7 ms·
Milan Airport WiFi sends your MAC address to advertisers and trackers
- steve_gh 7y agoThis looks like a fairly significant GDPR breach
- anontechworker 7y agoOof! Does anyone recommend any tools for protecting against this sort of stuff? I feel like a VPN wouldn’t even be enough here since the MAC address is coming through the headers. Edit: typo
- mrgreenfur 7y agoI think the full answer is to never trust anything on a page that isn't from the host domain: achievable via the uMatrix plugin. I dont understand why anyone would trust random scripts from a random company (and sometimes just an unnamed cloudfront endpoint). A less intense version is to use a PiHole or otherwise block bad domains at the DNS level via a regular ad blocker.
- deleted 7y ago[deleted]
- imglorp 7y agoLinux lets you reassign your own MAC. There's no reason to use the same one twice in public! :)
- aaron695 7y agoWindows does as well! Finally. And will change everytime you use WiFi. Just in the setting. Might have to be set per wifi network... IE - https://winaero.com/blog/enable-random-mac-address-in-windows-10-for-wi-fi-adapter/ https://winaero.com/blog/enable-random-mac-address-in-window...
- ComputerGuru 7y agoiPhones randomize the MAC address when connecting to hotspots (on a per-ssid basis, I think?). Other platforms do too (Windows 10 now has an option to do that automatically as well, but I can’t recall if it is enabled by default).
- Gaelan 7y agoIIRC (this is old and might have been wrong in the first place) iOS randomizes when it’s searching for networks but not when it’s connected to one.
- angott 7y agoIt’s not a bad idea. A randomized IP address at each connection would break many things on quite a few networks (IP-MAC static assignments, for instance).
- m463 7y agocould your just push it down a layer, maybe 802.1x or something?
- ComputerGuru 7y agoThere are other options, like generating a Mac based off the real Mac and the ssid or bssid.
- lbeltrame 7y agoRecent NetworkManager versions on Linux do the same (I don't remember if it's on by default or not, though).
- commotionfever 7y agoYeah it's by default. Learned this the hard way when setting up port forwarding by MAC address on home network. Was wondering why the forward would only last a couple hours
- 7y ago
- hoistbypetard 7y agoDoes anyone have a theory on what the "advertisers and trackers" want a MAC address for? If they're using it for anything load bearing, it seems like there is an interesting CCC talk lurking here for anyone who wants to visit that airport with a few hundred dollars worth of devices and stuff a few tens of million spoofed MAC addresses into the system.
- s5ma6n 7y agoSince MAC address ranges are allocated to certain manufacturers, it is a simple way to track your device type. Additionally, all MAC addresses are unique so it is the easiest way to match/combine your data from different trackers.
- RKearney 7y ago> Additionally, all MAC addresses are unique so it is the easiest way to match/combine your data from different trackers. This is not true. While it's intended for MAC addresses to be unique, there are plenty of instances where manufacturers re-use MACs when they run out instead of registering more. Additionally, there is no issue with multiple devices having the same MAC address as long as they're never on the same Layer 2 domain.
- s5ma6n 7y agoAs far as I know, IEEE is quite strict in this matter but I just searched for it now and have seen a couple of cases where people ran into duplicate MAC addresses. I would assume this is a rare occurrence and if not, it should still be okay to sometimes run into address collisions for advertising purposes. Thanks for the info.
- m463 7y agoYou are arguing that mac addresses are not unique, however that doesn't mean it doesn't match/combine your data extremely well.
- hoistbypetard 7y ago
- cproctor 7y agoThe problem with constantly shuffling MAC addresses is that they are used for device authentication on corporate/school/university networks. Does anyone know of a utility that generates MAC addresses as a hash of the SSID?
- buzzkillington 7y agoA bash script? You can scan for the networks in the area, select the one you want, run the name through, say sha256, select the first 8 characters and reset the mac address to that.
- cproctor 7y agoYeah, not that hard to do manually--I have a nice script for that. But I haven't looked into the logistics of hooking into the wifi connection process and doing this automatically :)
- buzzkillington 7y agoBack in my misspent youth I had a bash script that would connect me to whatever access point I needed. I can't imagine much has changed since then, just add the logic to change the mac address between entering the SSID and actually connecting.
- dan1234 7y agoWon’t that cause problems if 2 people do this in the same session (and generate duplicate MAC addresses)? I guess you could get around it by hashing the ssid + a personal salt.
- pow_ext 7y agoMilan Airports answered that they have submitted the issue to the "Information technology staff" source: https://twitter.com/pimterry/status/1192038174408753152?s=20 https://twitter.com/pimterry/status/1192038174408753152?s=20
- pimterry 7y agoUpdate - apparently they've now fixed this: https://twitter.com/MiAirports/status/1192433053743927296 https://twitter.com/MiAirports/status/1192433053743927296
- pow_ext 7y agoWe can't be sure about this, maybe the airport mask the data to a relay
- rnhmjoj 7y agoWhat I'm more worried about are probe requests, because sometimes I forget to turn off the wifi. Do you know whether the MAC address, or other identifying data, is sent in this case?
- oil25 7y agoMAC address of your radio, plus the BSSID of every wireless network you've ever connected to and saved.
- helper 7y agoBased on the screenshots it looks like the mac address is leaking out because its in the referer. I would guess this isn't intentional and shouldn't be hard to fix. I've worked with a number of captive portal systems and they all basically work the same way. The AP/controller intercepts http requests and redirects to the captive portal page with identifying information about the device (ip,mac,ssid,ap_mac,etc.). The captive portal http server shows the user a splash page to accept terms or enter a username/password or a credit card. Once the captive portal server decides the user should be allowed onto the network it needs to communicate that back to the wireless hardware which is done with the user's mac address. Based on the requests it looks like they have some ads/trackers on the splash page that are getting requests with a referer set to the original splash page url (which includes the client mac address). A no-referrer meta tag or an intermediate redirect would prevent this from happening.
- pimterry 7y agoWhile the mac address is a particularly egregious note, really they shouldn't be sending any data to ad firms whatsoever without consent, and fixing the referrer alone won't help much. Aside from the data they're explicitly sending in those requests, they're running the response as JS, thereby exposing a bunch of data about your machine & browser, and the response itself is setting a long-term 3rd party cookie too, so that ads on every other site you ever visit can tie all this (and the fact you've used the wifi in this airport) to a long-term profile. In Milan airport you can make a reasonable bet that most people are EU citizens, so sharing any of their identifiable user data at all for marketing purposes without consent is a huge and expensive no no. It's not a good look. Referrer aside, I suspect there's no legal option other than dropping this ad script from their wifi login page entirely.
- james_in_the_uk 7y agoConsent is not needed for quite a bit of electronic marketing. It is for setting cookies, which is probably going on here to facilitate the marketing, so your point stands, but it's a breach of the ePrivacy Directive not GDPR so fines are lower. No excuse though.
- jayalpha 7y agomacchanger Also extends time limites wifi. Or use my gypsy code import random import os mac='' os.system('/etc/init.d/networking stop') os.system('ifconfig wlan1 down') os.system('ifconfig eth1 down') os.system('ifconfig wlp8s0 down') os.system('ifconfig wlp7s0 down') for i in range(0,3): __r=random.randint(16, 256) __mac=mac+":"+str(hex(r))[2:] mac="00:07:E9"+mac print mac os.system('/etc/init.d/networking stop') os.system('ifconfig wlan1 hw ether '+mac) os.system('ifconfig wlp8s0 hw ether '+mac) os.system('ifconfig wlp7s0 hw ether '+mac) os.system('ifconfig eth1 hw ether '+mac) os.system('ifconfig wlan1 up') os.system('ifconfig eth1 up') os.system('ifconfig wlp8s0 up') os.system('ifconfig wlp7s0 up') os.system('/etc/init.d/networking start') os.system('ifconfig') print "echo 'MAC changed..." print "new random MAC "+mac
- jolmg 7y agoYou need to indent the code by at least 2 spaces so it doesn't collapse into a paragraph like that. Also, that script isn't really portable. Not everyone has those interface names nor /etc/init.d/networking.
- jayalpha 7y agoIt is gypsy code and works for me. Use macchanger instead of adopt the script for your purposes.
- jolmg 7y agoWhat is "gypsy code"? I first thought you were referring to a library or some kind of platform, but that doesn't seem to be it. The only definition I find of gypsy is that of the people. Maybe you're saying that it was written by a Gypsy, but I don't know why that'd be of interest.
- jayalpha 7y agoIt meant a quick and dirty fix.
- 7y ago
- dreamcompiler 7y agoGreat. Guess they have the MAC address of my laptop from when I was there last week then. Fortunately it was a burner Chromebook running Gallium Linux so that makes me care a little less.
- tomcooks 7y agoIn the title I suggest substituting Milan Airport with Milan Malpensa MXP Airport (for there are multiple Milan airports)
- fnord77 7y agohttps://github.com/feross/SpoofMAC https://github.com/feross/SpoofMAC
- Exuma 7y agoDoes this work with OSX? Its 5 years since the last update...
- feross 7y agoYes it still works.
- heavyset_go 7y agoHad this alias for years and it still works: alias random-mac='openssl rand -hex 6 | sed '\''s/\(..\)/\1:/g; s/.$//'\'' | xargs sudo ifconfig en0 ether'
- Exuma 7y agoAwesome, so does that change the permanent mac address that comes with the laptop, and it is forever gone? Or does it somehow "reset" when you restart, and you rerun this command multiple times
- heavyset_go 7y agoIt resets when you turn the NIC on and off, I believe.
- oil25 7y agoOn OpenBSD: # echo "lladdr random" >> /etc/hostname.athn0
- oil25 7y agoCan someone post a TLDR? Twitter blocks Tor exit nodes, so the content is unavailable: > 403 Forbidden: The server understood the request, but is refusing to fulfill it.
- o_____________o 7y agoOn my Mac, I leave this running all the time: https://github.com/halo/LinkLiar https://github.com/halo/LinkLiar
- mrgreenfur 7y agoThanks for sharing this! I know it's included in Win10 and in iOS, surprised it's not in OSX yet!
- elyrly 7y agothanks!