Live data from Hacker News

Mozilla Stumbler 1.0

play.google.com

101–110 of 158 posts

Re: Mozilla Stumbler 1.0

#101

Earlier quoted context omitted.

Here's an analogy: Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house. So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue: 1) A single person travels past your house and happens to notice which lights are on. 2) Someone travels past your house and records, on a piece of…

Analogies are analogies because they're similar, not identical. > You want people to stop "monitoring" your SSID? Stop freaking broadcasting it at all. This is technocentrical BS, washing the hands to justify doing what you want. 1) Most people don't know that their SSIDs are being recorded (with position), so how do you expect them to make an informed decision? It's not like the information is readily available (I w…

I don't think it is a privacy violation AT ALL. And nobody in this thread has even tried to explain why it is.

Just hand waving and "we don't have to explain ourselves, privacy is the default state!"

I gave an analogy above, you didn't even answer it. When does it become a privacy issue exactly?

Re: Mozilla Stumbler 1.0

#102

Earlier quoted context omitted.

Google provides an opt-out. They will ignore your AP if you append "_nomap" to the end of your SSID. Does Stumbler also support this? If not, why not? Ref: https://support.google.com/maps/answer/1725632?hl=en edit: Found the answer to my own question. Yes, they do support "nomap": https://github.com/mozilla/MozStumbler/issues/149

Is this really a thing? WTF? I feel very ashamed, as someone who works in IT, everytime this happens. I mean, people can opt-out, of course - but, in order to do that, they need to know what an SSID is, and how to change it. What about people who don't? Will we just assume that they don't care or that their opinion doesn't matter?

As someone who works in IT, I always feel ashamed to see outrage over this. We somehow want both privacy as well as a freaking radio beacon spreading out a signal to hundreds of meters away. Let there be no mistake: using a Wi-Fi router in your house means you are voluntarily broadcasting an identifier to anyone within hundreds of meters. There can be no honest expectation of privacy there.

If you don't want people obtaining information from a radio beacon in your house then do not put a radio beacon in your house. But don't pester companies for opting out of the passive database of radio signals you are voluntarily sending into the world. You cannot have your cake and eat it too.

Furthermore, there is nothing intrinsically revealing about an SSID. If your SSID tells people information about you, the problem is the SSID and not the collection of that information. It is trivial to change your SSID to a pseudonymous one.

I know that a lot of people are not aware of the privacy consequences, but those people are not the ones making a point out of this. Once you educate yourself about the privacy consequences of using a Wi-Fi router, do not blame people for collecting information that you are actively and voluntarily broadcasting!

Re: Mozilla Stumbler 1.0

#103
post #90

Earlier quoted context omitted.

But SSIDs are not private. At all. Should what the outside of your house look like be private information? How would that work? What about when I appear in the background of a photo someone took on the street?

> Should what the outside of your house look like be private information? Everyone knows that someone can record the outside of your house; not everyone knows that SSIDs with location can (and actually are!) registered. Do you notice the difference? You can't assume that WLAN specifics are as tacit as knowing that people can look at my house!

Even if you did explain to everyone that their SSIDs are being indexed - what would you tell them is actually being indexed? What personal information are they giving up? Your address, age, other residents of your house are already listed publicly. The name you gave your wireless network pales in comparison.

Re: Mozilla Stumbler 1.0

#104

Earlier quoted context omitted.

"fact of life of web server logging" = screw you, we're not even going to consider deleting our logs even as we talk a good line about how much we respect your privacy edit after downvote: also, mozilla engineering PMs will intimate on hackernews that it won't internally correlate and potentially sell any of the location and other information it most obviously could correlate about people, even though it has already…

We don't correlate your location data to ads. As a Canadian, that would actually be illegal and a violation of the Privacy Act. We never got authorization from individuals to do that correlation. We aren't perfect, but I think we do a pretty good job of respecting and protecting your privacy at Mozilla.

thank you for these clarifications.

one industry norm that makes these things tough (again, not Mozilla's fault) is that at least under US law, Mozilla could change its privacy policies at some point in the future and do a lot more than it currently does.

and... my parent comment was brash and probably deserved the downvote it received.

Re: Mozilla Stumbler 1.0

#105

Earlier quoted context omitted.

Analogies are analogies because they're similar, not identical. > You want people to stop "monitoring" your SSID? Stop freaking broadcasting it at all. This is technocentrical BS, washing the hands to justify doing what you want. 1) Most people don't know that their SSIDs are being recorded (with position), so how do you expect them to make an informed decision? It's not like the information is readily available (I w…

I don't think it is a privacy violation AT ALL. And nobody in this thread has even tried to explain why it is. Just hand waving and "we don't have to explain ourselves, privacy is the default state!" I gave an analogy above, you didn't even answer it. When does it become a privacy issue exactly?

> I gave an analogy above, you didn't even answer it. When does it become a privacy issue exactly?

You see, that's the problem - and that's the point. I did not answer because:

a) I don't really care about my SSID privacy. I do, however, care about other people right to know what's happening and to make informed (not implicit, by Google or Mozilla rules) decisions; and

b) I really don't (shouldn't) have to. It's not your concern when or how I feel my privacy being violated. I don't have to answer that, and it's a sad, sad society where this happens.

Re: Mozilla Stumbler 1.0

#106

Earlier quoted context omitted.

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

Here's an analogy: Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house. So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue: 1) A single person travels past your house and happens to notice which lights are on. 2) Someone travels past your house and records, on a piece of…

I think the difference we're talking about here between #1 and #3 is that #3 makes it much easier/cheaper to (for example) predict when you'll be out of town if they want to break into your house (router)...potentially even without ever traveling past it.

Just because this information is legal to collect, doesn't mean people think a nonprofit that claims to be committed to user privacy should be moving the center of gravity closer to your third scenario.

But maybe more importantly, we're not talking about "someone else" recording the information or just a few "people" "monitoring" an SSID. We're questioning the wisdom of an organization building software to systematically collect, store, and make an SSID far more readily available to far larger numbers of people.

Re: Mozilla Stumbler 1.0

#107
post #32
post #19

Will 1.0 be available on the F-Droid store, like earlier versions?

You can already auto-update from within MozStumbler itself.

Apparently not from the current latest (0.30.0) version on f-droid. I just went through the MozStumbler menus and did not see anything about (auto-)updating.

Re: Mozilla Stumbler 1.0

#108
I've been waiting for something like this. Most other location services I know about also crowd source data (after initially seeding it), but don't give the data back to the user.

Kudos for giving back what people gave you.

Re: Mozilla Stumbler 1.0

#109
post #80

Earlier quoted context omitted.

I understand what you're saying, but you have to draw the line between privacy and common sense at some point. It has been understood for awhile now that you have no expectation of privacy in public, at least as far as not being photographed, talked to, etc. Most people would probably agree that the paparazzi taking sneaky pictures of celebrities buying milk at Kroger aren't being very classy, but they'll also probab…

Sleazy paparazzi can exist in the world without breaking the law, but I expected more than that from Mozilla. One hypothetical example: SSIDs often betray vendor names out of the box, and home routers are typically embedded devices that don't frequently receive security updates. Suppose Mozilla makes its database public and lists my SSID--or more likely, some weakly-secure hash of my SSID--in a public database that l…

As you said, that's not a privacy issue but a security one. Also, in your example I'd argue it would just be easier to attack every single IP address and/or WAP rather than attempt to figure out which ones are Linksys and running a vulnerable firmware. It would take less time and also solves the case of non-default SSID names.

I'm still interested in seeing an example of how linking SSIDs to physical locations is a violation of privacy. Especially compared to, say, linking my full legal name to my house address which is already treated as public knowledge.

Re: Mozilla Stumbler 1.0

#110
post #58

Earlier quoted context omitted.

Is this really a thing? WTF? I feel very ashamed, as someone who works in IT, everytime this happens. I mean, people can opt-out, of course - but, in order to do that, they need to know what an SSID is, and how to change it. What about people who don't? Will we just assume that they don't care or that their opinion doesn't matter?

Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…

The privacy concern as I understand it is about access points moving in time, not about the snapshot of the data at a certain point.

So you can use my access point to find your location, but if I bring it to my next home, please don't record that in public data.

Post reply on HN