Google is mapping your wi-fi access point and the opt-out options stinks
tech.icrontic.com
tech.icrontic.com
Apple does the same thing, although they collect it from user's iphones and ipads: http://www.apple.com/pr/library/2011/04/27Apple-Q-A-on-Locat...
One of the original companies that did this was skyhook and they also use vehicles driving around: http://www.skyhookwireless.com/howitworks/
Google is actually going above and beyond normal industry privacy protections by offering a reasonably simple opt-out. They are recommending that others in the industry do the same. Calling instead for an opt-in system effectively destroys this whole service's effectiveness for everyone.
...but that doesn't create leverage or a good reason for having such a poor and inelegant opt-out. This is an "ends justifies the means" argument, which is in itself Machiavellian.
From a different perspective, there are other ways Google could handle an opt-out list - such as letting people add their SSID/Mac Address to a central opt-out registry they maintain.
This would be trivial to implement, but I would suggest that Google have intentionally created a high-friction solution of "-nomap" to your SSID simply to make it as difficult and unpalatable as possible. And that really stinks.
The HN crowd might skew a little different distribution in their technical ability to do things like identify a mac adddress.
1) The amount of Mac addresses for each vendor is very limited. Blacklisting a few Mac addresses would therefore blacklist lots of routers. Combining this with the SSID doesn't really help that much, as many users will stick to the default SSID. (And if you require that users change their SSID to a non-default one you can as well require that they just add a given suffix).
2) In the EU there have not only been complaints about Google offering the data, but also about Google processing the data. So I guess they want to make sure that their streetview cars that log this data don't log opt-opt routers at all. It's simple to do if the SSID has such a suffix. It'd be much harder if the software system in the card would need to query a central opt-out database before processing a router's data.
MAC addresses should be globally unique. If your hardware vendor is shipping lots of routers with a shared MAC, they've messed up really badly.
In the past (working at an ISP) I've seen collisions on Ethernet hardware (two Ethernet cards with the same MAC address). So if that even happens in a relatively small Ethernet, I assume that this will be fairly common if your address space includes each active WiFi router.
You can generally trust than a hardware-embedded MAC is unique.
http://blogs.msdn.com/b/oldnewthing/archive/2004/02/11/71307...
A serendipitous example of the difficulty of Google's opt-out "solution" is that the correct SSID suffix is "_nomap", not "-nomap"! The Icrontic article is incorrect. I would hope Google forgivingly matches any "*nomap" SSID.
http://googleblog.blogspot.com/2011/11/greater-choice-for-wi...
I love Google as a company but it seems that more and more of it seems to be getting shrouded behind lawyer speak. It makes me uncomfortable.
Thank you, that's a kind comment. But this happens on almost every comment I leave: I get downvoted once or twice and then the comment slowly gets upvoted.
I think I have a troll (or even a script) that downvotes new comments I make to HN. Sad.
Just because you can collect the data, doesn't mean you are allowed to. In countries with other definitions of privacy it can be considered a reasonable expectation the your AP's SSID is only visible to people within a small radius. The owners clearly didn't have the intention to have it collected by a major corporation, collated with other data about their location and then published world wide for entirely different purposes then for which the AP was set up.
In many countries, the law protects people against those kind of unintended consequences, and several European authorities have made it clear that they consider this kind of use an invasion of privacy. And that is considered more important than multinational giant's ability to offer an "effective" service.
You can argue the merits of this, but Google's stance of "just fucking opt-out then" is blatantly disrespectful.
Facebook / other social networks, poorly secured databases, warrantless GPS tracking (in the U.S.), cell phone data being stored; these are all orders of magnitude more worrying and more likely to cause harm.
But this attitude is exactly what I mean: nobody misunderstood anything. Really. Just because people have different values and priorities doesn't mean that they are too stupid to understand the issues. It certainly doesn't mean their laws can simply be ignored if you do business in their country.
Anyway, I'm going to stop arguing that point, since apparently this place is turning into Reddit, and downvotes our now used just to bury other opinions.
Even if you turn off SSID broadcast, your router will still send out broadcasts of some sort.
What ever it is that google is noting down about the broadcasting station and tagging it with its lat-long, if it also appears in some form in the packets that originate from a host behind this station, then some one can infer the geographic location of this traffic source. Is that the case here?
Unless that's the case, is there any other way someone can misuse this? The only other exploitation I see is tracking a router from it's point of sale to it's point of deployment and finding out the location of the buyer. Where else does the BSSID of the station appear other than within it's geographic neighborhood and the manufacturer's/retailer's database?
May be the database should not be indexed directly with this BSSID but a one-way hash of (BSSID, something-about-the-neighborhood) - to make sure no one can do an arbitrary lookup but will already need to be in the neighborhood of the station to make a successful query. At least it will raise the bar.
I in fact would like to use this in my app! Continuous location tracking using GPS drains out the battery so fast that it is not even an option for me. The significant location change accuracy is not good enough for what I'm doing. I'm trying to figure out how to use this service. Does any one know?
I just can't see what makes it so wrong, I mean I am not ecstatic about my router mac and general area being tied together but is it easy for someone to find where I am based on what wifi I am connected to through a browser?
The only time I see it being a problem is if you have malware and they are able to target you by location but depending on what malware you are infected with it might be just as easy for the malware users to look somewhere else for location.
Maybe I am just being dense.
If you disable your AP's SSID broadcast, then Google should not catalog your AP and if they do it by sniffing packets then I would say that's unethical.
But complaining about Google with SSID broadcast enabled is like hanging out in a singles bar after taking a vow of celibacy.
This is like complaining that your neighbors keep posting naked pictures of you on the Internet because you like to sunbathe nude on your front lawn.
If you transmit the rays, other people can record them. It's as simple as that.
See also: cordless phones, DECT, FRS, street view, pre-digital unencrypted 800MHz cellular
Under such a system, you'd have to know the SSID ahead of time, which probably means you're in close proximity to it already.
i) Google has unfortunate previous form. They've collected information from unsecured wifi, including snippets of emails; lists of people suffering from certain medical conditions; passwords; etc.
(http://www.bbc.co.uk/news/technology-11797907)
They've made a "mistake" once. People want to be sure they don't make the same mistake again. (Scare quotes around mistake because, really, that's a lot of data to be accidentally scraping.)
ii) EU tends to prefer "Opt In" over "Opt Out", and it needs to be an explicit opt in. That means the company has to tell you what they're gathering, and why, and give you the choice to agree. Sure, that makes it very hard for companies to gather information (such as this which is on the very lower end of the privacy scale) and do useful cool things with that data. Some people (and I'm one of them) welcome the clear bright line that explicit opt in would draw between ethical companies (like Google; they're not evil and this wifi data gathering doesn't come close to being evil) and unpleasant seedy dodgy companies, who wouldn't bother obeying EU best practice data laws.
Even Google disagrees with you.
(http://www.guardian.co.uk/technology/2010/may/15/google-admi...)
> "As soon as we became aware of this problem, we grounded our Street View cars and segregated the data on our network, which we then disconnected to make it inaccessible. We want to delete this data as soon as possible, and are currently reaching out to regulators in the relevant countries about how to quickly dispose of it."
Accessing a person's unencrypted wifi without their permission is, in England, a criminal offence and that's been tested by the courts.
(http://news.bbc.co.uk/1/hi/technology/4721723.stm)
Having said all that, this German case says that people shouldn't be stupid and they are responsible for the security of their networks:
Companies like Google and Skyhook have massive wardriving efforts. If Google gets legal challenges about data privacy, could individual wardrivers be exposed to the same legal challenges if they published people's Wi-Fi data publicly? This would put a damper on my hobby project..
WiGLE.net is a similar crowdsourced, wardriving project. They've collected 48M Wi-Fi networks over 10 years from wardriving hobbyists, BUT they refuse to make their data available for download or create a public web API. They force people to use a crappy Java client and undocumented network protocol to access their server. Plus, they resell their users' crowdsource wardriving data to undisclosed buyers!
Right or wrong, this tends to happen if you try to arrogantly dictate instead of negotiate. It turns public opinion against you and it pisses politicians off, even business-friendly conservatives.
You do this block by block for an entire city. So now you hold in your hands a notebook of all the WIFIs in the city. So let's say I blindfold you and throw you in a random street corner in the city. Using this notebook, your iPhone, and the wifi signals, you can easily figure out where you are in the city.
To be even more accurate, you may record the signal levels every 5 feet. So now from any given point, you can say "Linksys" has 5 bars, "Free_Porn" has 2 bars, and "Mom's Wifi" has 3 bars... I must be at the south east corner of 59th st.
So now you have a notebook of all these wifi signals. Your friend comes to visit your city and you give him a copy of your notebook. He can then use that to figure out where he is even if he can't get a GPS signal.
What's also nice about this is that it works indoors. Using a database of wifi signals, you can figure out that you're standing next to the kitchen in your 5th floor office.
That's basically what this wifi mapping is.
Just because the information is public doesn't mean you have the right to collect it and use it any way you see fit, and it certainly doesn't mean it isn't in invasion of privacy.
Given the issues in the past, this is just a big fuck you to Europe (and clearly deliberate, since it is explicitly cross posted in their European Public Policy Blog).
You can disagree with values and laws in other countries, but you don't just piss all over them like that and expect to still be able to do business there unhindered unless you have a serious attitude problem. Google is rapidly becoming the corporate embodiment of the "Ugly American".
When I was growing up, every household with a telephone got a book that had everyone's name and home address in it. That too was an opt-out system and that approach worked pretty well.
The phonebook was a well known consequence of having a phone, dating back to the days when the phone companies were state owned public services. These days it would be utterly unacceptable if for instance internet access providers would do the same thing. Again, context is everything.
And just to make it clear: as a European, you are not offended by an American company that thinks it has the right to ignore local laws and sensitivities?