Live data from Hacker News

iOS 8 randomises the MAC address while scanning for WiFi networks

twitter.com

231–240 of 264 posts

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#231
Has anyone stopped to ask if this is confirmed/true? TechCrunch/Gizmodo/etc... all picked up on this from Frederic's tweet but is a tweet really a definitive news source? Apple has been historically taciturn about documenting these things but does anyone have any more docs or sources for this issue?

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#232
post #106
post #6

If this becomes the trend (which in my opinon would be nice) it will become a big problem for companies that specialise in customer tracking e.g. for supermarkets and big department stores. Previously it was quite easy to track a customer, how long he or she spends time in the store, which floors he or she visits, etc. by putting up dummy WiFI-networks that the customers phones find by giving out their MAC-addresses.

Isn't that suppose to be illegal in first place? I mean without actual consent, tracking a device... Doesn't sound extremely ethical. That said in some airports, changing MAC address is illegal. Now that the iPhone will support the feature and most owners will have no idea what's happening, I guess these airports will have to change policy :-)

> That said in some airports, changing MAC address is illegal.

Would you mind providing some links? I'm interested to see how it's laid out

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#233
post #191

Earlier quoted context omitted.

I was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.

If you don't give your name or other identification, how would they hold you responsible if you abused the connection?

It's not that, trust me. They make good money with your data. Take it as a way of payment for the "free" wifi.

It helps the same purpose as the loyalty cards, especially the ones that outgrow the original business (I'm looking at you both Tesco ClubCard and Nectar Card). Getting "points" by using those at other businesses like petrol stations helps them profiling you for "better" advertising. They also keep you a bit more loyal to their associated brands, but we already knew that bit :)

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#235
post #217

Earlier quoted context omitted.

Assuming they track every single purchase made at a store along with the credit card number used (or at least some form of ID associated with that particular card), and all the times the MACs left the store, how many sets of data do you think they need to get a 1:1 match between MAC and person? Even for really large stores, I'm guessing it would only take 2-3 visits before they can link you to POS records with decent…

Amazon, does this and it creates (for me) a better shopping experience. When I go to amazon it knows what things I want to buy and puts them right in front of me. Then it points me to other items that are related. Amazon knows precise,y what I look at and for how long before I buy it. Why is this good for online shopping and bad at a B&M store?

I think most people (including me) would probably agree that all this tracking creates a better shopping experience. Taken to its logical conclusion, eventually the stores will know what I want to buy before I even know I want it- they'll place it front and center in front of my face, said face will light up in sudden understanding that this is what I've been missing all my life, and money will exchange hands. Snark aside, I really do agree that this is a better shopping experience.

But we're not just talking shopping experiences here- the data, algorithms, and extra tracking that fuels the (perhaps extreme) future I described above has costs, mostly in personal privacy. Maybe I don't want the conglomerates (and the government, since we all now know they've got their 'black boxes' in the datacenters) to know my penis size, how good my relationship with my father is, what medical conditions I have, and just about everything else one can think of. However, this is the future we're headed towards.

Secondly, I think _greim_ said it very well in this post elsewhere in the thread: "Giving marketers deep psychological and behavioral insight increasingly enables them to circumvent rationality and "hack" consumers in various ways." There is a fine line, I think, between offering exceptional shopping experiences and manipulating your customers.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#236

Earlier quoted context omitted.

I was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.

Name and email, you say? Check out the form you need to fill in to use free wifi at Brazilian airports: http://brazilsense.com/index.php?title=Wi-Fi_and_Internet_se... They want your: name sex marital status nationality place of birth profession identity document type identity document number street address city state country cellular phone number name of cellular provider landline phone number email address barcode…

At Beijing airport if you're not Chinese they require a scan of your passport photo page at a special kiosk where they then give you a unique access code....

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#237
post #51
post #45

Earlier quoted context omitted.

Maybe I'm a little high on design rhetoric right now, but I see this less in terms of Apple being a privacy/security company and more along the lines of Apple being a user-centered design company. No user wants their data shuffled around and sold, so any company that relies on the commodification of its users' data is inherently at odds with its users' needs.

Google probably also sees themselves as user-centered by providing advanced services for free.

It's an absolute fallacy that Google provides services for free. In fact, it is more much more expensive:

1. The advertisers who pay google get their money from us, added to the prices of the things we buy. There is no free lunch.

2. The overhead cost of advertising is huge and we pay for that too.

3. We pay the opportunity cost of a product that cannot put users first because they live or die by giving advertisers what they want (and what we want indirectly and secondarily). This includes both the cost of lost privacy as well as well as design that optimizes advertising revenue. As has been said, we are more Google's products than we are their customers.

4. We pay the social costs. Democracy and the free market assume people make voting and purchasing decisions based on facts and reason. Advertising as predominantly about manipulation and deceit. I believe this is the most expensive cost of services that rely on advertising revenue.

Added together, we are paying a lot more for "free" web searches and email than if we could just straight up pay Google for straight-up ad-free versions.

[This is a condensed version of a more detailed case with reference links that I made here: https://news.ycombinator.com/item?id=7485773]

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#239
post #192

Earlier quoted context omitted.

I was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.

Hello, my name is Guy Incognito. My email address is gincog@example.com. Unless it requires you to click a confirmation link or something similar to that, just use a fake address at one of the example.TLD domains. If they DO require confirmation, use mailinator or a similar service.

Catch 22 there: you have to be able to access mailinator.com in order to generate a throwaway email.

Re: iOS 8 randomises the MAC address while scanning for WiFi networks

#240
post #163

Earlier quoted context omitted.

> The MAC address is stable once a device is authenticated (connected) to the network. That is necessary to keep the gateway from having to issue a thousand ARP requests (one for every packet you send from a different MAC), but there is no reason why the MAC chosen to connect to the network couldn't change every time you disconnect and reconnect. That would at least prevent you from being tracked between visits to th…

True but wouldn't the landing pages of most of these services be able to document the OS, browser, resolution, type of device(tablet vs laptop and IOS vs android) and likely a lot of other stuff. I can narrow down a huge list to a very short list using above information along with the probes being sent out co-related to the signal strength. Timing of each probe can also be leveraged in uniquely identifying,most probe…

Hence the "using this tracking method" caveat. Now you have to do something much more complicated just to get less specific data. And it's a cat and mouse game: You put up a useless landing page, device makers set their browsers to require TLS for any page previously found to support it, preventing you from redirecting requests to the majority of popular sites. Or they could just detect the ARP misuse that makes captive portals work and patch that particular vulnerability, because screw captive portals entirely.
Post reply on HN