4 ms·
The randomisation feature of iOS was apparently not working for a long time despite Apple marketing otherwise [0] [0] https://arstechnica.com/security/2023/10/
by comprev 2y ago
The randomisation feature of iOS was apparently not working for a long time despite Apple marketing otherwise [0]
[0] https://arstechnica.com/security/2023/10/iphone-privacy-feature-hiding-wi-fi-macs-has-failed-to-work-for-3-years/ https://arstechnica.com/security/2023/10/iphone-privacy-feat...
- wutwutwat 2y agoUse any mac you want I'm sure we’re being fingerprinted other ways so it doesn’t matter. Security through obscurity isn’t security, after all.
- Nextgrid 2y agoMAC randomization prevents the local network from trivially tracking you based on access point logs. Of course, if your device runs software that broadcasts some unique identifier, the network may deploy some collector service to query/capture these but that's already extra effort. On iOS I don't believe apps can run a persistent network server in the background, so background tracking would actually be quite tricky even if you had a cooperating app. Fingerprinting is absolutely an issue for device-based trackers (whether apps or websites), but from the perspective of a passive network observer they're usually quite airtight and don't leak the collected data over insecure channels.
- wutwutwat 2y agoNot just access point logs, this isn’t WiFi specific. It’s to make packet inspection harder to link to a device. But, if I run say an airport network and control dns for dhcp I can track your dns requests (non encrypted dns) and interface info across MAC addresses and maybe even tag packets somehow. Also, if every device that connects is routed through a dedicated vlan only containing that device, it can randomize itself all it wants, it’s on a network by itself so it can’t “hide in the crowd”. Those are just things off the top of my head and am not a network person. I’m sure it’s not preventing the motivated from tracking you if they want to.
- Nextgrid 2y agoI don't disagree that a motivated attacker can set up advanced infrastructure to collect network-related fingerprints, but this requires active effort. MAC address randomization is designed to at least prevent multiple unconnected networks from trivially tracking a user by making up a per-SSID MAC address. Ideally, Apple would randomize MACs within the same SSID too, but this would break a lot of "free wifi for X time, then pay up" schemes that rely on consistent MAC addresses, and despite the appearances Apple is still very much in bed with the establishment and doesn't want to rock the boat too much by giving that much control to the users.
- Yeul 2y agoMaking tracking illegal by law will do more than any technology created by the tech industry.
- joshstrange 2y ago> despite Apple marketing otherwise That's a very uncharitable way to phrase that. It's not like Apple was lying or doing this on purpose. It was clearly a bug, a bug that was not wide known for 3+ years. It's not as if it was some open secret that everyone was taking advantage of. I'm not saying no one knew or that no one took advantage of it but I'd imagine the average consumer was complete unaffected by this bug.
- skygazer 2y agoI agree with you that it was probably unintentional, and an embarrassing failure, though not malicious. I mostly like Apple products and am tolerant of their business model and practices. But I was struck by your phrasing to wonder whether we really owe charitable interpretations to companies. I do think most people employed anywhere are probably well intentioned, and maybe we owe them something. But companies are almost algorithms that run on a substrate of people.