Smartphone-monitoring bins in London track places of work, past behavior
arstechnica.com
arstechnica.com
I started writing a small proof-of-concept android app to randomise the WIFI MAC to make it more difficult to track a phone and its owner. The android API doesn't support changing the MAC, so it requires a rooted phone.
Mostly working code can be found at: https://github.com/d5ve/RandoMAC
It's made tricky by being unable to change the MAC whilst the WIFI is enabled, and re-enabling the WIFI resets the MAC back to the hardware one. Also by my total inexperience with android apps and java.
...admittedly I'm having a hard time seeing how this squares with EU data protection laws but I'm sure the UK will pursue an opt-out in the name of free markets. I'm not kidding, sadly.
Also, that video...WTF.
MAC address is stored apparently so device movement tracking past other bins & in and out of shops can happen. As suggested in the article some qualities of the owner of the device could be inferred.
Possibly irrelevant comment: I bought a pay as you go mobile broadband dongle in a UK computer shop recently as I wanted to access internet from a location with no wifi. Paid cash (as it happened, I tend to for smallish transactions) and topped the device up in a newsagents' shop with top-up card that came in the box, again cash. I didn't realise we could still do that. I've since topped up by cash machine so there is an audit trail now.
Expect this not to last long at all.
https://news.ycombinator.com/item?id=6194832 (wired.co.uk)
In addition, here are some other sources for the same story:
https://news.ycombinator.com/item?id=6181893 (qz.com)
https://news.ycombinator.com/item?id=6183485 (qz.com)
https://news.ycombinator.com/item?id=6184423 (theatlanticcities.com)
https://news.ycombinator.com/item?id=6187750 (vice.com)
"Terrorism, Tracking, Privacy And Human Interactions. Daniel Cuthbert and Glenn Wilkinson, SensePost at 4CON 2012 in London."
http://www.youtube.com/watch?v=Vsn7_4qUdwk
Found a short summary attempt here. http://www.securityg33k.com/blog/?p=629
What concerns me most is the prospect of governments doing this sort of snooping. It will probably begin with a justification that the data are valuable for managing traffic patterns and for urban planning (or other seemingly harmless purposes). But then ultimately it will be used by the government for other purposes.
It might actually be a good thing if in the short term a few companies abuse the technology to the point that the public wakes up to the amount of information broadcast by their wireless devices. Perhaps it will motivate the industry to add more security as a default setting (iCloud VPN anyone?).
Can't just the government ask very nicely to TelCos for this kind of data?
This is an industry-wide version of what Facebook has been excellent at doing alone.
- Could the spec be modified (or maybe it already has such a mechanism?) to allow APs to broadcast themselves every 1-2 seconds, and remove this device polling mechanism?
- Instead of device polling constantly, could devices simply sniff the entire flow for frames containing a src/dst MAC address of any known APs (i.e. APs the user has selected to auto-connect to)? And only perform the polling when the user is in the AP selection screen?
- Another 'hack': since we're mostly talking smartphones which all have GPS now, could devices be set to only poll for APs if they're in an area they know a recognized AP is in? Probably battery life concerns though.
This is a business doing this and it may not last long due to privacy laws, but I wouldn't be surprised if exceptions were make for the UK government to use these to track its citizens.