If I livestream you the whole time and archive the video of everything you do and everything visible in your windows, I bet you'd not feel as comfortable.
This is exactly the problem here: Your neighbours or passerbys seeing your SSID is not much of a problem, but a total stranger anywhere in the world finding your address only by (B)SSID is a problem.
Especially since these are usually not considered sensitive; you can find quite a few posts showing fun WiFi names or tech support posts were the ID is visible. Hell, maybe some streamers inadvertently show them because they don't know the implication! Combine that with rough information of where the user is from (country should suffice) and you can come knocking on their door.
The real problem here is that we usually are very protective of our actual address. These databases make SSIDs equally sensitive data, without people being aware of this.
I am not sure I follow. Total strangers can find my address by looking up ... my address.
My ssid is probably _less_ associated with my name and other identifying info than my address is, for that matter. Whereas I regularly supply my address to forms when I sign up for things or order packages for delivery, I never really explicitly give out my ssid.
A passerby could collect my ssid. They might be able to narrow it down to my building (or maybe the neighbors), but that's not terribly interesting data to strangers trying to "find my address". There are more direct ways to go about that.
Is there a global open address book with everyone's addresses?
1. Military and TLA agencies excepted.
In comparison, changing your SSID is free and something you can do yourself.
[1] https://www.nbcnews.com/business/consumer/unlisted-number-fe...
Meanwhile, there's no open address book associating ssids to names or ssids to addresses either.
In the U.K. the electoral roll does have most people’s addresses - about 70% of the country.
But I don't have your exact address.
> Whereas I regularly supply my address to forms when I sign up for things or order packages for delivery, I never really explicitly give out my ssid.
You'd think so. But it's easy to accidentally do this by submitting/posting a crash report (they quite often contain the WiFi SSID), asking for technical support, sharing a screenshot or simply opening the wrong window while streaming. Maybe you posted once in an "AskReddit: What's a funny wifi name?" thread. I doubt you'd simply post your address freely online and it would be much harder to get you to enter it into a form controlled by me.
> A passerby could collect my ssid. They might be able to narrow it down to my building (or maybe the neighbors), but that's not terribly interesting data to strangers trying to "find my address".
Sure it is. Right now, you could be anywhere in the world; the chance that I'd just walk by your house is minuscule. Even knowing you're near Boston makes that very hard. Only thanks to this database I could find out your exact address in minutes, given your SSID and a cursory look at your profile.
You also don't have my ssid.
You do have my username. I am fairly confident that you could connect my username to my real name with some minor searching. From there, plenty of tax records, property records, and other important interesting information is just a few clicks away.
I am not arguing that we should or should not be sharing ssids. I am merely wondering why the OP is somehow worried about strangers across the globe somehow going from a list of random ssids to anything more interesting than that.
A list of names, addresses, phone numbers, emails, or other publicly available information (leaked or otherwise) is far more worrisome than a list of ssids.
It's not the end of the world, yes, sure. But it's not great either.
It's a sidenote, but the blow-up point of this is that it's one of the very few data privacy points for which you can directly show the impact. Usually, you have to go with abstract "if your data is leaked" or "someone at XCorp could ...", but in this case, if I can find your SSID I can send you your address, no further questions asked. And everyone knows people who know their SSID and/or can easily imagine this scenario. I'm pretty sure that's why this exact list is blowing up so much more than the far more egregious privacy violations we otherwise see.
It's enough to look at your profile to find out you're in Stamford, so locally unique is sufficient. I don't intend to find out your address, but it is usually quite easy to narrow down someones location to state or city level (you'd probably be able to do the same for me). So unless there are hundreds of SSIDs with the same name in your city, finding you is probably not that hard. For mine, state would be sufficient.
> and can't be used to geolocate on their own.
Sure thing! https://wigle.net/ has a perfectly fine API which allows you to search by SSID.
I really though you'd study CompSci ;) Oh well.
> Regardless you didn't use my SSID to figure that out, which is my point, we all have lots of data points out there that are more public than SSIDs and those will be used to compromise us much faster than the SSID method will.
I think we intermingled two separate points there:
- An SSID is not unique. My point was, despite this being true, it is usually possible to narrow down the location far enough using auxiliary information so that an SSID is sufficiently unique. That was the point of my previous response to you.
- An SSID is usually not considered sensitive. For the two of us there are enough other data points, but quite a few people prefer not to have their nick linked to their real name. I doubt they are aware how fatal sharing it would be. As mentioned in sister comments, the name is also quite often in crash logs, so something as simple as seeking technical help might lead to your home address being compromised.
Now, this list is surely not the end of the world, but the privacy implications are pretty bad IMO.
In what case would "a total stranger anywhere in the world" get a hold of your BSSID?
Your computer will poll for the SSID it's setup to auto-associate to (as they may be hidden). I get the SSID of your home network, and look it up in the database.
How creepy is it that these two not very privacy interrupting things -- collecting observed SSID in the wild, and your laptop attempting to connect to things it knows essentially broadcasts your home address when you're at a conference or a coffee shop? Hope you never have a stalker.
Worse, google's "opt out" procedure makes your SSID more unique and makes this attack even more effective.
Geographically speaking, how were those SSID's distributed? Were they spread all around the world, across the continent, or were they all in the same city?
For example, if your home SSID was known and those 216 SSID's were spread around the world, your home could likely be narrowed down based on some general facts from forum posts. "You spell honor with a U! You often complain about the rain on the forums, and those posts came from that ISP's IP block! According to the public coverage maps for that ISP in that English-speaking country that uses British spellings, your wireless network overlaps with this side of the street, give or take 30m. Let's check it out!"
Paranoid fantasy? I truly hope so.
https://developers.google.com/maps/documentation/geolocation...
there are also many open source wifi location databases that can be downloaded and queried locally
devices listening to ssid broadcasts for this purpose are common at grocery stores, malls, political protests, and more
Joe Stalker, however, probably won't get it from google. Unfortunately there are many other databases, including ones available at low cost (or free: https://wigle.net/ ) which the stalker is more likely to use, unless they work at google. And when you add "nomap" to turn off google's tracking you'll make your SSID more unique and trackable in every other database.
Since ssid is used as a seed in encryption, there’s value in making it unique.
AFAIK this sort of polling only happens if your phone has hidden networks remembered. Also, the probe it sends is for the ESSID (human readable string), not the BSSID (mac address). Most databases (including google) only allows for lookup by BSSID not ESSID so doing that sort of lookup is non-trivial.
Alas, no when you have a SSID remembered it doesn't know if it's hidden or not. (well maybe apple has some privacy behavior for this). It's not only used for hidden networks: clients probe so they can quickly enumerate nearby access points so they can switch over to them fast if they lose connectivity.
A few years ago when the whole "people are tracking your phones using wifi probes!" story got popular I ran packet captures on an android and ios device and found that neither made directed probe requests (ie. the kind that contained SSIDs). The man page for wpa_supplicant (which is used for android) seems to confirm this:
scan_ssid
SSID scan technique; 0 (default) or 1. Technique 0 scans for the
SSID using a broadcast Probe Request frame while 1 uses a
directed Probe Request frame. Access points that cloak
themselves by not broadcasting their SSID require technique 1,
but beware that this scheme can cause scanning to take longer to
complete.
https://www.daemon-systems.org/man/wpa_supplicant.conf.5.htm...If so the best way to have a phone that doesn't leak is to have a home network that does... maybe?
That certainly isn't a theoretical requirement; the alternative is "if you run a hidden network, your devices will not connect to it automatically". You'd have to tell them to connect.
An easy way around this would be to leave your wireless SSID on it's default (or set it to 'Linksys').
Exactly, and thus don't add _nomap.
Wifi needs an encrypted handshake
So your suggestion is to turn off WiFi completely on your devices, right?
If anything, SSID location is generally less sensitive than your name + phone number + city.
My point is that it used to be well-accepted that one’s home address and telephone number were explicitly public and indexed for easy access by anyone (at least anyone within the regional phone book’s coverage area). Now we get spooked that someone could obtain a home address using a fairly convoluted, difficult to target, and presumably expensive method involving the target’s smartphone attempting to connect to a wireless network and a large commercial database of wireless network locations.
I’m not even making judgements about this. I’m truly fascinated at how privacy threat models can vary so much from person to person and over time.
is there any services that coordinate this?
So you could do worse than just name your access point NETGEAR followed by a two-digit number. Of course, your laptop might decide lots of other networks are yours, but it won't have the password for them.
We make our SSID public so that we, or our friends, can easily access our WiFi, not so that somebody else use it as a tracking tool. Just because I make something possible, it doesn't mean that somebody else should take advantage of it ("hey, your car was unlocked, so of course I took it for a ride"), even more so when we talk about a huge corporation where the effort of taking advantage of this is much more than the effort that an individual must put to protect him/herself.
Want to use my SSID as a location tool ? I'm fine, but first you ask, and the let's talk about how much you're gonna pay for it.
Should companies have to ask you to use your house number as a location tool?
That number isn't on display for this person to use, it's more for your friends and mailmen to find your house, but well...
I guess the problem is the worldwide database it's put in.
Why is it a problem to know the gps location of a specific street name + house number? That seems like a pretty useful piece of information, especially in north america where a single street can span the entire width of a city. As for the downsides, what's the privacy implications of knowing that 73 elm street is located at -52.024290244005,101.13123390478796?
I have no issue with a police officer tailing and tracking a suspect with license plate ABC1234. That license plate number is publicly visible information. I do take issue with the police installing license plate cameras that give them a location history of the entire driving population of a city.
I have no issue with an acquaintance recognizing me by the shape of my face. If I go out in public, I expect to be publicly visible. I do take issue with Facebook running facial recognition on photos taken by their users, or installing their own facial recognition cameras, and sending advertisements and connection suggestions to me based on my proximity to other people.
I have no issue with my neighbor, trying to connect his wifi, seeing my SSID alongside his. The router needs to broadcast a publicly visible management beacon so that he can locate his wireless network and I can locate mine. I do take issue with Google making a global database to allow devices to use the visible SSIDs to determine their location.
I have no issue with a web server querying my browser to see what system fonts I have available, or what size my browser window is. These and other bits of information are useful to display the website I'm requesting to me. I do take issue with the server or their advertising partners using these characteristics to construct a fingerprint to track me across sessions or sites.
I recognize that there's no empirical difference between these uses. Public information is public, it's not obvious why the source should be able to determine how it's used or where the line is between acceptable, intended, private party use and unacceptable, automated, exploitative use. But I think I know what's acceptable when I see it.
But I wouldn't rule out that someone else looks at it differently to the degree that I'd pose it as a rhetorical question, as an example that's illuminating in its absurdity. That was really all I was trying to say.
Though whether or not it'd be a logistical nightmare for Google or startups really doesn't play into it; all kinds of privacy (and other) regulations are logistical nightmares for those whose business it is to violate them. E.g. kyc regulations were a logistical nightmare for financial services that didn't bother or didn't want to k their cs.
This is specifically prohibited by law. Now there are gray areas of things that are not prohibited by law that are usually not acceptable but I don't think this is even one of those. [1]
[1] Example might be if there is ketchup at a restaurant and no sign which says 'limit X packets' you could take all of the ketchup (does not violate any law) assuming you are in the restaurant as a customer.
Hiding the network name doesn't conceal the network from detection or secure it against unauthorized access. It also makes your devices constantly send out that SSID wherever you go when searching for networks. According to Microsoft [0]:
> Non-broadcast networks are advertised in the probe requests sent out by wireless clients and in the responses to the probe requests sent by wireless APs.
[0]: https://docs.microsoft.com/en-us/previous-versions/tn-archiv...
Like being the only person on the block who blurs out their house on Google Maps or Apple Maps, it could backfire due to the Streisand Effect.
I think there's a tradeoff here. Having people carve out more and more frequencies that become illegal to monitor might not actually make the world a better place in the long run.
Don't broadcast things you don't want received.
Google was successfully sued over this, and to my knowledge the law has not been changed in the decade since then: https://en.wikipedia.org/wiki/Joffe_v._Google,_Inc.
In particular, the SSID of a network is readily accessible to anyone with a Wi-Fi device, whereas the contents of data packets (even unencrypted ones) are not accessible unless you have packet-sniffing software and know how to use it. This seems to me like a fairly common-sense interpretation.
You can still own general-purpose radio receivers (subject to the usual FCC rules about radiated emissions and so on). The legal restrictions are about what you can do with that equipment.
...if true, then wifi itself is illegal, because every wifi station will "intercept" (i.e. receive) frames transmitted by nearby stations in order to avoid interference when attempting to transmit a frame.
Sure, whenever somebody else sends a Wi-Fi packet in your vicinity, the components in your phone are physically reacting to the signal that they receive, and inspecting the data to see if you're the intended recipient. If the packet is addressed to somebody else, and your device never stores or displays the payload, then obviously you are not intentionally intercepting anything.
The law assumes judges and juries are human beings, who have at least a modicum of intelligence and common sense. It's not a mathematical formalism in which the slightest contradiction lets you prove absurdities.
Let's not be pedantic here. We call a technology illegal when there is no legal way to use it. Wifi stations do not just discard frames not intended for them; APs typically keep track of the frequency utilization in their immediate vicinity in order to choose the least crowded channel for the networks they manage. More advanced APs (e.g. CBW APs) will also keep track of other APs and nearby stations long-term for various other purposes (mostly related to improving wireless throughput). There is also DFS/TPC in the 5Ghz band, which involves continuously listening for transmissions that are clearly not intended for any wifi devices (and recording the time and frequency on which such a transmission was received so that an AP does not select that channel again).
If your argument is that "displaying" the received transmission is the issue, then Google has done nothing wrong, because the BSSID/GPS database is not "displayed" to any human beings -- the entire system is automated, much like the CSMA and DFS/TPC technologies of wifi itself. Personally I think that is a weak argument since it would make it legally questionable to use a debugger on a device that operates in an explicitly unlicensed part of the radio spectrum.
You are right that judges and juries are human beings. They make mistakes when they are tasked with interpreting laws governing technologies they do not understand, and that is why we rely on organizations like the FCC, which are supposed to rely on actual experts when deciding compliance. I doubt that any major corporation would sell wifi equipment if there was any serious question about the legality of monitoring transmissions intended for other stations in the ISM bands. This whole debate sounds like another case of "Google did something, how dare they!"
This seems like a plausible argument to me. Google use similar arguments with, say, Gmail: their algorithms can read your mail and use what they learn to show you ads, but individual engineers can't, even for debugging purposes.
The restrictions are on how the hardware is used, not what it's technically capable of.
They are - they answer the question "where is the AP with this BSSID?" repeatedly.
Not a public api? Just get an ap, change the BSSID and put your android phone in a faraday cage with it.
Domestic abuse victim in hiding but still has the old AP/wireless printer? Thanks Google!
Your wireless router sends out a constant signal . That signal bounces off stuff, and can be measured in real time. Once a 3rd party has a calibrated measurement of your wifi signal, they can scan it and make relative measurements in real time. They can reconstruct what's going on in the room by reconstructing the triangulation of how the signal is changing. They've been able to fine-tune it enough to see a person breathing, or see their heart beating.
As this technology matures, I believe this will be the next-level of major privacy concerns.
Your SSID is there for you to connect to your private network. The fact that it is broadcasted is a technical limitation, and it is not intended for others beside you. Nobody besides technical people know that the SSID broadcasting can be disabled, and even less know how to use their wifi when it is disabled.
If they don't have an alternative to this opt-out then there's probably a GDPR case right there.
Yes - it's very useful for access points which change location often.
Somehow it doesn't seem the same though. Somehow intuitively it seems different when people just look at you on the street and when some organization compiles a single database where every move of every person is recorded.
Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
It's crowdsourced from android devices (apple does the same with iOS devices). AFAIK google also grabs it with street view cars.
>Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
>If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Yes, but AFAIK on android grabbing SSIDs require the "location" permission for this exact reason.
>Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
That's on them, not google.
I don't know. But in countries without strong privacy laws the carrier can sell something similar as triangulated by the cell network.
https://www.zdnet.com/article/us-cell-carriers-selling-acces...
Yes if you have it turned on and you're signed into Google.
> Is their advertising now using the SSIDs I pass by to track me even when I explicitly turn off GPS?
Turning off GPS stops GPS, not SSID tracking. Modern Android doesn't have a GPS toggle though. It has a "Location" toggle which stops the OS from sending the data to Google. However it does not turn off the location feature in Google Chrome (or other web browsers).
> If I turn off location history in Google, does this prevent that information being shared with others in the ad industry chain?
Google doesn't share their data with 3rd parties.
> Do I need to track all them down and find how to opt out of them having a database of my frequent locations?
No.
I used to work for one of those third parties, here's google's public docs detailing how they provide that information: https://developers.google.com/authorized-buyers/rtb/realtime... (note: "geo", "geo_criteria_id", "postal_code", etc.)