Google and their customers don't have much to gain through a proprietary implementation. If anything, open-sourcing Find My Device Network would allow third party devices to join the network, enhancing its value to Google's customers. Google emphasizes ad nauseum that this system is extremely private and secure, so third party implementations shouldn't be cause for worry.
Governments and various potentially dangerous organizations stand to benefit greatly from a closed implementation for reasons that hardly need explaining.
Google makes a lot of lofty claims about E2EE and privacy considerations in that blog post, I'd just like to see them prove it.
An open source version would make absolute no difference on what is trackable.
That's the point: transparency is necessary with critical data like this.
Unless, of course: That centralized data store were also open -- perhaps even by using something like DNS -- but then, anyone of sufficient skill would be able to craft an application to see where others' things are.
(Unless... E2E encryption for location data, so it can only be understood by those who generate it? Hmm.)
Something like shamir's secret sharing with split up keys effectively making the encrypted data useless, or based on time frames so you can only track the last "epoche" (like the last 24 hours, maybe?) similar to how HOTP/TOTP works could work nicely I'd imagine.
At Tholian (my company) we're using team based keys where at least 2 of x keys (the elected lead and co lead) in the team must co-sign a data changing action. It's peer to peer, meaning those peers can find each other and co-sign this without our servers having to store any transaction queue that could be compromised.
This way we prevent abuse, and if the feds come knocking on our doors, our users stay protected because without those keys we cannot see what's going on in any of the registered teams.
That's how I think it should be like, for any web service that supposedly keeps their privacy promises. If they don't do this, their promises were likely lies and once the root keys or the databases are compromised there's no turning back.
Looking at you, cross-tenant keys at Azure. Everyone knows you were and are still lying about the security aspects.
Try FMD. https://f-droid.org/packages/de.nulide.findmydevice/
The thing Google is announcing here is like the Apple "find my" network--it seems to allow you to use other people's devices to find your lost device simply based on a BLE ping.
That is something that is hard to build by yourself, and would benefit greatly from an industry-wide standard (more peer devices reporting locations!).
> simply based on a BLE ping
What if they disable Bluetooth?
The linked open source find my device app uses cell network to both receive commands and for location.
It wouldn't do a lot of good if thieves could just turn off Bluetooth, right?
The design of this is pretty clever: https://www.wired.com/story/apple-find-my-cryptography-bluet....
I presume somewhere you can turn this off for real, but the defaults seem sensible to me.
I'd guess that Bluetooth will never fully shut off, it would just look like it's turned off to other apps that would want to use it.
I think the real utility of tile/airtag/google-find-my-device is the network of other colluding devices listening for bluetooth pings and reporting on the location. Not least because apple (maybe google, don't know) forces your device to send reports if you want to use the feature. Heck, on modern phone OSs, you can't use BLE in apps without turning on the location service.
https://support.apple.com/guide/security/find-my-security-se...
With these few huge tech-companies, the industry has lost its natural "feature" that required competing players to work together and form an Alliance/SIG to make really big things happen.
Instead, the really big companies are happy to take the fruits from that time (Wi-Fi, Bluetooth, NFC,...) and build something proprietary on top instead of contributing back to it...
It also took them almost a DECADE to acknowledge that they should work together on this topic, and STILL they don't fully acknowledge that.
I wonder how long it will take for them to complete the journey on NOT cooperating on messaging, by butchering the RCS-specification in secrecy...
They don't need google for that. It's built right into the phone network.