practically speaking, there isn't any problem with SSID being bound to location information.
Education, journalism, research and the like fall into a different category... this also applies in the "photographs of people in public spaces" example. WiGLE would still exist in that niche.
Wigle also has opt-out.
https://location.services.mozilla.com/optout https://support.apple.com/en-us/HT207056
Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
No, actually, i'm just kidding. Mozilla, for example, literally blames it all on everyone else in their page.
You see, they are forced to do this because everyone else did it!
While it still possible for google to probably scan for these I doubt they do.