Apple and Google deliver support for unwanted tracking alerts in iOS and Android
apple.com
apple.com
Apple is only supporting latest version of iOS (17.5).
1. Your point still stands, but this is because this update is probably shipping as a Google Play Framework update, which works on >= 6.0. Google is not (to my knowledge) releasing a new firmware.
Apple would do well to decouple certain software components from iOS, IMHO.
2. In case others are curious about iOS version market share, statcounter's stats for April 2024:
17.4 (current until today): 51%
17.3: 22%
16.6: 4.3%
16.7: 3.18%
16.1: 2.8%
16.3: 2.12%
https://gs.statcounter.com/os-version-market-share/ios/mobil...
Our Android app shipped almost 3 years ago with minSdk=24 (Android 6.0) and we haven't had to update it.
We, to this day...with no talks of changing it any time soon, support all the way back to Android 5.0 (released in November on 2014).
Goes back to 3.1
Still a big win overall I’m just curious what number of devices basically don’t get important upgrades due to this method. (Surely a tiny amount compared to what you’d have if you relied on device manufacturers to update the OS.)
I'm not really convinced of this. When you control the entire hardware and software stack, and already provide updates for 7+(?) years per model, would doing this really change much? Google needed to do that because some cheapo manufacturers weren't really providing any updates to speak of, and Google has limited ability to force manufacturers to provide updates on any particular schedule.
It's funny, because to me this is really just the Linux model vs. BSD model, in a way. Linux base systems are cobbled together from various bits of software maintained by different people and groups. Many of those components can be updated independently of one another, including the kernel. The BSD model is to ship the entire base system as a versioned unit, and only update the entire thing monolithically. Android does the Linux model, iOS does the BSD model. Both models work just fine, depending on what your goals are and your distribution model.
I think the one thing I'd argue Apple should decouple from the OS is Safari. A web browser (and the underlying OS web view) should be independently updateable, even after a device stops getting OS-level security updates.
Every flagship iPhone since 2011 has gotten at least five years of OS updates, with additional years of security updates after that.
For instance, the original version of the iPhone SE is currently in its eighth year of support, and just got another security update a couple of weeks ago.
For instance, that original iPhone SE came out in 2016, the same year as the original Pixel phone. The iPhone is still supported by Apple today, while the Pixel phone was dropped from support by Google five years ago.
Google had to come up with a way to backport features to older unsupported versions of the OS because their support window was so abysmally short.
Hopefully, this won't be an issue going forward, with Google promising a comparable support window in the future.
On Android, the browser is separate and you can install alternative browsers. The current release of Chrome for Android works with Android 8 which was released in August 21, 2017 and dropped January 2021. Android System Webview (the browser engine that other apps can use so they don't have to ship their own) works the same way and is independently updated from the OS.
> Virtually any Android, Linux, or Windows device that hasn't been recently patched and has Bluetooth turned on can be compromised by an attacking device within 32 feet. It doesn't require device users to click on any links, connect to a rogue Bluetooth device, or take any other action, short of leaving Bluetooth on. The exploit process is generally very fast, requiring no more than 10 seconds to complete
https://arstechnica.com/information-technology/2017/09/bluet...
A browser update doesn't fix that and that and Blueborne was disclosed during the era when an Android device only had a support window of two of three years.
iPhones from over a decade ago were getting security updates, including for the browser, for seven or eight years.
Every month or so someone (usually a security company that wants to sell something) find a domesday exploit for android that is unpatchable, and then it gets patched or turns out to be a non issue.
Internet Explorer was usually only loosely tied to the OS. Yes, many versions of Windows came with some version of IE, but you could usually install a newer version if you wanted. Every once in a while, a newer version of IE required a newer version of Windows, but that wasn't typical.
As I understand it, on Apple systems, Safari comes with the OS and is updated together --- Safari updates come in OS updates. Mobile IE was very similar though, at least on Windows Phone 7 and newer.
That’s true on iOS but not exactly true on macOS. Upgrading macOS also upgrades Safari, but you can also install newer versions of Safari on older versions of macOS. You just can’t have older versions of Safari on newer versions of macOS.
iOS 17 runs on 80% of current iPhones in use
https://telemetrydeck.com/blog/ios-market-share-03-24/#:~:te....
Sure, you can often install a modern Linux distro on a 20-year-old device (though just as often, you cannot), but that's not the same thing as a single version of Windows being supported for 10 years. The analogous situation is indeed LTS versions of Linux distros, which certainly don't have 10-year support lifetimes, let alone 20.
But the support lifetimes make sense for the various vendors. Apple doesn't need to support a particular major version of macOS or iOS for all that long, because they make sure new versions of their OSes will run on fairly old devices (all of which are devices they've built, and have full control over), and they aggressively push people to upgrade to new major versions as they come out.
Microsoft has a lot of customers who value stability and consistency above all else, and on top of that, they have to support a wide variety of hardware that they don't and can't control. Supporting a major version of Windows for many years makes sense for them.
As for Linux, there's no one single source, so a rolling-release distro can decide to only support the bleeding edge, whereas a cloud provider might roll their own distro for server use and decide to support that for a decade, if they think that's what their customers want.
Or for contractual reasons, or for some technical reason it was easy enough to be "why not"
I track security patch counts of monthly Android Security Bulletin vs available APEX vs my aftermarket backports for A7 through A13 here: https://divestos.org/pages/patch_counts#aggregatePatchCounts
I recently tried an Android phone again for a few months, and the update/security situation is still a mess. E.g. Samsung does monthly updates on more premium phones. But a former flagship like the S22 would sometimes only get the update near the end of the month, even before the S24 is out. Having a phone with known CVEs for the better part of a month is… meh.
For some vendors, like Samsung, things are much better than a decade ago, but it’s still a far cry from Apple rolling out updates to all models simultaneously.
Out of curiosity , have you ever encountered any malware that exploits said CVEs? If a month delay would be so dangerous, Android users, even of new devices would be getting pwned left and right, let alone Android users of device no longer getting patches.
Source: Android user of old phone who hasn't been hacked yet so I'm not sure where exactly the dangers are, as the attack surface is mostly the web browser and the apps, both of which are scanned and covered by up-to-date patches from Google Play Store/Services even on my ageing phone. So as long as you don't browse extremely dodgy websites, and don't download shady apps you should be good as nothing else can't get to the Kernel CVEs on your unpatched phone.
Yeah, I'm sure some crafty malware dev can whip out a targeted virus that can exploit the chain of open CVEs on my particular phone through a MMS message or something, but I'm not sure targeting the 100 or so users left still using this old OnePlus model that's worth less than 20 Euros used (pointing to a user without much income), is a good use of their skills and time, when they could be frying much bigger fish with that know-how like going after Microsoft's Azure or something.
Nor am I being targeted by state actors who have these means. And if you are being targeted by state actors, they have access Zero-Days that even Apple or Google haven't patched yet so you're not safe anyway no matter what phone you have.
What are the odds that you'd ever know if you were hacked? If you have root access on your device your odds of being able to see something amiss are probably somewhat better than if you don't, but even then I wouldn't count on it. How many people detected Predator/Pegasus? It isn't just state actors taking advantage of zero days. A zero day gets that malware on your system, but once it's infected how would you know? There have been reports that millions of android phones are infected at the factory. (https://www.theregister.com/2023/05/11/bh_asia_mobile_phones...)
We know mass infections happen (see https://www.bleepingcomputer.com/news/security/over-nine-mil... and https://www.wired.com/story/android-gooligan-ghost-push-hack... and there have been some bold (if unverified) claims that most android devices are/were infected with something (https://www.zdnet.com/article/bt-almost-every-android-device...).
I don't know how you could possibly be confident that your device isn't infected with something. The devices are designed to keep you from having the ability to poke around too much at their internals and the radios make it difficult to monitor exactly what's being sent/received to the device.
Would you know?
>I don't know how you could possibly be confident that your device isn't infected with something.
Easy, my bank account is still full.
How are you confident your phone isn't infected? Being up to date is no guarantee. Until you can poke around with root access to inspect everything it's still Schrodinger's cat in a black box you trust to not be dead inside.
Because how would malware ever make it into my phone? It doesn't just magic itself onto your device once it stops received updates. It needs an entry point off the attack surface. And what's my attack surface since all your examples don't apply to me?
I never download shady Apps from the likes of Huawei AppGallery lol or even off the PlayStore and I don't use Android 5. All apps I use are whatsapp and Google chrome, and I also don't browse shady websites on my phone.
I very much doubt it.
> Easy, my bank account is still full.
That assumes the malware is intended to take your money instead of your data, or even just your internet connection. Malware can be used to attack/infect other devices or even just click ads. What kind of harm could someone who had full access to your device, including access to your internet activity, texts, location, camera, and microphone do to you without telling you about it (blackmail).
> Because how would malware ever make it into my phone?
Maybe it was installed at the factory. Maybe it came from literally any one of the many many vulnerabilities that made it possible to infect your device without any indication. Android phones have been compromised via text message, via Bluetooth, via QR code, and via apps.
It's great that you aren't doing anything obviously risky, but that isn't a requirement to get infected and the problem is you just can't know. You aren't the admin of the device. You don't have the authority to control what it does. You aren't allowed to see what it's doing. You can't see who it's communicating with or when.
Your average Joe six-pack like myself probably shouldn't really worry about it though, it seems more likely to be used against really high value targets.
You might want to try out another web browser that has aggressive ad blocking (Firefox, Brave, or Vivaldi should do it) since ads are one of the major methods of spreading malware.
Under rated advise. Too bad said Joe six-pack donesn't follow it because it thinks other browsers "have viruses"
To be fair, it's non-trivial to convert hacked bank credentials to actual cash, due to anti-fraud measures, KYC rules, and reversibility built into the finance system. A better indicator would be $1000 worth of BTC on an unencrypted wallet not being hacked.
Considering how many vulnerabilities have been in the media stack of Android, all that would take would be an image or an autoplay video on a website.
FWIW, while I don't think I personally had an Android device hacked, I do think I've had family members with devices potentially hacked. One family member running an older version of Android continued to have lots of accounts constantly getting stolen despite using a password manager and unique complicated passwords. Pretty much any time they'd be logged in to an app there would begin to be fraudulent orders or other mischief on that service. They never installed shady apps. Rotate the password on another device, no problems for a while. Log in on the phone again and within a day or two have the mischief start again. All that stopped after replacing the device.
Another family member started getting popover ads on their device despite not having any odd apps installed that would be the cause. Even after a "factory reset" the popover ads continued to plague the device, as if it was embedded in the ROM.
That one is probably not valid.
My bank app is sht, The 2FA is EMBEDED in the app; in the beggining it was a separate app. It also needs Google Play Services. And I live in a third world country with little accountabilty. On top of all that, most people use very cheap chinese phones which never get any update.
Still, bank accounts have never been depleted through hacking of phones.
This is complicated by their rolling updates per country, it can be few weeks between the first CSC (3 letter identifier for country and carrier variant) to receive an update and it being rolled out to the final one.
I was towards the end of that update cycle, so the Android security patch level could become quite detached from the actual month.
If something is actively exploited they definitely don't wait to months end. Also a Google update is not urgent if the vulnerability is not really exploitable on Samsung (they have some additional security) or a fix is already backported.
More recent versions of apps (like whatsapp, which requires to be updated regularly) are unnecessarily more demanding. Try disabling Play services, all Bloatware, all quasi-bloatware (calendar, contacts), all the way to the default keyboard. (pm disable-user --user 0)
Install FOS replacements with no internet connectivity, e.g. from f-droid and such (not affiliated)
It is easier to buy a new device, but I get attached to my pal ;)
Has Android gotten that bad? I last used it in 2018, and haven't exactly missed it since, but even back then I didn't think of Calendar or Contacts as quasi-bloatware.
In the best case when a page write fails the memory controller discards the page from the pool, when the pool becomes exactly equal to the official size the device goes into permanent read-only mode. (Which would brick any device it's built into. A PC you could pop in another drive, a phone you can't.) Many devices have failure modes worse than this.
The better the quality of the memory the more margin it has, and how much you write to a drive has little to do with how big it is--from a practical standpoint life expectancy is roughly linear with size.
For the flash itself (the giant mass of NAND or NOR gates making up the cells), in terms of TBW it's straight up linear with size. 2 TB flash storage has twice as many cells as a 1 TB (of the same make) therefore can eat twice as many write cycles (unless the manufacturer does something on the sly like change overprovision ratio based on capacity, change from TLC to QLC on higher capacity units and "forget" to mention it, etc., but those are factors beyond the basic logic gate arrays).
However I don't think size effects MTBF as that looks at factors unrelated to write cycles; things like catastrophic failure of a chip or a short that catches fire and burns down the server farm.
Realistically speaking, MTBF has little bearing when considering flash storage lifetime. TBW is where it's at. If the specs only give MTBF, I tend to assume the TBW is bad enough it's worth hiding and I'll avoid those . If not that, then it's either straight incompetence, recycled flash scam, or the manufacturer just doesn't give a shit (all of which are way worse than choosing to omit a low TBW rating).
It may seem like i'm nitpicking the word 'roughly' but i don't disagree with the sentiment. Depending on how you want to measure lifetime (jfc don't use MTBF), it isn't exactly linear, but it's not the flash's fault.
A lot of the early Fire TV devices are still out there running Android 5.0, and they are actively used.
I reckon the WhatsApp userbase OS distribution skews much more to older android versions compared to an app that mostly enjoys US/1st world country userbase.
With the number of Android devices out there, it really makes more sense to think about it in actual user/device count rather than percentages.
Just that Android devices are not involved in tracking of AirTags, as of today only iOS devices actually share the location of AirTags back to Apple.
They maybe want to change that, but considering the huge amount of volume disparity between AirTags and Google's tags, I assume Apple would have to pay Google for the service of extending their tracking-network...
https://deviceatlas.com/blog/mobile-os-versions-by-country#p...
That means someone can steal your stuff, and then disable the tracker so you can't find it. Most people and myself included were sticking these cheap tags on everything we own, and it was genuinely useful during travel or in scenarios where theft was a consideration.
This is by design. AirTags were never marketed as an anti-theft device. They had anti-stalking features from day one which were/are at odds with anti-theft.
It was marketed as helping you find things that are lost, nothing more.
If some scumbag ad company wants to track me, they can eat shit on my adblocker and not track me. The cost of preparing for that threat model is trivial, so I do.
Artificially limiting the use of a product goes against the hacker culture.
I mean, technically you are — doesn't mean anyone will listen.
FWIW, there are videos on YouTube showing you how to silence the speaker. No idea if they work or not, but it's hacker culture at work.
None of these companies ever agreed to be bound by that value, and aren’t under any obligation to adhere to the tenets of Hacker culture. Hackers as a group have failed to convince the public that these things matter, so as far as these businesses are concerned, they don’t.
Like, I agree, it sucks when companies restrict what I can do with a device. But when that happens I don’t talk about it like they betrayed me, I knew what I was buying and decided to buy it anyway.
I distinctly remember friends at Apple being surprised, in the aftermath of San Bernadino, at the backlash they received for refusing to break the encryption on the shooter’s phone for the FBI [1].
[1] https://en.m.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption...
This is a safety feature and its been there since day one.
Users can say they’re not interested in it because it doesn’t suit their needs - that’s completely fine.
Source? I just use them to find my keys and remote, didn't know it was popular to try and recover stolen property given the alerts when you're near not-your-airtag for any length of time.
There are any number of products allowing you to mount them inconspicuously.
https://www.washingtonpost.com/technology/2021/10/28/airtags...
https://www.axios.com/2023/05/24/apple-airtags-track-car-thi...
https://www.sfgate.com/travel/article/apple-air-tags-travel-...
https://www.govtech.com/public-safety/police-urge-caution-in...
Police agencies aren't systematic domain experts except in the application of force to obtain compliance, as well as not having an interest in accurate advice.
And of course where did I leave my keys and is my backpack in the car or at work stuff, but that's the obvious/advertised use.
So it is now on me to know whether my object is lost or stolen? Even if I magically knew all the details, that isn't a bright line rule. One person's "lost" luggage is another's stolen electronics. Clearly, more people are using these things to track down stuff that has been taken rather than find the remote control lost somewhere in their living room.
Will apple allow people to disable the tracking of other people's iPhones too in the name of privacy? What if my wife leaves her phone in my car? Can I get tracking disabled on that phone so she cannot track my location?
This isn't new - AirTags have always been this way. The only thing changing today is the cross-platform and 'standard' aspect to it...
No. AirTags let you track your objects whether they are lost or stolen. It's just that they also alert potential thieves to their presence, so any reasonably competent thief will be able to disable them.
> Clearly, more people are using these things to track down stuff that has been taken rather than find the remote control lost somewhere in their living room.
My use cases are to (a) find items that I misplaced or lost somewhere on my own. (b) track the whereabouts of luggage that got lost by an airline.
These cases are not particularly hindered by anti-stalking mechanisms.
You are technically not allowed AirTags in luggage because they contain li-ion batteries.
https://www.faa.gov/sites/faa.gov/files/hazmat/packsafe/reso...
The battery would be under the "In Equipment" column, not the "Spare" column.
When I recently pointed out to the lost luggage department at an airport that I knew for a fact that the luggage (or at least the tracker) was right at the airport, they did not appear to be surprised or concerned at all.
Clearly, adding “clearly” before a slight rephrasing of the unsupported assertion made upthread doesn't turn it into a supported claim.
I've had two reasons to need to "find" things with AirTags where I specifically didn't know where they were:
- airline bungle, so luggage was left at a transit airport.
- forgetting where something had been put down.
But the most common usage is the opposite, positive confirmation: we've just left for the airport, check if everything says "with you" once you're a few hundred meters down the road.
If the most likely reason for something to be "lost" is that it was stolen, maybe you should move somewhere with a less than apocalyptic level of petty crime.
- https://www.express.co.uk/news/uk/681961/Common-lost-items-k...
- https://www.prnewswire.com/news-releases/lost-and-found-the-...
The most likely reason to lose things is you're distracted, and fun fact: if you're a man you're more likely to blame someone else for it.
you should probably move
Singapore is the only place I’ve been where I didn’t worry about theft.
And while I don't know where you've been and what your tolerance level for "worrying about" theft is, I've never worried about theft anywhere but very touristy places in huge cities.
Personally, I'm careful enough with my keys etc (and lucky enough) that I don't lose them - I lived for several decades before the invention of the airtag, and developed habits not to lose things.
On the other hand, bicycles getting stolen? That happens.
That gave me a good laugh.
It makes me wonder if she lived in one of those places earlier in her life (before I knew her) and might be more justified than it seems... ?
I don't think this is a good situation, mind you, but I think people in my circle still misplace things orders of magnitude more often than their stuff gets stolen.
Edit: here is an article around the time of release describing how they work: https://www.washingtonpost.com/technology/2021/05/05/apple-a...
> To discourage what it calls “unwanted tracking,” Apple built technology into AirTags to warn potential victims, including audible alarms and messages about suspicious AirTags that pop up on iPhones. To put Apple’s personal security protections to the test, my colleague Jonathan Baran paired an AirTag with his iPhone, slipped his tag in my backpack (with my permission), and then tracked me for a week from across San Francisco Bay.
> I got multiple alerts: from the hidden AirTag and on my iPhone.
The AirTag has anti-stalking protection. An important feature, but not something the owner of the AirTag may want.
iPhones share the location of nearby AirTags with apple. Good for the owner of those AirTags, but the owner of the iPhone may not want this.
Yeah, that’s like, the issue with trackers. If I buy an AirTag to stalk my ex girlfriend, why should Apple want to help facilitate that goal?
It used to be that when you bought a computer, it was yours. It did your bidding, nobody elses. Security features it had were about keeping other people out, not keeping you out of your own device.
Now, mostly IMHO thanks to Apple, the idea has really shifted. The owner of the device is a "threat" just like anybody else is. The device protects itself against unauthorized actions from the owner, and it does what the mother company wants it to do, regardless of the owner's desires. If the owner is trying to stalk somebody, then that's a better outcome than having the stalker enabled, but we don't get to pick and choose which things the device follows it's owners desires or the mother company's. If the mother company wants you using their chosen DNS servers, or exfiltrating user data for analytics, or showing you ads (Amazon especially), that's what will happen. Now that we've made it acceptable for companies to behave like this, they are going to (ab)use it to the max. I think this is a tragedy of the commons personally. People optimizing for individual use cases at the expense of the collective, leading to disastrous results for the collective.
I've not heard that term before and can't find it, but I think I know what you mean. If it seems like I've gotten it wrong, then please let me know :-) Thanks that is a very interesting question. To some extent it may depend on perspective.
I don't think so, because this isn't the commons doing anything, it's just a dictator with all the power forcing people to make the right choices. At least in the case of government enforcement, there's (ostensibly at least) some rights you have and limits/restraints on the government, including democracy which keeps it in check against abuse.
When it's a private corporation like Apple or Amazon just making these decisions, you have little to no recourse (except maybe switch brands, but there aren't many viable options out there for most of these devices. It's not reasonable to point most people to the Pine Phone for example).
To be the opposite of Tragedy of the Commons, I would think it would need to be people self-organizing or self-regulating to prevent the tragedy. If a powerful overlord forces it, I think it's something else.
Yeah, but when your device can infringe on others, it's ok to curtail those features. No one has unlimited rights.
Cell phones already have volume limiters, too: https://www.theverge.com/23729051/ios-android-samsung-phone-...
Not great counter-arguments.
And that link about the volume limit? Come on, dude. That's a volume limit which the user can configure to protect themselves from hearing damage. Not even close to what this discussion is about. It doesn't even apply to the speaker! Completely irrelevant.
What? iPhones will prevent you from doing that? How?
> Cell phones already have volume limiters, too
I wonder if you've missed GP's point... Your volume limiting link looks like a feature that the user can control. That means that Apple isn't preventing iPhone users from violating other people's right to quiet in quiet areas.
One can debate whether anti-theft is a worthwhile trade-off for stalking, but because it's implemented as a peer-to-peer network, the consent of the owners of the other peers is relevant.
The huge shift here is that this feature exists in the first place - it's an on-by-default peer-to-peer network that runs on almost all phones, very few people know about and almost nobody would have consented to if they understood it could be used for stalking.
You can turn this off. Though, doing so is bidirectional: it also prevents your phone from sending out its own Bluetooth beacons when it’s not connected to the Internet, for other phones to pick up. Which might not be what you want. But if you’re worried about privacy impact, it probably is what you want.
Also keep in mind that the protocol already minimizes privacy impact by, among other things, encrypting the location coordinates with a key Apple doesn’t have.
If Apple's position is - "then don't buy it", they can come out and say it. They certainly have that right.
They have done that since day one, when AirTags shipped with anti-tracking features enabled...
But to disincentivize theft, any device would have to be built in such a way that swapping the electronics or discarding that tracking module makes the device you were protecting worthless. Lots of secure handshakes between paired components, very secure software kept up to date, etc. which sounds unrealistic in most cases.
Together with that network access fee probably makes such solutions economically infeasible today.
Or I could just buy an AirTag on my own.
> But to disincentivize theft, any device would have to be built in such a way that swapping the electronics or discarding that tracking module makes the device you were protecting worthless.
Not really. It just needs to be so difficult to remove without a key that thieves physically cannot remove / disable the tag without threatening the stability of the bike, car or whatever.
Doesn't need to be perfect, all it needs to do is provide sufficient survival time against your average crackhead.
You’re proposing something that may be a paradox. The only way to make something physically hard to remove is to integrate it. Locks are proven to be ineffective for this purpose. When this ideal lock is invented you will simply lock your bike with it directly and achieve the goal of theft deterrence to begin with. No need for tracking if stealing the bike destroys it.
Getting an AirTag into a mechanically locked compartment of your bike is useless. You even mentioned LPL so you know any such lock will be bypassed in a matter of seconds, maybe even less time than it takes you to put the AirTag you just bought in there. So your theoretical protection model hinges on something that doesn’t exist yet: a lock that you can easily open to put an AirTag in and service it but that nobody else can unlock.
Car or e-bike manufacturers paying for access to any “find my” network means they can heavily integrate the expensive electronics in a way that makes removing the “tracker” part truly impossible (it’s on a main controller chip) or severely devalues the object if you do (the chip/board is prohibitively expensive and impossible to find on the open market). It’s more expensive and kills self repair but reliable anti theft might be worth it to you. Think of the iPhone model here.
At the end of the day the Find My network exists to be used by different manufacturers [0]. The unpickable lock doesn’t.
[0] https://www.apple.com/newsroom/2021/04/apples-find-my-networ...
There's two different types of "stolen items"... you got organized theft, stuff like people stealing cars that are then parted out in Eastern Europe [1]. And then you got stuff like people going for joyrides - this is something that can be solved by even a decently hidden AirTag.
[1] https://www.auto-motor-und-sport.de/news/autoeinbruch-report...
And joy rides are the worst of all because the perpetrators aren’t around by the time you locate your car of bike. Locating it is actually the least of the worries, it’s usually crashed somewhere or thrown in the river.
But a phone, e-bike, or expensive camera, etc. are better served by integrated “Find My”. If it gets to Shenzen it’s lost anyway but otherwise removing the activation locks or location mechanism in practice will destroy the core of the device.
Locking an AirTag behind a mechanical lock cannot achieve the same. It takes a minute to pick or drill the lock and ditch the AirTag in an envelope to Shenzen. Think of LPL and what lock can prevent that. The lock is still the weakest link and if it can’t protect the bike directly, adding layers of complication directly relying on the same weak link seems pointless.
Every time this comes up, someone butts in with "they're for lost items, not stolen ones!", which is technically accurate but pedantic beyond reason. "Stolen" is a special case of "lost" for most people. In both cases the object is out of the owner's possession. "Stolen" just means it's deliberately missing and not accidentally so.
I understand, sympathize, and support the idea of making life harder for would-be stalkers. My gut instinct says non-notifying AirTags would make life harder for many more thieves than the self-tattling AirTags does stalkers. Apple and Google agree with each other that inconveniencing those losers outweighs abetting thieves. That's their decision to make. I'd still be irritated if I couldn't find my lost-with-the-help-of-a-thief bike because my AirTag told the thief I was looking for it.
These are hard questions. I can appreciate the challenges. And yet I'd still be highly peeved if I could my AirTag laying on the ground because it alerted a thief who then removed and discarded it.
This is a 0-sum choice & erring on the side of not letting this product be used for stalking seems like a sane choice. There are stalking products you can go buy that are more expensive that can give you the theft protection you want. Apple's and Google's monitoring network is unfathomably large and can passively monitor any device anywhere in the world. The threat vectors they have to balance against abuse is completely different.
The choice Apple faced clearly isn’t 1 stalking victim against 1,000,000 people unable to get to work. I use that example to show that it’s not as simple as “safety vs annoyance”. Apple and Google ran the numbers and erred on the side of safety. That doesn’t make it an automatic or simple choice.
The stalking issues go well beyond personal safety. Police officers, judges, politicians and cops who now have to worry about someone chucking a $25 airtag in their car which is much easier to do innocuously and those people have power to craft regulations and laws. Abortion rights are even more contentious now & stalking comes up there.
There just isn't a scenario where opting in the entire world-wide smartphone community into enabling mass stalking at a never before price point is a net positive - there just aren't enough poor people with stolen bikes to shift that equation. There's a reason AirTags destroyed Tile - Tile's network is laughably small & would always be that way compared with the reach you get at the OS level. That drastically shifts the threat model.
I understand the personal safety issues. They're important. I get it. That doesn't stop part of me from wishing I could use these cheap, convenient lost item devices to help me track down stuff that wasn't exactly accidentally lost.
As for crime prevention, I think you’re overestimating how much of a benefit that would have. Stolen device protections remove the value from the stolen device. That’s not the case for your stolen bike - thieves don’t actually care if you can track the device because a) knowing where your stolen property is doesn’t actually aide in it getting recovered b) as long as they can move the stolen product along quickly enough the information becomes too stale to action on it (remember - police usually need a search warrant). My cousin’s car got stolen with AirTags in it but he got lucky in that the police did something about it - plenty of news stories of AirTags in cars with people trying to get the police to do something and the police not being able to for a variety of reasons. And that’s cars which are orders of magnitude more expensive than bikes that police won’t bother with. Look up VanMoof theft stories to convince yourself that tracking is useless: https://www.reddit.com/r/vanmoofbicycle/comments/zbexyr/upda...
There are also dedicated devices, such as this one - https://www.t-mobile.com/devices/iot/syncup-gps-tracker-devi... - and lots of companies in China make similar products.
There is a genuine need for anti-theft technology. Apple doesn't have to address that market, likely because they're afraid of brand damage, but stalkers already have plenty of options available.
It’s not just brand damage - passive tracking using every single smartphone opted into the tracking vs active tracking where you have to expend more battery AND pay for an ongoing cellular connection each month is a tangibly different use-case with different threat models.
This math doesn't make sense to me.
You can argue that you'd be more dilligent about recharging but I'd counter that at scale you'd be the outlier. On average I'd actually expect an average battery life when stolen closer to 0 because people wouldn't be diligently recharging them & reattaching them (i.e. either the battery life would be 0 or the device wouldn't be attached to the desired property).
A 14-day battery life would then mean an average of 10.5 days of protection, which isn't too bad.
> You can argue that you'd be more dilligent about recharging but I'd counter that at scale you'd be the outlier.
I don't know about this. For bicycle users, charging their rechargeable headlights and taillights regularly (typically once weekly) is very much a habit already. This is just another thing to charge at the same time, which is a time they aren't riding their bicycle.
That said, I'm saddened that the approach seems shortsighted, since it doesn't sound like it considered a holistic picture, but rather was based on a specific value judgement. This seems to put other issues, like the whiplash around the approach to CSAM into perspective.
Seems like the calculus would only make sense when you are talking about big expensive items - cars, boats, RVs. But for those you probably want a non-bluetooth solution.
I only want AirTags or similar to guard against thieves. So if that is not going to work it's quite useless for me. Luckily for bikes, there is https://bikefinder.com/
And also, would it really hold up to just being cut with whatever tools the thief used to cut your bike chain?
When people "misuse" any technology, it seems the consensus nowadays is that the responsibility is shared between the technology creator/owner and law enforcement. Personally, I'm not fully sold as this is mainly a sociopolitical question.
(That doesn’t mean it’s easy. Doing pilot studies is a good idea.)
And I think you are taking a very US-centric view. For example, switchblades & similar quick-open knives aren't legal in many jurisdictions. So yes, many countries recognize that tools have a trade-off and are willing to legislate their usage depending on problems being observed.
It's very rare to find a true absolutist on any idealogy unless they're completely blinded - it's just that they draw the line further away than someone else / need a stronger argument to convince them. For example, I'm going to guess that you're not in favor of laissez faire with respect to nuclear weapons & tech - cause that shit is actually really easy and cheap to build these days & the sole difficulty is the regulations that surround it.
I use airtags to not just locate lost stuff, but also as a potential means to find stuff when stolen. Its not about me wanting a way to stalk someone, what a bizarre thing to say!
>It's very rare to find a true absolutist on any idealogy unless they're completely blinded - it's just that they draw the line further away than someone else / need a stronger argument to convince them.
Oh, I'm not a libertarian, I'm firmly pro-government. I'm just not pro-nanny state. I'm willing to compromise if the other side is too. However am I not allowed to complain, even a little?
Please describe how what you’re asking for is different than stalking the people who stole your stuff? More importantly, how would Apple/Google know how to differentiate between the two use-cases?
> However am I not allowed to complain, even a little?
You can always complain but your complaint is pretty non-sensical because this is private corporations making a decision and government isn’t involved, so it’s unclear how this is a nanny state. Go build your own tracker that meets your specifications?
100% indeed...
Stop your screeching that is feeding the asinine moral panic that has resulted in these things becoming worthless for tracking packages and stolen items.
2. Tile is a smaller target, so “I’ve never seen a news story” just means the reach of any such story is smaller.
3. Maybe Tile already has similar protections? It’s against their TOS [1]
4. Tile has been sued for stalking [2]
5. Tile is offering an anti-theft feature provided you have to use biometrics & give them a government ID and you have to agree that they’ll sue you if you use it for stalking [3]. So Tile too is clearly concerned about the stalking problem, they’re already being sued around it, & they’re a drastically smaller target than Apple and Google (no one is going to craft legislation around what Tile is doing). Apple is 3x the size of Tile by itself.
You can disregard it as moral panic but how would you distinguish that from a genuine concern of the potential for an abuse for a technology? Strict liability isn’t popular these days but it has ebbed and flowed as a doctrine. Failure to try to try to do a good faith attempt to prevent this problem would certainly land Apple and Google into hot water when a case of stalking inevitably happens using these devices.
[1] https://support.thetileapp.com/hc/en-us/articles/44102774937...
[2] https://whlawoffices.com/blog/why-was-tile-sued-for-tracking...
[3] https://techcrunch.com/2023/02/16/tile-takes-extreme-steps-t...
5. If Apple launched an AirTag Pro at twice the price with these controls but otherwise identical hardware, I'd be all over it. They're leaving money on the table.
Here's Tile adding anti-stalking features: https://techcrunch.com/2022/03/17/tile-launches-its-anti-sta...
So which is it? Is it unjustified moral panic with 0 evidence of harm & Tile isn't doing anything or are you just upset that these big companies aren't building the product you want to buy?
With 5 you're now shifting goal posts by introducing a non-sequiter to my point 5. I've clearly highlighted that Apple always balances money-making opportunities against their values around privacy & public safety. No one is forcing you to buy this product. You should also fully expect to see Tile utilize this standard so that they can leverage the reach of having every smartphone in the world scanning for these instead of just other Tile customers.
The anti-stalking bias degrades the product for people who've bought an AirTag and become victims of theft. It's a limited population. People are unaffected by default.
The anti-theft bias means everybody is a potential victim of stalking. If I have no interest in AirTags, anybody else can still tape one to the bottom of my car and track me wherever I go. Everybody is potentially affected.
Even if theft is far more common than stalking, an anti-theft bias would be a tough position for Apple to defend if it means they're potentially facilitating stalking for the entire population. It may not be ideal, but I can understand it.
I suspect if Apple went the Anti-Theft route, thieves would not stop thieving, they would just start searching large stolen items for air tags before bringing it to wherever they may.
AirTag isn't the right product for you. Buy a tracker from somebody else.
So if your bike thief had an iPhone, they'd be able to find the tag anyway?
AFAIK the only major difference is that it's now being baked into the Android OS so people don't need to actively download the app.
If you ever have something stolen, ask the cops how much time and effort they’ll dedicate to finding the stolen goods. They do not care.
(And no, this isn’t connected to current politics—I’ve not known cops to care about tracking down stolen good no matter how much evidence you can hand them, since at least the 90s)
This feels incredibly minimizing for people who have been stalked. Or people fleeing domestic abuse, human trafficking, or other forms of abuse where controlling a person’s movement is a large part of the harm being inflicted.
Stalking covers a wide range of activity that impacts people who are usually in a vulnerable or dangerous situation. The people who would use tags to track people aren’t just “losers”, they’re pimps, rapists, murderers, abusive spouses, and so many other awful things.
Inconveniencing them far outweighs someone stealing your luggage.
> All you need is a Mac and [...]
IIRC, they need you running macos to get the data via a plugin for apple mail. If you only needed an appleID, it could likely be done in a web browser.
Are you sure? It seems to me that the anti stalking features depend on the stalkee's / tief's software stack, not the stalker's stack.
Your phone can also refuse to send notifications about the location of a nearby tracker if it thinks it's being tracked, but if there are a bunch of other phones nearby that can relay that information there is nothing to stop them from doing so.
But the target's phone will still be notified that "Someone else's tracker is moving with you", won't it?
Sounds like you responsibility - your belongings, you should know where they are or if they are missing.
How would you have survived before AirTags?
But even with an unmodified tracker, it's quite hard to locate one in a car, because there is a lot of hiding spaces (especially if you put one in some hard-to-reach space such as under the carpet in the cabin etc...).
Using randomized or rolling addresses avoids detection to an extent, depending on how many randomized addresses one uses and how often they're rotated.
However, it's also trivial to detect randomized (or rolling) addresses due to the address being utilized for more than a single locality. Although, I'm not sure that either Apple or Google is actually doing the randomized detection even with this new patch.
I wonder if they would find a way to use this to disable ALL the airtags in an area.
For example, put a UAL airtag on a plane, and use that to disable all the other airtags.
Unless you think a huge, high-end airline "got confused"? It wouldn't have been against regs even if ti was a lithium ion battery because it's so tiny. What do you think they do about the millions of electric toothbrushes and shavers people travel with that have much larger lithium ion batteries?
They retracted it because it ended up causing a Striesand Effect, putting a lot of sunlight on how airlines do a very brisk business selling "lost" luggage.
... and lots of cases of "lost" luggage being due to the fact that decades after implementing paper tags, neither airlines nor bag/trolley manufacturers have gotten their asses together and worked on a standardized way to reduce instances of tags simply getting ripped off during handling.
Like, it wouldn't even be that hard. Place a long, wide recess maybe 2mm deep along the entire trolley, where the tag can be stuck in and is guarded that way against conveyor belts or other bags ripping off the tag.
And maybe invent a system where you have to scan your boarding pass and the tag barcode to leave the baggage claim area to reduce the amount of cases where people have taken the wrong bag.
Having dealt with battery regulations with airlines, couriers and postal services many times, yes, yes I do. They routinely fuck it up, even claiming that AA Alkaline batteries are too dangerous to ship.
I get significantly better responsiveness from them at an Australian airport or Singapore airport than I do at Bangkok airport. That doesn't mean they don't work, it just means it's unrealistic to expect minimum wage baggage handlers in Thailand to have an iPhone in their pocket.
There's a good bit of separation between the cabin and the cargo hold. I imagine it could be pretty difficult to get a read from a low power tag deep in a bag in a pile of other luggage with several other big metal plates between.
This has always been the case with AirTags. They've had anti-stalking notifications since day one, and disabling one is as easy as a quarter test of the case to remove the battery.
It has never been advertised for that has it?
I ask because I'm at a loss. BLE from these little devices has ~40ft of range on a good day, and even if a mesh network were involved, I fail to see what the airtag could do that would help you recover your item. Sound an alarm? Great, the thief knows where it is now, and they can just yank it out and throw it in the trash. Give you GPS coordinates? Great, that'll really help after you find security, tell them what happened, convince them it's urgent, and explain to them what they're looking at when you show them the app. Of course that all assumes the airtag (or a nearby mesh device) has a useful GPS fix, and the thief hasn't already found the tag and thrown it in a trash can or something.
Imo without these features it would be rather unlikely for a thief to find AirTags quickly or even realize it’s there.
The ~40ft range is more than enough, the global mesh network of all iPhones is the whole point of the AirTags, there’s no “gps fix”.
I'm still stuck on all of the friction involved in actually using airtags as a theft recovery device. Neither the tag or Apple's service can contact police or airport security on its own, so you're spending who-knows-how-long flagging down security, explaining the situation, and waiting for them to relay that message back to an appropriate authority who will go find the thief.
Alternatively, you skip the "talk to security" part entirely and go find the thief yourself (assuming you're comfortable with that sort of confrontation). You're still dealing with a moving target - one that can very easily leave the airport entirely, forcing you to choose between sacrificing your bag and potentially missing your flight, a cab, etc.
You also run into a proliferation issue. The more popular airtags become as a theft-recovery device, the more thieves will know to look for them and remove them from stolen items.
Bury the tracker somewhere too inconvenient to locate and remove quickly, and they'll count on not removing it until later (or they'll just ditch it once it starts beeping).
Which is annoying, because I have an Android and my wife has an iPhone, and it would be nice to be able to both track the same objects.
Ability to actually find lost items. AirTags are so successful (in the US) because of the ubiquity of iPhones which are, effectively, constantly reporting on the location of detected devices. A smaller network of listening/reporting devices will not be as effective unless it happens to be very popular right in the area the device was lost.
Apple and now Google trackers on the other hand build this functionality into the OS (or Google's near-OS bundle for Android), so if basically any phone comes within range of the tracker it will provide a location update.
I have zero affiliation with Tile and I have never bought any device like this of any sort, but this is useful information to me as someone who has been the target of frequent bicycle theft.
The criticism I will agree with is that it does feel worded a with a bit of a corporate polished tone that does give that vibe. edit: I think it's largely the "supercharge" descriptor.
Their comment at the top level also has that disclaimer and while it's written in a bit of a marketing tone, it adds substantive value to the discussion.
One major value of HN is that we get people who are actively involved in building various pieces of technology directly engaging with the community. When there's a strong disclosure of who they are, that's almost always a good thing. (Of course, some organisations don't encourage that disclosure and that's a little more ambiguous).
Personally I wouldn't purchase anything connected to that network, even if they now say they stopped selling precise data.
The Life360 network may be sizable but it's going to me nowhere close to the iOS or Android networks, and it's going to get a lot smaller with folks like me leaving. If Tile supported the Android Find My Device network I would have stayed.
I had a tile, however I fianlly got rid of it when I was unable to locate my keys in my house. It sent me on a wild goose chase saying that it had been last seen near my bins.
I was in the same room as them for the first 15 minute of it beaconing.
Airtags seem to acutally work reliably, and because you don't need the app running, has a good network to find them outside of my house
Had the odd experience of going to a retreat where everyone sat listening to speakers, and then all went to lunch, and then back to the speakers, then all to dinner, then back to the speakers. And my iPhone popped up an alert that there was an airtag following me. (It wasn't of course it was an airtag in another attendee's bag to track their bag which they had with them, near me kind of randomly, but being driven by the same forces of movement :-)).
This notification would be utterly useless if that were no longer the case: you'd spend half your time on a flight or bus ride closing the unwanted and unhelpful popups.
(Also, it’s possible someone had slipped a tag into that person’s luggage without their knowledge.)
Edit: I think I misread that. When you see an AirTag popup, you can choose to ignore it for the day or forever. That's from my recollection. I haven't seen one in ages.
I wonder if that last bit requires physical access to the tracker?
3.13. Disablement
The accessory SHALL have a way to be disabled such that its future
locations cannot be seen by its owner. Disablement SHALL be done via
some physical action (e.g., button press, gesture, removal of
battery, etc.).
Ledvina, et al. Expires 22 June 2024 [Page 26]
Internet-Draft Detecting Unwanted Location Trackers December 2023
3.13.1. Disablement instructions
The accessory manufacturer SHALL provide both a text description of
how to disable the accessory as well as a visual depiction (e.g.
image, diagram, animation, etc.) that MUST be available when the
platform is online and OPTIONALLY when offline. Disablement
procedure or instructions CAN change with accessory firmware updates.
These are provided as part of the onboarding process (Section 7).
https://datatracker.ietf.org/doc/draft-detecting-unwanted-lo...Yes. Physical access would likely be needed for most of these devices and would be sufficient for satisfying the RFC, based on the examples in section 3.13.
So you might get a notification of a device "following" you because I have a tracker in my bag but no phone (or my phone is off, perhaps; or maybe it's just malfunctioning and mis-reporting as happens sometimes). You play the sound and find out it's in the bag underneath your seat on the bus, but that's my bag. You could attempt to rifle through it and take my tracker and disable it, but I'd probably stop you.
I get these unwanted alerts every time my wife and I travel with luggage that she's placed AirTags into. I guess my phone thinks the owner isn't present because she doesn't have an iPhone. We both have Android phones, and she also has an iPad which she used to configure the AirTags but it's normally turned off.
My airtag occasionally thinks it's not with me and apple watch wakes me up in the middle of the night even though my bag is in the next room of this tiny flat.
Someone will find a way around this. It's too fun of a hack to go unanswered for more than a week. Now only the criminals will have this physical tracking ability (well,them and Apple+Google).
“Apple and Google have worked together to create an industry specification”
…
“Apple and Google will continue to work with the Internet Engineering Task Force via the Detecting Unwanted Location Trackers working group to develop the official standard for this technology.”
That’s what is happening here. I’m not sure why people are always quick to assume negatives without doing even the most cursory reading of linked articles.
The only possible interpretation of this is that Apple knows their current system wouldn't survive antitrust inquiries. So they're making a pathetically marginal concession ("well we did let you track the hostile users!") to cement the rationale of a pointlessly insular system. Once again, Apple is refusing to fully solve a fixable problem in order to artificially create a market in which to sell their solution.
IOW:
"BigCorpA and BigCorpG will continue to work with Why Must This Task Force No Longer Focus On Progressing The Common Good And Instead Now Need To Focusing On Helping Try To Mitigate The Mess That Big Corps Are Causing via the Trying To Unfuck BigCorpA's Massive Privacy Oversight working group to develop an official standard which only BigCorpA and BigCorpG will have the resources to implement."
We allowed the creation of a global tracking network under the false pretense of privacy. The entire Find My security model falls apart when considering "malicious" tags, and Apple knew about this from the start.
- 4x the cost plus ongoing fees
- 2x larger
- can’t buy it at any big box store
- relies on a third party who can also see what you’re tracking
- battery limited to weeks, not years
Accessibility and features make these way more compelling
In the security world, it seems accepted that no security effort is a silver bullet that's 100% impossible to get around.
Rather, it seems best practice to compose many layers of security efforts, which all work to raise the level of effort an attacker is required to exploit people.
So I think it's unfair to say this is a charade.
https://github.com/seemoo-lab/openhaystack?tab=readme-ov-fil...
Seems like in theory you could do that, though there are definitely heuristics you could apply to detect those tags, depending on how stealthy they are being.
Also on the servers side Apple could just limit you to a reasonable number of tags.
Making a tag that is not trackable is currently as easy as flipping a bit in the BLE advertisement. The same message is broadcast to all phones, but yes, a tag could also produce multiple identifiers and evade detection. [2]
[1]: Section 8 of "Abuse-Resistant Location Tracking: Balancing Privacy and Safety in the Offline Finding Ecosystem". https://eprint.iacr.org/2023/1332.pdf
[2]: "Track You: A Deep Dive into Safety Alerts for Apple AirTags". https://petsymposium.org/popets/2023/popets-2023-0102.pdf
They can't just go around the house waving a very expensive iPhone to find the items :D
Just knowing that you might be tracked when stealing would have been a massive deterrent. Now you know you can just hang out with the stuff you've stolen half an hour to see if it's tagged, and then take it home without repercussions.
All the same I wonder how this will fare on airlines where many people are doing exactly your setup for their carry-ons.
They're 70 years old. I'm sure seeing "AirTag found moving with you" is confusing them and possibly freaking them out.
I bought the airtag for my dog, but now am having second thoughts, I'm just imagining all the freakouts I'll cause when walking on trails.
You'd have to follow someone for 30+ minutes without your phone (or other device if you paired it with something else) nearby.
I’ve been notified of an “unknown AirTag” while I was home. When I checked the locations it was seen with me, it was a random zigzag within a block or two of my home.
I’m pretty sure what happened is that the AirTag belonged to one of my neighbours, there were some GPS distortions happening that made my phone think it was moving slightly, it kept hearing the AirTag’s signal, and it assumed I was being stalked while wandering near home. This person might have the same thing happening to them.
It's a common misconception that Airtags and similar products are designed to help you locate stolen items.
They not. "Tracker on stolen device" and "Tracker planted for the purposes of stalking" are indistinguishable situations.
They're to help you find things that you lost. They're amazing for that. They're sometimes helpful for finding stolen things too, but that is a side-effect.
It would be nice to be able to simply switch to a non-spammy vendor in that case, but that's not how the market works in the US.
Hence the term "unwanted" location tracking.
The assumption made by Apple is that the computer user _wants_ Apple to track their locaton; the assumption by Google is that the computer user _wants_ Google to track their location.
There will be no alert that Apple or Google are receiving location data. Why alert the computer user about something that they "want".
It's the same ruse with Google or Apple providing ad blocking. The ad blocking feature will only interfere with ads that are not serviced through Apple or Google. Ads provided by Apple or Google shall remain unaffected.
These companies are engaged in online ad services. Why would they protect the computer user from online ads and data collection that makes online ads more targeted. There will be tracking and there will be ads, along with an ongoing assumption that the computer _wants_ tracking and ads but only if provided by Apple or Google.
At least it explains why the roads are so busy. Though, I thought everyone was working from home... which would make stalking yourself much easier.
This means with a network of trackers, it is possible to track the location of a single airtag over the course of a 24 hour period even if you aren’t the owner.
Happy?
https://arstechnica.com/gadgets/2023/05/nypd-urges-citizens-...
For bread and butter theft, a bike theft in this case, an owner tried to get the orange county sherriff involved. They managed to come to where the ping was hitting, knocked on the door, couldn't do anything, had to leave. The bike owner went vigilante in this case and took the bike back, forcing the orange county sherriff dept to release this statement:
"As much as the convenience of technology plays a vital role in the quality of our lives, we want to remind our communities to utilize their local law enforcement services when they've been victimized by a crime instead of placing themselves into harm's way."
"GPS tracking devices, like an "AirTag", are used for tracking property like bicycles, backpacks, etc. Putting such devices onto property items will help you locate those items if missing or stolen; however, pursuing its recovery in a vigilante manner because the GPS device depicts its location could place you into a physically dangerous predicament."
https://abc7.com/ebike-theft-airtag-aliso-viejo/13091749/
For a point of reference on the policing culture in Orange County, they are currently running an ad campaign where they have "Crime doesn't pay in Orange County, you steal we prosecute" plastered on LA city and county busses. Its a little bit more active than other areas to say the least.
Why on earth re-invent the wheel? A bunch of clever folk have been doing this for years.
I hope that we can all applaud and value open source but the world is a mad place.
Android: https://play.google.com/store/apps/details?id=de.seemoo.at_t...
I can't find an Apple version so I might suppose that either Apple's nose is out of joint with regards the name, or an Apple version was never released 8)
In the end this is a very decent resource and it should have been covered off by phone floggers, years ago. It's rubbish that G and A are presenting this as something new that they have come up with.
And to nitpick, what kind of tracking do you actually want?
With Find My disabled, these Tracking alerts do not work.
What is this other industry spec?
> Chipolo, eufy, Jio, Motorola, and Pebblebee
What about Tile?
AirTags always need an iDevice to be close by to update their location.
Nit: they’re very very detectable, just not using your off the shelf phone.
If it’s hidden in a metal frame then it’s not going to get a good GNSS fix. And if you’re doing a deep sleep you’re powering down your GNSS module so not getting a proper warm fix.
We decided to opt out of the Google and Apple finding networks and the new proposed standards because it completely ruins the ability to use Bluetooth devices to deter theft. If you put an AirTag on say your bike, and thief steals it, they will get a notification and immediately just find and disable it.
We actually built a (controversial) feature that lets you opt out of anti-stalking features if you scan a government ID. As of today, we have zero known instances of abuse—the friction of scanning an ID is enough to make a bad guy think twice, and a committed stalker can just go get an LTE-enabled stealth GPS device on Amazon. It is crazy that the press and regulators focus on Bluetooth devices when actual stalking devices are readily available.
Some people are commenting on how small our network is. People don't realize that Life360 is on 1 in 8 phones in the US. We are huge outside of tech bubbles. If you are at an airport, mall, or anywhere with any meaningful density of people, our network is on par with the big guys. There is a J curve to the benefits of increasing density, and outside of rural areas we essentially have complete coverage.
Beyond this, we just announced a new satellite-to-Bluetooth network this morning, and we plan to open it up to developers in 2025. It won't matter where you lose your stuff, we will be able to find it. And thieves won't.
The world would be better if tracking devices did not exist. It's a shame you've decided to actively reject anti-stalking features.
You give the location of your missing property to the Police when stolen.
Tile/Life360 is now a superior product while AirTags are basically useless paperweight.
If you want to stalk someone you have always had numerous options including superior gps/cell based trackers.
They will do nothing.
It's a shame that stalking is a concern. It's a shame that this had to be implemented and effectively breaks the devices use case for most people. But I'm not even mad at Apple or Google, because I also think that it is their responsibility to protect people from being stalked.
Tile is also not an option for me, in Europe pretty much no one uses it. I will still try my luck with Apple and Google/Pebblebee Tags. Does anyone have experience how long it takes until you get notified about a tracker moving with you?
When we launched our anti-theft feature, we were clear that if we found there was widespread abuse, we would change course. We have had literally zero complaints of anyone being stalked with a device where anti-theft was enabled.
And I think you are misunderstanding the new standards. Google and Apple will proactively notify thieves of nearby trackers, and allow a thief to disable it. This is next level bad for anyone relying on their tracking device to protect against theft.
What is the data that would change your mind? I would change my mind if we found that more than .1% of our customers were abusing this feature.
I could see this being used in the aggregate to ascertain drop off points or chop shops, but at an individual level it doesn’t stop your stuff from being stolen. Even the aggregate case requires buy in from law enforcement to actually act on the information which is not a small thing.
First, it's highly likely that someone being stalked wouldn't realize a tile device was the cause. Secondly, you said Tile and Life360 are on only 12% of devices. So maybe 1 out of 10 stalkers will be successful in using your device to stalk. That's not enough data to state so conclusively that this doesn't happen. I'm sure if Tile was more popular (and thus more functional) and more stalkers knew they were the best devices for stalking, they would use them.
I carefully examined life360.com, trying to put myself in the shoes of somebody who was stalked, magically divined that life360 was involved, and wanted to report the issue. The extent of my options on life360.com are:
1. Do Not Sell or Share My Personal Information
And that's it. There does not exist a "contact us" or other general mechanism, and there certainly does not exist an abuse reporting mechanism. If that happens to exist behind other filters or paywalls then it's not relevant when discussing how the average customer would interact with your website.
With that in mind, I would expect an exactly 0% abuse rate regardless of how abusive your product actually is. You confirm that number. I'm not surprised.
The ball is in your court. How do you prove to the world that you _actually_ care about abuse? How _should_ a real abusee interact with your website? Why isn't it obvious? What are the exact numbers? And so on...
We encourage people to first go to the police, and we work with law enforcement to help bring criminals to justice on a regular basis.
Think about it for a second. If anyone could contact a tech company to get people's information based on a serial number, this would be abused by people who could steal your phone, airpods, or bag containing an airtag, claim to be stalked, contact the manufacturer directly, and get your home address from the manufacturer by giving them the serial number.
"If you feel your safety is at risk, you can contact your local law enforcement, who can work with Apple. You might need to provide the AirTag or its serial number."
https://support.apple.com/guide/personal-safety/stay-safe-wi...
A potential car thief doesn't know if your car has an alarm on it either, but he just assumes that it does because most do. With wide enough adoption of these devices, it could work out the same.
This is not a good fit for bluetooth. Bluetooth is trivially detectable whether it's tracked centrally or not.
Thieves will, however, reply to an alert that says there is a tracker following you and hit the "disable" button. Friction is key. Google and Apple are making it extremely easy for thieves. We are pushing back on this.
If you want to see the insanity of going after bluetooth devices, just search "stealth GPS device" on google and see what comes up. Ebay is targeting me with an ad that says "Hidden GPS Tracking Device for sale" There are legit LTE enabled stalkers right there in plain sight.
Being sued means nothing.
And if a stalker puts it there, me finding it is a feature.
> scan a government ID
Considering how badly companies keep my private data private, be it email addresses or even direct passwords, scanning a government ID for a $10 tag seems really bad from a privacy perspective. Once you get hacked too (like many other, larger companies have been), the hackers will have all the peoples ID scans too to use with another company implementing such features.
I'd rather have the assurance that at-risk groups like women, marginalized people, and notable people are not at risk of having a cheap and easy to use location tracker attached to them. As others have pointed out, these trackers are not meant for, and are ill-suited to use as anti-theft devices. We've had Lojack like devices for years and they'll still work all the same regardless of the reporting standard.
> People don't realize that Life360 is on 1 in 8 phones in the US.
So that's 12% of devices. Another way to look at it is you have a 1 in 8 chance that the device will work and notify you when a potential reporting device approaches it.
> CEO of Tile / Life360 here.
As an Android user who is only now getting to use Bluetooth beacon tech like our iPhone friends have had with airtags for quite some time, I'm in the market for these devices. Your statement here makes me think I should look for devices other than Tile, even if they did participate in the standard.
You were literally just sued for this https://news.bloomberglaw.com/privacy-and-data-security/tile...
Edit: Hey man I'm not engaging you on this, you chose to opt-out of this safety feature and you've enabled stalkers that target at risk groups like me. Nope.
And I feel like many people being critical of us are arguing with emotions and not data. You have to scan a government ID and agree to severe penalties for misusing our product. We have had zero instances of reported stalking from anyone who has enabled the anti-theft feature.
Can you articulate with data why what we are doing is problematic?
Most of the people your products are being misused to stalk can't even turn off their location sharing because the person who's insisted they install the app/hardware will assume that doing so means they're off spending time with someone else, or whatever their personal paranoid fantasy is. Why would someone being subjected to that contact you? It would just enrage whoever is monitoring their movements when their account was suspended, or whatever your process is.
The people misusing your products in that way don't think they're doing anything wrong, so they're not going to hesitate to have you verify their ID.
Other than location history, is there a big difference between Life360 and builtin iPhone location sharing? To me, that's not enough to put the product in a different category.
Though some things in that space are marketed to stalkers, there are legitimate use cases for such technologies, and therefore the only LTE tracking devices I’ve seen in person were sold at reputable stores.
So all I need is a stolen ID and then not only I am stalking but also ruining another person's life?
I'm sure we can come up with edge cases or potential ways people could cheat the system, but we are adding so much risk and friction to stalkers that they would likely just buy a real stealth GPS tracker with an LTE connection.
As a genuine question, why is there no outrage for these devices that are literally marketed as stealth trackers?
I was able to track down my stolen vehicle with the help of Tile and now put them hidden in all my vehicles since they don't alert like an Air Tag does.
It switches between modes at random (map, we’ll notify you, and the signal meter) when the signal is weak, and it says we have to replace batteries constantly. (Even though we just replaced them — is the tile shorted out internally, or do we have to reset a timer somewhere, or what?). Also, it spams upsell attempts while doing this. You may as well be displaying ads for competitors at this high-stress point in the UI flow!
Other than the above stuff, which feel kind of like bugs, I’ve noticed it’s hard to figure out which building (in a 1 acre space) our keys were last seen in. We own all the phones and tiles around here, so giving better precision probably wouldn’t be a privacy issue.
I’d rather go with a smaller, cross platform provider, but we’re seriously considering switching to AirTag.
Thanks for standing up for functionality vs. questionable privacy protection.
Anyway, we’re rooting for you; good luck!
Walk outside away from all other devices.
Walk 100 paces. Put tile down. Walk back to where you started.
UI flow:
1) It shows a map of across town (last ping was hours ago).
2) tap find -> your tile is nearby, wait while we connect (with done button)
3) timeout -> map shows a dot where the phone is, without a big uncertainty circle around it. Can’t zoom.
4) reopen app. Map resets to across town (or, worse, 50 ft in the wrong direction, so you think it pinged a location).
5) walk to pick up keys. No music or phone notification. (Later, an email arrives, usually.)
6) tap around to debug (want to pay for smart alerts?)
7) (when someone else asks me for help). Where’s my credit card?!? Tile is holding my keys hostage for $3!!
8) (if you didn’t pick up the keys) go to step 2.
This is deterministic on iOS with everything up to date. It’s been like this for over a year across multiple iPhone generations.
Emphasis on known. The whole point of stalking is to hide the device and not get caught. How would a typical victim even discover it? Or even if they figured out they were stalked, that it was with a Tile device and thus report it?
ID scanning is easy to defeat. This is just ripe for abuse and it's good that Apple/Google took measures to block stalking, even at the expense of anti theft use cases.
Considering the multiple examples listed in the lawsuit [1] that the CEO is aware of, there are certainly stalking instances that they know about. Just none that they know of since 2022 (when they introduced the anti stalking features) with the anti stalking features disabled.
[1] See links on page 13: https://storage.courtlistener.com/recap/gov.uscourts.cand.41...
At a meta-level, we don't think the bad behavior of a very very small number of abusive should degrade the product for tens of millions of good actors. Theft is unfortunately extremely prevalent and a key reason why customers by trackers - we think the greater good is to responsibly support this use case.
We have put safeguards in place that make it tough to use our products to stalk, and while nothing is perfect, the only complaints of stalking we have received are from people who were allegedly stalked by Tiles that did NOT have the anti-theft feature turned on. By adding this ID scanning friction, which includes a liveness check, we have empirical data that the bad actors go elsewhere.
I presumed such a device would require a low-power cellular service. Glad to see you're making it work using Bluetooth.
That said these higher requirements should not apply if the device has these anti-stalking notifications.
Btw I loved your TikTok account!
Do you have any info or statistics to share about the size of your network in Europe?
I'm currently in a city, and when I open the map it gives me a circle telling me that there are 1,807 people using tile in that circle. This city population is a bit shy of 1 million, and while the circle doesn't cover it all it does cover the densest parts, so if we conservatively say 400,000 people in that circle then that means that the percentage of people with the app is about 0.45%. Now I don't know if the Life360 users are included in that count, that said I also have never heard of anyone who uses it here.
As an aside, I do wish the app were able to update more often. I have a tile tracker on my bike (and obviously the app on my phone), and I can leave a place, bike ten minutes to home, lock up the bike, go inside, and the app will often still tell me that my bike is where it was before I rode it home. I guess there's a battery tradeoff there though.
Oh wait, these companies need this to squeeze more ~~money~~ value out of paying customers.
I am not complaining.
What it amounts to, is that the digital world enables so much information gathering and using flexibility, we need fine grain permissions and controls for our devices and services, so they "do the right thing" for all kinds of corner cases.
But we don't have an information infrastructure for that, so the best we can do is balance concerns.
It's a common misconception that Airtags and similar products are designed to help you locate stolen items.
They not. "Tracker on stolen device" and "Tracker planted for the purposes of stalking" are indistinguishable situations.
They're to help you find things that you lost. They're amazing for that. They're sometimes helpful for finding stolen things too, but that is a side-effect.
One is highly useful and moral, the other is highly immoral and potentially destructive.
But we don’t have an information infrastructure that lets tech understand the difference yet.
That was my point. I think I made it clearly.
Are they going to alert Android users that they have been tracking them?
Apple disallows disabling Bluetooth and WiFi easily because it allows them to track their air tags everywhere.
My solution is a Shortcut to disable Bluetooth, triggered by a widget on my Home Screen. It’s annoying that I need to allocate space for that, but at least I can (actually) toggle Bluetooth without opening Settings.
FB9992639 "Thank you for filing this feedback report. We reviewed your report and determined the behavior you experienced is currently functioning as intended."
Whether Apple intended this or not: The real world primary use case for AirTags is still tracking stolen crap. I would to _not_ want to alert thieves to the presence of an attached tracker in that case. I guess tracking your lost luggage is likely a #2, but if you were to survey what people were actually using them for, I'm betting it'd be #1 above.
The only way I can think of solving this is allowing a silent mode on the tracker that requires both a private key from the user (to avoid getting NSL'd) and a private key from law enforcement (Apple / Google already have law enforcement portals) and finally one-way hashing the keys and publishing the results to a public irrevocable block ledger. One could see if your key was on the list to see if you Airtag was silenced, but you couldn't pick out specific tags that were silenced. The law enforcement agency's keys would also be hashed and published, allowing us some transparency on who is requesting the most tag silences, so we could monitor the monitors. If this were bundled up in a blockchain, and the tags were programmed only to act on a blockchain, we could avoid abuse and gain a useful feature.
You're conflating your primary use case with the world's. 95% of the AirTags I'm aware of in the wild in both my family and friends are used for finding misplaced items - not stolen ones.
But this is not what you're now doing?
Unfortunately, this is practically indistinguishable from:
> I would _not_ want to alert my wife to the presence of an attached tracker in her purse