Google’s Wi-Fi Sniffing Might Break Wiretap Law, Appeals Court Rules
wired.com
wired.com
There is a distinction to be made here, but I'm worried about that particular one. It seems like it would be better to make it on something like accessing the data not meant for you and storing it/processing it (something closer to many privacy laws). Criminalizing the access of open wifi seems like it will quickly become problematic, and I'm sure some enterprising DAs will find it the perfect tool for some case they're having trouble making stick.
That said, this is just denying a dismissal, so we could get more nuance if this goes to trial.
It seems to me that collection of the packets is the crux of the issue.
The discussion here should be fun one way or the other.
Certainly it would be weird if a computer activity that were legal if done by a person suddenly becomes illegal if done by a company that brings on one more new hire, make one more dollar of revenue, etc.
But at the same time we do have those kind of different requirements elsewhere in law for "real life" things since the scale is way different, so it's not as if there would be no precedent.
I personally don't think sniffing packets on an open WiFi network should necessarily break wiretapping laws. Or at least not the same laws. Bugging someone's phone just feels like a more serious crime to me than packet sniffing an unprotected network.
I append _nomap to my SSID name in hopes that they wont collect the data they are scanning when they drive by. The word collect has different meanings these days so they may be storing the info but not look at it...
If you have SSID broadcasting enabled, it's public, and it helps other people detect your network, including those outside your home, easily.
I don't see how knowing your SSID/location is any worse than geo-IP, either way, your location can be identified a good majority of the time.
The real purpose of this system is to enable location API on the client without waiting for satellites. It's only going to get worse with BlueTooth LE beacons, which will soon be showing up everywhere and pinning your location down to the nearest meter indoors.
Why would Google intentionally save random stray packets of unencrypted wifi networks? What purpose would that serve?
This BBC report has a good summary: http://www.bbc.co.uk/news/technology-23002166
To my mind, this whole episode suggests Google has a rather lax attitude to privacy despite their official statements.
I'm not sure it's fair to expect privacy for your unencrypted data that's being broadcast on any unencrypted network. To me, that feels like reading someone else's postcard. It's not a cool thing to do, but is it really like wiretapping?
I agree that their response to this news does not inspire, but I wonder if that was an attempt to minimize what had the potential to be really bad PR.
Just to recall some facts about Google's wi-fi exploit : various regulators around the world have mostly agreed with Google's assertion that it did not deliberately plan to collect wi-fi data. Yet this incident also suggests a lax internal culture towards gathering data. This incident occurred without consequence for Google until it was discovered by external investigators.
The US Federal Communications Commission (FCC), when they were investigating Google over this matter, said that Google had "deliberately impeded and delayed" the investigation for months.
Earlier this year, Google were given 35 days to delete wi-fi data by the UK Information Commissioner's Office. Google had earlier pledged to destroy additional discs containing private data but had failed to do so. Does this sound like a company where privacy and data collection are treated with high importance?
Let's not forget that Google collects a phenomenal amount of tracking data. Sure, they take security seriously, but do they take privacy seriously?
The facts above are taken from the following BBC report: http://www.bbc.co.uk/news/technology-23002166
http://www.wired.com/dangerroom/2010/07/exclusive-google-cia...