Email or username:

Password:

Forgot your password?
Top-level
Brad Rubenstein “:verified:”

Incidentally that means, so long as your access point broadcasts its WiFi network name, you are also broadcasting (to everyone who can hear it) whether you've opted out. It's not just between you and Apple.

Not to mention that changing your SSID disconnects everything using it.

It just sucks all around.

@briankrebs

11 comments
tw000

@BradRubenstein @briankrebs I haven't seen it mentioned yet, but I guess they have to disambiguate Corporate or large WiFi networks by BSSID and MAC? Add another thing to the stack of "I'll dig into this when I get some time."

Brad Rubenstein “:verified:”

Thought experiment:

So, just supposing one finds oneself able to RCE into a machine in that happens to have a wifi card, just have it scan and list the access points in its vicinity.

That will give you everything you need to ask Apple (via its API) for the set of all the nearby access points, to calculate fairly precise GPS coordinates of that box, along with the ability to watch that set change over time to see what comes and goes.

But why would anyone want such a thing? I have no idea.

@briankrebs

Thought experiment:

So, just supposing one finds oneself able to RCE into a machine in that happens to have a wifi card, just have it scan and list the access points in its vicinity.

That will give you everything you need to ask Apple (via its API) for the set of all the nearby access points, to calculate fairly precise GPS coordinates of that box, along with the ability to watch that set change over time to see what comes and goes.

The Secretbatcave

@BradRubenstein @briankrebs The name used for it in location circles is WPS en.m.wikipedia.org/wiki/Wi-Fi_

There are a bunch of open APIs that allow navigation. I think Google had a semi public API at some point until a country took the@ to court for unlawful packet capture.

For phone makers it allows them to provide location services with a super low power budget. (GPS eats battery and you’re normally scanning for WiFi anyway)

Luci for dyeing

@BradRubenstein @briankrebs that’s exactly what apple uses it for: geo locating devices that do not have gps radios.

Amy ☣

@BradRubenstein@infosec.exchange @briankrebs@infosec.exchange How hard would it be to trace where someone's been based on what access points a device has accessed or saved? Or even seen from their phone? Like, would it be possible for one to figure out someone has visited an abortion clinic if there's a history of their phone seeing access points that are near the clinic?

Manawyrm | Sarah (☎️ 6502@GPN)

@BradRubenstein @briankrebs That's nothing new, this has been the case for the last 20 years?

Community-run WiFi mapping projects exist, even Mozilla has such a database (MLS).

still can't work out who i am

@BradRubenstein @briankrebs this is the same shit that Google did with mapping isn't it

Stephen Paulger

@BradRubenstein everyone that can hear it includes Wigle users. Wigle has mapped 1301 _nomap networks. Many of them are from before though.

wigle.net/search?ssidlike=%25_

Go Up