10 ms·
Maybe the industry should assign a bit in the BSSID to indicate a mobile AP that shouldn't be used for mapping purposes.
by gnu8 11y ago
Maybe the industry should assign a bit in the BSSID to indicate a mobile AP that shouldn't be used for mapping purposes.
- nitrogen 11y agoMaybe private data like BSSIDs shouldn't be used for mapping purposes in the first place.
- simoncion 11y ago> Maybe private data like BSSIDs... Is it private when you're screaming it on the street corner for everyone to hear? If we're talking about vocal utterances, the law says "no". It's... disappointing that the addition of a computer to a activity makes people lose sight of the similarities between that activity and very similar ones that have long-settled legal treatment. Edit: To drive the point home: There are many jurisdictions that require you to affix your street number to the exterior of the building in which you live using numerals that are sufficiently large to be read clearly from across the street. Noone would honestly make the claim that the data provided by those numerals is in any way private information, and that broadcasting your street number to everyone who was walking or driving by is in any way a breach of privacy. :)
- mindslight 11y agoIt's even more unfortunate that the committees designing these protocols don't think this way. People with an identifier number tattooed on their arm don't walk around continually reciting it. In fact, they generally wear long sleeves.
- mikeash 11y agoThat's the most unexpected and off-the-wall Godwin I've ever seen.
- mindslight 11y agoDoes being able to draw a parallel affect the validity of the point? Or is your memetic immune system misleading you? FWIW despite what our modern religion emphasizes, the Nazis were hardly the only ones to track prisoners with tattooed numbers
- mikeash 11y agoThe comparison between willingly assigned and transmitted MAC addresses and death camp tattoos is utterly absurd, both because it unnecessarily pulls Nazis into the conversation, and because they have no useful parallels purely from a technical point of view.
- mindslight 11y agoCalling them "willingly" transmitted is a bit of a stretch, given that people don't have much choice to turn just them off and defaults are a powerful thing. The useful parallel is the general inventorying and tracking of people. Luckily we don't have the rest of totalitarianism (yet), but this cornerstone is well laid due to naive designers. BTW you were the one who brought up the subject of Nazis.
- mikeash 11y agoRight, when you said "People with an identifier number tattooed on their arm" you weren't even thinking of Nazi concentration camp victims. Sure. Pull the other one. Every router I've ever seen has a pretty clear setup option for creating a hidden network. I agree that defaults are powerful, but they don't make it any less "willing," they merely expose people's indifference.
- mindslight 11y agoActually I was thinking of prisoners of the Japanese in WWII. As I said, the Nazis were hardly the only ones to number prisoners, and I suspect the phenomenon has more to do with technology than with the supreme evil tidily ascribed to losers of wars. I'm making a general point about identifiers and protocols. The same thing applies to client MACs, which are obviously being used to track phone users with wifi on. Obviously MAC addresses can be cycled, but that takes active diligence. If the protocol had simply been designed to eschew and hide such identifiers in the first place, the entire issue wouldn't even exist.
- simoncion 11y ago> It's even more unfortunate that the committees designing these protocols don't think this way. So. How would you design a system to permit associated or unassociated stations to passively determine whether or not they were in range of a given AP? Remember that unassociated stations may never have ever interacted with the AP in question before this moment.
- mindslight 11y agoThat's the easy part. If previous contact hasn't taken place, persistence is irrelevant. Simply envision the current system with a periodically changing BSSID as your proof of existence. If the AP and client possess a shared secret (as in WPA2), then there's no reason for a third party to be able to deduce any identifying information.
- simoncion 11y ago> That's the easy part. If previous contact hasn't taken place, persistence is irrelevant. A periodically-changing ID would do. Okay. How would you design a system to permit associated or unassociated stations to passively determine whether or not they were in range of a given AP? Remember that human-friendly names for a given AP are almost certain to collide.
- mindslight 11y agoFirst, for purposes of this comment I only need to address the situation where WPA2 is currently used (the majority of private APs). Second, I'm one person taking a few minutes to write a HN comment, not a design committee. Simple protocol: The AP and client have shared secret K (similar to the present WPA2 key). We define the identity of a network as this secret key. The AP can change "BSSID" every hour, while broadcasting [BSSID, Hash(BSSID, K)]. An interested client runs through their database of known private networks, checking if the broadcaster is any they know. This obviously has a number of shortcomings (eg our attacker is also known to groom people into uploading K to their silos), but it should illustrate the concept.
- datenwolf 11y ago> Is it private when you're screaming it on the street corner for everyone to hear? Yes, it is, if the screaming is between you and another person and not addressed at the public. > If we're talking about vocal utterances, the law says "no" Actually the law says "yes". At least in all the countries in which secrecy of telecommunications laws are in place. The general outline has been laid out by the ITU and the paraphrased rule is, that it is strictly forbidden to listen to communications to which one is not the intended communications partner and the signal is not addressed at the public. It's debateable if a SSID beacon is a public broadcast or not. But at least from most user's point of view their intention is not broadcasting to the general public if they set up an encrypted 802.11 access point.
- simoncion 11y ago> Yes, it is, if the screaming is between you and another person and not addressed at the public. CPC 632 disagrees with you. California is a two-party consent state when it comes to recording of conversations, but it does not require consent of both of the communicating parties if "...the parties to the communication may reasonably expect that the communication may be overheard or recorded." [0] I expect that you'd be hard-pressed to find a judge who would buy your theory that someone screaming out in public on the street corner would not reasonably expect that their communication might be overheard... regardless of to whom they were addressing their screams. > Actually the law says "yes". At least in all the countries in which secrecy of telecommunications laws are in place. ... The general outline has been laid out by the ITU... AFAIK, telecommunications law does not cover shouting-with-one's-vocal-cords-without-electronic-assistance-in-public. Do you have court decisions or rulings (that were not later overturned) that say otherwise? [0] http://codes.findlaw.com/ca/penal-code/pen-sect-632.html http://codes.findlaw.com/ca/penal-code/pen-sect-632.html
- schoen 11y agoYou can opt out of some of them with _nomap (maybe not all). https://duckduckgo.com/?q=ssid+nomap https://duckduckgo.com/?q=ssid+nomap
- FireBeyond 11y agoYeah, that's a horrific abomination. Why not "SSID_mappable"?
- knughit 11y agoBecause _nomap gets 99.999% coverage, and _mappable would get 0.001% coverage.