Density.io
density.io
density.io
In the UK, City of London already banned the wifi-enabled bins that were tracking MAC addresses.
It would be really easy to tie a name to MAC address (from point of purchase with a credit card), then see exactly where that person went via the 'sharing' of data with other retailers. This is certainly something you would expect to need 'opt in' to.
[source: I was doing other work for the bin company (renew) and saw the whole car crash from the inside]
That said. CCTV does not appear to be going anywhere, and there is very little difference between processing video footage to track people and tracking a MAC address. The only difference in this particular case is that 'sharing' of the data between retailers is touted as a feature (which of course it is).
http://www.cbc.ca/news/politics/csec-used-airport-wi-fi-to-t...
They used the wifi purchase at the airport to ID the user. They are likely already vacuuming up MAC addresses everywhere they can.
No, you shouldn't have to turn off a very commonly used service so that people can do better business by tracking it in an intrusive manner. Privacy should be the default option in such programs.
If the city used a ton of cameras + facial recognition to track you and your car everywhere and then sold that data to companies so they could optimize for whatever meaningless metric, would you still be as casual about this, and go "Oh, you should just cover your face and walk everywhere if you expect privacy."?
This over sharing should be addressed at protocol level.
Maybe, maybe not, but if you care about your privacy you shouldn't assume everyone will follow the rules. Opt-in would be tough too--they need to know who you are before knowing if you have opted in.
What privacy is that? Your device is broadcasting information, in the clear, to anyone who cares to receive that information. You've taken no steps to prevent anyone from receiving that information.
Your device is doing the equivalent of standing on the street corner and screaming various things. You can't rightly tell someone not to listen or write down what's being said.
I don't see how this is any more invasive than CCTV cameras that every business already has anyways.
Except there's one huge difference: anyone with eyes and ears can understand what the person is screaming. I would wager that even fewer than half of HN readers realize what's being broadcasted here.
What you're saying is that every human must have complete technological and implementation knowledge of any possible invention or they are not deserving of privacy. That position is not only elitist as a technophile, it's arrogant to think that any one person could possess that knowledge, let alone billions. At some point, you'll be the clueless one.
The idea that MACs should be somehow private because someone found a novel use for them doesn't even pass the laugh test. IP addresses are not "private". Your face out in a public area is not "private". Why is this different? How is this somehow worse than the CCTV cameras in most public places anyways? How is a MAC address PII by any stretch of the word?
I'm starting to really think "privacy" has joined the heap along with "patriotism", "socialism", and "terrorist", words which are being abused so badly they've lost all meaning and and as a result mean whatever their speaker wishes them to.
>That position is not only elitist as a technophile
One shouldn't hold strong opinions about things they don't understand even on a remedial level. This hand wringing is pure and simple fear mongering.
I think you might be misunderstanding the part of this I have a problem with, or perhaps my language wasn't explanatory enough. I have a problem with the company linking back this info to a specific person, not the information itself.
MACs shouldn't be "somehow" private. MACs are not private. But when you use them to tie back to a specific person who is in your shop (with the credit card purchase info), you are essentially tracking a person. I think this activity should be regulated and should be an opt-in thing for users. (Enforcing this regulation could be admittedly a challenge, but it will at least be a step in the direction of strongly discouraging businesses to implement such 'features'.)
Similarly, your face out in a public place is not private. But if I have a startup that sets up CCTVs in participating businesses' premises and then track the movement of specific customers from shop to shop and generate data like "Okay -- the same face that was tracked shopping at Nordstrom then went on to have lunch at the Whole Foods next door; and from the credit card that was used, we can see that it was Mr. Karunamon", it's going to run up against major privacy concerns. I think this is very similar, but not that controversial because it is not so visible.
I think any possible regulatory hurdles that could be imagined will make life for anyone who does anything neat with wifi or some other combination of information miserable. The credit card thing makes me wonder.. like what exactly are they grabbing? Just the fact that a card swipe was recorded at the same time that X wifi radio was in front of the register?
Somehow I'm still not bothered by this. As long as there's no "hidden" information being exposed (say, my CC#), my response is a big fat "meh". Combining different kinds of public information (as in, things that any person could just walk by and see) doesn't somehow combine to become private information.
I mean, let's see what pieces of data we're dealing with here:
* Entry to the store. Public. Via CCTV, door sensor, etc.
* Items selected. Public-ish. (Recorded after checkout, some stores use RFID tagging)
* Location in the store. Public. (Anyone can see.)
* Time card was swiped. Public. (Anyone in line can see)
* Basic WiFi information (Mac address, SSID, etc). Public. (Anyone with a smartphone can see.)
Given the fact that all of these pieces of information are freely available, I find it impossible to call for someone's head or feel even vagely "creeped out" by simply combining that info.Put yet another way, the information's always been there in the open, but now that someone decides to collect it, there's a problem??
The goal is not individual (person) tracking. The goal is identifying and operationalizing trends at an location-specific and network level.
We encourage users worried about privacy to opt out. But realistically, they're not individuals to the system. They're part of a trend.
As long as we get a statistically relevant percentage of movement (15-20%) we believe we can still be useful to the business. Worst case: a lot of people opt out, we drop from our current 60-70% capture to 20-30% capture and we simply extrapolate the remainder.
It's an inexact science but, we believe, very useful.
Best of luck!
Or they could use software produced by people with that knowledge and who had users' interests in mind, which would automate the appropriate way to handle these concerns. And if they're unable to judge softwares' merits, they should rely on the opinion of more knowledgeable friends.
In this case, the device could easily generate a new MAC for every connection attempt, and give you an option to make that identifier more persistent per-network.
But instead people listen to the TV (et al) as it tells them to keep buying new closed Androids and iDevices, and then act incredulous (or Stockholm syndromed) when for-profit companies end up betraying them.
The point is, this is trivially defeated without turning wifi off.
What makes WiFi (currently) more relevant is more people leave it on. Likely to even out over time as more bluetooth devices are made commonplace.
I thought it would be important to let others know that "just turning wifi off" would not be an effective measure against a system that uses bluetooth.
Source: http://translate.google.com/translate?sl=nl&tl=en&js=n&prev=...
How would you do it?
It's the systems-integration part, moving the data from the card swipe onto the right computer, that's actually hard. You might be able to partner with your payment processor to get at that stuff.
In version 3.0 we will be seeing the ability to identify shoppers who are on a shopping spree by ringing a beep as they enter the store. Sad.
They say they are hashing the MAC address (presumably on the device). However, they can't be salting the hash (else they wouldn't be able to match across different stores).
Since there is no salt (or a fixed salt), it is trivial to de-anonymise a specific MAC address (just hash it and see if any server has it).
Worse, there are only 46 bits that are variable in a MAC address, and there is structure in there (3 bytes manufacturer, 3 bytes serial), so a complete mapping from MACs to the hashed MAC is very doable.
A secret per-device key for a HMAC would preserve privacy much better, but would stop them doing the cool stuff they plan — the usual trade off.
In case it is, a HMAC (which a salted hash effectively is, except keys are secret) helps in the case of them losing the database, but not if they also lose the key, and the NSA will get access to the key as well as the database, so it won't help there.
Perhaps wifi devices should no longer provide constant MAC addresses....
But would that even be the end of it? With Wifi off the phone is still broadcasting on cellular channels. Could a device be built that listened to those signals and uniquely identify them?
There are several applications for OSX and various *nix distros that run at boot and randomize MACs. SpoofMac is probably the most well known: https://github.com/feross/SpoofMAC
I'd just like a background service for my Android device that would also randomize my MAC address... (perhaps it's time to investigate android development :P)
Unfortunately (from the apps that I've seen) it looks like only a rooted Android could support it.
First: You do not want a MAC collision. I have worked with hardware that sometimes picked a non-unique MAC and your life gets really weird and sucks away a lot of debugging time to find out why impossible things are happening.
Continuing – It made ethernet easy to implement. They could have added some complicated address negotiation protocol and then handled address collisions when partitioned networks healed, but it was "olden times" and something that complicated would not have gained traction.
Fast forward to Wi-Fi. The reason you have Wi-Fi instead of any number of other wireless ideas that died is because it looks like ethernet so people didn't have to think much about it, so you inherit that baggage.
If you really want to change your MAC address then you will want to make sure you aren't going to collide with anyone else. The odds are tiny, but it would be rude to ruin their day. Fortunately, there is a locally administered range of MAC addresses. If your first octet's last digit is 2, 6, a, or e then you are a locally administered unicast address. Assuming your network segment doesn't have an administrator actively handing out local addresses, drop 56 random bits in the remaining octets, cross your fingers, and bring up your network stacks.
I can confirm. Working with a bunch of Chinese hardware with non-unique MAC addresses is painful. It was easier to buy new NICs with real serial numbers than to work out how to fix them.
In fact, in order to make Density to GA comparison fair former needs to report all its tracking activity to a single source. Then they will be the same both in intent and implementation. Except, of course, for GA being free.
I asked original question assuming that you realize direct resemblance between Density and GA. But since you don't, I honestly don't understand how you cannot see it.
Those are very different things and they mean very different things in people's lives.
Also in terms of cost, there's a difference between tracking which imposes a marginal human cost of production versus tracking which can be fully automated by machine, even if there is still a per-machine cost.
A relevant example is the Supreme Court ruling on needing a warrant for using a GPS tracker on a car versus just tailing them.
I had seen news about this recently and am surprised that more people didn't notice how it is essentially the same, without funding, and less developed.
Also, people log in with Facebook to basically anything.
"it's free" and "get cool rebates" create such an incredible variant of SEP field[0].
Ofcourse I know that my smartphone broadcasts its mac/stored-essids every few seconds, thats why I have wifi disabled most of the time. Most people don't realize that, most people also don't realize the tracking capabilities of cookies. Laws in EU have begun to make it illegal to store cookies without the users consent, because even though its technically possible to block cookies, most people have no idea about that. So I can only hope that it will become one day illegal to violate peoples privacy like that!
https://meraki.cisco.com/blog/2013/12/get-a-visual-on-your-b...
So people are probably already being tracked... and no one has noticed.
Though in the UK I have unlimited 4G for £20 per month, so I just leave WiFi permanently disabled.
It's certainly more convenient, but also harder on the battery life as the phone continues to search for a signal.
I never ordered one as I missed the window of opportunity. But it was claimed by the creator and users that battery life was variable depending on the make and model of your phone, and whether you had lots of background apps attempting to do things.
The claim was that in some combinations you get better battery life by using Off Pocket, and with others you get worse.
Phones don't drain greatly when they don't have a signal. A day riding the tube system between meetings in London doesn't significantly affect my battery life, so I've no reason to believe that Off Pocket would've resulted in a different outcome.
The real issue with this is that most SMBs are unsophisticated when it comes to the technology stack they use. I saw this firsthand in many ways working at Swipely (swipely.com) as we figured out product market fit. While things like 'see where else your customers shop' might seem like an interesting feature from an outsiders perspective, the businesses don't actually care. They often barely have the bandwidth to worry about their own customers.
Also Cameras are fairly visible.
This tech is stealthy and most people won't have any idea that this is actually happening.
Agreed, this seems invasive and I dislike it.
(or some similar strategy if that still seems risky)
But then you have to start worrying about facial recognition.
Euclid Analytics keeps their customers secret, so if a store doesn't post notices, there's no way for us to know they're using the service. Will you be keeping your customers secret as well?
We're adding it to the site now.
People need to know about this and it should be an opt in!
This is why we can't have nice things.
Not only is it not new, its probably not going away.
As I understand it, the device is like a WiFi Router looking for nearby clients broadcasting their MAC. Since phones have the ability of turning themselves into WiFi Hotspots, could a phone/app offer this same capability, or is it missing a hardware piece that lives in Density/Pineapple?
If anyone knows or can say: What physical principle(s) is the sensor operating on? There doesn't seem to be much information on that (possibly deliberately).
We're working on more than just wifi as well.
I'd like to check if it's too crowded before I decide to go or not.
I guess for any kind of business with lines or waiting rooms, (banks, ATMS, restaurants) customers might appreciate a way to quickly gauge the crowd level before going.
But how does this device work exactly? Is every phone throwing around a mac address, even if it's not trying to connect to wifi?
For example I have my phone set to use 3G expect on my home network. Would I count?
What does that even mean? They're tracking not only the number of people in a location, but where they go ... then sharing that with their customers. From their own website:
Understand your business in the context of others:
1. Who you share customers with.
2. Where else your loyal customers love to go.
3. Where foot traffic in the city is trending.
How is that respecting my privacy?
"The real danger is the gradual erosion of individual
liberties through the automation, integration, and
interconnection of many small, separate record-keeping
systems, each of which alone may seem innocuous, even
benevolent, and wholly justifiable."
— Personal Privacy in an Information Society
U.S. Privacy Protection Study Commission, 1977
http://epic.org/privacy/ppsc1977report/--
In your system, I'm just an anonymous flow of movements. In the shops billing system, I'm just a CC number and a set of purchases. For the billing provider, I'm just a name and address tied to a CC number. And then with a couple of small leaps, suddenly my whole life is compiled on a single page detailing every breath I take.
So tell me again how I can't use this information to identify who a specific individual is.
http://www.wired.com/threatlevel/2013/03/anonymous-phone-loc...
"You tell me whar a man gits his corn pone, en I'll tell you what his 'pinions is." [1]
[1] http://paulgraham.com/cornpone.htmlProblem is, this is a really effective and totally passive system with great benefits. But privacy-wise, it's scary.
I want a phone that randomizes the MAC every time it connects to an AP.
If they provided incentives to install an app/visit a website to register for rewards or be entered into a prize in return for allowing density.io to track you that would be acceptable.
Or for that matter could it somehow look at cell signals?
The amount of privacy we think we have must be a small fraction of what we actually have.
Also it could be rather easily tricked by competitors, by constantly switching the MAC address.
'Click here to transmit 802.11* broadcasts with randomized MAC'