See https://inria.hal.science/hal-02394629v1 for the theoretical bases then hop to https://samteplov.com/uploads/shmoocon20/slides.pdf for an example applying to Apple devices
Those who said the randomization and other techniques were sufficient were wrong: https://petsymposium.org/popets/2020/popets-2020-0003.pdf will show you how they changed their mind :)
It's not just apple: google nearby has also been reversed: https://publications.cispa.saarland/2748/ and https://www.ndss-symposium.org/wp-content/uploads/2019/02/nd... talks about attacks, but there's no need for that: just find identifiers that let you link the addresses
Even if you don't have any identifiers, the Bluetooth address randomization happens only about every 15 minutes: the manufacturer specific data in the public advertisement (or even the frequency and the length of these advertisements) during these 15 minutes periods can be used for linking the randomized addresses
In other words, you could possibly track a given device through an area with enough sensors, e.g. a store, but not across visits.
The "randomization" seems to be a pseudo-randomization: with the seed and the timestamp, you should be able to deduce the future "randomized" addresses.
Ex: blocking 3rd party cookies always now. Breaks countless websites which I need to work reliably. “Manage unused website/app’s permissions” even after I specifically granted them! Randomized virtual credit card numbers in Wallet: for no good reason, you thoroughly fucked up a refund attempt for me, >$500! And randomized MAC addresses by default for EVERY. SINGLE. SSID. It’s unhinged. It’s fake protection.
As a matter of fact, I do not enjoy my devices lying to my ISP, or to my college campus, my medical clinic, or to my employers. Device, please identify yourself without wearing a fuckin’ Groucho mask on top, and put on your big boy pants.
Google calls it “my privacy” but it’s not their business model to keep my stuff private to me but to Google and their partners.
Google is trying to keep their own secrets like what their hardware MAC address really is, (because Google themselves are tracking everyone’s radio-enabled devices in every public space with far more sophisticated methods)
or hide/virtualize my credit card details, and protecting the card from crackers who wear hoodies, build EBM playlists, and use Firefox? that is a side-effect at best, especially considering how they are already a crazy non-bank middleman 3rd party with a miasma of shifting TOS and hundreds of advertising partners salivating to know what you paid for 3 milliseconds ago. Sheesh.