21 ms·
Apple allows some iOS apps to track user locations via lists of nearby SSIDs
- forward1 3y agoCan we talk about the fact iOS/macOS turns on the Wifi and Bluetooth radios after each system update? Almost as if the devices were made deliberately to maximize spying, contrary to the marketing lullabies.
- emmo 3y agoYeah I find this incredibly annoying.
- ShakataGaNai 3y agoHanlon's razor: Apple is just lazy and defaults all these things to on, rather than keeping tract of the settings since they are used or needed by 99% of people. Apple loves its Bluetooth keyboards and mice, after all.
- forward1 3y agoI don't think so. Apple likes to collect data as much as anyone else, they're just better at hiding it with euphanisms. To wit: iOS requires precise location be enabled just to show weather on the home screen; I can't set a static location and just get the weather report for that place. The whole thing just reeks of willful surveillance anti-patterns.
- coldcode 3y agoFYI, that API requires entitlements to be used, which are only available if you request them from Apple and justify their use. It's not a general-purpose API any app can use.
- lxgr 3y agoThat’s not really any consolation, since (according to the article) Apple has granted that entitlement to WeChat and Alipay. Yes, these are “super-apps” and Wi-Fi hotspot services are probably part of their offerings, but that’s just more reason this should be a user-grantable permission like “local network access”. If I don’t care for the hotspot feature, I don’t want the app to have that capability.
- MBCook 3y agoCertain apps have always gotten special treatment. If it’s big enough to mess with phone sales they’re allowed nonsense a normal dev would be permanently banned for. Ex: all the stuff FB has been caught doing over the years My understanding (no first hand experience) is that WeChat and Alipay are basically required in China. If a phone doesn’t have them, it’s worthless and won’t sell. So naturally they too can do nonsense that would get the rest of us booted to space.
- stavros 3y agoWhy does apple get to decide which app gets automatic access to my private data, on my device, without needing to ask me?
- electric_mayhem 3y agoDoes your employer have a donation matching program? It’s a great time of year to donate to the EFF.
- stavros 3y agoI donate to NOYB, but I second your sentiment.
- BobaFloutist 3y agoIt's so hard to prioritize non-profits these days. EFF is huge and super relevant, but so are aid programs to Ukraine or I/P, and reproductive health orgs. There's a lot going on I want to contribute to.
- mrtksn 3y agoTL;DR: Apps can access the nearby Wi-Fi hotspot SSID and MAC addresses through an API that is intended to help with connecting to hotspots. Then they can use this info to look-up in databases that collect SSIDs based on their locations. Seems like a valid concern, though the author's writing style can be off putting since has a tone with an agenda. However, AFAIK apps need to declare the use of this API and have a good reason for it(you fill up a form explaining why you need it and Apple has to agree to grant you the privilege). So, most likely your flashlight app is not tracking you. I'm sorry you don't like it but that's the truth, the author left out crucial details to make it juicier.
- INGSOCIALITE 3y agoi wouldn't be worried about my flashlight app tracking me, i'd be worried about the large players who probably GET the use of this API, google facebook etc etc.
- secondcoming 3y agoIf that app has ads then your info is being sent to advertisers. Why would a flashlight app even need your location?
- mrtksn 3y agoAs I said, it's a valid concern. However the author forget the mention that you need to apply and get approved to use this API. I find it dishonest and alarmist. Here's the request form that you fill up for it: https://developer.apple.com/contact/request/hotspot-helper/ https://developer.apple.com/contact/request/hotspot-helper/
- wwtrv 3y ago> However the author forget the mention that you need to apply and get approved to use this API. And? How is this any better? e.g. if I'm a dissident/etc. in China I would be much concerned about government affiliated large corporations being able to track my location than some random private developer (not that this specific API really matters that much if you're using those apps anyway). > I find it dishonest and alarmist. I find it a magnitude or two less dishonest than Apple (a company supposedly focused on user private) not informing their users that this is happening and directly requesting their consent.
- peddling-brink 3y agoDocs: https://developer.apple.com/documentation/technotes/tn3111-ios-wifi-api-overview https://developer.apple.com/documentation/technotes/tn3111-i... I’d guess a review would stop the smaller spam apps, but not the big players, as noted by the author and other commenters.
- JKCalhoun 3y agoThanks. The docs confirm that an entitlement is required to call this API — still does not make clear to me whether the presence of the entitlement brings up a prompt allowing the user to deny the use of the API.
- peddling-brink 3y agoIf it does, it would be for network, not location. Per the rules, this isn’t a location api, except it actually is. Iirc Android has always asked for location to enable Bluetooth, I wonder if there are similar apis there?
- JKCalhoun 3y agoYeah, Apple may want to rethink Network != Location.
- patrickserrano 3y agoThere is a setting to allow location for the "Networking and Wireless" system service. I wonder if disabling that would prevent this from working?
- otterley 3y agoIf you care about this, the best thing you can do to get Apple’s attention is to fill out the form at this site: https://www.apple.com/contact/feedback/ https://www.apple.com/contact/feedback/ and select “product feedback.” Doing so was instrumental to persuading Apple a few years ago to add an option “allow only once” when apps asked for permission to access the user’s current location.
- deleted 3y ago[deleted]
- donohoe 3y agoHow is it any different than an app that makes an request to their services API, thereby getting IP address which in itself can be used to get location information? There is always a vector for abuse, and I think Apple has taken large steps to reduce that. I find this story a bit of a non-event.
- lxgr 3y agoThere’s a huge difference! Wi-Fi positioning is usually accurate within a few meters; my IP is frequently on the other side of the globe (when using a VPN or just roaming globally).
- filleokus 3y agoIP gives you a rough location (like which city at best), SSID/BSSID can give you street/building level accuracy if it's in a database like https://wigle.net https://wigle.net Considering the scale of these apps, I'm guessing they have internal wifi<->location databases with fairly great accuracy.
- mrpippy 3y agoIt’s worth noting that use of NEHotspotHelper requires a special entitlement (com.apple.developer.networking.HotspotHelper) that you have to apply for, and presumably Apple won’t grant unless your app has a legitimate need for it. That said, this maybe shows an incompatibility between Apple’s privacy strategy and “super-apps” like WeChat and AliPay. When a company shoves all functionality into one app, that app suddenly has all the entitlements, and it’s harder to tell when and how any sensitive data is being used. The West generally doesn’t develop apps this way. For example, Comcast has a separate “WiFi Hotspots” app. Although LOL, they posted 2 days ago that its functionality is being combined into the main Xfinity app. Maybe the West is catching up.
- nequo 3y ago> com.apple.developer.networking.HotspotHelper Where do you revoke this entitlement on iOS? Settings → Privacy & Security → Local Network? Or is this something else?
- yunohn 3y agoAFAIK entitlements are not necessarily exposed as toggles.
- lencastre 3y agoGeneral > Reset > Reset Location and Privacy Settings
- ycombinatrix 3y agoYou didn't grant any location access in the first place, so why would this work?
- tick_tock_tick 3y agoThis is one of the special ones so you're not allowed to; Apple picks for you per app.
- turquoisevar 3y ago
- _justinfunk 3y ago>Credit: This article was written with the assistance of ChatGPT for the purpose of refining my English writing. I appreciated this disclosure. The English was still a bit clunky - but it was a great use of the technology to open up the article to a wider audience. It felt sincere to me.
- deleted 3y ago[deleted]
- m3kw9 3y agoApp that needs it will get it one way or another, is just not easy
- eduction 3y agoI thought users were prompted to give permission for this already? I get asked if I want to give “local network” access to apps sometimes (- lot these days actually) which I take to mean the ability to see local WiFi hotspots. I almost always deny this (and after reading this just turned it off for Spotify). I think the dialog that asks for permission could be improved, though, as most people don’t realize this can be used to deduce their location.
- rkunde 3y agoThat’s for sending and receiving local network traffic, eg. talking to devices on the same subnet, and discovery of Chromecast and similar targets. Edit: AirPlay does not require this permission.
- graftak 3y agoYou’d think that AirPlay would be abstracted away by an OS API that does the local network discovery itself.
- ascagnel_ 3y agoIn my experience, it is. My podcast app of choice doesn’t have that permission (I don’t even think it asked for it), but it has the ability to bring up the system audio output selector widget and do AirPlay. If anything, I usually see this for apps that want to do playback via Chromecast/Miracast. The well-behaved apps wait until the user interacts with Chromecast output, the iffier ones ask on first launch.
- deleted 3y ago[deleted]
- Hippocrates 3y agoI don't believe it is necessary for airplay, but probably is for Chromecast, Sonos, and many devices to establish ad-hoc connectivity for setup and operation. I take this popup to mean that they want to fingerprint and locate my home network or backdoor it somehow. I ALWAYS deny this access unless the app specifically requires it, and that is rare. WiFi based geolocationing should be a well known privacy threat by now. The popup should really communicate that better and provide tighter controls.
- tinus_hn 3y agoOne should realize that what they call ‘track user locations’ is actually ‘get a list of visible SSIDs’. Should be behind a permissions check, but not the end of the world.
- School-Cotton 3y agoVisible SSIDs are absolutely used to fingerprint location.
- dmboyd 3y agoAt least in the early days, every iPhone maintained a local lookup table between ssids and gps coordinates in a SQLite database. https://www.networkworld.com/article/752872/security-apple-officially-responds-to-ios-consolidated-db-tracking-file-controversy.html https://www.networkworld.com/article/752872/security-apple-o...
- tinus_hn 3y agoThat doesn’t mean seeing an SSID means you are at exactly that location. If you are in a city you see 50 SSIDs at any given moment. Are you at those 50 locations at the same time? No. Is there a way to triangulate where you are exactly? No, its unreliable and not an exact science.
- charcircuit 3y ago>Is there a way to triangulate where you are exactly? No The phone knows the signal strength of each ssid. Why can't it triangulate where it is?
- School-Cotton 3y agoIt can and does.
- ycombinatrix 3y agoyou're all over these comments trying to convince everyone that SSIDs can't be used to determine location, yet you don't know how triangulation works? are you trolling?
- ynniv 3y agoI thought local network access and WiFi details also required location services access for this reason.
- asylteltine 3y ago[flagged]
- andirk 3y agoWhether the user is aware and opt _in_ is the issue, right? But all of the network signals that are triggered by web applications, phone apps, OS, isn't it almost always possible to get SOME information about a user's geo location? There's a theory that Silk Road's Ross Ulbricht leaked his location via a Captcha on a website, despite actively covering his tracks. I think Bitcoin's Satoshi is/was an Australian bloke living in Japan because of his wording + timestamp on posts. I was able to send a friend a little hello message via a Facebook ad by hyper targeting them (before fb disallowed that), which also confirmed their location.
- gruez 3y ago>There's a theory that Silk Road's Ross Ulbricht leaked his location via a Captcha on a website, despite actively covering his tracks. How?
- Arch485 3y agoAssuming this is actually the case, probably a lot of heuristics that got "close enough" to his actual location.
- deleted 3y ago[deleted]
- einpoklum 3y ago[flagged]
- germandiago 3y ago[flagged]
- thih9 3y agoWhich popular apps use that? Is it possible to check this? Like most here, I don’t have Wechat or Alipay installed. But I’m interested in e.g. Instagram, Facebook, Whatsapp, Twitter, Tiktok, Snapchat, Chrome, Firefox, Photoshop, Lightroom, etc.
- rsync 3y agoI know I sound like a broken record but I really do think app stores owe us the ability to see, in advance, what permissions an app will request. I shouldn’t have to download and install the app just to see what kind of behaviors it is going to attempt. The app stores know this information and it would be trivially easy to present it in the details of the app prior to down loading.
- breakfastduck 3y agoYeah, this should absolutely be standard.
- sneeze-slayer 3y agoIn the Play store it is possible to see what permissions are required and data is collected.
- rsync 3y agoI wonder if it is possible, as an Apple developer, to query "permissions requested" via some other channel ? I don't know anything about the ways Apple developers interface with the app store to submit or update or index their apps ... is it through xcode ? I wonder if there is some function in that toolchain that actually does what I am proposing ...
- Willamin 3y agoThis is possible and relatively easy for Apple to do: for most (if not all) permissions, a declaration that you intend to ask for permission is required in the app's Info.plist manifest file. When permission is requested and you've forgotten to declare that your app asks for it, the permission will be immediately denied without prompting the user.
- paxys 3y agoReading through the linked docs, this API seems to specifically be for apps created by owners of WiFi hotspots to help users connect to those hotspots (https://developer.apple.com/documentation/networkextension/hotspot_helper https://developer.apple.com/documentation/networkextension/h...). > NEHotspotHelper allows your app to participate in the process of authenticating with hotspot networks, that is, Wi-Fi networks where the user must interact with the network to gain access to the wider Internet. > NEHotspotHelper is only useful for hotspot integration. There are both technical and business restrictions that prevent it from being used for other tasks, such as accessory integration or Wi-Fi based location. Before using NEHotspotHelper, you must first be granted a special entitlement (com.apple.developer.networking.HotspotHelper) by Apple. Which makes sense, but then why exactly are apps like WeChat and Alipay granted this entitlement?
- iforgotpassword 3y agoBecause the Chinese market is too important. For wechat you can maybe argue that it's a "super app" and probably also can be used to connect to wifi hotspots, but for alipay I fail to come up with an explanation..
- physicles 3y agoAlipay is also pretty much an everything app (it also has its own ecosystem of mini-apps built on Alipay's platform). Except for the social aspect, it's nearly interchangeable with WeChat.
- iforgotpassword 3y agoAh I see. It's been a while thanks to the pandemic that I've been there, and even then preferred just doing wechat so I dont have to deal with even more stuff. At least for regular payment almost all places accepted both options.
- BertoldVdb 3y agoYou can buy hotspot access with Alipay (scan QR code -> connect), presumably thats why.
- tqwhite 3y agoMy iPhone asks if I want to allow an app to access the Local Network. I assume that this 1) means that Apple does cover this situation and 2) my opinion that the phrasing "Apple allows applications to track user locations without authorization" is contemptible are both true.
- idiotsecant 3y ago[flagged]
- dang 3y agoCould you please not post unsubstantive comments and/or flamebait? It's not what this site is for, and you can make your substantive points without it. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
- 0x0 3y agoPretty sure that's a different thing just to prevent tcp/ip connections to other devices on your local subnet after you have already joined a wifi.
- lern_too_spel 3y agoThat's a different permission. My understanding is it is not necessary to read WiFi details, which just needs an entitlement from Apple and no user prompt.
- lutoma 3y agoI think that prompt is for something different.
- cdme 3y agoMy most blocked domain in nextDNS (which runs on all my devices) is metrics.icloud.com. books-analytics-events.apple.com is in the top 5 as well.
- captn3m0 3y agoNow I'm curious - which other apps have this entitlement? Is there a way for me to find out which apps on my phone have this entitlement?
- sonicanatidae 3y ago[flagged]
- mannyv 3y agoThey're not tracking locations because they're not using GPS. They are checking the environment for stuff that might have known locations, which is different. You can do the same with bluetooth/BLE.
- panarky 3y agoThis is a distinction without a difference. The user must be in control of whether their location is disclosed to an app.
- extraduder_ire 3y ago> You can do the same with bluetooth/BLE. Not anymore you can't. Sometime before 2020 apple, and also google, started treating BLE scanning as an operation needing location permissions. (I had to deal with this transition while submitting an iOS app that connected to a BLE device which actually had a GPS module in it) As of now, I still have to turn on location on my android phone to connect to some BLE devices.
- bdavbdav 3y agoSame difference as far as a user is concerned. And BT/BLE explicitly asks for permission.
- x1sec 3y agoSSID / BSSID is often enough to pinpoint the location. Recently someone debated this with me, so I asked him what his wifi AP name was, then proceeded to provide their home address. How? By searching it in https://wigle.net https://wigle.net. That ended the debate quite swiftly.
- neverrroot 3y ago[flagged]
- ralmidani 3y agoThis is one of the majors problems with completely locked-down platforms. Assurances that the owner of the platform respects your privacy and prevents others from violating it are really just a pinky promise.
- vlovich123 3y agoI think the perspective can be incorrect. No one expects Apple to get it perfect. Computing platforms are legitimately hard to secure, especially when you’re talking about privacy which is a lot more amorphously defined culturally vs typical CS security which is defined as subverting technical access controls. The key question is whether Apple will play a curator role in trying to reign in the ecosystem. They have in the past (eg Uber was doing shady shit and there was a game of chicken to get them to stop). Of course Alipay and WeChat may be harder especially how Apple China is such a huge market for Apple and critical to their success now. It’ll be interesting to see how Apple adjusts to this over the next few years. Open platforms also have this problem and also operate on pinky promises (perhaps even worse) so I’m not sure the point you’re trying to make unless it’s that “well if this problem isn’t solved I’d rather have an open platform”. The problem with that argument is that there are many issues and this is only one failure case which may be addressed in the future whereas open platforms have this one and many more that are unadressed.
- thund 3y agoOpen platforms can be reviewed and fixed more easily and faster
- vlovich123 3y agoCan you clarify with examples/technical description how an open platform will be able to review & fix privacy/security issues like this more easily/faster? As far as I know this wouldn't be news on Android because such permissions are granted as a matter of course without review. Keep in mind that most people use the Google or Samsung stores which aren't open platforms for verifying permissions aren't misused. For what it's worth spyware/malware consistently seems to target Android more than iOS [1]. To be fair Android has more units, but that's just one axis - iOS users should be more valuable to exploit because they're usually in a different socioeconomic bracket. Another data point is that Android developers get paid anywhere from $2k to $20k to add malware to their Google Play store app [2] - I can't find any articles similar for iOS so would be interesting to compare the marketplaces if anyone knows it for iOS. [1] https://nordvpn.com/blog/ios-vs-android-security/ https://nordvpn.com/blog/ios-vs-android-security/ [2] https://www.bleepingcomputer.com/news/security/cybercriminals-charge-5k-to-add-android-malware-to-google-play/ https://www.bleepingcomputer.com/news/security/cybercriminal...
- kevinsync 3y agoWhenever location data collection comes up, I always think about that Seinfeld episode where Kramer is receiving misdialed MovieFone calls -- at first he just talks to the person and reads the movie times out of the newspaper. Very helpful. Eventually, he starts emulating the phone menus, asking the caller "Using your touch-tone keypad, please enter the first three letters of the movie title, now." When this doesn't work, he blurts out "Why don't you just tell me the movie you want to see???" Why in the holy hell do app developers who are trying to provide some kind of location-specific data not just ASK YOU WHERE YOU ARE? "I'm in Los Angeles" would suffice 99% of the time. If you go to Idaho, and care enough, change your location in that app -- now you get local bulletins about russet potatoes instead of encampment fires. This is a rhetorical question, no need to answer it, just screaming into the void.
- ryandrake 3y agoI know you said not to answer, but for everyone else, apps can already do this using the OS's native permission controls, as of iOS 13 with the "Allow Once" option and as of Android 11 with the "Only this time" option.
- WendyTheWillow 3y agoYou want to change your location in every app manually, even when your device has a GPS receiver installed?
- mikepurvis 3y agoA happy medium would be if as part of the location-granting prompt, you could tell the OS "just give a city-level fix— this app doesn't need to know exactly where I am".
- 0cf8612b2e1e 3y agoAs someone who keeps GPS off, absolutely. Not that I think I can trust the phone actually disabled the GPS, but there is no reason my movements need to be tracked and recorded in detail. Make them go through the effort and pull up all the cellphone towers I ping. Day to day, there is a very good chance I am still in my home city as first configured.
- toasted-subs 3y agoApple sometimes provides a prompt for letting photos be shown. Seems like sometimes they expose all your photos to application without asking. Seems worse to give your users a false sense of security.
- dang 3y agoWe've heard complaints that this title is overstated, and I'd be happy to replace it with a better (i.e. more accurate and neutral) one, if anyone has a suggestion?
- joshstrange 3y ago"iOS apps can track a user via SSID scan with a special entitlement" I think that best describes it? Not sure but I agree the title as-is doesn't really ring true after reading the article.
- crotchfire 3y agoI think the title is fine.
- Pesthuf 3y agoThis three class developer system on iOS is ridiculous. There's the normal developer who can do little more on iOS that you couldn't also do with a web app. There's the "blessed" developer with special entitlements that lets them violate the privacy of their users in new and fun ways and also provide features nobody else can so the normal developers can't compete with their app. And then there's Apple and for their apps, the restrictions everyone else has to deal with are little more than suggestions. Wouldn't want third party apps to compete with Apple's on their own platform. If there's a legitimate use for these entitlements, everyone should be able to use them. And the ultimate choice for what an App should and shouldn't be able to do should be in the users' hands. But Apple needs to protect their shareholders from this horrid vision of the future.
- aurelien 3y agoApple is evil
- EchoReflection 3y agocase study in the power of word choice, this “headline” reads “Apple allows SOME iOS apps to track"... but the actual article to which this page links does not include the word "some", making (imo) Yingyu's article seem to indicate a much more nefarious situation.
- happytiger 3y agoWait until people learn about Google sidewalk if they think this is bad. It is fundamentally intrinsic to the technology of most digital technology that: 1) their very data-driven nature leads to information gathering, and 2) the colossal and inherently inexhaustible recurring revenues in that data collection will always pull organizations and their leadership towards data collection at scale. The only conceivable framework for preventing information collection is to attach data privacy to the individual as an human right. Even “opting out” as an intrinsic default won’t be enough, though it is regulators’ and industries’ favorite kick-the-can strategy. Otherwise it’s just a question of time, as the incentive for profit is overwhelmingly attractive to companies, regulators and markets. Apple, for all the talk of privacy, cannot maintain the fiction of privacy while simulaneously answering to shareholders with a scale advertising business or really any advertising business of any revenue importance at all. Their promise of privacy for users died spiritually if not practically the moment they decided to dramatically expand their ad business, as it shifted the company from serving users as their customer with devices to making those same users the product to be sold. So this kind of thing is inherent and will continue to emerge from Apple. The opt-in, limited nature of who is allowed access matters very little. Just follow the incentives to understand corporate behavior.
- KindAndFriendly 3y agoFor the last few months, I am consistently receiving spam calls (on my mobile number) shortly after I left the house regardless of weekday, time etc. I never thought about the idea that an app can track when I leave my (most frequently) used WiFi and derive from that I left home.
- tremarley 3y agoAnd unfortunately, there is no way to truly turn off WiFi & Bluetooth on iOS devices.
- graftak 3y agoThe latest iOS allows more (all?) automations to run without user acknowledgement so I made one that fully disables my WiFi when I leave my home. This does not solve the entire problem of course, but at least alleviates some of it.
- devilsAdv0cate 3y ago[dead]
- deleted 3y ago[deleted]
- m463 3y agoturn off location services, your phone still contacts ls.apple.com deep links, they go deeper than you think. ibeacons provide very precise indoor location, think of all the behavioral data a store app can collect. apple is not really your friend. seriously, apple should let you - know what is running - know what network traffic happens - control these thigns - run your own programs I would love an ios firewall program or non-neutered little snitch
- cglong 3y agoI wonder if Android's corresponding API has this same vulnerability. Based on my reading, it doesn't seem like it https://developer.android.com/develop/connectivity/wifi/wifi-suggest https://developer.android.com/develop/connectivity/wifi/wifi...
- bengale 3y agoIs this how Tado does home WiFi detection for geofencing? Our company has an app that does geofencing and we’ve had no end of issues getting it to work consistently. This would have been useful.
- raylad 3y agoIs there a similar capability for Bluetooth? I am trying to understand how TikTok can suggest "people you may know" when I have not shared my contacts, but have sat next to those people recently. Bluetooth seems the most likely.