Live data from Hacker News

iOS 8 randomises the MAC address while scanning for WiFi networks

twitter.com

241–250 of 264 posts

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#241
post #192

Earlier quoted context omitted.

Hello, my name is Guy Incognito. My email address is gincog@example.com. Unless it requires you to click a confirmation link or something similar to that, just use a fake address at one of the example.TLD domains. If they DO require confirmation, use mailinator or a similar service.

Catch 22 there: you have to be able to access mailinator.com in order to generate a throwaway email.

Not with mailinator. You just choose a username and it gets sent there. No need to go to mailinator.com first.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#242

I wonder what effects this has on law enforcement. It seems probable that if stores are using systems to track people by WIFI Mac, then law enforcement is probably doing the same. An interesting trade off. Also, does this apply to the other ID being broadcast, the Bluetooth MAC?

Im thinking this wont affect LEOs as they go through cell towers which is not wifi or bt. see: https://www.aclu.org/blog/national-security-technology-and-l...

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#243

Earlier quoted context omitted.

Without being too specific, you should assume that Large stores already do this. Any store claiming to have "in store wifi" is almost guaranteed to be tracking you through your mac address. The system that I'm familiar with only tracks where you're going. It didn't (as of a couple months ago) have any way of linking your mac back to a consumer profile.

I was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.

[deleted]

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#245
post #72

Earlier quoted context omitted.

No, you misunderstand iBeacon. The sole purpose of iBeacon is to let handsets detect it , not the other way around. In order to for it to be used to track users, the user would have to run an app that detects the beacon and then communicates back to the business. In other words, the user has to opt in to tracking.

> No, you misunderstand iBeacon. The sole purpose of iBeacon is to let handsets detect it, not the other way around. You are wrong, the point of iBeacon is to allow an app to track its position. Apple is not about privacy, they're about controlling what they consider to be their customers. They will be the gateway the users go through for any service whatsoever. They get their 30% no matter what.

You are confusing geolocation with tracking. Geolocation merely lets the handset determine where it is. "Tracking" implies there is another party involved in monitoring your location. That can't happen with beacons unless the user runs an app that communicates your location back to a third party -- which it could do with regular old GPS geolocation too. iBeacons are just another way to do geolocation.

Also, iBeacon broadcasts can be detected by Android, or any other platform that wants to. I'm surprised no one has said this on the thread. It's clearly not about Apple lock-in.

Here's an Android library for doing it: http://developer.radiusnetworks.com/ibeacon/android/

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#246
post #191

Earlier quoted context omitted.

If you don't give your name or other identification, how would they hold you responsible if you abused the connection?

It's not that, trust me. They make good money with your data. Take it as a way of payment for the "free" wifi. It helps the same purpose as the loyalty cards, especially the ones that outgrow the original business (I'm looking at you both Tesco ClubCard and Nectar Card). Getting "points" by using those at other businesses like petrol stations helps them profiling you for "better" advertising. They also keep you a bit…

Non-Disadvantage Cards.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#247
post #217

Earlier quoted context omitted.

Assuming they track every single purchase made at a store along with the credit card number used (or at least some form of ID associated with that particular card), and all the times the MACs left the store, how many sets of data do you think they need to get a 1:1 match between MAC and person? Even for really large stores, I'm guessing it would only take 2-3 visits before they can link you to POS records with decent…

Mix that with a camera at each teller to do good facial capture for cash customers and cameras at the door scanning people coming in and it gets a bit creepier.

You know what is really creepy, when the tellers and staff at a store are painfully happy and courteous. If feels like if I frown or show any irritation their neck detonator will go off.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#248

Earlier quoted context omitted.

I was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.

Name and email, you say? Check out the form you need to fill in to use free wifi at Brazilian airports: http://brazilsense.com/index.php?title=Wi-Fi_and_Internet_se... They want your: name sex marital status nationality place of birth profession identity document type identity document number street address city state country cellular phone number name of cellular provider landline phone number email address barcode…

I remember filling out that form. :-(

I also remember checking into a Brazilian hotel, where they wanted Brazilian guests, at least, to specify their highest level of formal education (!), as well as profession, date of birth, and the city from which the guest arrived and the city to which the guest planned to travel next.

I wonder if the last two are specifically meant to aid law enforcement investigations.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#249
The FTC held a workshop this spring about location tracking, particularly the retail analytics kind that this is calculated to thwart. I spoke there and was the person on the panel categorically opposed to the tracking (though I placed the blame on the wifi device makers for leaking a tracking identifier, rather than the people taking advantage of the tracking opportunity).

http://www.ftc.gov/news-events/events-calendar/2014/02/sprin...

You can also read the comments that various organizations filed about this:

http://www.ftc.gov/policy/public-comments/initiative-516

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#250
post #193

Earlier quoted context omitted.

unless Apple also decided to stop sending out the SSID list..

This only occurs for 'hidden' networks. If you do not have any hidden networks in your known network list than you will not be broadcasting SSIDs. This is yet another reason to avoid setting your AP to hidden.

Do you have a source for this? Is there any documentation of this in the 802.11 spec? I'm also wondering if devices send a single probe per SSID they're looking for, or one probe with a list of SSIDs?
Post reply on HN