CSEC used airport Wi-Fi to track Canadian travellers
cbc.ca
cbc.ca
You don't even have to connect to an open WiFi AP, or any AP. As Glenn Wilkinson demonstrated some time ago [1], the probe requests your device sends out can in many cases, identify you or at least the important locations you've been to. Basically, if WiFi is enabled on your device and it's not associated with an AP, it's constantly sending out requests asking for the [E]SSID of AP's it's previously connected to.
I also recommend this video: http://www.youtube.com/watch?v=03iEaKPRb9A
Yes, we shouldn't stop at being surprised. We should put our actions where our surprise/shock is and do something about it.
For example: leave your mobile phone permanently in flight mode and just all the other features, like agenda, clock, etc (or leave it always at home, if you don't have a landline anymore).
A more interesting idea would be to create an app that sends out random probe requests with a randomized MAC address. (While not sending out any real probe requests) I wonder if that would be effective at disrupting these sorts of surveillance techniques.
1. https://play.google.com/store/apps/details?id=net.kismetwire...
It's to really hard for me to take this article seriously without the release of said PowerPoint documents. All we have to go on, is that CSEC had access to device IDs and was capable of tracking their locations across airports. And while it's true that metadata can be used to create a graph and hence a wealth of information, ISPs generally are suppose to collect that info. The question is whether the contents of the messages were intercepted.
Even then, this article seems to provide a lot of reactions from professors and commissioners without really getting into the details. It's really not that difficult for anyone, yet alone the government, to track MAC addresses on Wifi networks and then start geolocating them.
Take for instance this GitHub project: https://github.com/DanMcInerney/wifijammer
You could easily jam Wi-Fi signals or even collect MAC addresses. Collect enough of them from different places, and you can locate people's travelling habits.
edit: I guess it all boils down to the extent of the use-cases, which tends to be anybody's guess.
"The document shows the federal intelligence agency was then able to track the travellers for a week or more as they — and their wireless devices — showed up in other Wi-Fi "hot spots" in cities across Canada and even at U.S. airports.
That included people visiting other airports, hotels, coffee shops and restaurants, libraries, ground transportation hubs, and any number of places among the literally thousands with public wireless internet access.
The document shows CSEC had so much data it could even track the travellers back in time through the days leading up to their arrival at the airport, these experts say."
This is commonly used to track carts in hospitals, etc.
You technically don't even have to be "actively tracking" users. You just keep the diagnostic logs of client registrations & signal strength for a while and map it when you care. I'd be more worried about a non-government entity using the data to survey people for blackmail or other gain (e.g. politicians: who is commonly located near the state capital, campaign headquarters, and strip club?)