Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

BOFH excuse #287: Telecommunications is downshifting.


comp / comp.sys.mac.system / Re: Surveillance Risk: Apple's WiFi-Based Positioning System

SubjectAuthor
o Re: Surveillance Risk: Apple's WiFi-Based Positioning SystemOscar Mayer

1
Subject: Re: Surveillance Risk: Apple's WiFi-Based Positioning System
From: Oscar Mayer
Newsgroups: misc.phone.mobile.iphone, alt.privacy, alt.internet.wireless, comp.sys.mac.system
Organization: A noiseless patient Spider
Date: Tue, 28 May 2024 21:37 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nobody@oscarmayer.com (Oscar Mayer)
Newsgroups: misc.phone.mobile.iphone,alt.privacy,alt.internet.wireless,comp.sys.mac.system
Subject: Re: Surveillance Risk: Apple's WiFi-Based Positioning System
Date: Tue, 28 May 2024 17:37:05 -0400
Organization: A noiseless patient Spider
Lines: 36
Message-ID: <v35iq0$p81u$1@dont-email.me>
References: <v33u3t$2pm5$1@neodome.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Tue, 28 May 2024 23:37:06 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="9bd91a7a9535c4c07a18599852577e9a";
logging-data="827454"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19kpidBT3Xv5eaPehmI8nH9"
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Cancel-Lock: sha1:YhQI97liIsPae7D7svDsxd4XvHA=
Content-Language: en-US
View all headers

On Tue, 28 May 2024 00:37:49 -0600, Charlie wrote:

> Surveillance Risk: Apple's WiFi-Based Positioning System
> <https://www.govinfosecurity.com/surveillance-risk-apples-wifi-based-positioning-system-a-25330>

Why would Apple design a system so incredibly horrific against privacy?

Basically you can track anyone simply by asking Apple for their location.
No permission? No problem, says Apple. Here's their location & also the
location of the nearest 400 people to that person. How's that for privacy.

Researchers find Apple's Wi-Fi Positioning System represents a serious
privacy vulnerability.
<https://www.macworld.com/article/2343297/apple-wi-fi-network-wps-vulnerability-location-services-leak.html>

"Apple's WPS server sends up to 400 other known Wi-Fi networks that may be
in the approximate vicinity of the device as part of its crowdsourcing
location database.

From this list, the requesting device searches for eight possible variants
and calculates its location based on this data. Apple's WPS system, the iOS
device, and the router on which the network is based operate with the
so-called BSSIDs (Basic Service Set Identification) and usually correspond
to the MAC address of the device, which is static in most cases.

The request via Apple's APIs is free, so Rye and Levin sent 30 requests per
second with 100 guessed BSSIDs.

The information on the current static location alone is life-threatening in
the wrong hands, as it indicates the location data of the Ukrainian
military units and of refugees as they move about in the Gaza Strip.

With Apple & Google, you can add "_nomap" to your Access Point SSID.

However, Microsoft requires you to give them all your MAC addresses first!
https://account.microsoft.com/privacy/location-services-opt-out

1

rocksolid light 0.9.8
clearnet tor