Earlier quoted context omitted.
Congratulations; I hope this gives us a safe, effective, open location service. The privacy policy[1] could be clarified for less technical readers, and even for others. I infer that collected data is anonymous because you write, 1) We receive publicly observable data about WiFi access points and cell towers around you, your estimated latitude and longitude, and the date -- Not associated with anything else, that may…
"fact of life of web server logging" = screw you, we're not even going to consider deleting our logs even as we talk a good line about how much we respect your privacy edit after downvote: also, mozilla engineering PMs will intimate on hackernews that it won't internally correlate and potentially sell any of the location and other information it most obviously could correlate about people, even though it has already…
Mozilla Stumbler 1.0
81–90 of 158 posts
Re: Mozilla Stumbler 1.0
#82Earlier quoted context omitted.
https://location.services.mozilla.com/downloads
> wifi AP database You linked to the download page where there's only the Cell Networks database.
I wrote about some of the topics a while back. Not all of it is up-to-date but it gives the broader context: http://blog.hannosch.eu/2013/12/mozilla-location-service-wha...
Re: Mozilla Stumbler 1.0
#83Earlier quoted context omitted.
https://location.services.mozilla.com/downloads
> wifi AP database You linked to the download page where there's only the Cell Networks database.
https://github.com/mozilla/ichnaea/issues/330
In a nutshell though, we don't know how to do this yet without creating a privacy nightmare.
Re: Mozilla Stumbler 1.0
#84Will this still collect hidden SSID's?
The first check is "if we don't get a SSID, we don't collect". That's what happens with hidden networks.
Re: Mozilla Stumbler 1.0
#85Earlier quoted context omitted.
i didn't say i didn't know how to secure against something like this or that it was not legal. my point was that this approach to data collection, consent, and privacy sharply and directly contradicts claims mozilla makes to users about being committed to their privacy. i think this reflects the opposite. maybe a better analogy would be someone from the ACLU photographing everyone they saw in public: legal and easy t…
I understand what you're saying, but you have to draw the line between privacy and common sense at some point. It has been understood for awhile now that you have no expectation of privacy in public, at least as far as not being photographed, talked to, etc. Most people would probably agree that the paparazzi taking sneaky pictures of celebrities buying milk at Kroger aren't being very classy, but they'll also probab…
One hypothetical example: SSIDs often betray vendor names out of the box, and home routers are typically embedded devices that don't frequently receive security updates. Suppose Mozilla makes its database public and lists my SSID--or more likely, some weakly-secure hash of my SSID--in a public database that later gets compromised (e.g. plenty of people know their own SSIDs). Then, through no fault of Mozilla's, there's some 0day announced for my router. Now, every script kiddie in the neighborhood's using metasploit against a pre-selected list of vulnerable routers, potentially even remotely depending on their ability to integrate information from other sources. Maybe that sounds like more of a security issue than a privacy issue, but at some point, the effect is the same.
Re: Mozilla Stumbler 1.0
#86Earlier quoted context omitted.
"fact of life of web server logging" = screw you, we're not even going to consider deleting our logs even as we talk a good line about how much we respect your privacy edit after downvote: also, mozilla engineering PMs will intimate on hackernews that it won't internally correlate and potentially sell any of the location and other information it most obviously could correlate about people, even though it has already…
"2) we may receive certain temporary data such as your IP address. This data is deleted after being used as follows". So yes, they do say they delete it. Also, Mozilla has a better track record with respecting user privacy than anyone else in this space. (And where is their intention to advertise?)
regarding Mozilla's intention to advertise: http://www.zdnet.com/mozilla-clarifies-defends-firefox-ad-po...
Re: Mozilla Stumbler 1.0
#87Earlier quoted context omitted.
Of course I do. Make this "opt-in". Using SSID naming conventions to do this is just dishonest: most of the people who will be scanned won't know what an SSID is. Even if they do, and do have the competence to change it, how many of them will know about this convention? More than this: how many "home network owners" know that their networks are being scanned and georeferenced? This opt-out scheme is ridiculous and pl…
"Make this "opt-in"" is a statement, not a procedure. How, and why? Would the cons outwheigh the pros?
Re: Mozilla Stumbler 1.0
#88Earlier quoted context omitted.
Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.
I understand the sentiment but really feel like it falls when looking at the actual situation. It's checking on things that are broadcast outside of your own property, and even offering a way to opt out. It's like transmitting radio waves from your property and asking that no one listens. You have a control over the distribution method or whether or not it even exists.
i know plenty of people for whom that's not a choice they're likely to know about. perhaps mozilla/google shouldn't be able to dictate my SSID or its visibility just because they don't want to incur the cost/complexity of obtaining affirmative, informed consent.
Re: Mozilla Stumbler 1.0
#89Earlier quoted context omitted.
Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…
Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.
What is it about SSID-based geolocation that compromises the AP owner’s privacy?
Re: Mozilla Stumbler 1.0
#90Earlier quoted context omitted.
Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…
Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.