Live data from Hacker News

Mozilla Stumbler 1.0

play.google.com

151–158 of 158 posts

Re: Mozilla Stumbler 1.0

#151
post #113

Earlier quoted context omitted.

Well, having your curtains open also broadcasts an image of your living room on EM spectrum for hundreds of meters for anyone with optics... Same for eavesdropping (laser mic). Easy to listen maybe but you will still get convicted in both cases.

The difference being that having a Wi-Fi router means actively powering a device that sends a signal beyond the perimeter and privacy of your home. A signal that, as evidenced by this app, can be passively [1] picked up and processed by any casual passer-by. Having a Wi-Fi router with an SSID is the equivalent of installing a speaker on the top of your house and have it constantly spell a uniquish name to the neighbo…

One could argue that the main purpose of the device (or the main reason users use the device) is not to broadcast identity, it is to let the user connect to the internet within the perimeter of their domicile.

Just like you can argue that the main purpose of windows is not so that people can look in, it's so that people can look out, and light comes in.

I agree partially with what you're saying, but there is a mismatch between user expectation and what the technology actually does. I don't think the fact that the user used it implies they consented to the technical side effects.

Re: Mozilla Stumbler 1.0

#152
post #145

Earlier quoted context omitted.

The privacy concern as I understand it is about access points moving in time, not about the snapshot of the data at a certain point. So you can use my access point to find your location, but if I bring it to my next home, please don't record that in public data.

This is a great example -- thanks. So, is it fair to say that there's no privacy concern if the API only exposes a one-way lookup? I.e. "here are the access points I can see -- where am I?" That also addresses the other concern raised below, that the database could be used to search for known-vulnerable routers.

Oh, another example that affects even the one-way lookup is stalking -- if I've been over to Joe's house before, and then he goes into hiding, I can say, "hey, I see Joe's access point, where am I?"

That could be mitigated by requiring at least two access points for a query.

Re: Mozilla Stumbler 1.0

#153
post #152
post #145

Earlier quoted context omitted.

This is a great example -- thanks. So, is it fair to say that there's no privacy concern if the API only exposes a one-way lookup? I.e. "here are the access points I can see -- where am I?" That also addresses the other concern raised below, that the database could be used to search for known-vulnerable routers.

Oh, another example that affects even the one-way lookup is stalking -- if I've been over to Joe's house before, and then he goes into hiding, I can say, "hey, I see Joe's access point, where am I?" That could be mitigated by requiring at least two access points for a query.

Both the Mozilla API as well as Google have this "you need to know two" protection. At Mozilla we go a bit further and also make sure the two BSSID's you are sending aren't almost identical. That happens in a lot of modern access points who are setup with separate 2.4 and 5GHz networks or those who have a guest network.

Re: Mozilla Stumbler 1.0

#154
post #124

Earlier quoted context omitted.

> I still don't find "anything that can be picked up passively from public property is fair game" a very compelling ethical standard This is a strawman. Any public information that can be picked up passively from public property is fair game is the real argument. Decrypting WEP, easy enough as it might be, is still unethical as the information was meant to be private. Making a database of public SSID broadcasts is co…

It's not the SSIDs but the BSSIDs that end up in the database, isn't it?

Yep. These services only store and transmit the BSSID (which is most often the mac address of the network card).

The only place the SSID (clear text name) is used is in filtering out things on the client end. Both looking for "no SSID" / hidden networks and the _nomap suffix. The SSID is never sent to any service.

Re: Mozilla Stumbler 1.0

#155
post #109

Earlier quoted context omitted.

As you said, that's not a privacy issue but a security one. Also, in your example I'd argue it would just be easier to attack every single IP address and/or WAP rather than attempt to figure out which ones are Linksys and running a vulnerable firmware. It would take less time and also solves the case of non-default SSID names. I'm still interested in seeing an example of how linking SSIDs to physical locations is a v…

I don't think you'll like my answer, but I think it was Schneier who said that it's not necessarily any one thing: it's having easy access to a bunch of different things, together.

I believe that according to law, the onus is on the owner in question to make sure their WiFi Router is secure. If a hacker takes control of your router, and downloads pirated material, you are considered responsible if you didn't take even necessary steps to protect yourself. Then you sue manufacturer, and all routers come with a set of different passwords and _no_map by default. That is the most likely logical course of action.

Everything else is idealizing. Same as with video and with DRM. Mozilla could take a principled stance and say no to patented codes and no to DRM, and then Google says yes to both of those things, reap the benefits, while the end consumer abandon Mozilla because it doesn't play YouTube or Netflix, and then Mozilla is no more.

If you don't like it, you can fork Firefox and/or choose not to trust Mozilla. The situation is super sad, but what else can you do? Be principled and disappear? Or compromise and survive?

Re: Mozilla Stumbler 1.0

#156
post #102

Earlier quoted context omitted.

Is this really a thing? WTF? I feel very ashamed, as someone who works in IT, everytime this happens. I mean, people can opt-out, of course - but, in order to do that, they need to know what an SSID is, and how to change it. What about people who don't? Will we just assume that they don't care or that their opinion doesn't matter?

As someone who works in IT, I always feel ashamed to see outrage over this. We somehow want both privacy as well as a freaking radio beacon spreading out a signal to hundreds of meters away. Let there be no mistake: using a Wi-Fi router in your house means you are voluntarily broadcasting an identifier to anyone within hundreds of meters. There can be no honest expectation of privacy there. If you don't want people o…

As you walk around, your phone broadcasts a list of wifi access points that you have connected to.

The existance of these databases mean that anyone who has unrestricted access to query the database, can probably figure out where anyone else who enters their vicinity, lives and works, completely passively.

Re: Mozilla Stumbler 1.0

#157

Earlier quoted context omitted.

We don't correlate your location data to ads. As a Canadian, that would actually be illegal and a violation of the Privacy Act. We never got authorization from individuals to do that correlation. We aren't perfect, but I think we do a pretty good job of respecting and protecting your privacy at Mozilla.

thank you for these clarifications. one industry norm that makes these things tough (again, not Mozilla's fault) is that at least under US law, Mozilla could change its privacy policies at some point in the future and do a lot more than it currently does. and... my parent comment was brash and probably deserved the downvote it received.

Selling user data would be completely against our mission and values, and I think it would be extraordinarily hard for such a change to make it through the internal immune system for such things. I think Mozilla is less likely to do bad things with your data than just about any other company (or government for that matter) out there.

(Disclosure: I work for Mozilla. I am helping write an updated set of privacy guidelines for engineering teams, to be as explicit as possible about how careful and respectful we need to be with data.)

Post reply on HN