Why Your Wi-Fi Router Doubles as an Apple AirTag
krebsonsecurity.com
krebsonsecurity.com
Aren't the locations on apple's servers end-to-end encrypted? I'm not sure what you'd be able to do with that.
Also surprised how many people don't know that their phones regularly try to connect to all wifi networks saved on the device, and that this unique combination which includes things like "my town mcdonald's" or whatever is enough to uniquely identify someone and usually locate them too.
What's with the scare quotes? It seems entirely plausible to me. eg. their process for capturing beacons were to put a wifi card in monitor mode, capturing any packets they see, and then filtering only for beacons. Somewhere along the way they forgot to add the filter, and as a result they were inadvertently recording all packets. Trying to imply that they were doing something nefarious makes little sense. The cars were constantly moving, so at best you got a few seconds of web browsing data before going out of range. As google should know, the value in data comes from being able to build a complete profile of someone, not knowing what one page someone visited was. Moreover, thanks to third party cookies and their embeds everywhere on the web, they don't need to drive around to capture your web browsing traffic. They can get a continuous feed just by operating their cdn/ad networks.
Also to be clear I'm not claiming that it's fine for them to do it, or that they should continue doing it, only that the scare quotes around "accidentally" was unwarranted given the lack of evidence towards malice and lack of motive. To make an analogy, accidentally-exposed-to-the-public breaches happen all the time. You can complain about how there were lack of controls/security, but people don't typically don't use scare quotes to imply the breaches were somehow intentional.
Found this out by just having the personal hot spot of an iOS device enabled and then turning on a android tablet. iOS doesn’t broadcast the SSID unless you have the settings screen of the personal hotspot open. Scary.
Source? AFAIK this behavior only gets engaged if the hotspot has a hidden SSID.
>Found this out by just having the personal hot spot of an iOS device enabled and then turning on a android tablet. iOS doesn’t broadcast the SSID unless you have the settings screen of the personal hotspot open. Scary.
This is opposite to my experience. I specifically have to enable "allow other devices to join" for non-ios devices to be able to join.
So I'll call "Source?" on it working like you describe.
That's a misnomer. It doesn't actually make it hidden, only transmit beacons with a blank ssid. That's why even if your network is hidden, it will show a "hidden network" option for you to manually enter the SSID[1]. Moreover, client devices that have hidden networks saved will send out probe packets with network names it has saved[2], so it can determine whether the hidden network is actually around. This is actually worse for privacy, especially if your network name is vaguely unique, because you're broadcasting this high entropy information everywhere you go.
[1] https://www.digitalcitizen.life/wp-content/uploads/2020/10/h...
[2] https://www.acrylicwifi.com/en/blog/hidden-wifi-network-secu...
On another note, I had missed that Apple recognizes the '_nomap' suffix and stops indexing/reporting its WiFI AP locations.
Apple’s API might return fake “trap addresses” that it could use to trace if their API data shows up in other companies’ location databases. Like the “trap streets” used to catch map plagiarists: https://en.m.wikipedia.org/wiki/Trap_street
> But in late March 2024, Apple quietly tweaked its privacy policy, allowing people to opt out of having the location of their wireless access points collected and shared by Apple — by appending “_nomap” to the end of the Wi-Fi access point’s name (SSID).
https://support.apple.com/en-us/102515 (Search for "_nomap")Google also supports this scheme: https://support.google.com/maps/answer/1725632
Wigle.net, too: https://wigle.net/phpbb/viewtopic.php?t=2330
Would I trust any of this? No.
Your address is needed so they can know exactly which place _not_ to map, of course.
But if you do it, you'll save $2 off the ad-supported Netflix tier.
https://privacy.microsoft.com/en-us/windows-10-open-wi-fi-ho...
It's a slippery slope to walk trying to regulate that one. One example: "No public citizen, you are not allowed to monitor our frequencies without paying our corporation a subscription fee."
At the same time, I write a blog for other humans to read. I'm annoyed that some companies are likely scraping it to train their LLMs. Beyond my annoyance, I don't know how far I'd want to go toward making it possible for humans to consume it but not AIs. The legal cures for that seem like they'd be worse than the disease.
If I understand correctly, the research was only possible because they were able to leverage the Google and apple APIs against each other. The lesson I get from this is these companies shouldn't behave like they exist in a vacuum and when exposing data or forcing global configuration (like the AP name) they need to be more careful.
I find your ideas intriguing and would like to subscribe to your _nomap geolocation service.
(Also, I note that the nomap.bot domain is available...)
consent isn't needed, given that broadcasting your SSID in the open clearly fails the "expectation of privacy" test.
Also from a practical angle, what exactly are you trying to prevent? That there's a wifi router at your house?
Until there’s technology that lets you do that easily I think this definitely violates privacy. Especially if unique information like MAC addresses is collect, and not only the Wi-Fi name.
I wonder how MAC addresses are treated under GDPR since e.g. IP addresses are considered personal information.
That's magical thinking.
Magical thinking is not a privacy problem. Magical thinking is a cognition problem.
A few Microsoft threads some may be interested in concerning _optout and the additional preventing clients from sharing WiFi passwords:
https://answers.microsoft.com/en-us/insider/forum/all/clarif...
https://answers.microsoft.com/en-us/windows/forum/all/turn-w...
https://answers.microsoft.com/en-us/windows/forum/all/preven...
(And do you change the MAC addresses of your bluetooth devices, too? Some of us do gather up bluetooth location information, as well.)
I don’t use much bluetooth at home. Zigbee is becoming an issue, but I haven’t moved since I’ve set it up.
Or the USPS when you let them know where to forward your mail to after you move:
https://www.forbes.com/sites/adamtanner/2013/07/08/how-the-p...
Edit: and of course, as kstrauser points out, voter registration records.
To divulge sensitive information like that is actively unsafe for certain types of people, because, as you note, almost every single vendor with whom you do business will blast it out all over the ecosystem until it shows up on SEO spam websites forever.
I've come across some folks pretty committed to staying "effectively off-grid" - even today.
Do you really think someone who is changing their BSSIDs when they move is putting the address at which they regularly sleep unguarded into public records?
Most of the Bluetooth devices that I am able to identify are things like televisions. When a Samsung TV moves, it's pretty likely that the people who own that TV have moved along with it.
So I'm told.
It would be actively dangerous for people like me if we were forced to regularly sleep in a location available to the general public.
Still, the distribution of these identifiers will vary by region, manufacturer and other factors. The best way to stay anonymous is to avoid using the wireless spectrum. You’ll never be in full control of your anonymity as long as anyone around you is broadcasting a unique identifier and your device is logging its observations of these identifiers, correlating them with GPS, and sending them to the cloud…
https://github.com/danielhoherd/homepass/blob/master/Raspber...
For example, suppose a device on your network is compromised: The attacker instantly get a freebie for a mailing-address they could use for identity-theft/impersonation, blackmail/extortion threats, or scams pretending to be an authority figure.
If you also have something like a home security system, they'll immediately know where to go if someone wants to burgle a room full of goodies (possibly visible via camera) as soon as the owner leaves.
The reverse direction is also an issue: Suppose someone already knows your street address, and is trying to figure out which wireless network to target in order to harass/hack/burgle you.
Even if these all seem unlikely, the information leak is all downside, no benefit.
(Your regions may vary!)
Emphasis on "try", provided the original network wasn't some kind of totally unsecured open one. (And nobody would do that nowadays, right?... Right?)
IANANetworkEngineer, but from what I can find about "Evil Twin" WiFi attacks, your device ought to remember and reuse the security info from the legitimate AP. Even if the hacker mimics the SSID and MAC, they probably won't have the other secrets needed to finish tricking your device into finalizing the connection.
> exposing your mac address
This can be avoided if your device is set to randomize its MAC on each connection to an SSID or that one in particular. However there are some networks where that is undesirable, like a home network that does some assigned IPs and port-forwarding across NAT, etc.
AFAIK only grapheneOS offers per-connection mac randomization. Windows comes close with "change daily". Regular Android has a developer setting that enables it for all networks, which causes issues like you mentioned.
This sums up the companies’ philosophies neatly.
It's the fact that Apple spews this huge amount of info that allowed this research to happen, after all.
That’s according to two researchers at the University of Maryland, who theorized they could use the verbosity of Apple’s API to map the movement of individual devices into and out of virtually any defined area of the world.
Apple isn't constantly computing your precise location. It's happening on device.
The fundamental problem is our devices are inadvertently broadcasting their own locations. Not that Apple is providing, in essence, a report on the public radio spectrum. (Do hidden SSIDs broadcast a BSSID?)
Of the entire world. Provided in a nice enough package that with a little patience researchers could collect the location 480 million devices.
> Do hidden SSIDs broadcast a BSSID?
They do something worse: they force devices that want to connect to them to broadcast the BSSID all the time, which allows passive listeners to track them (e.g.) across a shopping mall.
Public dbs: https://en.wikipedia.org/wiki/Wi-Fi_positioning_system#Publi...
This is ridiculous.
Some industry body like the IEEE Standards Committee should agree on a standard.
Knowing MS, they'll probably start recognizing _nomap sometime in late 2027.
> Apple’s API will return the geolocations of up to 400 hundred more BSSIDs that are nearby the one requested. It then uses approximately eight of those BSSIDs to work out the user’s location based on known landmarks.
> In essence, Google’s WPS computes the user’s location and shares it with the device. Apple’s WPS gives its devices a large enough amount of data about the location of known access points in the area that the devices can do that estimation on their own.
:)
Have never seen new computers out of the box that phone home more than Apple computers.
"Privacy is a fundamental human right" - Tim Cook, Apple CEO
"We don't collect a lot of your data and understand every detail about your life. That's just not the business that we are in," says Apple CEO Tim Cook, shown here at the NPR offices in Washington, D.C., on Thursday."
https://www.npr.org/sections/alltechconsidered/2015/10/01/44...
Imagine if in order to enjoy a fundamental human right one had to "opt-in".
To enjoy the right to life, append "_keepalive" to your name.
To enjoy the right to be free, not a slave, add "_master"
To enjoy the right to avoid torture, add "_notorture"
Apple marketing works. Reality distortion field.
Whatever business Apple is in, it collects a motherlode of data.
This is Apple and Google’s vulnerabilities.