Live data from Hacker News

Mozilla Stumbler 1.0

play.google.com

91–100 of 158 posts

Re: Mozilla Stumbler 1.0

#91
post #6

Earlier quoted context omitted.

Congratulations; I hope this gives us a safe, effective, open location service. The privacy policy[1] could be clarified for less technical readers, and even for others. I infer that collected data is anonymous because you write, 1) We receive publicly observable data about WiFi access points and cell towers around you, your estimated latitude and longitude, and the date -- Not associated with anything else, that may…

"fact of life of web server logging" = screw you, we're not even going to consider deleting our logs even as we talk a good line about how much we respect your privacy edit after downvote: also, mozilla engineering PMs will intimate on hackernews that it won't internally correlate and potentially sell any of the location and other information it most obviously could correlate about people, even though it has already…

We don't correlate your location data to ads. As a Canadian, that would actually be illegal and a violation of the Privacy Act.

We never got authorization from individuals to do that correlation.

We aren't perfect, but I think we do a pretty good job of respecting and protecting your privacy at Mozilla.

Re: Mozilla Stumbler 1.0

#92
post #58

Earlier quoted context omitted.

Can you say more about your privacy concern here? I'm not seeing it. As far as I know, the sole use of this database is to say, "if you can see this set of wifi networks, then you are probably at this GPS location." It's literally the same thing, except at a different electromagnetic frequency, as saying "if you can see houses with these addresses, you are probably at this GPS location." Kind of like a street map. I…

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

Here's an analogy:

Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house.

So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue:

1) A single person travels past your house and happens to notice which lights are on.

2) Someone travels past your house and records, on a piece of paper, which lights are on.

3) A Google car travels past your house and records, electronically, which lights are on.

Same thing with WiFi SSIDs here. It is like you standing on the roof of your home and shouting your ATM pin using a bullhorn, then complaining when someone else hears or records the information.

You want people to stop "monitoring" your SSID? Stop freaking broadcasting it at all.

Re: Mozilla Stumbler 1.0

#93
post #81

Earlier quoted context omitted.

"2) we may receive certain temporary data such as your IP address. This data is deleted after being used as follows". So yes, they do say they delete it. Also, Mozilla has a better track record with respecting user privacy than anyone else in this space. (And where is their intention to advertise?)

i agree that Mozilla has a better track record than most large tech companies in most areas, but that also sets a pretty low bar. i'm more of the opinion that if Mozilla really were as committed to user privacy as they claim to be, they might not respond so flippantly to questions about server logs. If it wanted to, Mozilla could even stop logging "certain temporary data such as your IP address." regarding Mozilla's…

Monitoring server logs is how we detected and implemented protection from a botnet scouring the database for SSID information.

Re: Mozilla Stumbler 1.0

#94

Earlier quoted context omitted.

No, Google was sued because in process of doing this, they "mistakenly vacuumed up e-mail messages, user passwords and other communication", that is, they recorded actual data packets instead of just the AP identifier.

does anyone really believe this occurred "mistakenly"?

As a programmer, I can completely believe I'd write a system for capturing and process beacons packets - to store the MAC and transmission power - that would also inadvertently capture and store data packets. In fact, using some off-the-shelve open source tools like Kismet, capturing data packets is the default - you need to manually disable it. That alone makes for an easy way to mess it up.

What I can't find is a "motive for the crime". What possible reason would they have to capture small samples of random data packets from random unencrypted APs?

Re: Mozilla Stumbler 1.0

#95

Earlier quoted context omitted.

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

You don't have to justify them, but the actual privacy-violating mechanism is worth explaining, no? What is it about SSID-based geolocation that compromises the AP owner’s privacy?

see my other comment for a hypothetical: https://news.ycombinator.com/item?id=8527229

through no fault of mozilla's, most home routers are ridiculously, pathetically insecure. this is not a situation that would be improved by making it easier to geolocate routers from specific vendors. if vulnerable routers become easier to find, my communications passing through that router could quickly become a lot less private. would mozilla be responsible? no. but that doesn't mean mozilla sharing my probably-vulnerable router's location wouldn't play a role in compromising my privacy.

Re: Mozilla Stumbler 1.0

#96

Earlier quoted context omitted.

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

Here's an analogy: Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house. So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue: 1) A single person travels past your house and happens to notice which lights are on. 2) Someone travels past your house and records, on a piece of…

Analogies are analogies because they're similar, not identical.

> You want people to stop "monitoring" your SSID? Stop freaking broadcasting it at all.

This is technocentrical BS, washing the hands to justify doing what you want.

1) Most people don't know that their SSIDs are being recorded (with position), so how do you expect them to make an informed decision? It's not like the information is readily available (I work in IT and I did not know about appending "no_map" to the SSID).

2) Everyone has a router, broadcasting the SSID. Do you really and honestly expect everyone to know how to disable it?

Re: Mozilla Stumbler 1.0

#97

Earlier quoted context omitted.

i agree that Mozilla has a better track record than most large tech companies in most areas, but that also sets a pretty low bar. i'm more of the opinion that if Mozilla really were as committed to user privacy as they claim to be, they might not respond so flippantly to questions about server logs. If it wanted to, Mozilla could even stop logging "certain temporary data such as your IP address." regarding Mozilla's…

Monitoring server logs is how we detected and implemented protection from a botnet scouring the database for SSID information.

there are indeed many useful ways that server logs can positively contribute to improving user privacy; i just thought the attitude of "well of course...that's what everyone else does" (even though that's true!) was dismissive of good-faith privacy concerns.

Re: Mozilla Stumbler 1.0

#98
post #90

Earlier quoted context omitted.

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

But SSIDs are not private. At all. Should what the outside of your house look like be private information? How would that work? What about when I appear in the background of a photo someone took on the street?

> Should what the outside of your house look like be private information?

Everyone knows that someone can record the outside of your house; not everyone knows that SSIDs with location can (and actually are!) registered. Do you notice the difference? You can't assume that WLAN specifics are as tacit as knowing that people can look at my house!

Re: Mozilla Stumbler 1.0

#99

Earlier quoted context omitted.

Your point is wrong from the beginning: I don't have to explain my privacy concerns, and neither do the others who don't know what an SSID is. "Privacy" should be the default and without need for justification, not the other way around.

Here's an analogy: Everyone who travels past your home can see if the lights are on in the evening. They can also see which lights are on in the front of the house. So I'm going to give you three scenarios and I want you to tell me when exactly it becomes a privacy issue: 1) A single person travels past your house and happens to notice which lights are on. 2) Someone travels past your house and records, on a piece of…

That solution is suboptimal. If you don't broadcast it, then properly provisioned clients have to probe for it. Which they do, on every channel. So you go from one device beaconing the SSID (your AP) to all client devices advertising it, on every channel.

Re: Mozilla Stumbler 1.0

#100

Earlier quoted context omitted.

I understand the sentiment but really feel like it falls when looking at the actual situation. It's checking on things that are broadcast outside of your own property, and even offering a way to opt out. It's like transmitting radio waves from your property and asking that no one listens. You have a control over the distribution method or whether or not it even exists.

so everyone should have to choose between having their home router's info added to large, aggregated databases and reconfiguring/not operating a router? i know plenty of people for whom that's not a choice they're likely to know about. perhaps mozilla/google shouldn't be able to dictate my SSID or its visibility just because they don't want to incur the cost/complexity of obtaining affirmative, informed consent.

Yes, everyone should have to chose that. This should be a choice to make when you are broadcasting a signal out beyond your property. This would be like arguing that your wireless network shouldn't show up in the dropdown list you see when trying to connect to a wifi network. If it's a major concern, then you always have the possibility of using ethernet, but this information is publicly available.
Post reply on HN