Live data from Hacker News

Mozilla Stumbler 1.0

play.google.com

141–150 of 158 posts

Re: Mozilla Stumbler 1.0

#141

Earlier quoted context omitted.

> ran with it without considering the fact that, in such data would probably be cleartext passwords. This part, I just don't buy. Maybe full-take captures was the most expeditious at the time, but to me the notion that Google's engineers didn't know or didn't realize that they would end up doing a lot of "incidental collection" in the process is laughable.

> This part, I just don't buy. And yet it's the one that Hanlon's razor explains very well. Goes to show that being terse in my original comment was the right move and you just can't wrap your head around the idea that, around the world, people do stuff without considering the consequences. The people in charge of your country, of your internet, of your health and your whole life, they're all humans and don't have we…

Not sure if you read the rest of my previous comment but Hanlon's razor is predicated on malice, so I still disagree.

I never assumed assumed malice here. But it's still preposterous that a company with such skilled engineers wouldn't know until they were sued that they had been collecting large volumes of additional information over the span of years.

That claim basically requires that this global mapping endeavour involving many people over multiple years was run by people who didn't understand the most basic aspects of wi-fi protocols but somehow flipped wireshark into monitor mode and then never looked at any raw captures anywhere to extract information from them, even while setting up collection systems used across the globe.

Doing that once could be a mistake; even collecting all of the data could be a mistake; but not even realizing they had collected vastly more than beacon packets--probably over most of the planet--for multiple years?

Hey...I guess anything is possible, but it doesn't pass the smell test for me.

Re: Mozilla Stumbler 1.0

#142
post #124

Earlier quoted context omitted.

I can also passively collect plenty of WEP traffic being broadcasted over public property and decrypt it on my computer (but I don't). Mozilla's not aiming to do anything remotely as invasive as that, but I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard, especially for an organization like Mozilla.

> I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard This is a strawman. Any public information that can be picked up passively from public property is fair game is the real argument. Decrypting WEP, easy enough as it might be, is still unethical as the information was meant to be private. Making a database of public SSID broadcasts is co…

It's not the SSIDs but the BSSIDs that end up in the database, isn't it?

Re: Mozilla Stumbler 1.0

#143

Earlier quoted context omitted.

Here's an analogy: Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house. So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue: 1) A single person travels past your house and happens to notice which lights are on. 2) Someone travels past your house and records, on a piece of…

I think the difference we're talking about here between #1 and #3 is that #3 makes it much easier/cheaper to (for example) predict when you'll be out of town if they want to break into your house (router)...potentially even without ever traveling past it. Just because this information is legal to collect, doesn't mean people think a nonprofit that claims to be committed to user privacy should be moving the center of…

It's the BSSID that is made far more readily available, not the SSID.

Re: Mozilla Stumbler 1.0

#144
post #131

Earlier quoted context omitted.

How about we stop being so condescending, educate people to make an informed choice, and stop asking Google, Mozilla and anyone with a smartphone to think for them?

I totally agree, and that's not the issue at stake. The issue is: what should we do while people are not educated enough to make an informed decision? Mozilla, Google (and some people in this thread) assume that it's right for them to decide if there are privacy concerns and advance with their initiatives. I don't. And they are, by marking this as opt-in, thinking for them .

It's still someone's own choice to install a Wi-Fi router and powering it on. The fact that many of them don't exactly understand that it might be privacy issue (if and only if they put identifying information in the SSID) does not mean that Mozilla and Google are thinking for them. The assumption that the router owner does not mean the SSID to be public is also not warranted.

If the SSID was mandated to be identical to someone's name (or any other identifying information), I'd say the problem you describe was real. But since it the information broadcast is mostly pseudonymous, I think it's quite a small thing you are arguing. If people are including personal information in their SSID, by all means tell them!

Re: Mozilla Stumbler 1.0

#145
post #58

Earlier quoted context omitted.

Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…

The privacy concern as I understand it is about access points moving in time, not about the snapshot of the data at a certain point. So you can use my access point to find your location, but if I bring it to my next home, please don't record that in public data.

This is a great example -- thanks.

So, is it fair to say that there's no privacy concern if the API only exposes a one-way lookup? I.e. "here are the access points I can see -- where am I?"

That also addresses the other concern raised below, that the database could be used to search for known-vulnerable routers.

Re: Mozilla Stumbler 1.0

#146
post #48

This seems similar to what Google did to receive massive fines a few years back.

It's the same thing, but Mozilla is cool and everything they do is good :), while Google is evil Remember that public opinion is an extremely mutable thing [1]. [1] Henrik Ibsen

...

At least state why you feel that my opinion is not valuable.

Re: Mozilla Stumbler 1.0

#147
post #19

Will 1.0 be available on the F-Droid store, like earlier versions?

I'm going to try getting an F-Droid build out today, but we've got some build issues with the fdroidserver. In any case - it will get to F-Droid real-soon-now.

Cool, very good to hear!

Re: Mozilla Stumbler 1.0

#148
post #6

Earlier quoted context omitted.

Congratulations; I hope this gives us a safe, effective, open location service. The privacy policy[1] could be clarified for less technical readers, and even for others. I infer that collected data is anonymous because you write, 1) We receive publicly observable data about WiFi access points and cell towers around you, your estimated latitude and longitude, and the date -- Not associated with anything else, that may…

Good questions! The stumbler reports Wi-Fi and cell tower locations and an optional nickname. The location data is stored anonymously. The nickname and just the number of reported networks is stored separately, solely for display on the leaderboard [1] or other gamification in the future. The IP addresses are just a fact of life of web server logging. They are not stored in the location or leaderboard databases. [1]…

> Good questions!

Thanks! My post's intention was to suggest that Mozilla revise the privacy policy to clarify it for everyone. What are your thoughts?

Re: Mozilla Stumbler 1.0

#149
post #145

Earlier quoted context omitted.

The privacy concern as I understand it is about access points moving in time, not about the snapshot of the data at a certain point. So you can use my access point to find your location, but if I bring it to my next home, please don't record that in public data.

This is a great example -- thanks. So, is it fair to say that there's no privacy concern if the API only exposes a one-way lookup? I.e. "here are the access points I can see -- where am I?" That also addresses the other concern raised below, that the database could be used to search for known-vulnerable routers.

> is it fair to say that there's no privacy concern if the API only exposes a one-way lookup?

It helps, but no. The data is still there to use. The API or Mozilla policy may change, or security may fail.

From what I can tell, there's no need to record either the devices gathering data or the devices looking up their location. Just don't store that data and everything is fine.

Re: Mozilla Stumbler 1.0

#150
post #79

Will this still collect hidden SSID's?

Correct me if I'm wrong, but I'm pretty sure hidden SSID's do not broadcast their network name and thus will not be found by a scanner.

Networks with hidden SSIDs can be detected many other ways. A little searching quickly will turn up methods.
Post reply on HN