Earlier quoted context omitted.
Well, having your curtains open also broadcasts an image of your living room on EM spectrum for hundreds of meters for anyone with optics... Same for eavesdropping (laser mic). Easy to listen maybe but you will still get convicted in both cases.
The difference being that having a Wi-Fi router means actively powering a device that sends a signal beyond the perimeter and privacy of your home. A signal that, as evidenced by this app, can be passively [1] picked up and processed by any casual passer-by. Having a Wi-Fi router with an SSID is the equivalent of installing a speaker on the top of your house and have it constantly spell a uniquish name to the neighbo…
Mozilla Stumbler 1.0
121–130 of 158 posts
Re: Mozilla Stumbler 1.0
#122Earlier quoted context omitted.
the only thing most people most of the time mean when they set up wi-fi is that they want to be able to connect their ipads and chromebooks to the internet at home. IMSI catchers intercept signals broadcasted from radios that commonly transit across public property. my point was that we routinely consider things other than protocol specs in determining whether and when signals should be collected.
> the only thing most people most of the time mean when they set up wi-fi is that they want to be able to connect their ipads and chromebooks to the internet at home. These are not the people I'm arguing against, and I mentioned that in my first post. People should definitely be educated about the privacy consequences of their equipment. I'm arguing against people who do know that an SSID broadcast is a public radio…
It's hard for me to think of ways these organizations could reliably know whether people don't mind their SSID being mapped or used for related purposes without asking them.
Re: Mozilla Stumbler 1.0
#123Hi all! We cut a 1.0 release of the Mozilla Stumbler finally. Have at it. File the bugs. Complain about battery life. Help us make this thing not suck and build out a proper open location service.
Also, why do you need access to my photos?
Re: Mozilla Stumbler 1.0
#124Earlier quoted context omitted.
The difference being that having a Wi-Fi router means actively powering a device that sends a signal beyond the perimeter and privacy of your home. A signal that, as evidenced by this app, can be passively [1] picked up and processed by any casual passer-by. Having a Wi-Fi router with an SSID is the equivalent of installing a speaker on the top of your house and have it constantly spell a uniquish name to the neighbo…
I can also passively collect plenty of WEP traffic being broadcasted over public property and decrypt it on my computer (but I don't). Mozilla's not aiming to do anything remotely as invasive as that, but I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard, especially for an organization like Mozilla.
This is a strawman.
Any public information that can be picked up passively from public property is fair game is the real argument. Decrypting WEP, easy enough as it might be, is still unethical as the information was meant to be private. Making a database of public SSID broadcasts is completely ethical as there should be nothing private about an SSID.
Re: Mozilla Stumbler 1.0
#125Earlier quoted context omitted.
does anyone really believe this occurred "mistakenly"?
As a programmer, I can completely believe I'd write a system for capturing and process beacons packets - to store the MAC and transmission power - that would also inadvertently capture and store data packets. In fact, using some off-the-shelve open source tools like Kismet, capturing data packets is the default - you need to manually disable it. That alone makes for an easy way to mess it up. What I can't find is a "…
thinking about it counterfactually, they could have pretty easily discarded everything that obviously was not what they were claiming to capture at the point of collection (and interfaces to do so are built into the open-source tools you allude to), but it seems pretty clear that they proceeded for a pretty long time.
Re: Mozilla Stumbler 1.0
#126Earlier quoted context omitted.
I can also passively collect plenty of WEP traffic being broadcasted over public property and decrypt it on my computer (but I don't). Mozilla's not aiming to do anything remotely as invasive as that, but I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard, especially for an organization like Mozilla.
> I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard This is a strawman. Any public information that can be picked up passively from public property is fair game is the real argument. Decrypting WEP, easy enough as it might be, is still unethical as the information was meant to be private. Making a database of public SSID broadcasts is co…
Re: Mozilla Stumbler 1.0
#127Earlier quoted context omitted.
Is this really a thing? WTF? I feel very ashamed, as someone who works in IT, everytime this happens. I mean, people can opt-out, of course - but, in order to do that, they need to know what an SSID is, and how to change it. What about people who don't? Will we just assume that they don't care or that their opinion doesn't matter?
As someone who works in IT, I always feel ashamed to see outrage over this. We somehow want both privacy as well as a freaking radio beacon spreading out a signal to hundreds of meters away. Let there be no mistake: using a Wi-Fi router in your house means you are voluntarily broadcasting an identifier to anyone within hundreds of meters. There can be no honest expectation of privacy there. If you don't want people o…
Of course they are not making a point - they are not aware. How would you expect them to make a point?
What you saying is: if they don't know enough about the subject to decide if a point should be made, then we should ignore the right to give (or not) an informed consent (because you can decide for them if the SSID is "intrinsically revealing" or not).
Re: Mozilla Stumbler 1.0
#128This seems similar to what Google did to receive massive fines a few years back.
[1] Henrik Ibsen
Re: Mozilla Stumbler 1.0
#129I remember reading how Wigle Wardriving calculated fixes and the method seemed unsophisticated and lame.
For example, if I bike down a street then fixes would be detected 100m ahead of me and always pinned to the road at my current location.
If I bike down the road in the other direction the next time, will be fix become more accurate?
Normally higher SNR fixes should have more weight than weak fixes. Do they?
Re: Mozilla Stumbler 1.0
#130Earlier quoted context omitted.
care to elaborate? are you arguing that saving/processing the full contents of raw captures from monitor mode is somehow easier/cheaper to process than filtering out obviously extraneous information at the point of collection? that's not at all obvious to me, and and one of the reasons i didn't find google's claims credible. it seems much more reasonable that they would have realized upfront that limiting the volumes…
> saving/processing This data was recorded . It was not processed, it was not saved, and it was not filed under "lets-take-a-look-at-the-passwords-in-this-log.txt". The engineers thought "Hey, let's capture wifi data in aggregate and do cool geolocation stuff!" and ran with it without considering the fact that, in such data would probably be cleartext passwords. As for time and money, those are two things Google has…
This part, I just don't buy. Maybe full-take captures was the most expeditious at the time, but to me the notion that Google's engineers didn't know or didn't realize that they would end up doing a lot of "incidental collection" in the process is laughable.