32 ms·
How do I opt my access point out of Google Location services?
- alias_neo 5y agoAre you aware that if you don't want Google to use your WiFi name for location based tracking, you have to opt-out by changing your SSID[0]? [0]https://support.google.com/maps/answer/1725632#how_opt_out&zippy=%2Chow-do-i-opt-my-access-point-out-of-google-location-services https://support.google.com/maps/answer/1725632#how_opt_out&z... EDIT: Added "name" after "WiFi" to try and clarify they're not using your actual WiFi network/bandwidth, just its name to link it with its location for GPS-free location tracking.
- ocdtrekkie 5y agoIt's still so incredible to me that someone thought "oh, yeah, let's make people change their SSID explicitly to opt-out of being used by our services, such that it forces them to re-add all of their Wi-Fi devices", and that passed any sort of muster at Google. Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it.
- mattzito 5y agoI'm trying to think of how one could do this in a way that wasn't even more intrusive? This way Google doesn't have to tie any identifying information about you to your SSID/AP, it can just silently discard the location data about those SSIDs. Otherwise people could abusively de-register SSIDs by doing the same sort of scanning Google is doing to improve location services, or have to force a user to authenticate and "claim" an SSID, which is much more intrusive. (disclosure: googler, but not in any way associated with any of this)
- awakeasleep 5y agoOpt-in
- whatshisface 5y agoWell, then nobody would do it. Maybe Google would have to pay them, or give them free stuff.
- ocdtrekkie 5y agoIf Google wants to use other people's stuff for their purposes, they should pay them. Not force them to jump through hoops to avoid Google abusing them.
- betterunix2 5y agoHow would that work? Keep in mind that we are talking about parts of the radio spectrum that were deliberately set aside for unlicensed use, without any sort of registration, centralized control, or reporting on the part of users. So how would Google or any other company know who to pay? Do you want to force users to register their APs, or to include some kind of payment information in wifi beacons? Or are you proposing that new restrictions be added to the ISM rules e.g. forbidding people from monitoring the band without first asking for permission from each station operator (note: this would completely break wifi)?
- ocdtrekkie 5y agoI think a user registration system would make sense: People who wanted to register their APs are probably using Google Location Services, and the incentive is hence, self-serving. Businesses may want to register their APs to help customers' devices locate themselves at their buildings. And yes, Google could incentivize people to register in some way. One thing you'll notice is that the most valuable companies in the world seem incredibly reliant on free labor: They take for free what other companies used to pay for or pay staff to create or gather themselves.
- alyandon 5y agoThose FCC registration records would then be public information. Would you feel comfortable with your name, address and MAC + SSID of your wireless AP(s) being registered in a public database and the onus on you to keep that registration information up to date every time you changed the SSID or swapped in something with a different MAC address? I'm not sure I would be. The ethics around Google's behavior aside - this is a tricky problem to solve. Edit: Why the downvotes? I'd really like for people that disagree to engage and tell me where I am either wrong or not arguing in good faith. If you believe this is a Google specific problem or somehow an easy problem to solve under the current FCC regulatory regime I'd be happy to hear about it.
- CogitoCogito 5y ago> I'm trying to think of how one could do this in a way that wasn't even more intrusive? Not to do it.
- oh_sigh 5y agoWe haven't figured out how to make websites not be able to fingerprint you. Better not use the internet until we do.
- Retric 5y agoWe have figured out how to avoid being tracked. Hide your IP address behind Tor. Transmit identical information as a significant group of people. Don’t store information from websites. The issue is that degrades the web in ways unrelated to tracking.
- NaturalPhallacy 5y ago>The issue is that degrades the web in ways unrelated to tracking. And so many sites, and CDNs treat those as hostile by default, and some outright refuse service. It's infuriating as a mere VPN user.
- paranoidrobot 5y agoI suspect that this is because a huge amount of traffic coming from those services is abusive. I know that's the reason we classed all traffic from those sources as suspicious unless they were willing to log in.
- hn8788 5y agoInstead of thinking "We can't think of a less intrusive way, so deal with it", how about "We can't think of a less intrusive way, so let's not do it until we do".
- calvinmorrison 5y agoI frequently get something like "why would you want to do that" running my unconventional browser settings. It's like people can't even comprehend people don't want to get tracked by FAANG
- jfrunyon 5y agoI'm not sure how "associating a publicly broadcast BSSID with coordinates" is tracking a person.
- drofmij 5y agoThis is probably related to them getting in trouble for scanning networks while mapping. If I remember correctly they were doing a bit of port scanning and looking for share drives in an attempt to id which SSID was attached to which address. This is probably part of the wrist slap they got from FCC. "Oh well you can totally opt out now so it's ok"
- bingidingi 5y agoIf I have a unique SSID (let's say, my social security number because why not at this point) and I move to a different apartment and keep the same SSID... then Google's effectively tracking a person. If you have basic address/name info you can even pinpoint who owns the SSID.
- callmeal 5y ago>I'm not sure how "associating a publicly broadcast BSSID with coordinates" is tracking a person. But it's not just that is it? If you log in to a google site from that publicly broadcast BSSID, you will get tracked by association, even if you have your location tracking turned off.
- stefan_ 5y agoYou can transfer lots of information elements in a beacon, you don't need to shit on the SSID.
- jfrunyon 5y agoOkay, now how do users set their devices to transfer this non-standard information in the beacon?
- stefan_ 5y agoThe same way you configure everything? You check a box where you configured your SSID in the first place.
- Sebb767 5y agoIf you run OpenWRT you might have hope for this (assuming the firmware supports it). This would not land in your average consumer router for a few years, if at all.
- ocdtrekkie 5y agoI mean, if Google was as zealous about standardizing privacy as they are about standardizing ways to track people, Google could get that configuration option introduced to the firmware of most common consumer routers.
- iudqnolq 5y agoThe guide says to open Google maps after making the change so that it can propagate. That makes me think it isn't that they ignore _nomaps, it's that they submit their locations to a database and clear the previous data for there. At that point it could just be a webpage that asks you for your location and SSID.
- utucuro 5y agoActually, having read the opt-out method article and knowing the personal data protection law of my country due to professional needs, I can say that what Google is doing is illegal in certain cases here. If Google ends up personal data as defined by law here, which does include present location coupled with name, then that ends up being illegal without a detailed data protection declaration and withdrawable explicit consent granted before ANY data can be collected at all. Intrusivity is not important, convenience must not be allowed to trump legality though.
- notriddle 5y agoIt doesn't seem hard to understand. They figured that SSIDs aren't private information, so having any method of opting-out at all is just a courtesy.
- stingraycharles 5y agoBy that definition, IP addresses are also public information. It’s not about the SSID or IP itself, it’s about it being connected to an individual.
- TheCapn 5y agoIts one of those cases where data becomes dangerous when there's enough of it. Google knows practically every SSID location in the developed world. Now your Android phone browsing and mapping every SSID it sees as you move about is a reliable "Location mapping" of the user even though they may have no GPS or have it disabled. You can map a person's movement through cities/towns just based on the SSIDs their device(s) saw as they moved about.
- skybrian 5y agoYou say that like it’s always a bad thing, but sometimes we actually do want to use our phones to find out our location, and GPS is often slow or doesn’t always work. The issue here is having control over when your phone looks up your location, not the existence of a database that makes it work.
- mindslight 5y agoThe existence of that database under the control of a surveillance company is the problem. If Google published the dataset so that many others could use it freely, then they would have an argument that they're just promulgating public data. However, by keeping it to themselves and forcing queries to go through Google (with a bunch of fine print attached), they're agglomerating personal data for their own private purpose.
- taneq 5y agoIt's perfectly in line with all of the other Google policies which are thinly disguised versions of "we want your data and if you don't give it to us, we'll punish you."
- oblio 5y agoSimple example, at least in Google Maps on Android. They have some sort of activity tracking. If you enable that, you can save locations, so that, for example, you can "favorite" your home and your office for easy access. If you disable activity tracking, you can't save anything. Those two are totally unrelated, and you're still using Google Maps through your Google account, so there are 0 technical reasons they couldn't just persist your saved locations in the Google Cloud. They just don't do it to force you to let them track your location.
- mateo1 5y agoTo me the most infuriating practice is that if you don't enable your location when you open google maps they will passive aggressively position your view at the most inconvenient place possibly, some times in the middle of the atlantic, as if they can't tell which city you are in.
- Nasrudith 5y agoPersonally I consider that an odd form of "politeness". It is 'creepy' when you buy a large ticket item and ad networks try to seranade you with a demand you already fuffilled. They can geolocate by IP but instead choose to "look away". I guess they do that because those who aren't familiar with it would be freaked out at how close it got. Geo-IP is mostly just hilarious to me from how they get it off like when loging in to gmail in Pennsylvania saying there was a login attempt from Washington DC. It shows some respect that you don't want focus on your actual geography but I also do stuff like look at real life places to see how well it matched with my initial imagination.
- tyingq 5y ago
- oh_sigh 5y agoHow would you prove ownership of an SSID otherwise?
- 8note 5y agoIt sounds a lot like robots.txt
- anfilt 5y agoJust don't broadcast your SSID. While it still possible for google to probably scan for these I doubt they do.
- NaturalPhallacy 5y ago>Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it. Oh absolutely. But to play devil's advocate, your wifi device is basically an always broadcasting radio antenna that rarely moves or changes. And SSIDs are broadcast by design. It's a digital landmark. I bet there are a lot of other companies other than google using it too. And even if you used google's opt out, they're not going to care. So opting out is pretty pointless anyway. So while it feels invasive because we lack a sensory organ for radio, your router is constantly broadcasting (advertising?) itself as a part of normal operations. SSIDs aren't private information. It's more akin to an amateur radio callsign, except you can change it at will. And since they're no consistent convention for naming your wifi there are probably 10,000 "FBI surveillance van"s. The only useful data to an outsider is location. This was going to be utilized by someone, and probably already is by the NSA. So google doing it is no big surprise. Again, devil's advocate here, but SSIDs are broadcast on purpose. Sacrificing security for convenience as always when people are involved.
- deleted 5y ago[deleted]
- soraminazuki 5y agoBy your logic, your house is a "landmark," so it'd be totally okay to surveil it. I don't think that flies.
- aeraiC5m 5y agoHouses can indeed be landmarks. Why are you equating landmarks to surveillance. That makes zero sense. No one is surveilling you through your WiFi SSID.
- just-ok 5y agoExcept they are: Google undoubtedly uses the set of WiFi networks near you for location-based tracking on Android, even if your GPS is off.
- hetspookjee 5y agoWell Judging by the blog a person working in ads recently published it's perfectly fine to throw up these dark patterns and misleading terms in the name of "free internet". And to top it off half of their half million salary is donated so any residing moral debt is taken care off like so.
- aconsult1 5y agoPretty sure in a few years people will have to name their kids John Notrack Doe as the only way to have FB stop ghosting them.
- crocodiletears 5y agoBeing able to prevent that at all would be a massive improvement
- DannyBee 5y agoYeah, i mean who else would ever do such a thing https://location.services.mozilla.com/optout https://location.services.mozilla.com/optout https://support.apple.com/en-us/HT207056 https://support.apple.com/en-us/HT207056 Presumably the only reason they picked this strategy is that they know it is such an absolutely ridiculous step that nobody does it. No, actually, i'm just kidding. Mozilla, for example, literally blames it all on everyone else in their page. You see, they are forced to do this because everyone else did it!
- LegitShady 5y agoIs there a link somewhere that says how they collect that information? If they're geolocating through chrome and building a database out of that I'd consider it a ubusive but if they're just driving around reading brooadcasted wifi ssids and correlating with the vehicles how position I'm not sure that's any worse than using any other landmark.
- alias_neo 5y agoIt's collected by every Android device on the planet which has background scanning enabled. Have neighbours? Have WiFi? Neighbour has GPS on? They can GPS pinpoint your WiFi by signal strength between the devices that "see" it, then correlate that with the GPS from the devices that are allowing it. I moved home a few years ago, just 200M away, my location in GMaps, when on WiFi remained at my old address 200M away for a good year (I moved my AP with me and kept the SSID).
- tgv 5y agoBut your telephone can tell them who's connected to that access point and what it's IP address is. Then they suddenly know more.
- yesbabyyes 5y agoAny device that has GPS and wifi can contribute data positioning that wifi BSSID. Google has Android which will do that for any device that has opted in (presumably, anyone using the feature for better positioning will participate in the collection). Others use other sources. Google's (and others) stance is likely that cellular and wifi information is publicly broadcast.
- LegitShady 5y agoI agree that wifi beacons are publicly broadcast. The issue is no way to use google services that require location without contributing to that data and not being up front about its use. But all the big companies are abusive in terms of privacy so it seems like it’s par for the course. I know its not technically a product but it always feels like these sorts of schemes should be illegal tying. Can’t make an iOS app without supporting safari? Should be illegal tying. Can’t use google maps without feeding google information about the wifi networks around you? Should be illegal tying.
- isaacdl 5y ago> To help apps like Google Maps work better, you can let Google's Location services use your Wi-Fi access point. Wow, that's pretty nasty. That sentence sure makes it sound like you're opting in, but in fact you have to rename the SSID with a "_nomap" suffix to opt out.
- edoceo 5y agoWas not aware, thank you. Creepy.
- gruez 5y agoWhy is it creepy?
- xvector 5y agoIt's not. I'm super surprised at the lack of understanding by HNers here. It's like folks here haven't heard of wardriving!? Open databases with 10B+ observations exist: https://wigle.net/ https://wigle.net/ Furthermore, it doesn't matter that these databases exist, because your SSID is hidden behind the location permission API for basically every OS. So practically speaking, your SSID being public is meaningless.
- varispeed 5y agoThis must be illegal, right?
- Sr_developer 5y agoIn a sane country, yes.In corporate ruled America no. But the important thing is that Google put some rainbows from time to time.
- lupire 5y agoWhy would collecting publicly advertised information be illegal?
- black_puppydog 5y agoI get your sentiment, but there is a big difference between that information being publicly available somewhere and someone building a centralized private database of it. At least, IF you assume that e.g. "database copyright" serves a valid purpose, then you could make a similar case here that the collection of all these data points is qualitatively different from collecting any single data point. Note: I used a capital "IF" up there because I do have issues with database copyright. But that's the world we live in...
- 0xEFF 5y agoIf they did the same tracking but to other phones instead of access points would that cross a line?
- betterunix2 5y agoAre you uncomfortable with the idea of someone monitoring the ISM band and collecting information about what is being transmitted and by which stations? If so, maybe you should stop using wifi, since that is actually part of the wifi standard (your phone is literally monitoring transmissions on your neighbors' wifi networks to avoid interference).
- tobr 5y agoLots of publicly available information is illegal to collect, for copyright reasons, privacy reasons, security reasons, etc.
- mike-cardwell 5y agoDon't forget to add `_optout` to prevent Windows hoovering it up as well. E.g, `mywifiname_optout_nomap`
- kozziollek 5y agoAt least somebody at Microsoft thought and _optout can be anywhere in the SSID. Good thing that you don't have to have two specific suffixes at the same time!
- wadkar 5y agoI can’t make sense of this. Are you telling me that any Android user with “default” pixel setup will use my SSID for location tracking? And that if my WiFi shouldn’t be part of Google’s (and Microsoft as well) data collection I need to suffix my SSID with _optout_nomap?? This has to be a joke. Any docs/refs/links?
- mike-cardwell 5y agoYes. That is precisely what you're being told. The Google evidence is linked upthread. Although, I've just done a search and it looks like the Microsoft feature that required the "_optout" substring was removed at some point. I'm going to leave it in my SSID for posterity.
- jfrunyon 5y agoWhen a user's phone attempts to get a location fix, it will use the beacons which are publicly transmitted by Wifi networks around it (I assume it's the BSSID/MAC address, specifically) to reference against (or update) a Google database mapping those BSSID's to coordinates.
- betterunix2 5y agoYour neighbors are currently monitoring your wifi network. That is how wifi works -- we all monitor each other's transmissions to avoid interfering with each other's networks. Most wifi APs will also monitor the ISM bands to find the least-congested channel to use, and will typically do so continuously and change to a different channel as needed. You may also have noticed that when you connect to a new network you start with a list of nearby SSIDs that you can choose from -- do you think looking at that list is a violation of privacy? Moreover, there are companies that operate large numbers of APs across a broad geographic region, and they may have a centralized system for managing those APs -- which means that they are collecting information about all nearby wifi stations (including client devices) across a broad region in a single place. Do you have a problem with that practice or view that as a violation of privacy? Radio is not private (except, possibly, cellular services, which may be treated as phone services with legal restrictions on wiretapping), especially when you are talking about unlicensed operation.
- mortehu 5y agoWiFi beacons are extremely important for good geolocation in buildings and in cities. Are you saying we should get rid of this functionality just to ensure nobody has a database of the physical location of hardware addresses? Phones already have random hardware addresses, so it's not like your movements are being tracked because of your mobile hotspot.
- quotemstr 5y ago> Are you saying we should get rid of this functionality just to ensure nobody has a database of the physical location of hardware addresses? "Privacy" advocates constantly demand that all of us bear the costs of worse technology just so they can have a little fake relief from their imaginary harms. We're long past the point of diminishing returns in preserving real privacy: now privacy advocacy is all about holiness spiraling. That said, I don't blame Amazon here: why wouldn't they take advantage of an opportunity to hurt a competitor at no cost to themselves?
- alias_neo 5y agoI didn't make any comment for nor against, I simply stated a fact. As for my opinion, I have no issue with the collection of the physical location of access points, I take issue with making me litter my chosen SSID with garbage so that I can opt out. Regarding hotspot, I'm not sure what you mean, none of this discussion is about mobile hotspot.
- mortehu 5y agoI wasn't responding to you, but what other way would you choose to opt out? SSID is one of the few things you can adjust on almost any access point. Hotspots are relevant because they are often personal and they follow you around, so if they didn't randomize their hardware address, then anyone could track your movements.
- jeromegv 5y agoThis is Google's problem to figure out (how we should opt-out, or if it should be a opt-in service), the fact that you are putting the responsibility on the user is crazy in itself. We are talking of a billion dollar company tracking the location of your own router against your will and without permission.
- dheera 5y agoCan one make a GPS spoofer with software-defined radio such that Google/Microsoft/Mozilla store the wrong GPS location for your SSID, while not being powerful enough to influence GPS users outside your premises?
- Sebb767 5y agoProbably, but it would still be illegal (sidenote: IANAL) and they usually don't enter your premise to find your WiFi. So the "easy" no-jail way to do this would be to reduce your transmit power.
- hatchnyc 5y agoIs this any kind of standard? Like if Microsoft comes along and says you need to change your SSID to end in "_noloc" rather than "_nomap" what are you supposed to do?
- yesbabyyes 5y agoClose, but no cigar! Microsoft has "_optout", but it can appear anywhere in the SSID. See https://superuser.com/questions/1005235/wi-fi-opt-out-microsoft-google#1202168 https://superuser.com/questions/1005235/wi-fi-opt-out-micros... Mozilla Location Services (and Combain which I think they collaborate with), WiGLE and others use "_nomap", though, so MS seems to walk their own path on this one.
- pratnala 5y agoSo I have to change my custom Wi-Fi SSD (something that I like) and add a brain-dead suffix called "_nomap" to prevent Google from tracking me? Who the hell greenlights such changes?
- mikro2nd 5y agoSo my network just became "Google Listening Post _nomap"...
- laurent92 5y agoI think people have been condemned for insults over SSID, so trademarks definitely apply ;)
- godelski 5y ago> Google/Microsoft Listening Post _optout_nomap FTFY
- mikro2nd 5y agoTo be clear, it was already "Google Listening Post" before I learned of this opt-out thing. The 5GHz network is/was "Facebook Listening Post _nomap" I find it absurd that we have to put this guff into our own networks just to opt out of the surveillance panopticon.
- extra88 5y agoYour router is publicly broadcasting its SSID ("Pretty fly for a WiFi" or whatever). Google Street View cars, Android devices, etc. have noticed the SSID in their vicinity and submitted the SSID with an approximate location to database. Now, when another device using Google's location service is trying determine it's location, it can submit the list of SSIDs (including yours) it can detect to get back a fairly accurate location. If you add "_nomap" to your SSID, Google won't use it; it's crude because broadcasting metadata along with SSIDs isn't a part of the WiFi specs. I don't see how using public router SSIDs as a landmark is "tracking you." If you use Google location services to determine your location based on your SSID or others, particularly while logged in to a Google account, then in some sense they're tracking you.
- cptskippy 5y agoTo be fair, they aren't using your WiFi. The SSID is like your house number. Claiming Google using your Wifi when it reads your SSID is like claiming someone is using your toilet because they read your house number off the front of your house.
- Sebb767 5y agoIt's far more unique than your house number. Nobody expects that I can show up directly at their house, if they just say their SSID or simply send me a screenshot of their Android home screen. Just search your SSID [0] and see for yourself. [0] https://openwifimap.net https://openwifimap.net
- extra88 5y ago> Nobody expects that I can show up directly at their house, if they just say their SSID or simply send me a screenshot of their Android home screen. (It's not relevant to the discussion but Android home screens show the name of the connected WiFi network?) Where can someone look up a lat,lng by entering an SSID? It sure doesn't work on the site you cited. It looks like the information that is there was explicitly shared by the router operator. SSIDs only need to differ from neighbors' SSIDs for convenience, to help tell them apart. If you already have neighbors using a default, like "xfinity", you might not want to choose that to avoid extra hassle when setting up new devices. But if you're concerned about someone learning your SSID and finding a database to map it to a location, can pick a generic manufacturer's SSID of which there will be thousands, if not millions, of devices using the same SSID.
- alias_neo 5y agoI'm not making any judgement on the practice itself, however, for the purposes of tracking, I suspect they use the BSSID The SSID is just the mutable part so you can opt-out, the actual identifier used is much more likely to be the BSSID which should be universally unique, and is (generally, or at least practically) immutable for any one piece of hardware.
- quotemstr 5y agoWhy wouldn't I want my wifi beacon used for geolocation? Good geolocation helps everyone. What exactly is the harm that Google is perpetuating here? This SSID stuff is a great example of something that sounds sinister when presented in vague and ominous terms by "privacy" advocates but is actually benign if you think about it for five minutes.
- kbenson 5y agoI'm not sure this one matters to me much. It's something you spew into the public space, and they're just recording the name and where it is. To me it seems no different than your address, or if your door is a certain color, or the color of your house. Zillow likely has a picture of the front of your house if you're in one, and a bunch of other info about it as well. Changing the SSID to prevent them collecting the info is sort of like hanging a big sign that says "no pictures" to prevent services from taking pictures of your house. It's a little ridiculous to have to do that, but it's also a little ridiculous to expect that people are going to ignore what is publicly visible. Honestly, I'm a little impressed that Google lets you opt out (and Microsoft apparently as someone noted, although with a different suffix).
- dang 5y agoA reader emailed to point out that this massive subthread is actually more on topic for https://news.ycombinator.com/item?id=27517547 https://news.ycombinator.com/item?id=27517547 than it is for https://news.ycombinator.com/item?id=27515230 https://news.ycombinator.com/item?id=27515230, so we've moved it thence hither.
- thatguy0900 5y agoIsn't the whole point of this comment to alert people who were concerned enough to check the other thread? Seems to defeat the point of it to move it to this thread, even if the comments are more on topic here.
- oxymoran 5y agoEasy, stop using all Google products.
- tmearnest 5y agoNope that won’t do it. Read the article
- maxpro 5y agoStill Google will use your AP for location services for other devices in the area
- UI_at_80x24 5y agoUnfortunately it isn't even that easy. The Google car that is used to take images of the StreetView also collected SSID's (and infamously got in trouble for sniffing packets too). So GPS location + Multiple SSIDs = triangulated location for mobile devices. Google is able to use each mobile devices' location, and it's GPS co-ordinates, and the location of your neighbours SSID, all that raw data makes for a very accurate location detection even without YOU ever using Google's services. You might have stood a chance if you lived in a Faraday cage, but the only thing that will stop this behemoth is legislation and politicians with morals.
- notriddle 5y agoThis isn't what the article is about here. A lot of Google stuff, including Android phones, and Street View and Waymo cars, engage in Passive Wardriving [0]. They build a database mapping SSID names to GPS coordinates. This is legal, even without requesting consent, because (1) it is not hacking, since they are not actually accessing your network, but merely "approaching" it (2) it is not a privacy violation, because there is no reasonable expectation of privacy for wifi SSIDs. As a courtesy, Google does allow you to configure your network to not show up in their database, much like robots.txt does for websites. But it involves changing your SSID, which is a very annoying way of doing it, because you have to reconfigure everything on your network to point at the new SSID. It's probably just an underhanded way of making it annoying enough that nobody bothers. [0] https://en.wikipedia.org/wiki/Wardriving https://en.wikipedia.org/wiki/Wardriving
- croes 5y agoIs this post inspired by alias_neo's comment for the post about Amazon blocking FLoC? https://news.ycombinator.com/item?id=27516231 https://news.ycombinator.com/item?id=27516231
- alias_neo 5y agoI was quite surprised to see this here.
- client4 5y agoActually yes! I found it surprising and thought it deserved a conversation. Thanks for posting the link in the other discussion. I've actually changed my SSID because of this ... though it may have the opposite effect of drawing more attention to my SSID because prettyflyforawifi_nomap doesn't have the same ring as the original.
- alias_neo 5y agoAnd my real issue with it is that I have to change my SSID to opt-out. I have many, many devices using my WiFi, some of them (home made) IoT devices with custom firmware and the SSID/BSSID baked in to the firmware. Changing my SSID is a huge undertaking and I'm sure Google is aware of this. I don't get to opt out, unless I want half of my home automation to stop working and potentially weeks of effort to get the rest of it back up and running.
- client4 5y agoI agree it's annoying the onus for opt-out is put onto the generally unaware public. I've been contemplating a project that would "poison the well" as it were. Users could submit a MAC address and SSID to a service allowing other users to broadcast this information to make SSID collection much less useful. The downside to this idea is that it would be easy-ish to filter out the noise if individuals had a constant SSID for their own use. Perhaps the better way to handle it would have devices rotate SSID's and/or passwords and/or router MAC's on a regular basis. Like algorithmically have all devices compute the SSID on a daily basis (with a few hours dual-broadcasting SSID's to account for clock issues) based on a seed.
- tgv 5y agoDoes it add networks that are not listed? And I suppose both your main and guest network have to be called "_nomap".
- eitland 5y agoHi all Googlers here :) Quite amazing isn't it that a company with so many extremely talented employees (I'm actually serious) can produce such utter nonsense at such scales ..?
- 0x0nyandesu 5y ago"googler" no longer exudes excellence or intelligence. Now it's just "I know how to play corporate politics".
- thatguy0900 5y agoThe most brilliant engineer in the world will produce a shit product if their managers tell them to. These are intentional annoyances to get you to hand data to Google, and they all dissappear when you do. Not shoddy programming.
- OldGoodNewBad 5y agoAs smart as some of them may be, as far as I’m concerned they are ALL shady individuals.
- dang 5y agoPlease don't break the site guidelines like this. Not cool. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- diegoperini 5y agoThe solution triggers me a little. I like pretty names.
- jventura 5y agoWhy should I have to change my AP's name to opt out, since I've never opted in?
- vesinisa 5y agoYes you have in a sense. Your WiFi router is broadcasting its SSID and anyone in range can pick up this signal. If you do not wish to broadcast your SSID, you should disable it in your router. What you are suggesting is to me no different than asking why a random passer-by can take a photo of your house. Because of course they can. Saying that a person can not take an image of your house unless you have explicitly put up a sign saying your house can be photographed is an absurd proposition and a sad privatization of the public sphere. The color of your house is not within the domain of your privacy, and neither is the location of your WiFi if you choose to broadcast your SSID.
- cle 5y agoExcept an average person can’t be expected to understand what “broadcasting an SSID” even means, compared to putting some numbers on your house that are required for essential services. It’s even doubly deceptive because then you need to understand the privacy implications of Google’s data capture, how it feeds into their ad business, etc. I understand all of this stuff but I don’t think it’s reasonable for people in general to, and I think people do have a “reasonable expectation of privacy” when it comes to their SSIDs. Nobody installs a router/AP and thinks “okay good, now Google can index my SSID”, they think “now I can securely connect my devices to my private network”. (Just to be clear this is not a legal argument.)
- vesinisa 5y agoThey don't need to understand the technical details to realize that network names are public information if they have ever connected to a network in an urban setting, where you can always see your neighbors network names in addition to yours.
- SuchAnonMuchWow 5y ago
- user3939382 5y agoAlternatively, and maybe sub-optimally depending on your priorities, disable SSID broadcasting on your AP(s). Google might index it from devices that are manually connected but it won't be usable for the geolocation of others.
- gruez 5y agoAFAIK that's actually worse because devices that remembered that SSID would be continually sending probes containing that SSID, everywhere you go. https://android.stackexchange.com/questions/221261/does-android-send-wi-fi-probe-requests-to-saved-hidden-networks https://android.stackexchange.com/questions/221261/does-andr...
- spiderice 5y agoExcuse my ignorance, but why is that a problem? Presumably, whoever is snooping on said broadcasts doesn't know how to find "my_awesome_wifi", do they? Would the attack be "harvest SSIDs from Starbucks and then drive around the neighborhood until you find the house it belongs to"?
- gruez 5y ago>Excuse my ignorance, but why is that a problem? fingerprinting/tracking. even with wifi mac randomization enabled, if you see a given client broadcasting a certain set of SSIDs you can use that to track them.
- norom 5y agoI find it quite ridiculous that a company is essentially demanding me to change the SSID of my network to opt _out_ of something.
- recursive 5y agoYou opted in when you started broadcasting information on the airwaves.
- rootusrootus 5y agoThat is not a fair comparison. You opted into the information becoming available to nearby people, you did not opt into having it aggregated and provided to the entire world. IMO this is one of the fundamental difficulties the era of digital data collection has brought to our society, things that were once not feasible (and therefore not a concern) are now trivial.
- yesbabyyes 5y agoI would have more acceptance towards this viewpoint if it was about automatic positioning using images of the neighborhood. To me, lamenting the era of wifi technology yet without ubiquitous use of smartphones seems a bit... quaint?
- rootusrootus 5y agoI think we should raise the issue repeatedly until we reach an informed consensus (apathy doesn't count as consensus IMO) as to how we handle information in the digital age. So much of our legal system is founded on principles that made sense not that long ago but are upended by the recent emergence of trivial mass data collection possible with current technology. We need to have a conversation about what is a sensible policy, and not just on tech forums.
- yesbabyyes 5y agoTo be sure, I agree with your general standpoint here. I just couldn't resist when the argument is based on the somewhat random convenience of broadcasting an (often user selected) id of your network, while simultaneously holding that nobody is allowed to keep track of that id. To be clear, I don't, at all, think this is a workable path forward. I also wanted to point out how brief a period of time this is. Imagine learning about some issue arising from movable type in the 15th century, being solved over a period of a few decades, helping the rise of some corporation/feudality long past. When it comes to policy, how about making APs not broadcasting a public id, while making it illegal to track any traffic on any identifiers for the spectrum? Would that be called for? Or does the convenience of setting up a new AP make up for the fact that a corporation may make a few more bucks out of an improved positioning service? I don't know, but I still find it funny that you would defend a particular decade in the early noughts, holding these few years as an ideal.
- trutannus 5y agoHow is this even remotely compliant with any basic privacy legislation?
- onionisafruit 5y agoIs mapping wifi access point locations covered by any privacy legislation?
- trutannus 5y agoLikely GDPR, yes.
- Hnrobert42 5y agoI am not so sure. An SSID is not personally identifiable information.
- Doctor_Fegg 5y agoI'm not so sure either. Sit on any train and you'll see lots of personal wifi hotspots called "Fred Bloggs's iPhone". That certainly is PI.
- deleted 5y ago[deleted]
- onionisafruit 5y agoGoogle doesn't want "Fred Bloggs's iPhone" in their data set anyway. A mobile access point is no use for geolocation.
- KingMachiavelli 5y agoI guess just change your routers broadcast Mac to an iPhone one. Maybe we could use randomized MAC for APs like we have for clients.
- rhn_mk1 5y agoCan't wait for the fun opting out of multiple services, each with a different suffix.
- AdmiralAsshat 5y agoThe kicker will be when those companies all sell their SSID info to each other, so that Amazon can supplement Google's warehouse with the SSIDs of everyone who appended "nomap" to theirs, and Google can return the favor with everyone who appended "no_amazon" to theirs.
- scottymuse 5y agoI figure the SSID is no less public than the street address. Anyone in the area can determine an address or an SSID, but that information isn't tied to identity. Unless of your SSID is 'scottymuse_5ghz or something.
- kube-system 5y agoIt is trivially easy to connect an SSID to an identity, as soon as someone runs any application on the network that has privileges to both an identity and the SSID.
- superjan 5y agoAnd how does one opt out of that?
- gruez 5y ago>It is trivially easy to connect an SSID to an identity As opposed to a street address? In most cases there's a 1 to 1 relationship between a house and a hotspot.
- kube-system 5y agoYes, it's just key-value data and basically every mobile OS has APIs that will hand it to a developer on a silver platter. I'm sure that this data is already available from various data brokers, just as address data is. But it's not a competition anyway. Address data being freely available doesn't make other privacy abuses any less bad.
- gruez 5y ago> Address data being freely available doesn't make other privacy abuses any less bad. If the mapping of SSIDs to GPS coordinates is a "privacy abuse", what does it say about mappings of house numbers to GPS coordinates? Should companies like google/tomtom be banned from collecting such mappings?
- sly010 5y agoThis is a bit like saying: Strangers looking for house #48 on my street are not allowed to look at my door and use my street number #42 on it to orient themselves. I am all for privacy, but this is a bit paranoid. Google is not distributing any information about an access points. A phone using wifi based location services simply listens to already existing SSID broadcasts. If you don't want your SSID broadcasted, turn off the broadcast. Is there aspect of this that I don't understand?
- Kim_Bruning 5y agoIt makes the laws really complicated too. Normally, I don't think there's an expectation of privacy for things that you transmit with a radio transmitter, so AFAIK it's still (mostly?) ok to own a radio receiver that can receive (almost) anything anyone transmits. (almost, because things like radar detectors are already illegal in some jurisdictions.) I think there's a tradeoff here. Having people carve out more and more frequencies that become illegal to monitor might not actually make the world a better place in the long run.
- shadowgovt 5y agoInterestingly, this varies from country to country, but in the US: yes. With very, very few exceptions, the law errs on the side of "If it's broadcast, anyone may receive it." Don't broadcast things you don't want received.
- teraflop 5y agoLegally, Wi-Fi communications in the US are not considered to be "broadcast", even if anybody sufficiently nearby can receive them. If you're not the intended recipient of a message, and you intentionally intercept it (or attempt to do so), and the content isn't "readily accessible to the general public", then you're breaking the law. Google was successfully sued over this, and to my knowledge the law has not been changed in the decade since then: https://en.wikipedia.org/wiki/Joffe_v._Google,_Inc https://en.wikipedia.org/wiki/Joffe_v._Google,_Inc. In particular, the SSID of a network is readily accessible to anyone with a Wi-Fi device, whereas the contents of data packets (even unencrypted ones) are not accessible unless you have packet-sniffing software and know how to use it. This seems to me like a fairly common-sense interpretation. You can still own general-purpose radio receivers (subject to the usual FCC rules about radiated emissions and so on). The legal restrictions are about what you can do with that equipment.
- ping_pong 5y agoWhat if everyone started using the same SSID name, would that be enough to obscure the information?
- gruez 5y agoIt works off the BSSID (ie. MAC address), not the ESSID (the human visible string).
- onionisafruit 5y agoI don't think so. I think they key off the mac address included in the ssid broadcast, not the ssid name.
- yesbabyyes 5y agoSure, but if everyone in the world renamed their networks to "_optout_nomap" it would work marvelously!
- everdrive 5y agoIs it not using the MAC address of the AP? I figured it wouldn't solely rely on the SSID?
- onionisafruit 5y agoIt does, but it gets the MAC address from the ssid broadcast. What this is saying is that if that broadcast includes an ssid name that ends with "nomap", then the broadcast will be ignored.
- polskibus 5y agoOutrageous. I have to opt out by changing my network, instead of Google asking for my permission or at least providing a form for opt out. Reconfiguring the router and all machines that work with it is just too much work, also it does not work retroactively (but should imho). It's PII at least in some situations, and for someone with Google's power.
- shadowgovt 5y agoIt's analogous to the robots.txt file, which one must host to opt-out of crawling (and everyone's basically fine with). Public network, publicly-accessible data. Public airwaves, publicly-accessible SSID. Google is assuming (much as it assumed with crawling the Internet) that information broadcast in the clear into the world is fine to aggregate. (Personally, the only part I'm sad about is that since there's no hidden metadata channel to take advantage of in the 802.11 protocols, they can't squirrel away the "nomap" in a hidden state and instead have to gum up the human-visible SSIDs to transmit the intent to not be indexed).
- laumars 5y agoThere’s a big difference too in that when you publish a website, you intend for it to be aggregated. Whereas people don’t intend their SSID to be aggregated. It’s more similar to walking along the street compiling a list of what colour curtains people put up in their window. Sure you’ve technically got it on display but people don’t really expect that information to be aggregated and shared. Ease dropping on a conversation on the bus or a train is another example. You can’t really complain if someone overhears but that’s a far cry from someone then publishing what they overhear
- jjulius 5y ago>There's a big difference too in that when you publish a website, you intend for it to be aggregated. You're framing this as an absolute and that's just not true. Were it the case, robots.txt wouldn't exist and I wouldn't be using it.
- durnygbur 5y agoHey Google if you don't agree to hire me please redirect google.com to google-nohire.com. Otherwise I consider my imaginary contract binding.
- coldacid 5y agoGoogle can fuck off and die. This should be opt-IN, not opt-out.
- pokot0 5y agoThey can take pictures of my backyard from satellites, planes and distrubute and sell them them to anyone like it's theirs. And i can't opt out. I am a little worried when politicians will start making laws to control them. The reaction might be "let's just go with the other party" which creates the basis for a 1984-esque future...
- pulkitsh1234 5y agoGoogle is selling this data openly using their Geolocation API, check this: https://developers.google.com/maps/documentation/geolocation/overview#wifi_access_point_object https://developers.google.com/maps/documentation/geolocation...
- plusCubed 5y agoI remembered that Apple has such a database too, and interestingly, here's a project that reverse-engineered queries to Apple's Wi-Fi geolocation service: https://github.com/zadewg/GS-LOC https://github.com/zadewg/GS-LOC
- fnord77 5y ago> To opt out, change the SSID (name) of your Wi-Fi access point (your wireless network name) so that it ends with "_nomap." For example, if your SSID is "12345," you would change it to "12345_nomap." LOL. Are they kidding?
- markstos 5y agoWe can hope that Microsoft will require _bing_nomap as their suffix, While Apple will be more privacy-minded and require _yesapplemaps to be added if you wish to opt-in. Opting out of Google while opting into MS and Apple scanning is left as an exercise to the reader.
- randomperson_24 5y agoApple already does that and based on what I found there is no way for your router to opt out. Source: https://support.apple.com/en-in/HT202339 https://support.apple.com/en-in/HT202339
- sixothree 5y agoFollowed by: "To help ensure your changed SSID is submitted to Google quickly, open Google Maps on an Android device with Wi-Fi turned on. To establish a location fix near your Wi-Fi access point, tap My location My location."
- thamer 5y agoThis is such a Google solution. It reminds me that there was a version of Google Maps on iOS where if you wanted to cache a region of the map locally for offline use, you would (1) zoom out to view the full area to cache and (2) search for "OK Maps" to cache that area.† Yes. Searching for "OK Maps" to cache it. You know, instead of maybe adding a button like in any normal app made for human beings? I'm not at all surprised by this _nomap "solution". † 2013 article: https://www.cnet.com/how-to/how-to-cache-offline-maps-in-latest-google-maps-for-ios/ https://www.cnet.com/how-to/how-to-cache-offline-maps-in-lat...
- ArnoVW 5y agoIsn't this a PII? According to GDPR, wouldn't they need a justification for storing it? (informed consent, business reason, etc.) They had a huge stink on this some years ago when 'some random engineer decided to add it to Google Maps sniffing'.. and now it's opt-out? I must say I'm surprised.
- plusCubed 5y agoGoogle and Apple both have WiFi geolocation databases. As far as I can tell there's no way for an AP to opt-out of Apple's database. Interesting tidbit from [1]: "In older versions of Apple's mobile OS (1.1.3 to 3.1), Apple relied on Google and Skyhook Wireless to provide location-based services -- so Apple left data collection to them. But ever since April 2010, starting with iPhone OS 3.2 and continuing into the current iOS 4 software, Apple has started using its own databases to provide location-based services to iOS devices." [1] https://www.wired.com/2011/04/apple-iphone-tracking/ https://www.wired.com/2011/04/apple-iphone-tracking/
- caturopath 5y agoDoes anyone have any good pun SSIDs ending in _nomap?
- boston_clone 5y agolazy attempt for meshed networks: leaf_erikson_nomap
- client4 5y agoWhat did the Google Street view car say in the middle of the lake? _nomap.
- AnssiH 5y agoNote that there are other AP location databases in addition to Google's, such as Apple's or https://wigle.net/ https://wigle.net/ , the latter being publicly searchable.
- ldng 5y agoIt that applied in Europe also ? Forcing to opt out is illegal, it must be opted-in AFAIK.
- whydoineedthis 5y agobetter way: don't allow your network to be broadcasted. This should really be the default for any home network.
- msoucy 5y agoWhen exactly did this "opt-out" start? I'm seeing cnet articles from 2011 about this exact thing.
- magicalist 5y agoLooks like it. Some of the articles from that year point to https://googleblog.blogspot.com/2011/11/greater-choice-for-wireless-access.html https://googleblog.blogspot.com/2011/11/greater-choice-for-w...
- athenot 5y agoSo a fair response would be to start broadcasting the whereabouts of Sundar Pichai until he decides to opt-out of this by legally changing his name to Sundar Pichai_nomap.
- adam-p 5y agoNote that MS used automatically share your WiFi creds with your friends unless you had "_optout" somewhere in your SSID. ...But at least it wasn't strictly "ends with" (unlike Google's), so "_optout_nomap" should work. (Except MS killed the feature anyway.) [1]: https://krebsonsecurity.com/2015/07/windows-10-shares-your-wi-fi-with-contacts/ https://krebsonsecurity.com/2015/07/windows-10-shares-your-w...
- williesleg 5y agoYou opt out but you don't really.
- ChrisMarshallNY 5y ago> To opt out, change the SSID (name) of your Wi-Fi access point (your wireless network name) so that it ends with "_nomap." For example, if your SSID is "12345," you would change it to "12345_nomap." That's annoying, but I don't actually care, that much. My access points are locked down about as well as possible, and having them in there actually helps to improve map accuracy. I just switched ISPs, and I'm currently getting ads that think I'm in New Jersey. As soon as my new router gets re-mapped, I'll be getting ads that make it seem as if stock photo models are local lawyers. Anyone that really wants to get into my access points could probably do so, but I also have a few layers of security (multiple routers of different manufacture), as well as fixed MAC addresses (which is a pain for the iOS devices). Also, I'm surrounded by neighbors that have much lower-hanging fruit.
- cellularmitosis 5y ago> Also, I'm surrounded by neighbors that have much lower-hanging fruit. You don’t have to outrun the bear, you just have to outrun the other campers ;)
- belatw 5y agoThe world now belongs to 2 entire generations who never read 1984.
- losvedir 5y agoWhat's the point of SSIDs, really? They just need to be some strong unique in your proximity. I got tired of coming up with witty puns and just used my street address. Is there any downside to this? In fact, if everyone did this, the alleged privacy problem would go away. Wifi stations really would just be like street numbers. I'm not sure I understand the threat model here.
- sneak 5y agoNote that publicly-searchable AP databases such as https://wigle.net/ https://wigle.net/ operate on the BSSID MAC address (serial number, effectively) of the base station/AP. Packets are transmitted with this information unencrypted at all times. This means that when you move your AP from your old house to your new, your move is publicly visible unless you replace your AP when moving.
- idatum 5y agoThere is a dark pattern in Android that is tangentially related only, but I need to share it: The service in Android using (B)SSID for "a better experience" is configured off on my phone, and I explicitly turn off all location services when I don't actively need it. Every time I turn on location, then open Google Maps, Maps prompts me to turn on the "enhanced experience". Picture yourself in a bit of a rush, needing to do some quick navigation using your phone and Maps, and how easy it is to quickly dismiss that prompt without realizing you just offered Google more data. Note: My default behavior regarding Google is to give them the absolute minimum amount of data.
- sneak 5y ago> Every time I turn on location > give them the absolute minimum amount of data Contradiction, Mannie! PS: Offline GPS turn-by-turn navigation devices from China are about $50 now. I use them myself ever since I decided I wanted to stop leaking my realtime location to Apple and Google.
- colanderman 5y agoMaybe it's my imagination. But GPS-only location services on Android have progressively gotten worse to the point of utter uselessness today. My G1 could obtain and retain a GPS-only lock nearly as well as my dedicated Magellan GPS handheld. Meanwhile my Moto G4 will try for hours and be unable to obtain even the remotest idea where I am. The more cynically minded might even suggest Google has purposefully let GPS-only capability degrade as a dark pattern to push users to opt in to SSID-based services.
- geraneum 5y agoThat's how I ended up paying for YouTube premium one time! I clicked on a YouTube (short)link on Twitter or somewhere and YouTube app opened, then a blocking dialog asked about premium membership and the button to get the membership (after trial period) is bolder, so you are more likely to press it accidentally if you are eager to watch the video! I got so angry that I deleted my payment method from my Google account. They research patterns, and they know how and when to ask you to press a button. Not illegal but unfair IMO. Take this post for example, changing SSID is so inconvenient that the user might not want to go through the whole process.
- chagaif 5y agoI don't have an SSID I'm Jewish...
- phreack 5y agoThis is death by a thousand cuts. Yet another small annoyance that can be easily dismissed or explained away as is happening in the comments, and we never realize the precise point where we have been stripped of any possible privacy or anonymity in the name of profit and ads.
- batch12 5y agoThere are repeated questions asking how this is a privacy concern. One use case as an example: I become interested in you. I sniff traffic to see which wifi access points your phone tries to connect to. I look up the SSIDs and find a plausible match for your home or workplace. I show up so we can hang out.
- igetspam 5y agoAh. Yet another total dick move that google makes. It's not new but it should be a reminder that google loves data. Your data. And they'll do whatever the hell they want with it, whenever they want.
- jetanoia 5y agoReminds me in a way of paparazzi and so I wonder, when will ‘automated paparazzi’ become a thing, and when will it be considered to have gone too far? Certainly too creepy for the public to allow (or even imagine) today but perhaps in 5 or 10 years the masses may be sufficiently conditioned to consider the privacy tradeoff worth whatever conveniences (or ‘security’ benefits) it dishes up for them. Marketed as ‘public view’ imagine Boston Dynamics or drones with more ai, solar powered, operating at amazon or google scale. Maybe they’ll even dress them up like birds and other wildlife to give it an ‘organic’ or natural feel. Fun times.
- randomperson_24 5y agoApple is doing that since iOS 5 (the oldest I could find) and there is probably no way to opt out. In fact it's even worse. Source: https://support.apple.com/en-in/HT202339 https://support.apple.com/en-in/HT202339 But apple is good while Google bad :) Edit: found out a newer post [1] with absolutely no mention on how to opt out. They also send barometeric pressure level for some reason. They might also start sending device temps to predict the temperature at different places across globe and "help their customers" [1] https://support.apple.com/en-us/HT203033 https://support.apple.com/en-us/HT203033
- ChuckMcM 5y agoHere is a better idea, don't use it unless the ssid has the suffix "_map" sigh.
- indianmouse 5y agoWhy in the world I've to change my access point to opt out of google's data collection? Why are they collecting information in the first place? Stop collecting information. This is way beyond anything but privacy intrusion. It's like telling another some big corporation that one has to change the name else they will profile you irrespective of what you do... Atrocious isn't? Publicly available information doesn't mean that you will whatever you want with it. Tomorrow, (already their OS, Android is doing it), they will collect everything about a person and this is going way beyond who has signed up for. This needs to stop. All in the name of providing services or improving lives of people. Who cares about the dark side? How much profiling has gone into the collected data? What kind of risks it may pose in the future? This needs to stop... the sooner the better... Everyone has the right to be private. It doesn't mean one has to throw away everything in public about them. Isn't? I know I might start another discussion thread, but I'm sure there will be people who will battle for and against... But it doesn't matter...
- Ayesh 5y agoShoutout to Mozilla location services (https://location.services.mozilla.com/ https://location.services.mozilla.com/) that make it very obvious, permissive, and sort of fun to do this.
- hamilyon2 5y agoNo need to worry. Yandex ssid mapping, Apple ble "find device" beacons, Foursquare, uber, governments, amazon echo, samsung's tvs and everyone's dog already got you covered. There is zero need to hide your ssid and location drom google location services.