Live data from Hacker News

How does Apple privately find offline devices?

blog.cryptographyengineering.com

121–130 of 184 posts

Re: How does Apple privately find offline devices?

#121
post #99
post #57

Earlier quoted context omitted.

I meant, don't turn your phone into a beacon. (as a setting is ok) The idea would be yes -- connect to bluetooth headphones or your car. Connect to wifi in your home. Allow NFC transactions on command. But no, don't promiscuously advertise your device. Don't look up every bluetooth beacon you encounter or crowdsource every wifi access point.

If your WiFi is on, it’s already doing this. It’s saying, here’s all the networks I’ve joined in the past. Are you one?

I thought it was:

- hidden ssid access point - your phone will broadcast unique data looking for it (initially the ap must listen and respond)

- regular named ssid access point - your phone can passively listen for the name and join if it is available. (initially the phone must listen and respond)

Re: How does Apple privately find offline devices?

#122

Total aside, but kinda relevant. I lost my phone like a dufus about a two weeks ago. Battery died and I had no idea where it was. When I pulled the my google location history, it was too coarse to tell me anything other than 'at your house'. However, I was able to pull the raw data from google and post process it by time stamp into a series of rasters that were fine enough for me to see that the phone was definitely…

This rules, thanks for sharing!

Re: How does Apple privately find offline devices?

#123

Earlier quoted context omitted.

Or they have decided that it's too creepy to use at all, so they don't use it for targeted advertising. Seriously, why does everyone assume that companies are evilly cackling in volcano lairs? They know that violating user trust is really expensive and a bad idea. By the way, I'm pretty sure I've seen that Google's advertising targeting is only allowed to use "neighborhood level" location, which is designed to be coa…

On the other hand, if the information is aggregated to a final answer, why is the data then kept? What if the _wrong people_ get ahold of the more sensitive information _because_ the data was kept beyond its useful life?

So that you can later change your aggregation method. Just run the raw data trough it again.

Re: How does Apple privately find offline devices?

#124

Earlier quoted context omitted.

Or they have decided that it's too creepy to use at all, so they don't use it for targeted advertising. Seriously, why does everyone assume that companies are evilly cackling in volcano lairs? They know that violating user trust is really expensive and a bad idea. By the way, I'm pretty sure I've seen that Google's advertising targeting is only allowed to use "neighborhood level" location, which is designed to be coa…

On the other hand, if the information is aggregated to a final answer, why is the data then kept? What if the _wrong people_ get ahold of the more sensitive information _because_ the data was kept beyond its useful life?

In their defense: it is perfectly fine with me to keep my location data, so I can download it later and do cool and/or useful things with it as long as

- it is opt in,

- it can be deleted by me

- is not given to anyone else

For all my trashing of Google lately (check my comment history) I actually expect and belive them to defend my raw data in a way that few others are able to. It all boils down to incentives:

- as long as they keep the data between them and me they can sell targeted ads again and again. If the data leaks then others can skip the middle man.

- as long as they keep their reputation as nice guys that is an immense advantage.

Now this might of course be changing, so everyone should consider if they personally trust this arrangement going for the future:

- it seems some part of the organization is tightening the screws around the Chrome team to squeeze out more revenue.

- of the data is available there is always the risk of attacks both cyber attacks as well as legal attacks.

Re: How does Apple privately find offline devices?

#125
post #75

Earlier quoted context omitted.

Or they do and have internally assessed that it would be too creepy to provide to users, but are happily using it to better target advertising.

Or they have decided that it's too creepy to use at all, so they don't use it for targeted advertising. Seriously, why does everyone assume that companies are evilly cackling in volcano lairs? They know that violating user trust is really expensive and a bad idea. By the way, I'm pretty sure I've seen that Google's advertising targeting is only allowed to use "neighborhood level" location, which is designed to be coa…

From my experience from within large companies will do everything within the boundaries [1] of law to make more money.

[1] sometimes outside if they think they can argue it to be a novel situation

Re: How does Apple privately find offline devices?

#126

Can the signal be jammed? Or simply put the stolen device in a metal box. As for the tracking: I really like the idea. However, in my country finding your device isn't the issue, it is getting it back that's the problem. Police won't go and enter the particular house were your device is.

I'm not sure how useful a device is that has to be kept in a metal box at all times.

My new startup: Faraday gloves

Re: How does Apple privately find offline devices?

#127

The problem I see with this is that your phone always has to be broadcasting the BLE beacon, regardless of if it is lost or not. Otherwise it could randomly end up lost in a place with poor/no service... and would never be found For phones, how often is this really an issue? Sure, this is useful for the Tile type "dumb" devices... but if my phone has no cell or data service... it's probably because the battery is dea…

> your phone always has to be broadcasting the BLE beacon, regardless of if it is lost or not

It could have an X-hour "deadman timer" after which if it still hasn't successfully phoned home and been told it's not lost, it starts pinging?

Re: How does Apple privately find offline devices?

#129
> generate the list of pseudonyms from a single short “seed” that both Timmy and Ruth will keep a copy of. This is nice because the data stored by each party will be very small. However, to find Timmy, Ruth must still send all of the pseudonyms — or her “seed” — up to Apple, who will have to search its database for each one.

I would imagine something along the lines of TOTP would provide a better mechanism here. There would be no need to scan a whole list of pseudonyms, and the BLE would rotate the identifier it transmits frequently. The lassie device can include GPS timestamps when it reports the device to apple.

Re: How does Apple privately find offline devices?

#130
post #101

Well...a bit off topic but kind of relevant. My car got broken into and my iPad nicked. I was able to locate that, however, the cops here in NZ were really unhelpful. They said the GPS location wouldn't be sufficient for a search warrant as they have had many cases of false positives. I said I would give the ssid and ip address of their wifi network, even then they wouldn't agree for a raid. It was only when the thie…

Legally could you go get it, and in the resulting skirmish perhaps attract the attention of the police? Is trespassing to retrieve stolen property still trespassing?

This reminds me of a (probably apocryphal) story a South African friend of mine told me once about the state of policing down there in the late nineties / early noughties.

The story goes that a man wakes up in the middle of the night to the sound of burglars looting his garage. Given the occurences of aggravated robberies in SA at the time, often involving guns, he didn't want to confront the miscreants himself, and so called his local police department.

Apparently since no actual violence had been done at this point, the police-person to whom he was speaking claimed that they had no free units to come and attend, and that they'd send a car round in the morning to collect evidence. At this point the call ended.

The man who was being burgled was understandably unimpressed with this, thought about what he could do, and then rang the police back.

"Don't worry about the burglars here. I shot them." he says.

Within minutes his house is surrounded by police cars, and the burglars are under arrest.

The commander of the responding officers says to the man "I thought you said you shot them?"

The man replies "I thought you said you had no units free?"

Post reply on HN