21 ms·
Retail stores use Bluetooth beacons to track customers
- legitster 7y agoThis is really big in the WiFi space. Aruba, Cisco, etc all market services to public places like malls where you throw in a huge public wifi network, and regardless of whether you connect or not, they can see phones looking for known network and track traffic patterns. Malls can then see which stores have highest foot traffic on what days, etc. It's actually one of the things that justifies the expense for huge, expensive free wifi deployments. And it is used to more accurately price locations around malls. The other alternatives to getting the same kind of data is security camera analytics. Sometimes literally someone just watching footage and taking notes on who they see and what kind of demographics, etc. Which is problematic in it's own right.
- TaylorAlexander 7y agoWell they automate the security camera analytics now too. I just saw this one recently: https://www.sentinelcv.com/ https://www.sentinelcv.com/
- TecoAndJix 7y agoA lot of Verizon stores are owned by third-party companies. I had the chance to speak to one of the regional reps in a college class and he told me his company [1] does facial tracking of everyone who comes in the store. It also monitors employees and how many breaks they are taking/what they are doing (like hiding in the stock room). [1]https://www.tccrocks.com/ https://www.tccrocks.com/
- asdff 7y agoMy uni did this to tell you how busy the libraries were.
- css 7y agoSo... turn off Bluetooth and Wifi when you go into a store? Put subtle lines on your face with makeup to confuse their facial recognition systems? What else do we need to do now to go out in public?
- mschuster91 7y agoWhat you need is something similar to EU-GDPR! This would be illegal on so many levels in Europe.
- asark 7y agoExtend laws against creepy stalking to mass, blanket versions of same, even when a corporation does it, online or IRL.
- module0000 7y agoPhysically dismantle every data broker's office and data center? Not sure what else would be effective.
- asdff 7y agoTurn off your phone?
- jandrese 7y agoIIRC turning off Bluetooth does not turn of BTLE, at least on some devices. So even if it is "off" you can still be tracked.
- notJim 7y agoHonestly, part of this doesn't bother me that much. It doesn't bother me for a store to know where I'm standing while I'm in their store. What does bother me is the part where they can get lots of other data and use it to build a profile of me that spans far beyond their store. The fact that this Pulsate company encourages devs to include my email address, for example, seems really invasive, and probably would be illegal under the GDPR?
- itronitron 7y agoyet another reason to just shop online or at mom-and-pop shops
- ddavis 7y agoYou know tracking customers is a hell of a lot easier online. Mom-and-pop shops are probably the only way to go to avoid being targeted now.
- gerbilly 7y ago> Mom-and-pop shops are probably the only way to go to avoid being targeted now. Yeah, and pay cash before they get rid of it and make us all pay for everything with wechat bucks or whatever.
- legitster 7y agoMom and Pops are likely using this technology too. Location analytics are a built-in feature of many sub-$300 access points.
- kevin_b_er 7y agoAndroid has a feature called "nearby device scanning" so even if you turn off bluetooth, apps can still do BLE. I suspect stuff like this, where many many apps can spy on you on behalf of others, is why Google made BT access a Location category. But it means your weather app that uses location to tell you where you are? It is selling your location via BT beacons to 3rd parties.
- xur17 7y agoI really wish android differentiated between foreground and background location permissions.
- imperialdrive 7y agoMeet the newest Android Q (10) which is available as a beta. The permission levels are there for what you wish. It's impressive to see just how many apps were previously getting background location (and many other) permissions by default. Eye opening experience for someone that figured it wasn't that bad.
- xur17 7y agoThat is very good to hear - excited to try it out.
- cherrypepsi 7y ago> Meet the newest Android Q (10) which is available as a beta. The permission levels are there for what you wish. I would like to congratulate Google for such hard work. I mean, CyanogenMod 7 in 2010 could revoke any app permission at the user's will, but you know, computers are difficult
- OrwellianChild 7y agoFor those who are interested, this feature can be deactivated. The location in settings has moved around a bit, but you can just search for "nearby device scanning" and shut it off for both Wi-Fi and Bluetooth.
- ajkjk 7y agoNothing would make me want to buy yogurt less than an ad on my phone while I'm looking at yogurt. I would hope everyone would feel the same way, to disincentivize this.
- tlholaday 7y agoI agree, ads should go to wrist, not to phone.
- halbritt 7y agoThis is what I'm thinking. The first time this happens, I'm not going to buy the thing, but I'm going to jump through whatever hoops are necessary to disable this feature on my device. If that doesn't work, I'm going to get another device and then I'm never going to patronize whatever retailer did this. I suspect eventually this will make people irate and these sorts of things will become opt-in.
- _bxg1 7y agoThe best way to protest surveillance capitalism is to make it ineffective. If you get a pushy or creepy ad, go out of your way to avoid that product or brand. Even if it is appealing to you. Even if it's a good deal. Send the strongest kind of signal against targeted ads: money.
- TeMPOraL 7y agoI do whenever I can. For instance, for close to a decade now I maintain a blanket ban on Groupon for that one time they spammed me with retargeted ads a bit too hard (3+ same ugly pink ads simultaneously on a single webpage).
- RobertDeNiro 7y agoI would agree. But the skeptic in me thinks that once this behaviour is mainstream enough, people will forget how outraging it is and just accept it.
- bdz 7y agoApple's iBeacon location-aware shopping goes live today (2013) https://www.theverge.com/2013/12/6/5181302/apple-store-ibeacon-rollout https://www.theverge.com/2013/12/6/5181302/apple-store-ibeac... Beacon Technology Arrives in 50 Target Stores (2015) https://corporate.target.com/article/2015/08/beacon-technology https://corporate.target.com/article/2015/08/beacon-technolo...
- madMapper 7y agoNow that the privacy pendulum is swinging the other way I'm curious if Apple will ultimately be the undoing of this thing they helped create. If devices using iOS 13 start broadcasting a constantly changing bluetooth ID as a part of the new "Find My" feature these systems won't be able to track users from beacon to beacon or know how long you were in range of a single beacon. This will probably wreak havoc on traffic counters and other infrastructure that use bluetooth bacons to do things like monitor highway congestion and foot traffic
- eunoia 7y ago> If devices using iOS 13 start broadcasting a constantly changing bluetooth ID They've always done this. I think you have your threat model inverted. Beacons aren't tracking phones around stores. 3rd party SDKs installed in apps are tracking user's indoor location via beacon triangulation and uploading that data. A subtle, but important difference.
- dawnerd 7y agoI didn't know it was a secret? Figured it was pretty common knowledge back when iBeacons and similar were announced and when major retailers like Target even made press releases about it https://techcrunch.com/2017/09/20/target-rolls-out-bluetooth-beacon-technology-in-stores-to-power-new-indoor-maps-in-its-app/ https://techcrunch.com/2017/09/20/target-rolls-out-bluetooth... Kind of funny that Apple pushing privacy basically helped create this kind of tracking to begin with. Edit: NYT article mentions other apps selling data to retailers. I think it's time apps start asking permission to use BTLE. No reason a weather app needs that kind of access.
- notJim 7y agoI had heard of the technology, but had no idea how widespread it was. To be honest, I had assumed it never took off.
- raverbashing 7y agoApple? Maybe it's the big stores and advertisers want to know everything about everybody that are to blame?
- dawnerd 7y agoYes Apple. They rolled out iBeacons and created a whole toolkit on ios that enabled tracking - at least a lot easier than it would have been.
- raverbashing 7y agoThanks, this makes sense, though beacon technology is not exclusive to them
- slg 7y agoWasn't this tracking the defining business use case going all the way back to when Apple introduced them in 2013? These devices might not be well know, but I don't think anyone was actively trying to hide why businesses were installing these things.
- 7y ago
- eastbayjake 7y agoA provocative thought experiment: are you more annoyed by retailers recommending a product you just purchased from them, or a retailer recommending a product you probably will need soon? In a world blanketed by advertising, I would rather see relevant advertisements than be bombarded by garbage. Maybe I will get a deal, maybe I will discover something I like, maybe I will ignore it... but the spray-and-pray untargeted advertising that tries to advertise arthritis medication to me as a 31-year-old man is guaranteed only to annoy.
- ceejayoz 7y agoIn isolation, I'd prefer the better targeted advertising. In reality, I'm not comfortable with the amount of privacy violation getting that targeted ad requires.
- frgtpsswrdlame 7y agoI find highly relevant advertisements creepy. A sort of advertising uncanny valley. I'll take the minor annoyance of a garbage ad bombardment any day over, what is to me, the much more concerning feeling of being surveilled.
- kardos 7y ago> Maybe I will get a deal, maybe I will discover something I like This is what the ad industry exploiting the fear of missing out [1] looks like when they tout the virtues of "relevant ads". You might draw a comparison with casino marketing to gambling addicts, alcohol to alcoholics, etc -- it's rather slimy. [1] https://en.wikipedia.org/wiki/Fear_of_missing_out https://en.wikipedia.org/wiki/Fear_of_missing_out
- 2bitencryption 7y agoam I understanding this mechanism right? 1. Set up a bluetooth beacon in the diary aisle that broadcasts as a connectable (nor not?) device with an "SSID" (or the bluetooth equivelant) that is a known GUID 2. apps on your phone can scan for available bluetooth devices, and see the presence of the GUID, which is enough for them to know you are in the dairy aisle of Store 1234. if that's right, does this mean disabling bluetooth, or restricting a device's access to scan for devices, will preclude this?
- Malic 7y agoBasically it means those loyalty apps stores put out? Are you sure you know what that app is doing...? You are right that disabling bluetooth or being aware of what apps your phone has is what is required.
- seieste 7y agoYou don't need the Target app to be tracked by Target, since the tracking beacon code can be in any number of unrelated apps (weather, news, games, etc.)
- andrewgioia 7y agoThis is rage inducing. I went into this article thinking "ok as long as I don't have the Target or Ikea or whatever app installed on my phone, I'm fine." While that is a primary way, this needs to be outlawed: > These companies take their beacon tracking code and bundle it into a toolkit developers can use. The makers of many popular apps, such as those for news or weather updates, insert these toolkits into their apps. They might be paid by the beacon companies or receive other benefits... Ban this, full stop, on both ends of this transaction. The Reveal Medias and the scummy app devs using their ~~SDKs~~ trojan horses. At the very least these apps need to be named and shamed, I find this fraudulent and extremely difficult for end users to police. I have very minor hope that Apple at least will one day shine light on this or ban apps who are not transparent about the data they're sending and to whom, as it doesn't conflict with their business model and they seem to be moving there. For now I have to essentially disable bluetooth when I get out of my car.
- sysbin 7y agoI'm guessing this can be policed by a service allowing the user to see a map containing location detail & time accessed information per apps installed. Thus, showing the user which apps installed are signaling with bluetooth and when they're entering specific stores throughout the day.
- nickpsecurity 7y agoSounds like a good idea!
- jon-wood 7y agoThis is a feature that's being added to iOS 13, along with occasional popups reminding you that an app has location privileges, and a map of where it's been tracking you. https://9to5mac.com/2019/06/08/ios-13-location-permissions/ https://9to5mac.com/2019/06/08/ios-13-location-permissions/
- rolltiide 7y agoThis is how an app like Facebook can show you an ad on something you were talking about. It would be naive to point the finger at Facebook listening to you, it would be more accurate to assume its EVERY OTHER app (including FB) gathering data about you and your surroundings - MAYBE ONE IS ACTUALLY LISTENING - but whether any individual app is or isn't, the data brokers have all the data as well as other people like you that have probably reacted to the same external stimulus and can be predicted to be thinking about a certain product around that point in time. POOF - an ad about that thing you talked about, now on your Facebook feed. Zuckerberg gets hauled in front of Congress, accurately says "what? no we don't do that", data brokers and software engineers laugh to the bank and let Zuckerberg get crucified for their sins.
- decebalus1 7y agoThis book https://www.amazon.com/Aisles-Have-Eyes-Retailers-Shopping/dp/0300212194 https://www.amazon.com/Aisles-Have-Eyes-Retailers-Shopping/d... goes into quite a bit of detail about various techniques retailers use to track customers.
- dTal 7y ago>Location marketing aims to understand “online-offline attribution.” If a Starbucks coffee ad is sent to your email, for example, marketers want to know if you actually went there and bought a coffee. The only way to know is to monitor your online and offline habits at all times. Make no mistake: the purpose of marketing is to maximize information asymmetry. The natural end point is totalitarian: they know everything about you, and you know nothing at all, blindly obeying.
- cortesoft 7y agoThat is not the purpose of all marketing. That might be the purpose of this kind of tracking, but I don't think telling people the product you created to serve their need is inherently evil. At its best, marketing is a way to let people know the goods and services you have that can make their lives better. This is marketing at its worst. I really enjoy this explanation of why targeted advertising is such a horrible thing: https://zgp.org/targeted-advertising-considered-harmful/ https://zgp.org/targeted-advertising-considered-harmful/
- TeMPOraL 7y ago> This is marketing at its worst. This is marketing at its real. As practiced. > I don't think telling people the product you created to serve their need is inherently evil. Of course it isn't evil, but this is not what marketing is doing - and claiming so amounts to a motte-and-bailey defense of an industry that's rotten to the core and quite openly malicious towards their fellow human beings.
- cortesoft 7y agoI am not defending these practices at all, I am just saying the idea of marketing is not inherently evil. I also think you are being unfair if you say there are zero companies that do marketing right.
- TeMPOraL 7y agoI won't go so far as to say there are zero companies doing ethical marketing, but I am convinced there are very few of them - simply because ethical marketing is at severe competitive disadvantage to unethical one.
- bb101 7y agoShouldn't there be a setting under Privacy to turn responding to beacons off? I'd be interested in a list of popular apps or SDKs that use beacons -- so I could uninstall them pronto.
- seieste 7y agoThe cynical part of me thinks this is the real reason to get rid of the headphone jack -- to make it inconvenient to turn off bluetooth.
- TaylorAlexander 7y agoOn the iPhone turning off Bluetooth using the control center doesn’t even turn it of fully, precisely so that these location services (and other features) are still available. https://www.vice.com/en_us/article/evpz7a/turn-off-wi-fi-and-bluetooth-apple-ios-11 https://www.vice.com/en_us/article/evpz7a/turn-off-wi-fi-and...
- brianzelip 7y agoThis is such a dark pattern.
- ac4tw 7y agoIndeed. Sidenote, it behaves differently if you've enabled airplane mode (or at least so the UI would indicate). In airplane mode, it gives no message and the wifi/bt icon goes transparent. If you're not in airplane mode, the wifi/bt icon goes light gray and it says 'disconnecting <device type> devices until tomorrow' but the radio is still on as your article mentions. Personally I miss the old behavior where it just turns it off, but I'm often in airplane mode so I get the old behavior anyway and great battery life :P
- shrimp_emoji 7y agoOn the other hand, I'll tolerate whatever dystopic hellscape before going back to the tangly shitshow of wired earbuds.
- delecti 7y agoConveniently, thanks to modern technology, you can have a headphone jack and bluetooth support on the same device.
- eddiecalzone 7y ago
- TaylorAlexander 7y agoYep and I’ve been researching this for robotics. The new WiFi standard 802.11mc includes improved time-of-flight measurement of radio packets such that the device can be localized to within 1 meter reliably. Android 9 and the Pixel already support this, though WiFi APs supporting this are still in the early phases. Google WiFi supports it tho. The good news is that this technology does not tell the AP where you are, only the device knows. However an app on your device could share this information with advertisers. https://www.crowdconnected.com/blog/testing-wifi-rtt-on-android-p-for-indoor-positioning/ https://www.crowdconnected.com/blog/testing-wifi-rtt-on-andr...
- spockz 7y agoSo when can we start using this stuff to get indoor navigation or navigation inside tunnels to work properly? If we are being tracked we should get some benefit from it as well.
- muricula 7y agoIn order for this to work the apps have to listen to bluetooth signals from the beacons (or register a hook for an OS level beacon listening service?). How do I prevent an app from listening to bluetooth? Is this gated by the iOS "access current location" permission, or the "bluetooth sharing" permission? The iOS docs I've found are unclear: https://developer.apple.com/ibeacon/Getting-Started-with-iBeacon.pdf https://developer.apple.com/ibeacon/Getting-Started-with-iBe...
- HaloZero 7y agoIs there a way to determine which apps have the SDKs from Reveal or other companies?
- smilliken 7y agoYes. My company (MixRank) downloads and analyzes mobile apps. Among other things, we determine what SDKs, APIs, etc, an app uses. We have 20k SDKs identified and track all of their installs/uninstalls.
- wkavey 7y agoI actually implemented a nearly identical system for my senior design project, except we targeted the smart home ecosystem. Basic use cases would be automatically turning on/off lights or having a music stream/temperature preference/... follow you as you move throughout your house and enter/leave rooms. All implemented by an app on your phone detecting strategically placed beacons.
- vertoc 7y agoHaha I did a very similar thing for mine - it was using these to replace clock in systems for hourly workers, no more need to clock in or out, the app would auto detect when you entered/left the building
- takk309 7y agoBased on the title of the article I was expecting the stores to passively collect data based on the MAC address. I guess I was way wrong. I am a traffic engineer and we use passive BT MAC address scanners to sort out origin/destination and travel time. This is done by setting up multiple detectors around a study area. Each detector saves the time and MAC address of every device it detects. We later match the MAC addresses that have been detected at multiple locations and that gives us the travel time between them. The raw data is rather useless for any other purpose, to us at least, and is tossed after we are confident in the data results. If a store were to use something like this, they would have to tie my MAC address to me, which I doubt would be too hard. I don't see anything wrong with passively tracking people in a store, mall, shopping center, etc., as long as it is used to inform the owners of movement patterns in the area. To use the information to push notifications and determine purchasing habits of people is over the line.
- wkavey 7y agoTo me there is a difference between what you describe, where hardware deployed in stores collect detected bluetooth signatures, and what this article describes, which is YOUR OWN DEVICE reporting on your movements.
- crazygringo 7y agoI feel like I need a lot more clarification here, can anybody help out, whether on iOS or Android: 1) Some random third-party app has to be running on your phone to detect beacons and send the data back... how viable/likely is this actually? It seems like this would only ever effectively detect a tiny percentage of users at best who just happen to have one of the apps open while walking around a store? 2) For an app to detect beacons, don't you have to give permission for the app to use Location Services? I've tried Googling it but can't seem to find a definite answer... I'd be surprised (and saddened) if Apple or Google are allowing apps to detect beacons without explicit location or Bluetooth permissions. 3) If the goal is to track as many users as possible... wouldn't it be far more efficient to look for Wi-Fi devices that are scanning, and identify them by their MAC address? I don't understand what Bluetooth beacons enable that Wi-Fi scanning doesn't. 4) The article lists companies that provide these third-party toolkits... but not a single name of an app that uses them, or what percentage of phones contain an app with them. Since this is the main accusation of the article... I don't understand why they wouldn't provide even a single instance of proof. I've just seen a lot of very questionable reporting from the NYT in the past on tech/security/privacy, so I'd like to understand better how real this is or not.
- vertoc 7y agoUnsure about the others but for (2), no. These beacons use low energy Bluetooth so when the app finds a beacon with just Bluetooth (which doesn’t require explicit permission afaik) it can simply report back with that - presumably the owner of the beacon (the store) knows where the beacon is and now they know your approximate location without any phone location services necessary
- wkavey 7y agoI can answer some of these... keep in mind this perspective is from the Android ecosystem, where I was able to get a similar system working. 1. Apps can be running in the background. I'd say its more common than you think 2. You need to provide location permissions (either the ACCESS_COARSE_LOCATION or ACCESS_FINE_LOCATION). It seems like every app requests these permissions anyway, so not a red flag just on its own. 3. Something scanning for a WIFI devices has no way (easily) to coorelate those addresses back to a user. With this bluetooth low energy method, the users own phone is the one who reports the detection back to {company}'s servers, so it can pass along any/all other information it has about you. Their location accuracy is also pretty crazy (radius is within centimeters if they've done it well). 4. Bluetooth low energy is actually crazy easy to set up, see here for more... https://developer.android.com/guide/topics/connectivity/bluetooth-le https://developer.android.com/guide/topics/connectivity/blue...
- dreamcompiler 7y agoNot if I keep Bluetooth turned off, which I usually do. Admittedly this is easy for me since my phone still has a headphone jack.
- russh 7y agoYou may have been misinformed about the effectiveness of keeping Bluetooth "turned off".
- dreamcompiler 7y agoI also keep Location History and Bluetooth scanning off, just because I want less Google in my life. Apparently those are important too. [0] https://qz.com/1169760/phone-data/ https://qz.com/1169760/phone-data/
- social_quotient 7y agoIt’s worse. I have personal knowledge from a lot client work in this space. There are companies offering some basic functions like “wayfinding” so the retailer or mall wants to give wayfinding to the user in their app. Sounds good, in fact it’s cheap, and they will even handle the beacon deployment... hook up sdk to wireshark and find it sending lots of data, some of it comes to me (retailer api) but a metric ton of it is going back to the provider. Being able to see the installed solution in multiple retailers and seeing the app code you start to notice persistence between them... retailer and mall didn’t even ask for this. They just wanted wayfinding.
- AndrewKemendo 7y agoYes that's exactly how this gets implemented in practice. I did quite a bit of client work here too, specifically around using already existing surveillance camera networks to build user profiles. At the end of the day the goal is to optimize for the intersection of "what the user wants" and "what we want to sell." So, a low collection system will give bad recommendations and a really good recommendation system will have an immense amount about the user. Now that I talk with people on the other side of this, it's clear that most don't really care as long as they are getting good suggestions. I had this conversation just a few weeks ago with a young lady and her take was: "It's kind of creepy, but if it gives me good suggestions, I don't really care."
- ganoushoreilly 7y agoI've used systems that leverage passive detection of Bluetooth, Wifi, and other radio signals as an indicator. No Apps required. Tying beacons into points of authentication (login from workspace) or transactional data at a register. A large portion of it was actually focused around security and not product marketing, but the tech is the same.
- brianpayne2 7y agoDoes the BT detection work the same way that WiFi access point scanning works? I know that app developers use this WiFi tech from a client (device) side to determine location, but I am a bit disturbed about the aspect of this being so accurate with BT devices.
- LeifCarrotson 7y agoMaybe the existence of such toolkits is a Chesterton's Fence that says you can't make this work without something installed on the phone. But this would be possible without these trojans. If the Bluetooth beacon configures itself as a master, and enters inquiry mode, phones that pass nearby will happily respond with their Bluetooth ID (see https://www.bluetooth.org/docman/handlers/downloaddoc.ashx?doc_id=457080 https://www.bluetooth.org/docman/handlers/downloaddoc.ashx?d..., section 8.4). You can also do the same with Wifi access points: Phones are constantly broadcasting their MAC address during active scanning for networks. The location from signal strength isn't as good (a Bluetooth beacon can pin you down near the Yoplait yogurt, a Wifi beacon and signal strength measurement just put you in dairy) but it's getting better (worse?). See: https://www.crc.id.au/tracking-people-via-wifi-even-when-not-connected/ https://www.crc.id.au/tracking-people-via-wifi-even-when-not... I imagine it would not be perfect but would be acceptably easy to use these "anonymous" MAC addresses to connect you to a name and address on a debit card. If your MAC and 20 other people left the store Friday at 2PM, and you and 20 other people went through checkout, and then your MAC and checkout are seen with 20 different people next week it's pretty trivial to identify you. The cynic in me, though, says that even a minor loss of fidelity in tracking data weighed against the minimal risk and cost of building the spyware makes it worth building both.
- TeMPOraL 7y ago> Maybe the existence of such toolkits is a Chesterton's Fence that says you can't make this work without something installed on the phone. But this would be possible without these trojans. Without these trojans the store would have on its hands a major networking infrastructure project. With these trojans, all they have to do is drop a few battery-powered beacons in their venue and store their IDs along with coordinates in a database.
- LeifCarrotson 7y ago"The store" that implements these is probably not a mom-and-pop. Places like Walmart succeed because of their ability to execute major logistics and networking projects. If the beacons increased Wal-Mart's revenue by 1%, the "major networking infrastructure" project could be a $5 billion department, larger than Google's entire R&D operating expenses.
- umvi 7y agoWhat I don't get is: 1. Pretend it's the 1900s. Walk into a general store, shopkeeper sees you looking at ammo for 20 minutes and then leave without buying anything. Next time you walk in, he recognizes you and says he'll give you a discount on ammo if you buy in bulk. This is totally cool, not a violation of privacy, and both parties benefit. win/win 2. Use a computer to do the same exact thing automatically Rage, pitchforks and proverbial molotov cocktails and people going on privacy diatribes. What's the difference?
- draw_down 7y agoCome on.
- Kenji 7y agoIt's rage-inducing because the 1900 shop keeper doesn't keep a book about you specifically, notes down your presence to the last second, follows you home or into other establishments, etc. Also his memory is not accurate and no tangible proof (it's just his word after all), so nobody can download his memory if they want to spy on you for whatever reason (dissident, whistleblower, etc.)
- samdixon 7y agoHuman, local, and friendly interaction vs mega corporation using a profile they built without asking that has pulled as much information on you as possible while simultaneously using algorithms trying to determine how to get you to buy as much stuff as possible and pushing advertisements right to your phone.
- Raphmedia 7y agoNow, imagine instead that this store has an employee who follows you around with a notebook that quietly nods and writes down everything you're doing. At the same time, they are talking on the phone with a third party. You hear them say, "So their names is John Smith? All right, all right, all right. What is their medical situation? Cancer, you say? Yeah, they're looking at razors right now. They are wearing the new Nike shoes. Just sneezed. Again. They are looking at allergy medication now."... Then you look around and notice that every person in the store is followed by one of these employees. You freak out a little bit and leave the store. The next store has the same kind of employees. As soon as you enter, the phone rings. The employee from the previous store calls your new "supervisor". On the phone, you hear a voice describing everything you've just done next-door. This is what this situation would look like in an imaginary world of 1900s.
- imroot 7y agoTo me, this isn't big news -- It's at the point where I turn wifi and Bluetooth off when I'm shopping. Look at some of the filings by Kroger: https://fccid.io/PBR-SZG3APWC/Users-Manual/Manual-3994818 https://fccid.io/PBR-SZG3APWC/Users-Manual/Manual-3994818 They are tracking down at the bay level for some items.
- tantalor 7y ago> I turn wifi and Bluetooth off You believe that makes a difference?
- 24bug47 7y agoThe only option is to cage your phone in a Faraday bag and only use it when necessary. Trust no company. Trust no government.
- bduerst 7y agoIt doesn't for Apple users. Location and other bluetooth features are still on after you turn it "off". https://www.zdnet.com/article/ios-11s-control-center-may-say-bluetooth-wi-fi-are-off-but-thats-just-not-true/ https://www.zdnet.com/article/ios-11s-control-center-may-say...
- 24gttghh 7y agoThat's the control center shit. I made a shortcut widget that actually shuts it off for this scenario.
- asdff 7y agoAirplane mode? Shutting off the phone? Not like I get service in the grocery store anyway.
- Spooky23 7y agoHow do they actually make money? Merchandising isn’t rocket science. I wonder if there is real roi?
- disposition2 7y agoHopefully not a dumb question... Are there any apps / options that allow for only connecting / responding to a previously connected unless overridden?
- move-on-by 7y agoThis is a bit off topic, but how could I do this at home? Seems like it could be a great addition to home security systems. Criminals know to cover their faces with all the cameras and they use stolen vehicles that can’t be traced back to them. I bet they still have their phones with them. I’m not sure the police would take action on a device’s MAC address- but it’s still another data point. Perhaps there are hardware/usb sticks designed for this purpose?
- tacLog 7y agoI do wifi tracking for a living and no there is no off the shelve solution for consumers that I have ever seen. You can accomplish this with a raspberry pi, a wifi adapter that supports monitor mode, and tcpdump set to the right filters. However, I don't see why anyone ever would. As others have mentioned many of the top wifi brands, Cisco, Aruba, and Meraki (now owned by Cisco) provide this kind of information to clients at their enterprise level. The reason this doesn't exist for consumers for security at least is that in the use case you described it is hard to tell what MAC address belongs to each device. Even in a neighborhood, you will detect hundreds of macs a day due to mac spoofing that modern phones do.
- move-on-by 7y agoBuilt-in RaspberryPi WiFi can do monitor mode. Kali Linux even has a raspberry pi image. RaspberryPi also has built in Bluetooth that supports 4.1 and low energy. Since Bluetooth is a less powerful signal, is there anything I could do with that?
- tacLog 7y agoI haven't tried to track phones with bluetooth, it seems like it wouldn't be possible because phones aren't always announcing themsleves. A by product of battery limitations I would guess. The more common use is tracking powered tags for the purpose of asset tracking in say hospitals or similar. I didn't know the onboard adapter supported monitor mode, that is ligitmately useful knownledge for me. Thanks, it should be simple to build your own sniffer to just plan around with. Carefull if you are in the EU though, not that it is removely possible to catch a silent sniffer.
- manyxcxi 7y agoHaving done some proof of concept work for a couple of very large retailers using BLE/beacons I believe most of the scumminess isn’t on the retailer side but the 3rd party API/framework. The requests we were fielding was for better ability to find things in the store, floor maps for every store with wayfinding, and the ability to use the app to get more contextual info on demand. For those not completely in the know on beacons: they are broadcast only and it is the apps running in the background on your phone that shuffle off the data on your phone. If you were running a device free of the offending apps, your privacy is fine on that front. The WiFi tracking is a different story though.
- 0xffff2 7y agoI'm a developer, but I've never touched mobile dev at all. Could you clarify what "running in the background" means here? I see it come up a lot and I'm never quite sure. Specifically, if I have an app installed, but it's not open in any way (e.g. in iOS I double tap home and swipe up on the app's window to close it) can the app still run any code? Am I safe from these "background" vulnerabilities as long as I aggressively kill apps that I'm not actively using, or is simply having the app installed enough to let it run a certain amount of code on my device?
- manyxcxi 7y agoThey can if given permission to. For certain apps in iOS it’s usually an application asking for location permissions without a real good reason for it, that’s why (in my opinion) it seems like weather apps are some of the worst offenders for this stuff, as it makes sense to give it location permissions. There are other permissions that can be abused as well, but location is the dead give away. I can’t speak to Android as it’s been a long time, but iOS is pretty strict about what you can and can’t do in the background. There are certain events that will “wake up” an app, even one that is killed. You’re not necessarily safe if you have a bad app installed and kill it. I usually just recommend avoiding free apps that seem super heavy on ads. Because the ad framework is likely abusive, even if the developer didn’t intend it.
- 7y ago
- g8oz 7y agoWe need to articulate the changes we need from Apple & Google. Something along the lines of a) permission required for any app to use Bluetooth or BLE - preferably differentiating between whether the app is running in the foreground or background b) a way to turn off both Bluetooth and BLE at the OS level. Then pressure needs to applied either through public opinion or through legislative efforts.
- landonxjames 7y agoApp level bluetooth permissioning is actually planned as a part of iOS 13 https://www.apple.com/ios/ios-13-preview/features/ https://www.apple.com/ios/ios-13-preview/features/
- dmje 7y agoThe really simple answer? Give up your smartphone. It's eating your life anyway, crossing boundaries with your family / work. You're addicted to checking: your downtime is zero, your free space to think: negligible. Mindfulness: none. Mindlessness: maximum. Just a thought.
- graenxa 7y agoI am tempted by this more and more. I'd be curious to hear from anyone who's tried it
- asdff 7y agoThere was a HN thread about it the other day, but I don't see the point of rushing out to buy a nokia if you've already bought a smartphone; that's just doubling down on e waste. You can always detox your phone though. Delete all your third party apps, stay off mobile web and it's a de facto dumb phone with a battery that lasts a day instead of a week like your old razr.
- dmje 7y agoI'm just over a year into it. I'm going to write this up in more detail at some point but broadly my strategy has been: 1) Keep a smartphone without a SIM in it at home on wifi for banking / 2FA / etc 2) Move everything social off it. I was never a FB user, but I'm into Twitter and news - so those two got canned, as did Instagram 3) Take work email off it. If you can't, turn off all notifications. If people want you, they'll ring you. 4) Anything you want to do, do it on your desktop - you have way more control here. I use https://heyfocus.com https://heyfocus.com on "hardcore" mode, which blocks Tweetdeck, email, news, HN, whatever so I can actually get work done 5) Have a dumbphone for out-and-about use. It's painful, awful texting, no camera - but it is remarkably liberating to have moments of boredom, moments when you'd normally take a photo but can now just admire the view, moments when you have to actually "ring" someone (I know, this is apparently a thing..) 6) Never let your smartphone into your bedroom, ever 7) Put any gadgets on charge upstairs after 6pm, and leave them there on silent until the morning It works for me. It hurts, and sometimes I slip (if I have to travel with work, I normally re-sim-ify my smartphone for maps or whatever), but in general I feel more a part of the world I'm supposed to be spending my life in, rather than down a rabbithole of virtual nothingness. The first and easiest way to try this is simply to leave your phone at home when you go out for a period of time. Redirect calls to your partner if you need - but just try it. There's a Zen saying: "if you don't have 10 minutes to meditate each day, you should meditate for 20 minutes". If it hurts, try it for a longer period of time!
- rapht 7y agoOn Android, this just had me 1. Settings > Security 2. Click on Location 3. Enhance location precision 4. Disable "Bluetooth Analysis" aka the use of BLE beacons
- Skunkleton 7y agoAFAIU, on iOS disabling location access will stop apps from accessing beacons entirely, and apps have to prompt to establish this permission.
- wakkaflokka 7y agoI setup Home Assistant with the Raspberry Pi Bluetooth module to detect when my fiance and I were home or away (to turn on/off lights, turn off WeMo switches to the curling iron that my fiance always forgets). After a few weeks of forgetting I had it running, I logged back into the Home Assistant dashboard to notice that it was tracking nearly all of my neighbors Android phones, iPhones, headphones, TVs - when they were home, when they were away. Entirely passively. Most devices had names that could very easily be linked back to the user - i.e. "Joe's iPhone". Just to reiterate - this was _entirely passive_. I did nothing but enable the Bluetooth presence detection module in Home Assistant on my Raspberry Pi, and over time it built up a detailed log of when nearly all of my neighbors were home or away. Luckily I was able to quickly turn off tracking of devices that weren't explicitly enabled. What confuses me, is that I thought iPhones had randomized MAC addresses? In the Home Assistant known_devices.yaml file, you can give aliases to phones based on their MAC address. And my iPhone has never changed it's MAC address, because Home Assistant continues to track it with ease. Not entirely sure how that works.
- mattkrause 7y agoiOS randomizes the MAC address when scanning for networks but provides its true name when it joins one.
- PeterCorless 7y agoThis isn't new. I wrote this blog about beacons back in 2015 for the NoSQL vendor Aerospike; there aren't just audio (high frequency) beacons. There are also RF and other spectrum beacons: https://www.aerospike.com/blog/silverpush-unifies-people-devices-data/ https://www.aerospike.com/blog/silverpush-unifies-people-dev...
- agumonkey 7y agomass background tracking is becoming the defacto leading industry
- fyfy18 7y agoWhat exactly are retailers doing with this data, that they couldn't do before? If you go to a supermarket and pay by credit card, the supermarket is going to have a profile on what type of things you like to buy, even if you aren't a member of their loyalty program. They've been doing this since loyalty cards became popular in the 90s. It seems somewhat benign, and not very useful, that they know I spent 45 seconds in front of the yogurt section, compared to the average at that time of 28 seconds. Maybe a friend I haven't spoken to for a long time started messaging me. Or maybe I was helping an elderly person get something from the top shelf. The part about eending ads to your device is FUD, any app that starts doing that without my permission is getting uninstalled straight away.
- sizzle 7y agoWe aren't privy to the back office deals they are brokering with our data across advertisers and what not.
- SwaraLink 7y agoI think the biggest misconception here is the belief that Bluetooth LE beacons are tracking phones. The beacons themselves operate as transmit-only and don’t receive any data and therefore don’t perform any tracking themselves. The more correct way to look at this is that the apps are tracking a user’s location, and the beacons are providing the app with information to determine the current location. If the app’s knowledge of your location provides some service and the user is opting-in, this shouldn’t be a problem (just like I opt-in to provide Google Maps my location). The keys here are (1) users should be aware that an app knows your location, and (2) User should have the ability to opt-in to providing my location to the app. The mobile operating systems should do a better job of making the user aware and making it very easy to opt in or out. Maybe an ideal solution would be where (assuming the user opts-in) the OS automatically controls whether an app has the ability to use Bluetooth locationing when the GPS detects that I’m in a certain area. For example, the Target app is prevented from using Bluetooth tracking most of the time, but when my phone GPS sees that I’m in a Target store it automatically enables it while I’m there, and disables it when I leave.
- uwaco74 7y agoletjamz.com
- polskibus 7y agoYou can set similar tracking yourself with rpi, hass.io and presence detection module that can register and track MACs on Bluetooth and wifi
- wodenokoto 7y agoThe other day I had to send a video to a friend. Too big for email and fb messenger wouldn’t let him download it once received, so I ended up trying airdrop and got a list of names of everybody’s iPhone or iPad around me. Apparently we are all telling anyone around us who cares to listen who we are.