Live data from Hacker News

iOS 8 randomises the MAC address while scanning for WiFi networks

twitter.com

221–230 of 264 posts

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#221
I wonder what effects this has on law enforcement. It seems probable that if stores are using systems to track people by WIFI Mac, then law enforcement is probably doing the same. An interesting trade off.

Also, does this apply to the other ID being broadcast, the Bluetooth MAC?

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#223
post #6

If this becomes the trend (which in my opinon would be nice) it will become a big problem for companies that specialise in customer tracking e.g. for supermarkets and big department stores. Previously it was quite easy to track a customer, how long he or she spends time in the store, which floors he or she visits, etc. by putting up dummy WiFI-networks that the customers phones find by giving out their MAC-addresses.

Have the stores release apps (or one app that works for the system they use) that trades a percentage off, coupons, etc, for location data.

"We'd like to learn a little about your shopping habits, and that includes sending anonymized data about your time in our store. In exchange for this, we'd love to offer you 25% off this purchase and 10% off all future purchases".

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#224

Earlier quoted context omitted.

Your assumption is incorrect - Probe requests do not contain the MAC of the AP, only the SSID. Wifi clients usually only save the name and security type/PSK of previously joined networks. In many situations, the same SSID is broadcast by multiple different APs with different MAC addresses in the same area so it wouldn't make sense to remember a specific SSID/MAC pair. If the same client (iPhone) probes for a list of…

each individual probe request will be coming from a randomized MAC, so there shouldn't be any "list" of SSIDs to compare.

The randomized MAC address doesn't help here. If two probe requests have different MAC addresses but the same SSID list, then the tracker can guess that they are the same device.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#225
post #193

Earlier quoted context omitted.

Your assumption is incorrect - Probe requests do not contain the MAC of the AP, only the SSID. Wifi clients usually only save the name and security type/PSK of previously joined networks. In many situations, the same SSID is broadcast by multiple different APs with different MAC addresses in the same area so it wouldn't make sense to remember a specific SSID/MAC pair. If the same client (iPhone) probes for a list of…

unless Apple also decided to stop sending out the SSID list..

This only occurs for 'hidden' networks. If you do not have any hidden networks in your known network list than you will not be broadcasting SSIDs. This is yet another reason to avoid setting your AP to hidden.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#226
post #194
post #174

I think this is a feature for stores implementing WiFi tracking systems, not a hindrance. If I own a store, I really want to understand traffic patterns. If I can do that without causing a privacy shitstorm, I think that's a benefit.

You can't understand patterns from random data. Am I missing something you're seeing?

Traffic analysis and some statistical methods should give you a lot of interesting data. Yes it's not individualized long-term tracking, but you can figure out when and where people are visiting, and I think even tease out how long people spend at each point, even if the MAC is randomized for each request.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#228
post #28

We learned during the prosecution of Swartz that MAC addresses are the analog of VIN number numbers, and that tampering with them is a sign of ill intent. I await the federal case against Apple or an Apple customer with bated breath.

You're ignoring the drastic differences in context between Swartz's actions and Apples. Context matters.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#229
post #174

I think this is a feature for stores implementing WiFi tracking systems, not a hindrance. If I own a store, I really want to understand traffic patterns. If I can do that without causing a privacy shitstorm, I think that's a benefit.

They can use their extensive existing network of closed circuit video cameras to identify traffic patterns. Unless they want to tie customers to profiles (e.g. MAC to a credit card transaction) the resulting data would be the same. Cameras are even better at this because it counts everyone, smartphone owning or not.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#230
post #184

Earlier quoted context omitted.

Thanks, everyone, for reminding me why I stopped reading and commenting on Apple-related threads on HN. 27+ downvotes later, I still haven't changed my mind, but if you wish to try, logic works better than weak justifications for exploitative, sociopathic corporate behavior and targeted downvoting.

I don't think your downvotes relate to criticising Apple per se; they're due to a poor argument style. I am no great fan of Apple, but hurling vague accusations and FUD, then shifting the goalposts when anyone tries to refute you, adds little to the conversation besides noise. > I still haven't changed my mind Well you should have. You've been thoroughly shot down. The fact you don't accept that says more about you t…

Thanks for your comment. Consider my response below to apply to the thread, not just to your comment specifically.

  ------
I don't think your downvotes relate to criticising Apple per se; they're due to a poor argument style.

I'll admit I haven't invested my best efforts into my comments on this thread, but where other than an Apple thread would every single comment by one person be downvoted beyond -4? It's not worth the effort if one knows one's comments will be grayed out anyway.

Even mpyne's much more thorough comment was downvoted, so it's clear that the downvotes aren't strictly targeting poor argumentation. Furthermore, if that were the case, there's no reason to target every single comment by a person equally, as inevitably some of them must be better argued than others.

  ------
then shifting the goalposts when anyone tries to refute you

I never shifted any goalposts. All I said was that it's difficult to reconcile user IBM's claim that Apple wants to be the "privacy" company with their actual behavior, then provided clarifications when prompted.

  ------
You've been thoroughly shot down.

Where? I see lots of disagreement, but no disproof. Show me the counterargument of the form, "Apple can be trusted despite these events because...".

It's easy to shoot somebody down. Just yell louder. What I've yet to see is a solid refutation to any of the things I said. A downvote is argumentatively equivalent to yelling, "Shut up!" So let's see how many "Shut ups" there are, and how many refutations.

It takes 5 counted downvotes to bring a comment from +1 to -4, where all of my other comments currently lie (I don't know how the HN anti-voting-ring algo turns clicks into actual downvotes, so there may be even more). However, beyond -4 points the comments can still get lighter. I'll assume that #aeaeae is the original -4 comment, since it's the darkest of my comments on this thread. I also have comments at #bebebe, #cecece and #dddddd. So I'll count #ae as 5, #be as 6, #ce as 7, and #dd as 8 or more.

  Original comment - https://news.ycombinator.com/item?id=7865747 - #dddddd - 8+
  Location history - https://news.ycombinator.com/item?id=7865843 - #bebebe - 6
  [Tracking]       - https://news.ycombinator.com/item?id=7866011 - #dddddd - 8+
  [Logging]        - https://news.ycombinator.com/item?id=7866147 - #dddddd - 8+
  Physical access  - https://news.ycombinator.com/item?id=7866013 - #dddddd - 8+
  Cloud sync       - https://news.ycombinator.com/item?id=7866132 - #cecece - 7
  Good citizen     - https://news.ycombinator.com/item?id=7865835 - #dddddd - 8+
  Worthy of trust  - https://news.ycombinator.com/item?id=7865835 - #cecece - 7
  Thanks, everyone - https://news.ycombinator.com/item?id=7866375 - #aeaeae - 5
  ------
  Total: 65+ downvotes
That's 65 or more counts of "Shut up," not including mpyne's comment. How many actual comments?

  Still don't know   - https://news.ycombinator.com/item?id=7865810
  This again?        - https://news.ycombinator.com/item?id=7865877
  Tracking semantics - https://news.ycombinator.com/item?id=7866094
  User's devices     - https://news.ycombinator.com/item?id=7865867
  Do you have proof  - https://news.ycombinator.com/item?id=7866098
  Orthogonal         - https://news.ycombinator.com/item?id=7865778
  Big corps not good - https://news.ycombinator.com/item?id=7865871
  ------
  Total: 7 comments (4 one-liners)
Only seven comments, four of which were one-liners with less content than most of my own comments. The remaining comments are mostly distractions from the actual claim, that Apple's past behavior doesn't lend itself to trust with one's privacy.

So again, where's the refutation? MAC address randomization is awesome, but why can I trust Apple to take the position of the "privacy" company?

Post reply on HN