Live data from Hacker News

Google is mapping your wi-fi access point and the opt-out options stinks

tech.icrontic.com

41–50 of 51 posts

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#41
post #2

SSIDs are a signal you broadcast to identify yourself. if you don't want people receiving that signal, stop broadcasting it. if i stand on my roof and shout at the top of my lungs "HEY LOOK AT ME", i can't then expect people not to look at me. broadcasting your SSID is essentially the same thing, and you can't blame google for the fact that your router does this. pretty much any router will allow you to turn off SSID…

You don't have to broadcast an SSID (the human-readible name for the access point) for Google's system to pick it up. I'm pretty sure (based on some packet sniffing I've done on the Android Google Maps app suite) that Google's grabbing the BSSID, the MAC-address-like thing that uniquely identifies a Wifi wireless device. Even if you turn off SSID broadcast, your router will still send out broadcasts of some sort.

The arguments for and against could be evaluated better if someone can explain how one can misuse this service.

What ever it is that google is noting down about the broadcasting station and tagging it with its lat-long, if it also appears in some form in the packets that originate from a host behind this station, then some one can infer the geographic location of this traffic source. Is that the case here?

Unless that's the case, is there any other way someone can misuse this? The only other exploitation I see is tracking a router from it's point of sale to it's point of deployment and finding out the location of the buyer. Where else does the BSSID of the station appear other than within it's geographic neighborhood and the manufacturer's/retailer's database?

May be the database should not be indexed directly with this BSSID but a one-way hash of (BSSID, something-about-the-neighborhood) - to make sure no one can do an arbitrary lookup but will already need to be in the neighborhood of the station to make a successful query. At least it will raise the bar.

I in fact would like to use this in my app! Continuous location tracking using GPS drains out the battery so fast that it is not even an option for me. The significant location change accuracy is not good enough for what I'm doing. I'm trying to figure out how to use this service. Does any one know?

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#42
post #14

Earlier quoted context omitted.

You are absolutely right, an opt-in system would destroy the whole location-by-wifi-ssid service for everyone. ...but that doesn't create leverage or a good reason for having such a poor and inelegant opt-out. This is an "ends justifies the means" argument, which is in itself Machiavellian. From a different perspective, there are other ways Google could handle an opt-out list - such as letting people add their SSID/M…

I don't know why your comment is being down voted. It's perfectly okay for people on Hacker News to be expected to add "_nomap" to the SSID but for most people, they just won't even be aware that Google's collecting this data, let alone figure out how to opt-out. I love Google as a company but it seems that more and more of it seems to be getting shrouded behind lawyer speak. It makes me uncomfortable.

I don't know why your comment is being down voted.

Thank you, that's a kind comment. But this happens on almost every comment I leave: I get downvoted once or twice and then the comment slowly gets upvoted.

I think I have a troll (or even a script) that downvotes new comments I make to HN. Sad.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#43
Here's a little update: the majority of Dutch parliament rejects Google's proposal. http://translate.google.com/translate?sl=nl&tl=en&js...

Right or wrong, this tends to happen if you try to arrogantly dictate instead of negotiate. It turns public opinion against you and it pisses politicians off, even business-friendly conservatives.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#44
post #36

Earlier quoted context omitted.

Street View has been quite controversial in many European countries.

Business has been quite controversial in many European countries.

Business at the expense of civil rights has been quite controversial in many democratic nations. Shocking, really.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#45
post #38

To all the people saying "Don't broadcast it if you don't want it collected" or "what's the problem" - there are two problems here. i) Google has unfortunate previous form. They've collected information from unsecured wifi, including snippets of emails; lists of people suffering from certain medical conditions; passwords; etc. ( http://www.bbc.co.uk/news/technology-11797907 ) They've made a "mistake" once. People wan…

The collection of data was a result of Google storing the whole packet which was broadcast unencrypted for anyone to see. To me this is similar to not installing curtains in your house and then getting upset about people taking naked pictures of you. If privacy is important to then you have to take the first steps to protect it. It is unreasonable to put the burden of protecting your privacy entirely on everyone but you. If you don't bother to do something simple like encrypt your wifi I have to assume that means you don't care if it public. (I personally leave my wifi unencrypted for this exact reason.) As for cost and required knowledge installing curtains is probably trickier and more expensive then having the Geek Squad setup encrypted wifi.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#46

The person who wrote the article this link goes to doesn't seem to understand what Google's Wifi AP database is for. He seems to think it's going to be some searchable database instead of just used for device positioning. It would have been better to just post the link to the Google blog post instead of this misinformed blog.

To be useful for device positioning, doesnt it by definition, have to be searchable?

Not necessarily directly. It could work by saying "Here's a list of SSIDs I can see", to which the server responds "You're probably at [, , ...]".

Under such a system, you'd have to know the SSID ahead of time, which probably means you're in close proximity to it already.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#47
post #37

Coming up next: Hyper-local ad targeting that knows to-the-block your position. Current IP-address based targeting is not very accurate, but knowing where you are exactly by your router opens up another frontier of monetization potential.

Which...may not be a bad thing. If I'm gonna see ads, I'd rather see ads that are relevant to me. If I'm gonna sell ads, I'd rather sell them to people who are most likely to find them useful/actionable.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#48
post #45
post #38

To all the people saying "Don't broadcast it if you don't want it collected" or "what's the problem" - there are two problems here. i) Google has unfortunate previous form. They've collected information from unsecured wifi, including snippets of emails; lists of people suffering from certain medical conditions; passwords; etc. ( http://www.bbc.co.uk/news/technology-11797907 ) They've made a "mistake" once. People wan…

The collection of data was a result of Google storing the whole packet which was broadcast unencrypted for anyone to see. To me this is similar to not installing curtains in your house and then getting upset about people taking naked pictures of you. If privacy is important to then you have to take the first steps to protect it. It is unreasonable to put the burden of protecting your privacy entirely on everyone but…

People are stupid, but exploiting that stupidity is still evil. (I'm lousy at analogy, but here's an attempt: People dis-enrobing with no curtains are stupid, but it's the pervs who post pictures to the Internet; polite people glance and walk on.)

Even Google disagrees with you.

(http://www.guardian.co.uk/technology/2010/may/15/google-admi...)

> "As soon as we became aware of this problem, we grounded our Street View cars and segregated the data on our network, which we then disconnected to make it inaccessible. We want to delete this data as soon as possible, and are currently reaching out to regulators in the relevant countries about how to quickly dispose of it."

Accessing a person's unencrypted wifi without their permission is, in England, a criminal offence and that's been tested by the courts.

(http://news.bbc.co.uk/1/hi/technology/4721723.stm)

Having said all that, this German case says that people shouldn't be stupid and they are responsible for the security of their networks:

(http://www.bbc.co.uk/news/10116606)

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#49
post #44

Earlier quoted context omitted.

Business has been quite controversial in many European countries.

Business at the expense of civil rights has been quite controversial in many democratic nations. Shocking, really.

By civil rights you refer to the right to prohibit anyone from taking a single pictures of your house from public property? Personally, I'd rather have the right to not be interrupted by people asking for money during dinner.

Re: Google is mapping your wi-fi access point and the opt-out options stinks

#50
post #23
post #21

Earlier quoted context omitted.

> The amount of Mac addresses for each vendor is very limited. Blacklisting a few Mac addresses would therefore blacklist lots of routers. MAC addresses should be globally unique. If your hardware vendor is shipping lots of routers with a shared MAC, they've messed up really badly.

They should, but in practice it seems they aren't. In the past (working at an ISP) I've seen collisions on Ethernet hardware (two Ethernet cards with the same MAC address). So if that even happens in a relatively small Ethernet, I assume that this will be fairly common if your address space includes each active WiFi router.

I think lotu's probably right. I'd suspect users causing these collissions before I'd suspect that network hardware manufacturers don't know to allocate unique MAC addresses to each card.

You can generally trust than a hardware-embedded MAC is unique.

http://blogs.msdn.com/b/oldnewthing/archive/2004/02/11/71307...

Post reply on HN