Now that you have your fingerprint, you can leave a few scanners around where you're trying to track the congressmen. IE, if you want to blackmail, put it around strip clubs.
Seems like a major security hole to me.
Due to the extremely narrow circumstances [1] under which the MAC address randomization is actually used, the feature may as well not exist.
At least for Android, someone else agrees: http://code.google.com/p/android/issues/detail?id=65890
Not only is a "hidden" AP not really hidden at all, it makes a lot of functionality much more difficult, such as channel choosing and reconnect.
If you use WPA2 PSK and choose a long, random password (you want enough entropy that brute forcing it is impossible - for example, 20 completely random and independent characters taken from a dictionary of 62 characters gives you ~105 bits of entropy, which should be enough, while 8 characters or a few dictionary words might not cut it) impersonating your phone is not feasible if your laptop is configured to only ever connect using the saved pre-shared key.
Exactly, even if it's not broadcasting network names, almost every student in the Netherlands will have the train's WiFi hotspot in their list of networks.
One thing I still want to check out is whether the laptop will connect to an open network with the same name as a known network that was password protected.
Keep in mind that your devices are also broadcasting a variety of globally unique identifiers everywhere you go.