It looks like this feature was removed eventually, but it's just one of those tasteless things that MS does every once in a while.
It looks like this feature was removed eventually, but it's just one of those tasteless things that MS does every once in a while.
> (So if you want to opt out of Google Maps and Wi-Fi Sense at the same time, you must change your SSID of, say, myhouse to myhouse_optout_nomap. Technology is great.)
I knew about the Google Maps thing, I didn't know about this. That kind of stuff is so presumptuous and user hostile it's outrageous.
The system has to be resistant against bad actors taking someone else off the map who chooses to opt in.
It would be better if the syntax were simpler, like changing myhouse to __myhouse (double underscore == private identifier).
By setting SSID a certain way, you simultaneously show your intent to opt out and prove that you're the operator.
* I'm using GPS here as shorthand for all GNSS systems (including GLONASS and Galileo).
We used to joke about making a digital sign above our office door saying "Welcome to ___" which would use the location returned by the Google AGPS service.
Maybe this has been useful when introduced, but I'm not convinced it still is the case.
People HATE HATE HATE and complain loudly at their phones if they fall back to pure A-GNSS positioning.
The "_optout_nomap" postfix atleast gives a veneer of privacy that your SSID doesn't need to be sent by every nearby device to a backend service to see if it's in the opt-out database and logged/read by some government backfeed etc.
Why not the same thing, but opt-in rather than opt-out?
I’m happy for how easy it is to do this.
Iirc the same optout method is used opting out of WiFi scanning.
Blanket behavior like this should always be opt in with explicit informed and uncoerced consent. A laughable proposition in this corporate world but a worthy aim nonetheless.
Unfortunately nothing opt in ever gets wide adoption. So I expect to keep seeing these sort of infernal acts as people get bright but misguided ideas that require broad adoption to work. for example googles wifi cataloging does not work at all if to get cataloged you have to put "_cataloged" in your ssid.
Sharing your host's WiFi password with all your contacts should never get a wide adoption. It should never be an option anyway.
It shows Microsoft's astonishing ignorance of security.
If you have a contact, they are in their settings, and they're nearby and they can see your wifi network, a prompt will appear on your phone which asks if you would like to share wifi credentials with them.
There's some foolery going on to stop it popping up if you're using the device normally, like you have to be in settings or the home screen - or recently unlock your phone or something... But it's very explicitly: opt-in.
It's not opt-in for the owner of the network, who should really have a say in the matter.
I do use this feature from time to time, but it's typically on networks where either I'm the owner, or the owner's given me permission to share the creds.
This also opens up an attack surface (which I got to experience firsthand on a burner device at DEF CON 31), where someone spoofs an Apple device requesting network creds. The attack itself involves spamming share requests and catching you off guard, causing you to hit OK, or you just hit OK out of notification fatigue.
Why? It’s literally just a shortcut for asking for the password from someone who already has it and then having it read it out loud or texted. If the owner of the network doesn’t want that happening they need to explain that in either case.
It doesn’t, they have exactly as much agency as they would if the shortcut didn’t exist.
> As the person running the network, should you not have some degree of control over who gets to join your network, be it fully open, fully closed, or anywhere in between?
If you want more control than a shareable password provides, it’s on you to implement something other than a shareable password. A feature that merely helps people share passwords doesn’t change that.
How does this work? Isn't there any verification done through iCloud or something? I don't expect my phone to know about all my contacts' iphone identifiers.
I just tried this the other day with my cousin's wife whose phone number I don't have stored in my contacts and it didn't offer to share the wifi password until we both added each other's number.
Computers were opt in.
Too fucking bad for them. This opt-out bullshit for everything like this, marketing emails, etc. is bullshit. I’m sick of it.
The proper way would be to design the protocol so that the identification information is useless in addition to disabling SSID broadcast.
That would of course mean that joining a device to network would be way harder unless you enabled at least network name broadcasting, which enables tracking again.
[1] under polish law, majority [2] of uses of received broadcast/shared public medium signal, is automatically legal. The only provision of privacy is encryption of said signal, because it's treated like shouting the information in public space.
Bypassing encryption is what turns it into unlawful violation of privacy.
[2] for historical reasons there's a mess involving radio&TV tax which was supposed to be paid per receiver, a bit like UK TV license.
I usually try to use this feature when traveling: either I or my wife will add the new Wi-Fi and share with the other. It works roughly 3/4 times, but the remaining 1/4 is infuriating because there’s no button to manually start the sharing and no info about why it doesn’t work.
I would prefer a reliable button to AirDrop the Wi-Fi credentials instead of unreliable magic.
In the iOS way, your guest can share the creds privately to another person.
In the normal way, your guest can share the creds verbally to another person, which might be overheard by other unintended listeners.
I guess the ideal would be to allow the network owner (which would be determined by what method?) to share to guests with a flag set for no further sharing (and no viewing of credentials).
Or banish machines running Microsoft software from the network.
I like this term, hopefully it enters dictionary. Stupidity doesn't buy yachts, vile malice does.
Anti-market behavior is today completely normalized, so Gates is very much not alone. Malice is not an unusual phenomenon.
If the former, you'll need to present an argument that Microsoft did not hold back the entire industry for 20 years with low quality products, severe user-hostility, and monopolistic practices.
If the latter, you should read up about the 1980s and 1990s and early 2000s.
OP didn't mistake anything, this would be a public office clerk and they don't have private jets nor yachts.
Take that background, and how MAPI essentially prioritises internal email capabilities, and slowly a perfect storm for creation of such misfeatures emerges.
Internally to a corporation, in Outlook/MAPI/Exchange way richer world, implementing such a feature is both simple and possibly easy more useful (less annoying emails to write when you want to just give a short reaction).
But then you hit two confounding factors - systems outside of corporate Exchange server - so instead of using a richer messaging feature you make it into extra text message - and systemd outside the corporate, where your message now leaks out.
This way you can start with reasonably well thought out user story, and end with crap like the way reactions work - and weird extra headers
And they are everywhere.