How do I opt my access point out of Google Location services?
support.google.com
support.google.com
[0]https://support.google.com/maps/answer/1725632#how_opt_out&z...
EDIT: Added "name" after "WiFi" to try and clarify they're not using your actual WiFi network/bandwidth, just its name to link it with its location for GPS-free location tracking.
Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
Otherwise people could abusively de-register SSIDs by doing the same sort of scanning Google is doing to improve location services, or have to force a user to authenticate and "claim" an SSID, which is much more intrusive.
(disclosure: googler, but not in any way associated with any of this)
And yes, Google could incentivize people to register in some way. One thing you'll notice is that the most valuable companies in the world seem incredibly reliant on free labor: They take for free what other companies used to pay for or pay staff to create or gather themselves.
Would you feel comfortable with your name, address and MAC + SSID of your wireless AP(s) being registered in a public database and the onus on you to keep that registration information up to date every time you changed the SSID or swapped in something with a different MAC address?
I'm not sure I would be.
The ethics around Google's behavior aside - this is a tricky problem to solve.
Edit: Why the downvotes? I'd really like for people that disagree to engage and tell me where I am either wrong or not arguing in good faith. If you believe this is a Google specific problem or somehow an easy problem to solve under the current FCC regulatory regime I'd be happy to hear about it.
Just add the suffix "_optin" to your SSDI and you're opted in.
This is what they're currently requiring for the opt-out, I can't see why the same solution can't be used for opt-in...
Taking it to a bit of a silly extreme - what happens when 100 different companies want to use public SSID data? 100 different opt-in codes? 1 code for all? What if I want to allow 5 companies out of that 100 to use that data and exclude the other 95?
If two companies use different suffixes, that makes it impossible to opt out of both.
Edit: The only reason this isn't already an issue is because Microsoft made their opt-out work anywhere in the SSID
For comparison, take a look at 802.11y, which operates in the 3.6Ghz band, a "lightly" licensed part of the radio spectrum. Before you can set up 802.11y stations you must first register with the FCC (or whatever the equivalent in your country is called) and receive a license, and all your stations must be identifiable (you are not free to choose your SSID). That is already far too much for consumer devices (802.11y is meant for WISPs; it has better propagation characteristics than the unlicensed bands and you are allowed to transmit at higher power), and that is a "lightly" regulated radio band. Typical regulations e.g. the bands used by cell phones require far more coordination with governments -- more paperwork, more money, and many more rules about permissible operations.
Finally, for what it's worth, nobody has ever had to pay anyone for ISM band operations, including just recording transmissions on the band. In fact, if you are using wifi, you have been monitoring and analyzing nearby wifi transmissions this whole time without ever paying anyone -- that is part of the wifi standard. Just connecting to a wifi network means your device is monitoring transmissions from other people. So here is a final bit of snark for you: HOW DARE YOU USE WIFI WITHOUT PAYING YOUR NEIGHBORS?!?!?!?!?!
2. I have APs that do collect and store data about nearby wifi stations and transmission patterns as part of a system that improved wireless throughput.
3. What difference does it make if it is being stored?
If it's just nearby ones then that's much less of a problem.
> 3. What difference does it make if it is being stored?
Imagine saying that about someone else's telephone call...
Listening out for interference is not at all the same as siphoning up information.
You seem to be saying that if an AP stores information about other "nearby" APs there is no problem. What if I am operating thousands of APs across a broad geographic region using a centrally managed AP controller? That is a common practice for large organizations and that is exactly the setting where you see APs collecting and storing information about other wifi stations. Is that not a large enough scale to be a concern? I have to wonder at what point you are drawing the line here. What is an unacceptable scale?
> It is no different from a database of street addresses and corresponding GPS coordinates.
The locations of streets are public records.
> There is no reasonable expectation of privacy for SSIDs or wifi beacons -- everyone knows they can see their neighbor's SSIDs.
Being able to see your neighbor is very different from being able to see everyone's neighbor.
I do not see how SSIDs are in different in any meaningful way. We are literally talking about building a map -- a map that includes the locations of SSIDs, to be used as a kind of landmark, no different from a map that includes other landmarks (e.g. "the house with the red siding") that could conceivably be used to help a person identify their position on the map. There is zero expectation of privacy for SSIDs, just like there is zero expectation of privacy for the exterior of your home.
Is there any specific objection beyond, "This is happening at a large scale?"
If you don't want to be tracked by Google, don't use their software.
Now, if you're having a hard time avoiding their software because it's become a de-facto standard that's a separate problem. The bottom line is that we shouldn't be in a position where we don't have a choice not to use software from Google (or Apple, or Microsoft, etc). As long as these companies are in a position to offer software that can't reasonably be avoided, you should expect them to optimize these offerings at the expense of their users.
I don't have to use their free browser, their free smartphone OS or even their search engine, but they will still freeload on my Wi-Fi for location tracking and will record my router location without consent, and the only way to opt-out is appending a stupid _nomap to the end of my ID.
You don't want anyone to monitor your wifi network? Either don't use wifi, or switch to a band that will not propagate beyond your home (60 ghz).
Listening and putting it in a massive database along with other sensitive data, such as location, are two completely different things, though.
Repeating what I said in other comment: What Google is doing is a cool hack and might be fully legit, but it's foolish to claim there's no potential privacy issues in it.
Wifi is convenient because it is unlicensed and loosely regulated. The price of that convenience is that you have no particular claim to privacy with your wifi transmissions, and everyone knows it -- that is why we encrypt the contents of those transmissions. Building a database of AP locations is not a privacy issue at all -- it is no different from building a database of landmarks (or publishing a travel guide with a list of landmarks in various towns), or for that matter, creating a map by gathering information about roads/buildings/etc.
It's not just Google doing it - see https://wigle.net/ with over 10B observations. So your privacy would be at risk even if Google didn't collect SSID/location information.
Fundamentally, asking people not to do something has never been a security measure that's worked. You need to implement some tangible, real protections. We already have those in the case of SSIDs, namely, the SSID and AP information aren't accessible to an app without location permissions in modern operating systems.
You’re right that it’s technically public, just like the license plate on a vehicle. However, there is still a privacy expectation that all of that localized data won’t be pulled into a massive database for correlation.
It’s beyond the SSID, using your logic, it would also be fine if Google observed all of the client frames to track the locations of users that don’t use Google services. Randomized MACs aren’t usually used for home WiFi so this is completely feasible and well within your “privacy” framework.
This argument “don’t use google” or “don’t use Facebook” is very frustrating because others make this decision for me. If only it was possible to not use these services.
Not to do it.
Hide your IP address behind Tor. Transmit identical information as a significant group of people. Don’t store information from websites.
The issue is that degrades the web in ways unrelated to tracking.
And so many sites, and CDNs treat those as hostile by default, and some outright refuse service. It's infuriating as a mere VPN user.
I know that's the reason we classed all traffic from those sources as suspicious unless they were willing to log in.
But it's not just that is it? If you log in to a google site from that publicly broadcast BSSID, you will get tracked by association, even if you have your location tracking turned off.
I wouldn't bet against Google being capable of exfiltrating BSSIDs via their broad swathe of 'Google Services' most Android devices are running (and probably most iOS devices too).
Both have location privacy controls that govern that, and there's no particular reason to believe they ignore them.
(And Apple might be too, but they've got different motivations and incentives around iOS user privacy that Google for Android users...)
Turning WiFi SSIDs in to location data doesn't track people directly, but it does enable the mass surveillance of people's devices, and that's something that's quite reasonable to opt out of.
cite?
Apple is also collecting & phoning home all SSIDs with a GPS location that they come across, for example. So is Mozilla for that matter, and Mozilla also uses the same _nomap suffix as Google does ( https://location.services.mozilla.com/optout ). It's how browsers on laptops are able to get a location, which is also true on again both Apple & Microsoft devices as well.
So no, Google can't just opt to not do this at all. Not if they want to be competitive. The entire ecosystem could collectively decide to not build an SSID location database at all, but since SSIDs are not identifying this is going to be a struggle to justify.
Google knows practically every SSID location in the developed world. Now your Android phone browsing and mapping every SSID it sees as you move about is a reliable "Location mapping" of the user even though they may have no GPS or have it disabled.
You can map a person's movement through cities/towns just based on the SSIDs their device(s) saw as they moved about.
The issue here is having control over when your phone looks up your location, not the existence of a database that makes it work.
I just don't see why this is a problem when apps can't even access your SSID without a location permission.
If you want everyone to have that data publicly then have your government do it...
I'd think it similar to a journalist reporting on a story. Its public, butthe value they add is private
https://www.theatlantic.com/technology/archive/2012/05/googl...
It seems like it should fall under a regulation similar to photographs. You can take photos of me in a public place and do whatever you want with them until you're using my likeness in a commercial capacity... then you need to ask me first. Opt-out isn't enough, it needs to be opt-in. If that doesn't work for your business then too bad.
In the end, asking people to please not snoop on you never has and never will be a security measure that works. You need something tangible to protect your privacy, so as to make it virtually impossible.
We already have this. Every modern mobile OS gates the SSID API behind location permissions.
Given such protections, practically speaking, there isn't any problem with SSID being bound to location information.
Education, journalism, research and the like fall into a different category... this also applies in the "photographs of people in public spaces" example. WiGLE would still exist in that niche.
Wigle also has opt-out.
If you enable that, you can save locations, so that, for example, you can "favorite" your home and your office for easy access.
If you disable activity tracking, you can't save anything.
Those two are totally unrelated, and you're still using Google Maps through your Google account, so there are 0 technical reasons they couldn't just persist your saved locations in the Google Cloud.
They just don't do it to force you to let them track your location.
It shows some respect that you don't want focus on your actual geography but I also do stuff like look at real life places to see how well it matched with my initial imagination.
I have no skin in this game - I have however been a very satisfied https://wego.here.com/ user since they were Nokia Maps back in 2012.
If you just want to look at the map you can say no.
I just opened up Google Maps on my Android 10 device with activity tracking off. They've changed the UI, now it's sneakier. I can set them and there's a faint gray text underneath that says, and I quote:
"Personal places will be used across Google products, for personalized recommendations, and for more useful ads."
Dark Pattern to the ten thousandth power.
They're literally turning my input of my home and work address as an implicit consent to enable activity tracking (!!!)
Again, there are absolutely 0 technical reasons why the two have to be related. Software of all kinds from the beginning of time has had "saved"/"favorite"/"starred" functionality, without ad tracking related to it.
The ones you mention are put in lists and you have to navigate to them, about 3 screens.
There's no technical reason why the highest UI real-estate values "Home" and "Work" couldn't be saved independently of the ad settings.
The final straw for me was when I disabled location services for Google Play Services[1] and the Gmail app, of all things, started nagging me about Google Play Services not having location data. Every time I opened it. Why the fuck does a mail client need location data so badly it has to nag you on every startup?
Oh wait, it doesn't. It's just their most popular app and so the premier spot for a nag screen.
My life's been de-Googled (apart from the odd video on YouTube) since the start of 2018 and my skin feels so much less crawly.
[1] You know, after they pushed all app developers to stop using the GPS APIs and instead get location through Google Play Services, so that you had to 'consent' to Google Play Services getting your location data if you wanted ANYTHING to be able to use location data?
While it still possible for google to probably scan for these I doubt they do.
Oh absolutely.
But to play devil's advocate, your wifi device is basically an always broadcasting radio antenna that rarely moves or changes. And SSIDs are broadcast by design.
It's a digital landmark.
I bet there are a lot of other companies other than google using it too. And even if you used google's opt out, they're not going to care. So opting out is pretty pointless anyway. So while it feels invasive because we lack a sensory organ for radio, your router is constantly broadcasting (advertising?) itself as a part of normal operations. SSIDs aren't private information. It's more akin to an amateur radio callsign, except you can change it at will.
And since they're no consistent convention for naming your wifi there are probably 10,000 "FBI surveillance van"s. The only useful data to an outsider is location.
This was going to be utilized by someone, and probably already is by the NSA. So google doing it is no big surprise.
Again, devil's advocate here, but SSIDs are broadcast on purpose. Sacrificing security for convenience as always when people are involved.
The wiki definition seems to me to fit.
> Surveillance is the monitoring of behavior, activities, or information for the purpose of information gathering, influencing, managing or directing.
Perhaps people are comfortable with google using their publically available SSIDs so their android phones get better location info?
https://location.services.mozilla.com/optout https://support.apple.com/en-us/HT207056
Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
No, actually, i'm just kidding. Mozilla, for example, literally blames it all on everyone else in their page.
You see, they are forced to do this because everyone else did it!
I moved home a few years ago, just 200M away, my location in GMaps, when on WiFi remained at my old address 200M away for a good year (I moved my AP with me and kept the SSID).
Google's (and others) stance is likely that cellular and wifi information is publicly broadcast.
But all the big companies are abusive in terms of privacy so it seems like it’s par for the course.
I know its not technically a product but it always feels like these sorts of schemes should be illegal tying. Can’t make an iOS app without supporting safari? Should be illegal tying. Can’t use google maps without feeding google information about the wifi networks around you? Should be illegal tying.
Personally, I just decline that option and stay with regular GPS. I remember a time before GPS (or Glonass, or Galileo, etc) and I have to say, I think it's just amazing. (I also remember a time with "selected availability", and while I appreciate that that particular veil has been lifted, I am a little bit concerned with the amount of power this gives to the US military. While I am sure Google would be basically an organ of the US military during war, it still feels better that alternatives outside of military power exist).
edit: on my pixel this setting for 'google location' was hidden beneath a 'more settings' dropdown in the location setting page. I had no idea it was there. Definitely dark patterns of hiding settings they don't want you to know about. Thanks.
Wow, that's pretty nasty. That sentence sure makes it sound like you're opting in, but in fact you have to rename the SSID with a "_nomap" suffix to opt out.
Open databases with 10B+ observations exist: https://wigle.net/
Furthermore, it doesn't matter that these databases exist, because your SSID is hidden behind the location permission API for basically every OS.
So practically speaking, your SSID being public is meaningless.
At least, IF you assume that e.g. "database copyright" serves a valid purpose, then you could make a similar case here that the collection of all these data points is qualitatively different from collecting any single data point.
Note: I used a capital "IF" up there because I do have issues with database copyright. But that's the world we live in...
I think it would be reasonable to have various restrictions on all kinds of large scale datasets, especially when they include data that is easy to connect to individuals, and especially when it was not compiled with their explicit (informed, opt-in) consent. This includes public information such as what I’m wearing, where I am at what times, when and where my wifi is on.
They publicly advertise their face though, right?
Just the fact that information is available, it does not imply there is a consent for 3rd party to do anything with it.
> ALPRs on police cars
Government is usually exempt from those things or have license.
The fact is that your ability to simply plug in a wifi router and use it with any devices you want, without having to coordinate with anyone or buy a SIM card or whatever else, comes with the understanding that anyone else can monitor your wifi network for any purpose (and in fact this is a requirement of the wifi standard). If monitoring someone's wifi transmissions required their explicitly approval, nobody would be able to use wifi -- every time you moved your phone from one place to another, you would first need permission from every wifi station operator to monitor their transmissions before your phone could use wifi (you would not even be able to join a network you had previously used, because doing so requires your phone to listen to beacons being transmitted by nearby APs).
But the intention of accessing your network for the purposes of choosing a network you're authorized to use is different from connecting to networks you know you do not have authorization to use, and then for a purpose that a reasonable person wouldn't expect would be assumed.
I.e. I think it's reasonable to expect that I grant permission to my neighbours and passers-by to access my network for the purpose of choosing their own network. I don't expect that they will be adding my address to a data-set.
And maybe individuals do speculatively connect to random networks, but that's different to doing it at an industrial scale.
You seem to be hung up on what is being done with the recorded beacons, but we are talking about the unlicensed band, so you have no reasonable expectations about what is being done by anyone. That is the point of the unlicensed band. It is meant to be a free-for-all, which is the only thing that is suitable for consumer applications (imagine if every phone, laptop, router, drone, microwave oven, baby monitor, etc. you purchased required you to get permission from everyone around you before it could be used).
Good thing that you don't have to have two specific suffixes at the same time!
And that if my WiFi shouldn’t be part of Google’s (and Microsoft as well) data collection I need to suffix my SSID with _optout_nomap??
This has to be a joke. Any docs/refs/links?
Moreover, there are companies that operate large numbers of APs across a broad geographic region, and they may have a centralized system for managing those APs -- which means that they are collecting information about all nearby wifi stations (including client devices) across a broad region in a single place. Do you have a problem with that practice or view that as a violation of privacy?
Radio is not private (except, possibly, cellular services, which may be treated as phone services with legal restrictions on wiretapping), especially when you are talking about unlicensed operation.
What Google is doing is a cool hack and might be fully legit, but it's foolish to claim there's no potential privacy issues in it.
Broadcasting your SSID from a fixed station means forfeiting privacy rights over the SSID. You have plenty of alternatives to the 2.4Ghz and 5Ghz bands if you are concerned -- 60Ghz equipment is easy to buy and has many advantages, and wired connections are another option. I have zero sympathy for people who are worried about the privacy of their radio transmissions, especially transmissions on the unlicensed bands. Radio by its nature is not private.
As for the monetization issue, is that really the argument here? You have no problem with open-source location databases like OpenWLANMap, which is literally the same thing as Google's database but without any profit motive? That seems pretty weak. Heaven forbid someone should make money doing something that is otherwise unobjectionable...
If people want to partake, fine. But don't make it a burden for me to opt out. AND MORE IMPORTANTLY, most people are not tech people and will not even know of this and many are not technically savvy to know how to change their SSID if they even know where to find out how to opt out. Many WAPs around me still have their default ssid from the box from their ISP provided device and probably only WAP because thats that the cable guy had them do when he plugged the box in.
Google should be given credit for offerring an opt-out -- they had zero obligation to do so and there is zero expectation of privacy in this case (it is no different from collecting a database of street addresses -- anyone can drive down a street and write down all the house addresses, and nobody has a right to object to that).
People should have a reasonable expectation of privacy when their SSID isn’t deductible past their private land. It’s spying cellphones not street vehicles that’s collecting most of this data. And for what benefit?
If you don't want them to have data for something which is only detectible on your own land, just turn off Google's location services. Of course, the odds are very high that it's not only detectible on your own land.
That’s the problem it isn’t something most people are aware of let alone have much of a choice about. This is Google deciding it’s probably not illegal to spy on people in their own homes.
Sure, their probably not actually listening to conversation, but consider if they where would you consider they where spying if this was the level of consent given?
> If Location Services is on, your iPhone will periodically send the geo-tagged locations of nearby Wi-Fi hotspots and cell towers (where supported by a device) in an anonymous and encrypted form to Apple, to be used for augmenting this crowd-sourced database of Wi-Fi hotspot and cell tower locations.
Apparently it's not, and `_optout` for Windows is real. FML.
Source: https://superuser.com/questions/1005235/wi-fi-opt-out-micros...
On the plus side, world-wide roaming would be much closer after that.
Mozilla Location Services (and Combain which I think they collaborate with), WiGLE and others use "_nomap", though, so MS seems to walk their own path on this one.
FTFY
I find it absurd that we have to put this guff into our own networks just to opt out of the surveillance panopticon.
I don't see how using public router SSIDs as a landmark is "tracking you." If you use Google location services to determine your location based on your SSID or others, particularly while logged in to a Google account, then in some sense they're tracking you.
Not all wifi networks are stationary. I doubt most people know to add a _nomap to their hotspot name to avoid being tracked.
No we don't.
> collecting data from people's networks using their Google Maps wifi-sniffing vehicles
That was an error due to misconfiguration, failing to discard the data beyond that which identified the network for location mapping.
[1] https://www.wired.com/2012/05/google-wifi-fcc-investigation/
Even that story portrays the payload collection as basically one "rogue" engineer's intention, not a part of a business or project plan. While other engineers accessed the collected payload data later, they may have reasonably assumed that if they had it, someone had ok'd it.
So rather than a coding error, it was an organizational failure to oversee the engineers' work, the FCC's report says as much.
1. we didn't do it
2. we did it by accident in small cases
3. we did it by accident in worse cases
4. we did it intentionally but one guy was responsible
5. we did it but it was just one rouge dev. team
Add to that the unredacted report noting that Google kept delaying and hindering the investigation and it is rather clear that "6. we did it and management was neck deep into it" is more likely than not.
Seems like basic data security to me. If my credit card number (valuable data) is posted to the dark web I have to assume someone will use it and it's insecure. Google has the data, so they can now use it whenever they decide it's valuable. Until I have evidence that it can't be used, I have to assume it's insecure.
I don’t think any of these are relevant to the subject of whether Google tracks the movement of hotspots.
Just like how you're allowed to use peoples images in public but if you only photograph one person and follow them around that's considered stalking and/or harassment.
It's weird to me that with tech we always bring up "well it is public" as if it is the same as our public laws but they aren't. Not only is the degree to which information can be gained substantially higher on the internet, but we have laws that would prevent similar actions in public and it generally considered creepy but the public. The only difference I see is that in public you have a better chance of seeing the person following you than you do online. I'm sure there's some psychology to this: people acting different when being watched through cameras vs in person.
Should there be a way to tell the Google cameras to turn off when they drive by, and similarly, to tell the Google wifi setups to ignore our publicly broadcast network?
I imagine they have the right to take pictures from the street and record publicly broadcast names.
It seems like the entire specification of wifi should evolve to natively build these flags into how we manage our wifi, but even then, could we ever prevent a car driving by from reading the name of our SSID and logging the location and name for their personal use?
Perhaps the solution is that we should not publicly broadcast our SSID at all. Like bluetooth, we should "pair" and then stop the broadcast.
It's worse than that:
https://www.nytimes.com/2012/05/01/technology/engineer-in-go...
A Google engineer went a step further, however, the F.C.C. report said, and included code to collect unencrypted data sent from homes by computers — e-mails and Internet searches — as specially equipped cars drove by. That data collection occurred from 2007 to 2010.
Google long maintained that the engineer was solely responsible for this aspect of the project, which resulted in official investigations, some still unresolved, in more than a dozen countries. But a complete version of the F.C.C.’s report, released by Google on Saturday, has cast doubt on that explanation, saying that the engineer informed at least one superior and that seven engineers who worked on the code were all in a position to know what was going on.
Phones already have random hardware addresses, so it's not like your movements are being tracked because of your mobile hotspot.
"Privacy" advocates constantly demand that all of us bear the costs of worse technology just so they can have a little fake relief from their imaginary harms. We're long past the point of diminishing returns in preserving real privacy: now privacy advocacy is all about holiness spiraling.
That said, I don't blame Amazon here: why wouldn't they take advantage of an opportunity to hurt a competitor at no cost to themselves?
As for my opinion, I have no issue with the collection of the physical location of access points, I take issue with making me litter my chosen SSID with garbage so that I can opt out.
Regarding hotspot, I'm not sure what you mean, none of this discussion is about mobile hotspot.
Hotspots are relevant because they are often personal and they follow you around, so if they didn't randomize their hardware address, then anyone could track your movements.
Do you want to live in a world where wifi requires permission? Trying tracking down all the people in your area who are using wifi -- I have literally hundreds of wifi stations around me, operated by dozens of different people, and I have no idea who they are or how to contact them. The next time you turn on your laptop, before connecting to a wifi network (by which point you have already recorded transmissions from other wifi networks in the area), try making sure you have everyone's permission -- after all, you would not want to benefit (by being able to use wifi and not having to carry an ethernet cable around) from your device monitoring another person's network if they did not say it was OK!
Most wifi is operated in the unlicensed band, which is meant to be permissionless. That makes it convenient and suitable for consumer applications, and it also means that you have NO right to complain that Google and Microsoft dared to record your wifi beacons without asking your permission.
If you are worried about this, do you realize Google Photos also stores the location of photos of objects, and owners of those objects cannot opt out of this "tracking"?
If Google wants to build a database of access points that we all pay for (both the device and its energy consumption), I, at a minimum, want access to a copy of such a database so I can use it too.
(It's not relevant to the discussion but Android home screens show the name of the connected WiFi network?)
Where can someone look up a lat,lng by entering an SSID? It sure doesn't work on the site you cited. It looks like the information that is there was explicitly shared by the router operator.
SSIDs only need to differ from neighbors' SSIDs for convenience, to help tell them apart. If you already have neighbors using a default, like "xfinity", you might not want to choose that to avoid extra hassle when setting up new devices. But if you're concerned about someone learning your SSID and finding a database to map it to a location, can pick a generic manufacturer's SSID of which there will be thousands, if not millions, of devices using the same SSID.
Yes, nearly always in the top drawer [0], but I've also seen widgets on the home screen or in the status bar.
> Where can someone look up a lat,lng by entering an SSID?
Others already linked it, but https://wigle.net/ allows you to - sorry for linking the wrong map!
> . But if you're concerned about someone learning your SSID and finding a database to map it to a location, can pick a generic manufacturer's SSID of which there will be thousands, if not millions, of devices using the same SSID.
I don't know about the US, but in Germany most manufacturers have an unique appendage to the name, i.e. "Vodafone HomeBox DEHGTN". And the name doesn't have to be totally unique; if you can narrow the location down to a country or even a city (which is usually not that hard if you read someones post history or talk with them) it should suffice.
Also, it's not big when someone is aware of this tracking possibility. The real problem is that most people aren't.
EDIT: Just to prove my point, it took me 2 minutes to find out you're in Massachusetts [1]. If you're SSID is a bit unique, this is probably already sufficient.
[0] First panel in https://www.lifewire.com/thmb/xl-AHFNqlM-WwZ9z0JyAGx3B6Ww=/2...
They're relying on EVERYONE to keep them up in order to provide their service.
Essentially, people for a router and to keep it up and running, but it's google that can sell its service, but won't share the database of routers with the people maintaining them.
Changing the SSID to prevent them collecting the info is sort of like hanging a big sign that says "no pictures" to prevent services from taking pictures of your house. It's a little ridiculous to have to do that, but it's also a little ridiculous to expect that people are going to ignore what is publicly visible. Honestly, I'm a little impressed that Google lets you opt out (and Microsoft apparently as someone noted, although with a different suffix).
I think there's a tradeoff here. Having people carve out more and more frequencies that become illegal to monitor might not actually make the world a better place in the long run.
Don't broadcast things you don't want received.
Google was successfully sued over this, and to my knowledge the law has not been changed in the decade since then: https://en.wikipedia.org/wiki/Joffe_v._Google,_Inc.
In particular, the SSID of a network is readily accessible to anyone with a Wi-Fi device, whereas the contents of data packets (even unencrypted ones) are not accessible unless you have packet-sniffing software and know how to use it. This seems to me like a fairly common-sense interpretation.
You can still own general-purpose radio receivers (subject to the usual FCC rules about radiated emissions and so on). The legal restrictions are about what you can do with that equipment.
...if true, then wifi itself is illegal, because every wifi station will "intercept" (i.e. receive) frames transmitted by nearby stations in order to avoid interference when attempting to transmit a frame.
Sure, whenever somebody else sends a Wi-Fi packet in your vicinity, the components in your phone are physically reacting to the signal that they receive, and inspecting the data to see if you're the intended recipient. If the packet is addressed to somebody else, and your device never stores or displays the payload, then obviously you are not intentionally intercepting anything.
The law assumes judges and juries are human beings, who have at least a modicum of intelligence and common sense. It's not a mathematical formalism in which the slightest contradiction lets you prove absurdities.
Let's not be pedantic here. We call a technology illegal when there is no legal way to use it. Wifi stations do not just discard frames not intended for them; APs typically keep track of the frequency utilization in their immediate vicinity in order to choose the least crowded channel for the networks they manage. More advanced APs (e.g. CBW APs) will also keep track of other APs and nearby stations long-term for various other purposes (mostly related to improving wireless throughput). There is also DFS/TPC in the 5Ghz band, which involves continuously listening for transmissions that are clearly not intended for any wifi devices (and recording the time and frequency on which such a transmission was received so that an AP does not select that channel again).
If your argument is that "displaying" the received transmission is the issue, then Google has done nothing wrong, because the BSSID/GPS database is not "displayed" to any human beings -- the entire system is automated, much like the CSMA and DFS/TPC technologies of wifi itself. Personally I think that is a weak argument since it would make it legally questionable to use a debugger on a device that operates in an explicitly unlicensed part of the radio spectrum.
You are right that judges and juries are human beings. They make mistakes when they are tasked with interpreting laws governing technologies they do not understand, and that is why we rely on organizations like the FCC, which are supposed to rely on actual experts when deciding compliance. I doubt that any major corporation would sell wifi equipment if there was any serious question about the legality of monitoring transmissions intended for other stations in the ISM bands. This whole debate sounds like another case of "Google did something, how dare they!"
This seems like a plausible argument to me. Google use similar arguments with, say, Gmail: their algorithms can read your mail and use what they learn to show you ads, but individual engineers can't, even for debugging purposes.
The restrictions are on how the hardware is used, not what it's technically capable of.
Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
It's crowdsourced from android devices (apple does the same with iOS devices). AFAIK google also grabs it with street view cars.
>Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
>If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Yes, but AFAIK on android grabbing SSIDs require the "location" permission for this exact reason.
>Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
That's on them, not google.
I don't know. But in countries without strong privacy laws the carrier can sell something similar as triangulated by the cell network.
https://www.zdnet.com/article/us-cell-carriers-selling-acces...
Yes if you have it turned on and you're signed into Google.
> Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
Turning off GPS stops GPS, not SSID tracking. Modern Android doesn't have a GPS toggle though. It has a "Location" toggle which stops the OS from sending the data to Google. However it does not turn off the location feature in Google Chrome (or other web browsers).
> If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Google doesn't share their data with 3rd parties.
> Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
No.
I used to work for one of those third parties, here's google's public docs detailing how they provide that information: https://developers.google.com/authorized-buyers/rtb/realtime... (note: "geo", "geo_criteria_id", "postal_code", etc.)
Your computer will poll for the SSID it's setup to auto-associate to (as they may be hidden). I get the SSID of your home network, and look it up in the database.
How creepy is it that these two not very privacy interrupting things -- collecting observed SSID in the wild, and your laptop attempting to connect to things it knows essentially broadcasts your home address when you're at a conference or a coffee shop? Hope you never have a stalker.
Worse, google's "opt out" procedure makes your SSID more unique and makes this attack even more effective.
Geographically speaking, how were those SSID's distributed? Were they spread all around the world, across the continent, or were they all in the same city?
For example, if your home SSID was known and those 216 SSID's were spread around the world, your home could likely be narrowed down based on some general facts from forum posts. "You spell honor with a U! You often complain about the rain on the forums, and those posts came from that ISP's IP block! According to the public coverage maps for that ISP in that English-speaking country that uses British spellings, your wireless network overlaps with this side of the street, give or take 30m. Let's check it out!"
Paranoid fantasy? I truly hope so.
https://developers.google.com/maps/documentation/geolocation...
there are also many open source wifi location databases that can be downloaded and queried locally
devices listening to ssid broadcasts for this purpose are common at grocery stores, malls, political protests, and more
Joe Stalker, however, probably won't get it from google. Unfortunately there are many other databases, including ones available at low cost (or free: https://wigle.net/ ) which the stalker is more likely to use, unless they work at google. And when you add "nomap" to turn off google's tracking you'll make your SSID more unique and trackable in every other database.
Since ssid is used as a seed in encryption, there’s value in making it unique.
AFAIK this sort of polling only happens if your phone has hidden networks remembered. Also, the probe it sends is for the ESSID (human readable string), not the BSSID (mac address). Most databases (including google) only allows for lookup by BSSID not ESSID so doing that sort of lookup is non-trivial.
Alas, no when you have a SSID remembered it doesn't know if it's hidden or not. (well maybe apple has some privacy behavior for this). It's not only used for hidden networks: clients probe so they can quickly enumerate nearby access points so they can switch over to them fast if they lose connectivity.
A few years ago when the whole "people are tracking your phones using wifi probes!" story got popular I ran packet captures on an android and ios device and found that neither made directed probe requests (ie. the kind that contained SSIDs). The man page for wpa_supplicant (which is used for android) seems to confirm this:
scan_ssid
SSID scan technique; 0 (default) or 1. Technique 0 scans for the
SSID using a broadcast Probe Request frame while 1 uses a
directed Probe Request frame. Access points that cloak
themselves by not broadcasting their SSID require technique 1,
but beware that this scheme can cause scanning to take longer to
complete.
https://www.daemon-systems.org/man/wpa_supplicant.conf.5.htm...If so the best way to have a phone that doesn't leak is to have a home network that does... maybe?
That certainly isn't a theoretical requirement; the alternative is "if you run a hidden network, your devices will not connect to it automatically". You'd have to tell them to connect.
An easy way around this would be to leave your wireless SSID on it's default (or set it to 'Linksys').
Exactly, and thus don't add _nomap.
Wifi needs an encrypted handshake
So your suggestion is to turn off WiFi completely on your devices, right?
If anything, SSID location is generally less sensitive than your name + phone number + city.
My point is that it used to be well-accepted that one’s home address and telephone number were explicitly public and indexed for easy access by anyone (at least anyone within the regional phone book’s coverage area). Now we get spooked that someone could obtain a home address using a fairly convoluted, difficult to target, and presumably expensive method involving the target’s smartphone attempting to connect to a wireless network and a large commercial database of wireless network locations.
I’m not even making judgements about this. I’m truly fascinated at how privacy threat models can vary so much from person to person and over time.
is there any services that coordinate this?
So you could do worse than just name your access point NETGEAR followed by a two-digit number. Of course, your laptop might decide lots of other networks are yours, but it won't have the password for them.
We make our SSID public so that we, or our friends, can easily access our WiFi, not so that somebody else use it as a tracking tool. Just because I make something possible, it doesn't mean that somebody else should take advantage of it ("hey, your car was unlocked, so of course I took it for a ride"), even more so when we talk about a huge corporation where the effort of taking advantage of this is much more than the effort that an individual must put to protect him/herself.
Want to use my SSID as a location tool ? I'm fine, but first you ask, and the let's talk about how much you're gonna pay for it.
Should companies have to ask you to use your house number as a location tool?
That number isn't on display for this person to use, it's more for your friends and mailmen to find your house, but well...
I guess the problem is the worldwide database it's put in.
Why is it a problem to know the gps location of a specific street name + house number? That seems like a pretty useful piece of information, especially in north america where a single street can span the entire width of a city. As for the downsides, what's the privacy implications of knowing that 73 elm street is located at -52.024290244005,101.13123390478796?
I have no issue with a police officer tailing and tracking a suspect with license plate ABC1234. That license plate number is publicly visible information. I do take issue with the police installing license plate cameras that give them a location history of the entire driving population of a city.
I have no issue with an acquaintance recognizing me by the shape of my face. If I go out in public, I expect to be publicly visible. I do take issue with Facebook running facial recognition on photos taken by their users, or installing their own facial recognition cameras, and sending advertisements and connection suggestions to me based on my proximity to other people.
I have no issue with my neighbor, trying to connect his wifi, seeing my SSID alongside his. The router needs to broadcast a publicly visible management beacon so that he can locate his wireless network and I can locate mine. I do take issue with Google making a global database to allow devices to use the visible SSIDs to determine their location.
I have no issue with a web server querying my browser to see what system fonts I have available, or what size my browser window is. These and other bits of information are useful to display the website I'm requesting to me. I do take issue with the server or their advertising partners using these characteristics to construct a fingerprint to track me across sessions or sites.
I recognize that there's no empirical difference between these uses. Public information is public, it's not obvious why the source should be able to determine how it's used or where the line is between acceptable, intended, private party use and unacceptable, automated, exploitative use. But I think I know what's acceptable when I see it.
But I wouldn't rule out that someone else looks at it differently to the degree that I'd pose it as a rhetorical question, as an example that's illuminating in its absurdity. That was really all I was trying to say.
Though whether or not it'd be a logistical nightmare for Google or startups really doesn't play into it; all kinds of privacy (and other) regulations are logistical nightmares for those whose business it is to violate them. E.g. kyc regulations were a logistical nightmare for financial services that didn't bother or didn't want to k their cs.
This is specifically prohibited by law. Now there are gray areas of things that are not prohibited by law that are usually not acceptable but I don't think this is even one of those. [1]
[1] Example might be if there is ketchup at a restaurant and no sign which says 'limit X packets' you could take all of the ketchup (does not violate any law) assuming you are in the restaurant as a customer.
They are - they answer the question "where is the AP with this BSSID?" repeatedly.
Not a public api? Just get an ap, change the BSSID and put your android phone in a faraday cage with it.
Domestic abuse victim in hiding but still has the old AP/wireless printer? Thanks Google!
Yes - it's very useful for access points which change location often.
Your SSID is there for you to connect to your private network. The fact that it is broadcasted is a technical limitation, and it is not intended for others beside you. Nobody besides technical people know that the SSID broadcasting can be disabled, and even less know how to use their wifi when it is disabled.
If they don't have an alternative to this opt-out then there's probably a GDPR case right there.
Hiding the network name doesn't conceal the network from detection or secure it against unauthorized access. It also makes your devices constantly send out that SSID wherever you go when searching for networks. According to Microsoft [0]:
> Non-broadcast networks are advertised in the probe requests sent out by wireless clients and in the responses to the probe requests sent by wireless APs.
[0]: https://docs.microsoft.com/en-us/previous-versions/tn-archiv...
Like being the only person on the block who blurs out their house on Google Maps or Apple Maps, it could backfire due to the Streisand Effect.
Your wireless router sends out a constant signal . That signal bounces off stuff, and can be measured in real time. Once a 3rd party has a calibrated measurement of your wifi signal, they can scan it and make relative measurements in real time. They can reconstruct what's going on in the room by reconstructing the triangulation of how the signal is changing. They've been able to fine-tune it enough to see a person breathing, or see their heart beating.
As this technology matures, I believe this will be the next-level of major privacy concerns.
Somehow it doesn't seem the same though. Somehow intuitively it seems different when people just look at you on the street and when some organization compiles a single database where every move of every person is recorded.
If I livestream you the whole time and archive the video of everything you do and everything visible in your windows, I bet you'd not feel as comfortable.
This is exactly the problem here: Your neighbours or passerbys seeing your SSID is not much of a problem, but a total stranger anywhere in the world finding your address only by (B)SSID is a problem.
Especially since these are usually not considered sensitive; you can find quite a few posts showing fun WiFi names or tech support posts were the ID is visible. Hell, maybe some streamers inadvertently show them because they don't know the implication! Combine that with rough information of where the user is from (country should suffice) and you can come knocking on their door.
The real problem here is that we usually are very protective of our actual address. These databases make SSIDs equally sensitive data, without people being aware of this.
I am not sure I follow. Total strangers can find my address by looking up ... my address.
My ssid is probably _less_ associated with my name and other identifying info than my address is, for that matter. Whereas I regularly supply my address to forms when I sign up for things or order packages for delivery, I never really explicitly give out my ssid.
A passerby could collect my ssid. They might be able to narrow it down to my building (or maybe the neighbors), but that's not terribly interesting data to strangers trying to "find my address". There are more direct ways to go about that.
Is there a global open address book with everyone's addresses?
1. Military and TLA agencies excepted.
In comparison, changing your SSID is free and something you can do yourself.
[1] https://www.nbcnews.com/business/consumer/unlisted-number-fe...
Meanwhile, there's no open address book associating ssids to names or ssids to addresses either.
In the U.K. the electoral roll does have most people’s addresses - about 70% of the country.
But I don't have your exact address.
> Whereas I regularly supply my address to forms when I sign up for things or order packages for delivery, I never really explicitly give out my ssid.
You'd think so. But it's easy to accidentally do this by submitting/posting a crash report (they quite often contain the WiFi SSID), asking for technical support, sharing a screenshot or simply opening the wrong window while streaming. Maybe you posted once in an "AskReddit: What's a funny wifi name?" thread. I doubt you'd simply post your address freely online and it would be much harder to get you to enter it into a form controlled by me.
> A passerby could collect my ssid. They might be able to narrow it down to my building (or maybe the neighbors), but that's not terribly interesting data to strangers trying to "find my address".
Sure it is. Right now, you could be anywhere in the world; the chance that I'd just walk by your house is minuscule. Even knowing you're near Boston makes that very hard. Only thanks to this database I could find out your exact address in minutes, given your SSID and a cursory look at your profile.
You also don't have my ssid.
You do have my username. I am fairly confident that you could connect my username to my real name with some minor searching. From there, plenty of tax records, property records, and other important interesting information is just a few clicks away.
I am not arguing that we should or should not be sharing ssids. I am merely wondering why the OP is somehow worried about strangers across the globe somehow going from a list of random ssids to anything more interesting than that.
A list of names, addresses, phone numbers, emails, or other publicly available information (leaked or otherwise) is far more worrisome than a list of ssids.
It's not the end of the world, yes, sure. But it's not great either.
It's a sidenote, but the blow-up point of this is that it's one of the very few data privacy points for which you can directly show the impact. Usually, you have to go with abstract "if your data is leaked" or "someone at XCorp could ...", but in this case, if I can find your SSID I can send you your address, no further questions asked. And everyone knows people who know their SSID and/or can easily imagine this scenario. I'm pretty sure that's why this exact list is blowing up so much more than the far more egregious privacy violations we otherwise see.
It's enough to look at your profile to find out you're in Stamford, so locally unique is sufficient. I don't intend to find out your address, but it is usually quite easy to narrow down someones location to state or city level (you'd probably be able to do the same for me). So unless there are hundreds of SSIDs with the same name in your city, finding you is probably not that hard. For mine, state would be sufficient.
> and can't be used to geolocate on their own.
Sure thing! https://wigle.net/ has a perfectly fine API which allows you to search by SSID.
I really though you'd study CompSci ;) Oh well.
> Regardless you didn't use my SSID to figure that out, which is my point, we all have lots of data points out there that are more public than SSIDs and those will be used to compromise us much faster than the SSID method will.
I think we intermingled two separate points there:
- An SSID is not unique. My point was, despite this being true, it is usually possible to narrow down the location far enough using auxiliary information so that an SSID is sufficiently unique. That was the point of my previous response to you.
- An SSID is usually not considered sensitive. For the two of us there are enough other data points, but quite a few people prefer not to have their nick linked to their real name. I doubt they are aware how fatal sharing it would be. As mentioned in sister comments, the name is also quite often in crash logs, so something as simple as seeking technical help might lead to your home address being compromised.
Now, this list is surely not the end of the world, but the privacy implications are pretty bad IMO.
In what case would "a total stranger anywhere in the world" get a hold of your BSSID?
The service in Android using (B)SSID for "a better experience" is configured off on my phone, and I explicitly turn off all location services when I don't actively need it. Every time I turn on location, then open Google Maps, Maps prompts me to turn on the "enhanced experience". Picture yourself in a bit of a rush, needing to do some quick navigation using your phone and Maps, and how easy it is to quickly dismiss that prompt without realizing you just offered Google more data.
Note: My default behavior regarding Google is to give them the absolute minimum amount of data.
> give them the absolute minimum amount of data
Contradiction, Mannie!
PS: Offline GPS turn-by-turn navigation devices from China are about $50 now. I use them myself ever since I decided I wanted to stop leaking my realtime location to Apple and Google.
The more cynically minded might even suggest Google has purposefully let GPS-only capability degrade as a dark pattern to push users to opt in to SSID-based services.
They research patterns, and they know how and when to ask you to press a button. Not illegal but unfair IMO. Take this post for example, changing SSID is so inconvenient that the user might not want to go through the whole process.
https://taskernet.com/shares/?user=AS35m8m3Ara1eYCAa0qvSgM5o...
[1]: People with a rooted Android phone that don't want GLA (Google Location Accuracy) but don't want to (or can't) disable it completely either.
LOL. Are they kidding?
Opting out of Google while opting into MS and Apple scanning is left as an exercise to the reader.
It reminds me that there was a version of Google Maps on iOS where if you wanted to cache a region of the map locally for offline use, you would (1) zoom out to view the full area to cache and (2) search for "OK Maps" to cache that area.†
Yes. Searching for "OK Maps" to cache it. You know, instead of maybe adding a button like in any normal app made for human beings?
I'm not at all surprised by this _nomap "solution".
† 2013 article: https://www.cnet.com/how-to/how-to-cache-offline-maps-in-lat...
It becomes a different issue when a corporation collects this information for business purposes. They are not random passersby. But I expect them to treat it with the same courtesy -- ignore, move on.
If you care about this, the burden is on you to make sure the signal does not go outside of your house or to make our wifi work in private mode (probably easiest solution). Google is simply taking advantage of what is essentially public information, they are doing it at scale and this should not be problematic at all.
We need to understand that when we live in a technologically advanced civilization (sufficiently advanced as to have Google cars driving around) there are some things we will have to give up as a part of enabling the technologically advanced environment that we chose to live in.
What we would have a problem with is not collecting then, but the way it is being used. A reasonable way to handle this for Google would be: rather than having a SSID opt out, have ad-tech opt-in as in 'we can optimize our ads based on your detected wifi location, would you like that?' Meaning: yes, it's fine that you collect publicly available information at scale, but if you want to use it for me (or against me, depending on your view), you have to ask me. Otherwise it would be violating my right to privacy.
There is no such thing. I have no problem finding the SSID for "hidden" networks.
> they are doing it at scale and this should not be problematic at all.
In fact it is my entire point that this is extremely problematic. Technology enables a whole new range of behavior not previously feasible, and society hasn't yet developed a way to deal with it. Just because Google can do something it does not mean they should do it.
> yes, it's fine that you collect publicly available information at scale, but if you want to use it for me (or against me, depending on your view), you have to ask me. Otherwise it would be violating my right to privacy.
I disagree. The existence of the aggregated data on me is itself the risk, itself the violation of privacy, not the moment when they leverage it for a particular purpose. This data aggregation is dangerous and needs to be regulated.
I do not believe in a utopian corporate world where everything Google does is for my benefit.
Yes I meant hidden networks, and I didn't know they were discoverable. Really? Why are are they called hidden then?
> The existence of the aggregated data on me is itself the risk, itself the violation of privacy
Yes it is a risk, but it is not in itself a violation of privacy. I think you are conflating secrecy and privacy a bit here.
You parents or close family posses a lot of private information about you and the very act of possession is not violation of privacy (but it does pose a risk that you have to live with, hoping and expecting they will respect your privacy).
Violation of privacy occurs at the moment this information is used in a way you would not approve.
Anonymity - you do not know about me
Secrecy - I do not want to share information with you
Privacy - I am OK to share my information with you and I trust you to not use it in a way that I would not approve ofI feel like I’m missing something when folks complain that someone geotagged the publicly-viewable SSID that their router, by the owner’s choice, shouts to anyone that will listen. And then act like it’s this big privacy invasion when someone does listen.
Why are we to assume that it isn't fine just because there's more of it?
Scale matters!
For all the "scale matters!" in this topic, no one seems to be able to articulate why. Were laws broken? Hell, were unspoken rules broken? What is $BAD_THING that will happen if $X "at scale!"? But instead what I read are broken analogies that don't stand up to scrutiny.
* If I kill an Armenian it's murder, if I kill every Armenian it's genocide.
* If I buy some shares of Google it's investing, if I buy every share of Google it's a takeover.
* If I happen to know where you are because a saw you in town it's a coincidence. If I know where you are 24/7 it's surveillance.
* If a friend sends my address to someone it's no big deal. If they post my address publicly it's doxxing.
The logic "if I can X at some scale then I can do X at any scale" doesn't follow because doing X at different scales might be totally different things. I don't think Google slurping up SSIDs is going to make $bad_thing happen but the justification for them doing the sluping is more complicated than "well it's fine if I wrote down one SSID..."
What you are suggesting is to me no different than asking why a random passer-by can take a photo of your house. Because of course they can. Saying that a person can not take an image of your house unless you have explicitly put up a sign saying your house can be photographed is an absurd proposition and a sad privatization of the public sphere. The color of your house is not within the domain of your privacy, and neither is the location of your WiFi if you choose to broadcast your SSID.
(Just to be clear this is not a legal argument.)
There is a similar debate about being photographed while in public: the fact that I'm walking in the street shouldn't allow anybody to take pictures of me, just because it has been decided that doing so would remove any "expectation of privacy".
That's my image. That's my house. If I don't want people to take picture of it and put in on the internet, it's my choice. And I don't think it is that unreasonable to want to control it.
I don't care about cityscape where the picture is taken from afar, where you can not discern any details of my house. But I don't want strangers to be able to see for example if I have dogs just by googling my address on internet.
In a world where free public spaces are becoming increasingly rare, we should strive to retain and protect them rather than make everything private and controlled.
That being said, I do think the privacy of what is clearly and truly in the private sphere should be protected strongly – such as what goes on inside your house outside of what is directly and easily visible to the street. But there need to be just as strong rights to enjoy the virtues of the public sphere to counterbalance the strong protection of the private sphere.
by empowering a private company to profit from what this person considers to be private?
Don't do that, it'll counter-intuitively have the opposite effect: if you disable broadcasting the SSID on your router, then all the clients (phones, laptops, etc) which wish to connect to it have to broadcast that SSID when searching for nearby access points, instead of just asking all nearby access points for their SSID. That is: disabling broadcasting the SSID on the router means requiring broadcasting that same SSID from all the clients, even (and especially) when they're nowhere near that router.
I'd argue that by the same reasoning, SSID and MAC address are even more identifying, because IP addresses aren't as static as changing your WiFi configuration. Driving around and mapping this type of data should probably be considered a violation of the GDPR in the same way tracking the IP address of users visiting a website is.
I'm fairly certain you could make a claim against Google for processing this data without consent, without an immediate retraction (Google Streetview still lists 8 year old photos here) or opt-in.
Receiving data is fine, but processing it and mapping it out is not. In the same way, gathering IP addresses for logging and diagnostic purposes is okay, but selling "what IP accessed what page" is not. Taking a picture of your house from the street is not illegal, yet if I were to point a camera at your house that takes a picture every second so I can sell accounts for a premium "vesinisa's house stream" online, you'd probably get the police involved in its removal eventually. Intent matters as much as the actions themselves in most cases.
But the issue arises from the fact that this is done in bulk and is comprehensively catalogued centrally. I think that commenting on a person photographing your house misses the point, because the scale is the thing that matters here. It's not the individual act of recording your SSID, but the scale of doing it in bulk that transforms this activity into something that is unlike photographing your neighbor's house.
For Street View, you can opt yourself out by telling Google: https://www.forbes.com/sites/zakdoffman/2020/09/27/how-to-hi...
Whereas for the WiFi map, you apparently have to opt yourself out by changing your SSID.
...But at least it wasn't strictly "ends with" (unlike Google's), so "_optout_nomap" should work. (Except MS killed the feature anyway.)
[1]: https://krebsonsecurity.com/2015/07/windows-10-shares-your-w...
As opposed to a street address? In most cases there's a 1 to 1 relationship between a house and a hotspot.
But it's not a competition anyway. Address data being freely available doesn't make other privacy abuses any less bad.
If the mapping of SSIDs to GPS coordinates is a "privacy abuse", what does it say about mappings of house numbers to GPS coordinates? Should companies like google/tomtom be banned from collecting such mappings?
People who are concerned about their address privacy will often put their home in the ownership of trust or a corporation. That data, despite being regularly collected, is exploitable, and is often exploited. I'm not saying this should be legally changed, but pointing out that it is reasonable to bring up the concern.
Your characterization of it as a "privacy abuse" suggests otherwise. Moreover, my argument is that most people wouldn't call a mapping of street numbers to gps coordinates a privacy abuse, so it would be absurd to call a mapping of BSSIDs to gps coordinates a privacy abuse as well since they're both pretty similar.
Abuse is all about what someone does with the data.
I probably would have been more clear if I had said "potential privacy abuses" above. Any time this data is given/sold to third parties without any legal framework for protecting it, it is ripe for potential abuse.
Okay, what are some plausible privacy abuses that can come from this?
An SSID is created by a private individual for private use and its use as a tracking tool must be discouraged.
Why is this relevant? SSNs are government assigned but they're private.
>looking up who lives at a certain address is not trivial and will certainly raise eyebrows
But we're not talking about address-to-person or ssid-to-person mappings here, we're talking about address-to-location or ssid-to-location mapping.
>An SSID is created by a private individual for private use and its use as a tracking tool must be discouraged.
What about other privately made identifying features? ie. "I'm in front of the ranch style house with blue walls and a tire swing out front".
Compare that to the name of your private router that happens to be broadcasted far outside your house for technical reasons.
To be honest I am not sure where I stand on the issue, but I sympathize on the uneasiness of a global corporation taking advantage of a situation in a way few people ever thought about. That's where I think the perception of the public/private status diverge for most people.
Stop collecting information. This is way beyond anything but privacy intrusion.
It's like telling another some big corporation that one has to change the name else they will profile you irrespective of what you do...
Atrocious isn't? Publicly available information doesn't mean that you will whatever you want with it.
Tomorrow, (already their OS, Android is doing it), they will collect everything about a person and this is going way beyond who has signed up for. This needs to stop. All in the name of providing services or improving lives of people. Who cares about the dark side? How much profiling has gone into the collected data? What kind of risks it may pose in the future?
This needs to stop... the sooner the better...
Everyone has the right to be private. It doesn't mean one has to throw away everything in public about them. Isn't?
I know I might start another discussion thread, but I'm sure there will be people who will battle for and against... But it doesn't matter...
Interesting tidbit from [1]: "In older versions of Apple's mobile OS (1.1.3 to 3.1), Apple relied on Google and Skyhook Wireless to provide location-based services -- so Apple left data collection to them. But ever since April 2010, starting with iPhone OS 3.2 and continuing into the current iOS 4 software, Apple has started using its own databases to provide location-based services to iOS devices."
That's annoying, but I don't actually care, that much. My access points are locked down about as well as possible, and having them in there actually helps to improve map accuracy. I just switched ISPs, and I'm currently getting ads that think I'm in New Jersey. As soon as my new router gets re-mapped, I'll be getting ads that make it seem as if stock photo models are local lawyers.
Anyone that really wants to get into my access points could probably do so, but I also have a few layers of security (multiple routers of different manufacture), as well as fixed MAC addresses (which is a pain for the iOS devices).
Also, I'm surrounded by neighbors that have much lower-hanging fruit.
You don’t have to outrun the bear, you just have to outrun the other campers ;)
Google is assuming (much as it assumed with crawling the Internet) that information broadcast in the clear into the world is fine to aggregate.
(Personally, the only part I'm sad about is that since there's no hidden metadata channel to take advantage of in the 802.11 protocols, they can't squirrel away the "nomap" in a hidden state and instead have to gum up the human-visible SSIDs to transmit the intent to not be indexed).
It’s more similar to walking along the street compiling a list of what colour curtains people put up in their window. Sure you’ve technically got it on display but people don’t really expect that information to be aggregated and shared.
Ease dropping on a conversation on the bus or a train is another example. You can’t really complain if someone overhears but that’s a far cry from someone then publishing what they overhear
You're framing this as an absolute and that's just not true. Were it the case, robots.txt wouldn't exist and I wouldn't be using it.
Also you shouldn’t really be using robots.txt any more unless it’s a simple “Disallow: /“ because ironically bad actors use it to decide what URIs to hit. If you have content up you want to limit access to, you’re much better off putting it behind an auth layer (even if it’s just simple HTTP auth + fail2ban)
And certainly in the era when search engines were being developed (in the early '90s, when robots.txt came into existence), there was no such aggregation expectation because the technology wasn't there to do such aggregation yet. Linking from one document to another has always been a part of the standard, but I don't think one could assume anything one published would end up in a vast auto-generated index.
On the flip side, Google operates under the general assumption that in the absence of reasons to the contrary, there is nothing wrong with info aggregation. "Aggregation is okay" is their default stance. Organizing the world's information and making it universally accessible are tent-poles in their mission statement.
I know, I run such website myself (it’s where I upload family photos to share with other family members. Basically the good bits of Facebook but without having to deal with Facebook).
However your point is that my generalisation was unsound and thus far you’ve just listed edge cases. Edge cases I acknowledge, sure. But edge cases are allowed to exist when one uses generalisations because the purpose of a generalisation is saying “in general” (ie most of the time) and not “all of the time”.
So while your points are valid, they’re not a rebuttal.
> And certainly in the era when search engines were being developed (in the early '90s, when robots.txt came into existence), there was no such aggregation expectation because the technology wasn't there to do such aggregation yet
Aggregated index sites still existed back then. The difference between then and now was that they were curated by humans.
My first website was published in 1994 so I do remember the early web pretty well :)
> On the flip side, Google operates under the general assumption that in the absence of reasons to the contrary, there is nothing wrong with info aggregation. "Aggregation is okay" is their default stance. Organizing the world's information and making it universally accessible are tent-poles in their mission statement.
I’m well aware of Google’s original mission. I don’t think it’s fair to say this remains their current mission (maybe one of their missions but they’re a much larger organisation now and each department will have their own goals and measurements).
However the point of this discussion wasn’t what Google’s past nor present mission was/is, it’s whether it’s ethically sound in the very specific context of SSID aggregation.
Not at all. Changing a robots.txt file doesn't break anything. Changing my SSID would mean reconfiguring 50 devices, many of which are not terribly simple to reconfigure.
I have many, many devices using my WiFi, some of them (home made) IoT devices with custom firmware and the SSID/BSSID baked in to the firmware. Changing my SSID is a huge undertaking and I'm sure Google is aware of this.
I don't get to opt out, unless I want half of my home automation to stop working and potentially weeks of effort to get the rest of it back up and running.
Perhaps the better way to handle it would have devices rotate SSID's and/or passwords and/or router MAC's on a regular basis. Like algorithmically have all devices compute the SSID on a daily basis (with a few hours dual-broadcasting SSID's to account for clock issues) based on a seed.
Source: https://support.apple.com/en-in/HT202339
But apple is good while Google bad :)
Edit: found out a newer post [1] with absolutely no mention on how to opt out.
They also send barometeric pressure level for some reason. They might also start sending device temps to predict the temperature at different places across globe and "help their customers" [1] https://support.apple.com/en-us/HT203033
What do I do if I only want to opt out of Google?
https://android.stackexchange.com/questions/221261/does-andr...
fingerprinting/tracking. even with wifi mac randomization enabled, if you see a given client broadcasting a certain set of SSIDs you can use that to track them.
Certainly too creepy for the public to allow (or even imagine) today but perhaps in 5 or 10 years the masses may be sufficiently conditioned to consider the privacy tradeoff worth whatever conveniences (or ‘security’ benefits) it dishes up for them.
Marketed as ‘public view’ imagine Boston Dynamics or drones with more ai, solar powered, operating at amazon or google scale. Maybe they’ll even dress them up like birds and other wildlife to give it an ‘organic’ or natural feel. Fun times.
Packets are transmitted with this information unencrypted at all times. This means that when you move your AP from your old house to your new, your move is publicly visible unless you replace your AP when moving.
In fact, if everyone did this, the alleged privacy problem would go away. Wifi stations really would just be like street numbers.
I'm not sure I understand the threat model here.
I become interested in you. I sniff traffic to see which wifi access points your phone tries to connect to. I look up the SSIDs and find a plausible match for your home or workplace. I show up so we can hang out.
There is zero need to hide your ssid and location drom google location services.
I am a little worried when politicians will start making laws to control them. The reaction might be "let's just go with the other party" which creates the basis for a 1984-esque future...
https://gdpr.eu/recital-30-online-identifiers-for-profiling-...
> Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols, such as internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags. This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them.
WiFi maps do not fall within the scope of existing European privacy legislation. They do not consist of ‘location data’ as defined by the E-Privacy Directive, nor do they consist of ‘personal data’ under the Data Protection Directive, except in highly unusual and very rare circumstances.
Quite amazing isn't it that a company with so many extremely talented employees (I'm actually serious) can produce such utter nonsense at such scales ..?
They had a huge stink on this some years ago when 'some random engineer decided to add it to Google Maps sniffing'.. and now it's opt-out?
I must say I'm surprised.
The Google car that is used to take images of the StreetView also collected SSID's (and infamously got in trouble for sniffing packets too).
So GPS location + Multiple SSIDs = triangulated location for mobile devices. Google is able to use each mobile devices' location, and it's GPS co-ordinates, and the location of your neighbours SSID, all that raw data makes for a very accurate location detection even without YOU ever using Google's services.
You might have stood a chance if you lived in a Faraday cage, but the only thing that will stop this behemoth is legislation and politicians with morals.
A lot of Google stuff, including Android phones, and Street View and Waymo cars, engage in Passive Wardriving [0]. They build a database mapping SSID names to GPS coordinates. This is legal, even without requesting consent, because (1) it is not hacking, since they are not actually accessing your network, but merely "approaching" it (2) it is not a privacy violation, because there is no reasonable expectation of privacy for wifi SSIDs.
As a courtesy, Google does allow you to configure your network to not show up in their database, much like robots.txt does for websites. But it involves changing your SSID, which is a very annoying way of doing it, because you have to reconfigure everything on your network to point at the new SSID. It's probably just an underhanded way of making it annoying enough that nobody bothers.