Live data from Hacker News

Mozilla Stumbler 1.0

play.google.com

71–80 of 158 posts

Re: Mozilla Stumbler 1.0

#71
post #34

Earlier quoted context omitted.

Is this really a thing? WTF? I feel very ashamed, as someone who works in IT, everytime this happens. I mean, people can opt-out, of course - but, in order to do that, they need to know what an SSID is, and how to change it. What about people who don't? Will we just assume that they don't care or that their opinion doesn't matter?

I guess you have a better suggestion, and am curious to hear about it.

Of course I do. Make this "opt-in".

Using SSID naming conventions to do this is just dishonest: most of the people who will be scanned won't know what an SSID is. Even if they do, and do have the competence to change it, how many of them will know about this convention? More than this: how many "home network owners" know that their networks are being scanned and georeferenced? This opt-out scheme is ridiculous and plain "hand-washing" - they obviously don't expect people to use it.

Re: Mozilla Stumbler 1.0

#72
post #34

Earlier quoted context omitted.

I guess you have a better suggestion, and am curious to hear about it.

Of course I do. Make this "opt-in". Using SSID naming conventions to do this is just dishonest: most of the people who will be scanned won't know what an SSID is. Even if they do, and do have the competence to change it, how many of them will know about this convention? More than this: how many "home network owners" know that their networks are being scanned and georeferenced? This opt-out scheme is ridiculous and pl…

"Make this "opt-in"" is a statement, not a procedure. How, and why? Would the cons outwheigh the pros?

Re: Mozilla Stumbler 1.0

#73
post #34

Earlier quoted context omitted.

I guess you have a better suggestion, and am curious to hear about it.

the obvious option is to request consent instead of violating people's privacy and make a dragnet data collection effort like this opt-in instead of opt-out. but that's clearly not the intention here, because how dare anyone question someone else's motives/objectives/priorities for collecting data about devices they don't own. in fact, we're supposed to think this is the "nice" version because a google-funded nonprof…

> seeing mozilla move in this direction while talking about how much they respect everyone's privacy is a strategic stumble indeed.

Yup. I'm as heartbroken as I can be with a company.

A "hand-washing" attitude towards privacy from Google, Facebook or a telco is expectable. But from Mozilla? This saddens me, way more than the support of DRM in the web.

Re: Mozilla Stumbler 1.0

#74

Earlier quoted context omitted.

the obvious option is to request consent instead of violating people's privacy and make a dragnet data collection effort like this opt-in instead of opt-out. but that's clearly not the intention here, because how dare anyone question someone else's motives/objectives/priorities for collecting data about devices they don't own. in fact, we're supposed to think this is the "nice" version because a google-funded nonprof…

> seeing mozilla move in this direction while talking about how much they respect everyone's privacy is a strategic stumble indeed. Yup. I'm as heartbroken as I can be with a company. A "hand-washing" attitude towards privacy from Google, Facebook or a telco is expectable. But from Mozilla? This saddens me, way more than the support of DRM in the web.

agree completely--it's one thing to do this sort of thing (it's probably legal, etc.), but to do it while claiming to be fighting for user privacy is really galling to me.

Re: Mozilla Stumbler 1.0

#75
post #72

Earlier quoted context omitted.

Of course I do. Make this "opt-in". Using SSID naming conventions to do this is just dishonest: most of the people who will be scanned won't know what an SSID is. Even if they do, and do have the competence to change it, how many of them will know about this convention? More than this: how many "home network owners" know that their networks are being scanned and georeferenced? This opt-out scheme is ridiculous and pl…

"Make this "opt-in"" is a statement, not a procedure. How, and why? Would the cons outwheigh the pros?

> "Make this "opt-in"" is a statement, not a procedure. How, and why?

I don't really care about the procedure; Snailmail, if need be. Convenience is not a valid argument for breaking privacy.

> Would the cons outwheigh the pros?

The answer to this is dependent on one's stance. As you may imagine, from where I stand, they do (clearly). I can't see any "logistical inconvenience" justify breaking privacy by default.

Re: Mozilla Stumbler 1.0

#76
post #58

Earlier quoted context omitted.

Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

How do you feel that privacy is being violated by scanning SSIDs and pinning those SSIDs to GPS coordinates? I believe JackC's point is that there isn't a privacy concern here. The consumer's router is blasting out the SSID for everyone to hear, just like if you were standing on your roof shouting, or had a poster on the outside of your house. There's nothing wrong with those things being recorded, what makes SSIDs different?

Re: Mozilla Stumbler 1.0

#77
post #58

Earlier quoted context omitted.

Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

I understand the sentiment but really feel like it falls when looking at the actual situation. It's checking on things that are broadcast outside of your own property, and even offering a way to opt out. It's like transmitting radio waves from your property and asking that no one listens. You have a control over the distribution method or whether or not it even exists.

Re: Mozilla Stumbler 1.0

#78
post #28

Earlier quoted context omitted.

The NOGAPPS project lists Mozilla Location Service support as an upcoming feature ( http://forum.xda-developers.com/showthread.php?t=1715375 ).

Great! And although that post was made June 2012 I note it has been maintained and has recent updates.

Hanno from Mozilla here. Marvin reached out to us about a month back and we have been slow to respond. He just got an email back a week ago. So I think this is still going to happen, but no concrete timeline yet.

Re: Mozilla Stumbler 1.0

#80
post #55

Earlier quoted context omitted.

How is this any different than robots.txt? I don't see your point. If you are ignorant enough to not know how to secure against such measly attempts at privacy breach, how will you secure against a more determined hacker? Further more the SSID is publicly broadcast, so that any device you authorized can identify and connect.

i didn't say i didn't know how to secure against something like this or that it was not legal. my point was that this approach to data collection, consent, and privacy sharply and directly contradicts claims mozilla makes to users about being committed to their privacy. i think this reflects the opposite. maybe a better analogy would be someone from the ACLU photographing everyone they saw in public: legal and easy t…

I understand what you're saying, but you have to draw the line between privacy and common sense at some point.

It has been understood for awhile now that you have no expectation of privacy in public, at least as far as not being photographed, talked to, etc. Most people would probably agree that the paparazzi taking sneaky pictures of celebrities buying milk at Kroger aren't being very classy, but they'll also probably say it's fair game at that point.

Likewise, I would argue that broadcasting your SSID over the electromagnetic spectrum is public. As far as privacy is concerned (I have a slightly different opinion when it comes to security) I still haven't seen any compelling argument explaining how having your SSID mapped to a location is an any way a violation of privacy. Maybe you have one?

Post reply on HN