"Motion is detected based on the amount of signal disruption taking place between the Xfinity Gateway and your selected WiFi-connected devices, so motion from small pets (around 40 pounds or less) can be filtered out while keeping you notified of large movements more likely to be caused by humans."
This means, respectively: ensure personal info is stored securely so hackers can recover little. Don't transmit info to remote servers to limit what advertisers get. And just store as little as possible in the first place because this is the legal means to have little to subpoena or discover.
Useful info, when absolutely necessary, should be locked behind a password, as constitutional rights preclude law enforcement from making someone disclose it.
The irony is that all of these metadata leaks and correlation attacks etc were theoretical at the time these technologies were created and developed, unless you’re NSA level compute power, both human and silicon. Now, any script kid has enough info to try to build an array of SDRs to do the same thing, and no one will care when they do besides the feds who cry foul about their turf being stepped on by plebeians. The public will never care because their eyes will already have glazed over once you mention MAC addresses and SSIDs.
It doesn't particularly matter what hobbyists get up to. It matters what's available at scale on the mass market, what's widely deployed, what data is legally permissible to collect on a large scale, and what data is legal to sell.
Law enforcement can't subpoena that which does not exist. The best defense to these sorts of things is often to place legal limits on collection, retention, and sale.
Your take is both alarmist and defeatist.
Legal limits on national security agencies are not enforceable due to Five Eyes etc. Allied foreign spies do what American spies don’t. I’m just admitting the political reality of the situation. What you do with that information may be limited, but it’s not a failing on my part that this is the status quo.
You're not talking about what they're talking about. They're talking about limiting corporate data collection. If companies don't build this into routers, then 99% of routers won't be collecting this data, and foreign spies won't have any data to steal.
Laws are powerful enough to stop that.
> wiretaps
I said 99%, not 100%.
> any third party in range of the WiFi network can likely do the same thing passively
But they won't do it in bulk without a lot of motivation (like profit).
I guess if you’re truly concerned you shouldn’t have WiFi at home or a mobile phone. Too bad 5G signals have similar capabilities, but at least the signals don’t propagate as well.
That ... might or might not be an issue, but it's not _this_ issue, ie the one we were originally talking about here.
A targeted order to wiretap (or otherwise spy on) a specific person or entity is entirely different from widespread data collection, retention, and sale for whatever corporate purpose. With widespread collection the data is then sitting there in a data lake waiting to be subpoenaed by law enforcement at their leisure for any arbitrary reason they happen to think up potentially years in the future.
> they are going to be legally compelled to do them, so the network structure’s form follows that function
You can't be compelled to hand over that which you do not have. Neither can you be compelled to modify your product in a particular manner absent market wide legislation; see FBI v Apple if you doubt that.
I do see what you mean, but they are differences of degree, not kind. It could be considered a best practice to minimize PII etc, but even other groups don’t do any better. Signal still uses phone numbers.
> > they are going to be legally compelled to do them, so the network structure’s form follows that function
> You can't be compelled to hand over that which you do not have. Neither can you be compelled to modify your product in a particular manner absent market wide legislation; see FBI v Apple if you doubt that.
I agree. However, Apple is also confident enough in their legal team, reasoning, funding, and likely legal outcomes that they will flout NSLs in America, and yet they will cave to UK in that they disabled Apple’s Advanced Data Protection (in UK) which means that iCloud files aren’t really E2EE if the government can just say that you can’t do that anymore. Not your keys, not your files and the security and privacy of said effects thereof.
It’s almost a legal impossibility and would be a bad move geopolitically to give up this full take capability and it is not happening. It’s wishful thinking to believe otherwise.
Is that not literally the entire purpose of the legal system?
> will likely not do anything that isn’t implemented by standards bodies, such as WiFi standards
I imagine beamforming techniques are only going to become more commonplace over time.
> Once Comcast has the data, it is available to law enforcement via the Third Party Doctrine
Unless they were legally obligated to purge it from their servers after a few weeks. Or if they employed E2EE so as not to have access to the data in the first place.
> Is that not literally the entire purpose of the legal system?
The legal system is subverted by the national security apparatus by necessity and by design. The information gathered by ISPs is necessary to prevent interference with ground-based radars around airports, and is necessary for fraud detection and internal security of the network. It would be feasible to make it so that this information would be gathered and retained only for a short period of time to establish and maintain network integrity, such as handshakes and other bits and bytes exchanged and retained inherent to the protocols used. The legal doctrines that establish the legality of full take surveillance have been argued before FISA courts, so an act of Congress or a test case would likely be necessary to prompt any legal reexamination of the relevant issues. However, national security issues are not really able to be resolved legislatively, because executive orders will always enable that which cannot be done on the books, which presupposes that which is done is done by the book to begin with.
What is done in the shadows must stay obscured due to means and methods, and this ideology isn’t amenable to change, political or otherwise. There is not much else to say on that point as it is observational and experiential based on my lived experience and history of interactions with law enforcement, national security professionals, and private security as a service provider and former licensed security guard, as well as being a victim of police overreach and charge stacking. I’ve worked with law enforcement and been work for law enforcement. I’ve fought the law to a draw, and I’ve fought the law and lost due to bad calls by refs. I’m working on becoming a better citizen and community member so that I can be a helper. More than that, I can’t say. The future is hopeful and yet the challenges are real, and changing. Old guards are giving way to young Turks. It’s an interesting time to be alive.
> > will likely not do anything that isn’t implemented by standards bodies, such as WiFi standards
> I imagine beamforming techniques are only going to become more commonplace over time.
The beamforming and other technologies used with modern WiFi are what enable the motion detection “for free” because the WiFi signals act as radar signals, the contours of the perturbations of which are already baked into the WiFi protocol. It’s insecure by design against this side channel attack.
> > Once Comcast has the data, it is available to law enforcement via the Third Party Doctrine
> Unless they were legally obligated to purge it from their servers after a few weeks. Or if they employed E2EE so as not to have access to the data in the first place.
You would have to reimplement the standards to make everything that squawks rotate their identifiers regularly, ideally after every transmission. It’s possible I suppose. I don’t think the political will is there to mandate this, and there are not that many people who work on these kinds of problems. Look at who created TOR. You’d have to run that kind of system everywhere, and only use it for everything, and that system would have to be part of the protocol or otherwise unable to be disabled by end users. Otherwise, you’re at the status quo we have now, where the weak links are the first to break.
If this sounds like a stretch, the weak links are always people, not protocols or pipes. That’s why this is magical thinking. As principled as you and I are, bad guys don’t have principles. Those who fight bad guys have principles, and they also have more coffee and mathematicians and hashrate.
Congress will never rule against the national security apparatus because there is no political will to do so. I can count on one hand the folks in Congress who are on relevant committees to even consider legislation on these matters who is in any way critical at all, and they largely agree with you that something needs to be done. But they don’t have the votes to do anything because the issues aren’t relevant to voters. No one cares the way you or I do, or they would probably become lawyers or politicians, as well as soldiers and broadcasters.
If you think something constructive and positive needs to be done, I would likely agree that the impetus for change exists. I’m all ears.