Digital signs in Brookline are collecting data from your phone as you walk by
brookline.news
brookline.news
This is basically a door people counter made for areas where you couldn't have a door. Malls used that tech 30+ years ago, little LED sensor that counted up every time the beam was broken. Small LCD screen usually at the bottom of the gates you pass through going in. If not a gate, then usually a beam with a reflector on the other side and the screen was on back of the beam/sensor unit.
For this use case, easier to count active mac addresses to figure out how busy each area is, doesn't have to be precise but it lets the town and advertiser know whether it makes sense to install a sign somewhere. Gives a general idea of ad impressions and is way cheaper and less intrusive than using cameras.
With that out of the way, I'd be more concerned if these were like other kiosks that also broadcast wifi and that connection was collecting unique information. This should be the main concern, this is where the good easy to correlate personal information is. That and cameras on advertising devices that do face/attention recognition.
I'm not surprised nor especially troubled that the sign gathers pseudonymized MAC addresses in hourly buckets. In the last several years there's a mini-trend of startups attempting to provide more or less anonymized smartphone traffic data to cities and towns for urban planning purposes.
In theory this is good! Ideally it helps city hall be more data driven and see things that might not filter up to city hall, in a "pave the cowpaths" way (E.g,. do we need a new circulator shuttle stop? What's happening that one weekend in May that drives so much foot traffic and that we're not aware of at city hall, and should send a police detail to control that intersection? Oh, that brewpub has an annual event we didn't know about that blew up on Instagram.)
In practice I think the problem is the wins tend to be minimal compared to the effort involved.
All that said, I don't love the conspiratorial, low-trust assumptions you're encouraged to make by the bare statement "They’re collecting data from your cell phone."
But without privacy regulations I suppose that's where things will inevitably go -- people will assume a priori that "data collection" is itself threatening. (I certainly foresee a lot of rich retirees agitating to cancel the contract at the next Brookline town meeting.) So I wonder if the main benefit of better privacy regulation in the US would be preventing further deterioration of the basic trust that allows the "collective intelligence" vision of the 00's to come to fruition.
The MAC randomization means that it will be a different MAC shouting this SSID every time. But the billboard vendor can see there is someone walking past it each day at 10am looking for a wifi network with SSID "PrettyFlyForAWifi."
And they can search that SSID in a public wifi map like Wigle.net to find the location of your house.
To mitigate this, find the most common router name in your country and use that for your home network.
But....... if I do that, and my neighbors all definitely have it, how does my phone know which one to connect to? Am I leaking my password to my neighbor's APs, or does it use a hash somehow?
How do I tell my friends "My Wi-Fi is xfinitywifi... not that one... not that one... uh just put in the BSSID"
Hopefully someone who knows the answer will reply... :)
A malicious router doesn't know ahead of time whether the SSID in a probe request refers to an open network, so it could try to establish it and see if the client connects. (Even for closed networks, it's also possible there is a bug in some client software that would ignore errors caused by the server supplying the wrong key?)
They don't, as far as I know.
Bluetooth EDR ("classic Bluetooth") doesn't broadcast anything at all as far as I know, and only listens for connection requests (that need to know your MAC address to be able to ping you).
Bluetooth LE devices are a bit more noisy in terms of broadcasting but support privacy addresses for service announcements.
Doesn't MAC randomization used by both Apple and Android devices make this redundant?
I'm not really sure what the general public would actually do with this data - but they paid for it so they should have access. Even better would be to not collect it at all. Is there some way to increase the cost of collecting/storing data like this so that more municipalities/organizations will just consider stuff like this "not worth it"?
Even in cases where courts have found that the government (or their agents e.g. a police officer) didn't have the authority to surveil the public without a warrant they were able to purchase private data and construct a parallel chain of evidence that didn't involve the warrant-less surveillance.
Edit: I have mixed feelings on this initiative as a whole. "Bike Counters" are frequently used by cyclists, for instance, to argue areas need better infrastructure. The question is how can it be done in a non-invasive way, and this data should absolutely be public if it's being collected
[0]: https://townforms.com/FOIADirect-BrooklineMACitizens/Public/...
Regardless - these are elected officials and their departs using public money for what some might consider surveillance. What's the issue with a little sunshine on how this all works?
I can see why they would choose to do this -- it provides some privacy while not confusing most users (who might have to reauthenticate, or might no longer be in an allow list). I'd prefer to get a new one each time I connected to an SSID but I'm sure I'm in the minority.*
I wouldn't be surprised if every one of these devices had the same SSID. Why not?
* 99.999% of the population wouldn't know a MAC if it bit them on the nose, and I'm sure prefer it that way. Not an unreasonable position to take, TBH.
And that's if you actually joined the network (who joins a billboard's wifi network these days? Celluar data is plentiful even for cheap plans). If not, the only MAC that's sent is a random phone that's reset every scan/15 minutes (forgot which one it was).
It will work for people just passing by.
What does work is sending out btle beacon signals, putting a sdr 5G cell.
The whole market for this kind of tracking is filled with fake data..
That sounds super illegal because the spectrum 5G operates on requires a license to use. You can partner with cell carriers to use their licenses, but why would they partner with you? They'll be quite happy to use their existing infrastructure and hoard the data for themselves.
For example, if your connection is bad, some provider offer indoor 5G stations. Not sure how they deal with the license in that case
Edit: unless you enable "Wi-Fi non-persistent MAC randomization" in developer options (this should be the default imo, and should be a per-network option like persistent randomization and device mac address)
Imagine using this in India where they law requires that every public wifi require a phone number to authenticate before use.
- Leave home: turn wifi off, turn mobile data on
- Arrive home: turn wifi on, turn mobile data off
- Bluetooth off unless paired with car / earbuds
*Need to check MAC randomisation settings
One exception is if you have ever connected to a hidden SSID: Due to how the protocol works, your phone has to broadcast that SSID name occasionally to probe for any access points nearby that might be part of it. Newer iOS versions specifically warn of this when connecting to one.
I don't think it's too much to ask of a mobile OS to make that safely possible without exposing PII over the air to any advertisers nearby.
- Wi-Fi on at home
- Wi-Fi off outside home
- Only enable the cell radio if I'm expecting an incoming call or about to make an outgoing call
I live in hell and it's everyone else's fault, everyone is wrong but me.
;)
These should be defaults.
Android has options to WiFi scanning off. Does OSX?
But that doesn't actually work. Saying that as an iPhone user who keeps turning Bluetooth off in the Settings app, but it doesn't stick. It's always on again a day or so later (the next time I check).
So either iOS is buggy in this regards, or it's not actually possible to turn Bluetooth off permanently. :(
It's not buggy, it's covering for the 90% of people out there that forget they turn it off and then helplessly wonder why things are not working.
The fact that I can’t then add the shortcut to the control center is just insult to injury. The shortcuts widgets don’t cut it.
While I’m ranting, the fact that a simple shortcut that uses system default apps (Recognize music and then opens Notes to paste the title and artist) requires me to enter a passcode to run – with the Allow Running When Locked setting on – makes me doubt settings in iOS mean anything.
e.g (just one example) turning WiFi completely off degrades the ability to geofence, one's automations may be delayed or non-functional and one would be bewildered as to why. Turning WiFi off one day, forgetting about it, then having apparently unrelated things not work the next day is hard to diagnose.
There's a next-day trigger for sure for the WiFi disconnect+no-auto-reconnect ("disable WiFi" in the support page†) but I must admit that I don't know what's the exact trigger - if any - for the master WiFi switch in Settings.app ("turn WiFi off" in the support page†) to be turned back on. Next day? After a software update (e.g an automated nightly one)? Exiting hotspot mode? As you suggested, a bug? Nothing and it's people forgetting they have turned it back on "temporarily"? The support page† doesn't say anything about it.
Should one desire to enforce WiFi off as a policy, the shortcut can act as a safety net around all these cases, the tool is available to help automatically enforce the policy, and I don't think it's helpful to sit and hold one's breath til one turns blue because it shouldn't do what it's doing, refusing the opportunity to get control back.
I agree that Shortcuts is awfully limited, sometimes inexplicably so. I mean, picking up a random wallpaper from a Photo album every X hours should be entirely doable, yet there's just no way to do it.
† https://support.apple.com/en-us/102412
EDIT: I have tried the hotspot thing.
- set iOS WiFi off
- request hotspot connection from another device
- iOS WiFi turns on
- if no known autojoin AP is in range
- iOS WiFi turns on
- hotspot connection succeeds
- upon hotspot disconnect iOS WiFI stays on (BUG #1: should restore WiFi off)
- if a known autojoin AP is in range
- iOS WiFi turns on
- iOS WiFi connects to AP (BUG #2.a: should not connect to AP)
- hotspot connection fails (BUG #2.b: caused by #2.a?)
- WiFi stays on, connected to AP (NOT BUG: consequence of #2.a)
- (optional) re-request hotspot connection
- iOS WiFi disconnects from AP
- hotspot connection succeeds
- upon hotspot disconnect iOS WiFI stays on (NOT BUG: consequence of #2.a, which caused WiFi state == on at second hotspot-request-time)
- iOS WiFi eventually joins AP
This may happen unattended if the requesting device has "auto-join hotspot" enabled.Especially if you're relying on something to be in the state you (literally) configured it to be in, and it turns out the software makers "know better than you". :/
That said:
- data collection ranges from minimised to eliminated by features like MAC randomisation
- battery impact of WiFi + BT on but disconnected is a rounding error
About the only functional use I can think of would be if devices still had headphone jacks, you could probably get away with snaking headphones out and listening to music/podcasts/whatever you'd already downloaded.
> Assistant town administrator Devon Fields, who led the implementation of the program before her recent departure from the position, [...] The town’s transportation division previously had an employee who worked directly with Soofa regarding data collection, but they left the department more than a year ago and have not been replaced. [...] the department has not been actively using information collected by the boards, [...] Fields will be the incoming deputy city manager of operations for the city of Chelsea.
Is that contract regretted by the city? If so, how much?
(The journalist seemed to hint that the program was a flop for Brookline, but didn't get much into that. For a career move, Chelsea is a different kind of Greater Boston city than Brookline is, so could be a more interesting challenge, or better growth opportunity.)
I haven't researched the exact terms of the contract, but it's possible the signs were pro-bono, as
1. Part of it is that advertisers can pay ~$100-$250 a month to display ads on these signs and I'm guessing soofa takes a cut 2. In Brookline, these were sponsored by Brookline Bank, so they get free advertising
Probably easier to do what you describe with a laptop or smartphone.
> collecting data from prople's phones ... and then sharing that information with the town
By "sharing" I assume they mean "selling". The question to ask is who in the city approved this and what is their relationship with Soofa?
A town close to me has a sign that shows the number of people that have gone past on the sidewalk. Possibly counts stuff by a magnet/weight sensor or such in the ground. Never have thought that was in any way a privacy problem. Neither is this.
That kind of extreme NIMBY attitude would have us living in caves if it wasn't for the other side. The worst of it is that it just attacks what is honest and visible the first, encouraging dishonesty and secrecy because stuff like this would never actually come to hurt you in any tangible way. I hope you come to realize that.
I'm curious how often governments (as opposed to businesses) have done this?
Maybe one day, Apple? will allow us to see and block pinging signals attempting to harvest data.
https://www.simonandschuster.com/books/No-Place-to-Hide/Robe...
Your phone is the one doing the pinging. I guess Apple could stop it doing that, but then it would be slower to get your location and the Airtag system would be less effective.
The problem is that the tech industry has been so abusive about electronic data collection for so long that it's burned through even the smallest sliver of trust about such things.
This is one thing with iPhone that infuriates me. Even if you "turn off" the WiFi it will always turn back on after a short time and connect to known networks. or if I change to another location with a known network it will automatically connect to it after turning the WiFi back on. For the life of me I can't find a way to keep it off consistently.
You can also turn them off in Settings. Also anytime a macOS or iOS update is applied, Apple turns back on Bluetooth even if it was turned off.
They want you to leave them on so their Find My network can function, regardless of what the user wants.
The concern I raised at the time was that the company was being allowed to install general purpose equipment housings in prime heavy-foot-traffic locations -- and the company could use these to deploy surveillance capitalism equipment they controlled.
Looks like that's a direction Soofa is going in.
“I’ve never heard anyone cite useful data, you know, useful to the rest of us, that resulted from the Soofa signs being located in various locations,” said Brookline select board Vice-Chair John VanScoyoc in an interview with Brookline.News. He elaborated that the data being collected does not offer any new perspective that couldn’t be easily observed.
Is this a challenge to attackers to find a use case for the data?Uh, false? What IP address? This sentence is meaningless, users don’t connect to the sign, so there’s no IP to it.
This article is just scaremongering by people who don’t know technology.
The rest of the article is not necessarily scaremongering, but they don't explain the issue well: it's not just a "giant clicker" as described, because it collects personally identifiable information (cellphone MAC address) without permission. This would be illegal in many other countries.
Additionallu, they claim the data is "encrypted" but since it's not an open algorithm it's possible that it's flawed, either because it's deterministic or reversible.
On many phones they rotate. Are they still PII?