Hundreds of Devices Hidden Inside New York City Phone Booths
buzzfeed.com
buzzfeed.com
A beacon in a New York City phone booth ad would need to recognize a corresponding app to push beacon-linked content to that phone.
From what I can see from reading the article this isn't the scary "things that watch you without your knowledge" but more like "things you can connect to if you're nearby" - and given that there's WiFi hotspots and other things in this category too, it doesn't seem all that frightening. In other words you'd have to have allow your phone to connect to them for them to gather any info, and in that case it's not much worse than connecting to a WiFi hotspot setup for marketing purposes (e.g. http://www.washingtonpost.com/blogs/the-switch/wp/2013/10/19... ).
(The fact that the majority of people leave their phones in a "promiscuous" mode with all the radios enabled and constantly looking for things to connect to, and submissively install apps without reading their privacy policies/terms of use carefully, is a different although related issue - but this is something you can educate yourself and protect against.)
"In its current iteration, a Gimbal beacon requires a third-party app to trigger advertisements, and requires those apps to receive 'opt-in' permission from users in order to collect data and send notifications. (Users, of course, also need to have Bluetooth enabled.) ... Gimbal-powered apps may collect your current location, the time of day you passed the beacon, and details about your device."
If the beacons are doing anything more, it is not reported in this article.
One smells like conclusions are a bit premature, the other smells more like inevitability.
Not everyone really understands what's going on with their phones or real intent of others (i.e the stores who provide wifi) so I think it unfair to lay blame on consumers for being 'uneducated'. There is a lot more overlap between 'things that watch you' and 'things you can connect to' than people realise. I'm reminded of the London bin tracking of last summer [1].
[1] http://qz.com/112873/this-recycling-bin-is-following-you/
I'll be more interested in keeping an eye on the URL-centric 'physical Web" experimental project recently revealed by Google (https://github.com/google/physical-web) as that potentially removes the need for app-based mediation of beacon (without the "i" prefix) interactions, uses the universality of http and URLs for content identification, and could make for a much lower-friction way of implementing beacon integration across different platforms.
I like it - might have to try a RPi build for one
iBeacons are an interesting "first move" for the technology thanks to the weight Apple / iOS puts behind the potential for adoption, but the current model of interaction is just too convoluted / clumsy:
iBeacon broadcasts UUID/major/minor > subscribed app listens > app checks internal database or more probably fetches some data from a web-based API > decides what to do with that data / response.
vs
beacon broadcasts a URL > OS (or subscribed app) pulls data from URL > user (or app) decides what to do with that data / response
The abstraction provided by the iBeacon model is interesting but arguably too abstract, whereas the simple use of a URL is decidedly simple and logical by comparison, and (potentially) cuts out the app mediation.
If you combine the simplicity of using a URL with the idea that either the OS interacts with it directly or an app with a URL- or domain-specific mapped intent takes over that interaction then you get a simpler and more transparent journey as a result.
I think it's very early days for the Physical Web project, but it should definitely be one to watch!
There is obviously some potential for data snooping and privacy issues, but if the experiment becomes a full standard then it will likely be fleshed out much more to avoid this issue.
Pulling metadata from a publicly broadcast (and therefore inspectable) URL still feels more transparent than the iBeacons implementation, which mediates all beacon interactivity through the "black box" of an app with unknown configuration (with regard to exactly which beacons it listens for - it could be a single UUID, or it could be all beacons) which could be phoning home with all kinds of data without the user knowing.
What about these URLs recording client IP addresses and locations (based on the known beacon location)?
Is there no way to put everything in the beacon? Will users be prompted before their devices perform actions dictated by a third party? Will beacons be featured in future pwn2own contests?
If apps like that take advantage of beacons, do you still think this is FUD?
Also - what's wrong with Fear, Uncertainty and Doubt in general? It's not being used by one competitor here to knock down another one - so, I just don't see the problem with worrying about what will become of these beacons.
It would be much more powerful if tech journalists could actually convey in a "man on the street" friendly way what beacons actually do (i.e. basically sit there in a corner repeating their name over and over again) versus what apps could do and what kinds of data could be stealthily gathered as a result of beacon proximity (or lack thereof).
Also, I don't disagree that creating an infrastructure for the potential to gather data via a suitable app down the line without any real oversight is a bad thing.
According to the Gimbal website, "Gimbal proximity beacons communicate over Bluetooth Smart and are built and configured to Apple's iBeacon specifications..."
[1] http://www.bbc.co.uk/news/technology-23665490 [2] http://qz.com/112873/this-recycling-bin-is-following-you/
Or does London have widespread public wifi?
I know people that think that the phone they bought "has Internet" and they must pay a monthly fee for that. They don't ask themselves how that happens so I guess that some people never turn their WiFi off unless they must learn to maximize battery life.
I'm not going to turn off Wifi when I leave work and then turn it on again when I get home... I've never even heard of anyone doing that, it sounds pretty annoying to have to keep track of...
Personally, I think I'd rather just have it scan for access points. Apple's MAC randomization has the right idea (if perhaps an imperfect implementation)
Sometimes I feel that valid concerns on privacy are doing to IT what pollution did to chemistry: people got so panicked that blindly reject any valid contribution that technology might give.
It isn't Luddite paranoid, or cheap sensationalism to point this out; it's good journalism, coming from a surprising source (BuzzFeed, which for years seemed to have cheap sensationalism written into its very DNA).
I'm not sure I'm a fan of shadowbanning people either, except in really exceptional situations.
FFS, Buzzfeed. This is buried practically at the end, AFTER the giant infographic and 10+ grafs of scare text. It's like running the headline:
YOUR BREAKFAST MAY CONTAIN POISON
and then at the end of the article:
"Well, if you bought the cereal that said 'CONTAINS POISON' on the box and decided to eat it right now, that might be true."
That's just not correct. Bluetooth beacons can log and report information about devices that come within range of those beacons with active Bluetooth radios. Only interactive-time applications of a beacon need the cooperation of an app on a wide-area connected device.
Beacons that don't have external power generally can't use WiFi or mobile networks to do it, but this information can be uploaded on demand. For example, this information could be collected when coins from pay phones are collected.
Moreover, these beacons are reportedly installed in pay phone kiosks that do have wired connectivity. It's possible, even likely, that they "phone home."
There will come a time and soon whereby people will not be able to do a thing without someone tracking it.
Even the city knows when I take a crap thanks to "smart meters".
I'm waiting for someone to figure out how to force all those various beacons to talk the same language. Right now, everyone is trying to lock users in to a particular brand. It's incredibly annoying (and the same thing goes for the entire IoT and home automation market).
And they're being removed: http://www.buzzfeed.com/josephbernstein/new-york-city-to-adv...
There are a lot of phone stalls still around though - a number of which have been sites for experimental improvements for some time now, including a Google initiative to outfit some with public wifi: http://www.nyc.gov/html/doitt/html/business/future-of-public...