8 ms·
> We’ve normalised the idea that Bluetooth is always on. Phones, laptops, smartwatches, headphones, cars, and even medical devices constantly broadcast their pr
by trashb 8mo ago
> We’ve normalised the idea that Bluetooth is always on. Phones, laptops, smartwatches, headphones, cars, and even medical devices constantly broadcast their presence. The standard response to privacy concerns is usually “nothing to hide, nothing to fear.”
I guess anything you send out can be used to profile you.
Some of my friends live on a farm near a semi busy road, however far enough from other farms to not be able to receive their wifi. They showed me their router logging all the wifi accesspoints that appear/disappear. There where A LOT of access points named "Audi", "BMW", "Tesla" etc. similar to those devices leaking bluetooth data. We had a discussion that it would be easy to determine who was passing by at what times due to these especially when you can "de-anonymize" the data for example link it to a numberplate.
I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.
- pixl97 8mo ago> even medical devices constantly broadcast their presence I mean yes, said medical devices are a whole lot less useful to me if they are not transmitting data. For some of this stuff you can't have your cake and eat it too.
- xanrah 8mo agoThere’s a middle ground here. There is no technical reason a pacemaker constantly broadcasts itself - there is ways to allow communication to such devices without yelling your name all the time. And there is definitely no reason for such a name to be a unique identifier.
- pixl97 8mo agoI mean if not a name, how would a mac id be any different?
- ssl-3 8mo agoThere are technical reasons, though. Let's suppose we have a pacemaker, and it has data that is beneficial to read -- maybe even in real-time on their pocket computer, or opportunistically as the patient walks by their reader-device, or however that is done. So we want this data, and we want it over RF. It probably seems obvious that it should only transmit when it is told to do so, right? So how do we tell the pacemaker to transmit? On its face, that problem seems solved by integrating a receiver that sits and waits for a valid instruction. Except: That receiver takes power to run. And since changing batteries inside of a person is problematic, we want them to last as long as they can while still performing the desired task. Now we get to the not-obvious part: In terms of power, it's often less costly to intermittently transmit a string of data than to continuously operate a radio receiver. And maybe it's a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway. But a transmit-only radio? Good luck hacking that. So... we do intermittent transmission, and this works for pacemakers. It also works for the cheap Zigbee thermometer I have (wherein I don't normally request the temperature; it just delivers it periodically, and it runs for years and years on a coin cell). (Now: Should that pacemaker data be encrypted? Yes, of course. And so should the ID. In fact, the whole transmission should be indistinguishable from background noise by unrelated devices. In this way, authorized devices can then use pre-shared keys to receive and decode these messages and others receive nothing. That kind of cuts BLE and thus also the pocket computer out of the monitoring mix, but tradeoffs are tradeoffs.)
- palata 8mo ago> In terms of power, it's often less costly to intermittently transmit a string of data than to continuously operate a radio receiver. The fair comparison would be intermittently transmitting a string of data versus intermittently operating a radio receiver, wouldn't it? Maybe it's still less costly to transmit, that I don't know. But I am interested about it :-). > And maybe it's a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway. This part resonates more with me.
- ssl-3 8mo ago> The fair comparison would be intermittently transmitting a string of data versus intermittently operating a radio receiver, wouldn't it? Good point. I don't know that this would actually work with BLE, as implemented on our pocket supercomputers (which I presume to be a useful part of the support system of a modern pacemaker). But if we change the requirements to "Some kind of maybe not-even-invented-yet RF thing, maybe with a rechargeable translator device that a person keeps in their pocket to convert to BLE when that's useful" then: Sure. Intermittent receive could be used instead. Whether that's more efficient or not is an interesting problem. Transmitters tend to use more instantaneous power (ie, Watts) than receivers do, but a transmission can be very, very short. It doesn't care whether anything is listening or not. Transmitter wakes up, blurts out what it has to say, and goes back to sleep. If a chunk of BLE data of this size takes 1ms of transmit time (it might), and it happens every 60 seconds (it might), then that's transmitting for 1.44 seconds per day. So total consumed power over time (ie, Joules per day, or whatever) can be very low. That's part of how we got here -- BLE is built around this concept, and it all converges to make this easy to accomplish. Meanwhile: An intermittent receiver tends to use less instantaneous power, but it usually needs to operate for a longer period. It wakes up and actively listens for instructions for a period of time. If none are received, then it goes back to sleep. Synchronizing free-running clocks is hard (and disciplining them is expensive, power-wise, compared to a sleep state), so maybe that receive window is 50ms every minute. Worst-case: The receiver operates for 72 seconds per day. Even if receiving uses just 1/10th the instantaneous power as transmitting does (this is probably in the right ballpark), then the intermittent receiver still uses a ton more power over time -- especially if there are no transmissions to receive. (The receive window obviously closes if/when a transmission is received, so having something to hear can improve this some.) But the end goal isn't just to wake the pacemaker up by pinging it. The end goal is for it to transmit data. So we still get to wake up the transmitter and have it do that. Now, these are all made up numbers -- I think they're somewhere near reality, but maybe not. But it seems like kind of a double-whammy, to me, compared to intermittent transmit. :)
- just6979 8mo agoThat middle ground has been eroded by cost-cutting. Example: my mother had a cardic resynchronization device, and it had some kind of NFC type thing to enable the full wireless comms mode: wave a wand over her shoulder and the device's radio wakes up for a set time to send data or receive adjustments. So it wasn't always transmitting, but it did require the doctor's office or hospital to have that NFC wand to initiate any kind of data aquisition or reconfiguration. If it has an always-on BLE radio, the provider would just needs the phone/tablet/laptop with appropriate software that is already required. Since any device like is already going to have a radio equivalent to a BLE radio, then removing the NFC parts from the device (and especially from the provider side) is some amount of cost savings. I think most patients would disagree that this privacy trade-off is NOT worth it, but you have remember that the patients aren't usually the actual customers in the US health care system. (And most manufacturers are going to have the US market as a target at least somewhat.) The most common actual customer is actually the insurance companies, and they'll take every single fraction of a penny, along with "an arm and a leg".
- 0x1ch 8mo agoI was wardriving my neighborhood and realized my elderly neighbor's CPAP machine is broadcasting some type of BT signal 24/7. I imagine it's transmitting some important stats, but it did make me have a 2nd thought about medical devices being IoT or BT enabled.
- kccqzy 8mo ago> being IoT or BT enabled Please don’t conflate these two. I have lots of BLE wearables and other sensors. They only send data to my own computer which I control, unlike IoT devices which by definition send to a third party on the Internet. To me it is far more important to protect against strangers on the Internet versus someone wardriving the neighborhood. On a related note, did you know that EU has a Radio Equipment Directive (RED 2014/53/EU) that came into effect in 2025. It all but guarantees that such Bluetooth communication will be encrypted.
- bigiain 8mo ago> I have lots of BLE wearables and other sensors. They only send data to my own computer which I control That's perhaps technically correct, but a naive interpretation of the risk. I don't need to see the data your BLE devices are sending you, all I need is traffic analysis and meta data from the signals they are broadcasting - and they broadcast that to anyone within detection range which includes attackers with much higher gain antennas than you who can likely pick up those broadcasts at ten times the distance any of your devices will communicate at. "Flying helicopters low and slow over the Tucson desert in Arizona, the FBI has been using "signal sniffers" to try to locate Nancy Guthrie's pacemaker. As the search for the 84-year-old mother of US Today show anchor Savannah Guthrie entered its third week, investigators took to the sky with advanced bluetooth technology. They were hoping to pick up signals emitted from the device implanted in Ms Guthrie's chest to help trace her whereabouts, US media outlets NewsNation and Fox News reported." https://www.abc.net.au/news/2026-02-16/nancy-guthrie-pacemaker-signal-sniffer-suspected-kidnapping-fbi/106348848 https://www.abc.net.au/news/2026-02-16/nancy-guthrie-pacemak...
- kccqzy 8mo ago
- dietr1ch 8mo agoWhat forces devices to constantly stream data? You can batch updates and probably save power thanks to it.
- kccqzy 8mo agoBecause these BLE devices are so cheap that they don’t have storage. And BLE transmission is already very power efficient: the power consumption of BLE is probably the same order of magnitude as powering flash storage.
- officeplant 8mo ago>There where A LOT of access points named "Audi", "BMW", "Tesla" etc. That's one of the funniest things about wardriving with Wigle on your phone. I can often see the SSID of "Jennifer's Equinox", "Jacks Suburban" right after I get cut off by someone in said vehicle. The vast majority of car bluetooth/wifi I see tends to have varying amounts of identifying information. It's almost as bad as the fact that apple still defaults to Jacks iPhone/iPad etc with no option to rename the device until you've finished setting it up. Companies are not out to protect us with default settings and the majority of users need to wake up to this fact.
- saghm 8mo agoThis might just be me being uninformed as someone who doesn't drive but how are you seeing what wifi networks are available so quickly right after being cut off? My very naive instinct is that looking at your phone or opening up a menu with the available wifi networks on your car's display seems like it would require a noticeable decrease in attention to the road, so I'd almost expect an uptick in being cut off from other people who are annoyed with your driving.
- officeplant 8mo agoSmall town, phone is on a dash mounted holder. Sometimes I leave Wigle up just to eye every now and then to see how much crap I'm picking up while war driving. I am not without sin when it comes to driving a car.
- reactordev 8mo agoWhat would be next level wardriving would be to break into their Bluetooth and have a conversation about their driving habits. It can be done, relatively easily.
- SoftTalker 8mo agoI disable bluetooth on my phone, though periodically I find that it's back on. Edit: iOS
- deleted 8mo ago[deleted]
- craftkiller 8mo agoI have the opposite experience: GrapheneOS has an option to automatically turn your bluetooth off after a configurable period of not being used. So when I need to use bluetooth, I turn it on like normal. Then, without thinking about it, it automatically turns off. The end result is my bluetooth is only ever on for a couple hours each month when I'm making phone calls.
- littlecorner 8mo agoDid not realize I could do that! Thank you!
- rationalist 8mo agoI only see an option to turn back on tomorrow. How do you find this option?
- craftkiller 8mo agoIt's under Settings > Security and Privacy > Exploit Protection > Turn off bluetooth automatically Definitely not the most obvious location. I would have expected to find this under the bluetooth settings.
- rationalist 8mo agoAwesome, thank you. I don't recall that being there when I first installed GrapheneOS. I need to go through the settings more often I guess. It might be a cool feature if settings were highlighted or had a red dot or something until it was viewed (like an unread notification).
- jasonfrost 8mo agoThere's an Android app that can find devices, make profiles, and you can track location for as long as they're connected. So you can profile passerbys and even get notified when the profile passes through again. I forgot what is was called
- dylan604 8mo agoYears ago when BT beacons were newish, I was talking to an AdTechBro that wanted to create the ability from Minority Report where the kiosk recognizes a user, not by eye scans but by recognizing mobile device, so they could offer a personalized whatever. The creepiness wasn't something they eased into. It was pretty much instant.
- RunningDroid 8mo agoAre you thinking of BLE Radar? https://github.com/BLE-Research-Group/MetaRadar https://github.com/BLE-Research-Group/MetaRadar https://f-droid.org/packages/f.cking.software https://f-droid.org/packages/f.cking.software
- autoexec 8mo ago> I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. Many places do this. The department stores in the mall, target, even grocery stores do it.
- Fnoord 8mo agoDon't worry about Tesla's being tracked. Via Bluetooth this has existed for at least 7 years [1] (was mentioned on HN as well). Tesla know (also for 7 years), Musk doesn't care 'since license plates can also be tracked'. I used it in train stations, and get hits when passing highways via train or bus. Esp. fun if you stand still due to traffic lights or traffic jam, since you can try to get a visual. The only lesson to be learned here is that it allowed one to learn in 2019 Musk is overrated. But you can also learn that lesson from the book The PayPal Wars which predates this by 15 years. > I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at. Not allowed in EU. [1] https://www.teslaradar.com/ https://www.teslaradar.com/
- xaldir 8mo ago> Not allowed in EU. I'm surprised, I know for a fact that some stores definitely have the ability to do that on their hardware.
- m-s-y 8mo agoand i can commit crimes with my kitchen knives, yet they’re still legal
- thenthenthen 8mo agoUtrecht Central Station does this, there are stickers at the entrance notifying the ‘public’ of this. Or its just a sticker;p
- Fnoord 8mo agoOnly under strict rules, i.e. anonymized one way hash not relatable to a legal person. It isn't allowed to track a person that way.
- sneak 8mo agoIt’s done in Europe’s second busiest airport, Amsterdam Schiphol. I saw the advisory signs (so they can pretend that you gave informed consent by walking out of the jetbrige) up just last week. https://media.licdn.com/dms/image/v2/D4D12AQHCyctOFz_EJg/article-cover_image-shrink_720_1280/B4DZonJzLHIgAI-/0/1761593472707?e=2147483647&v=beta&t=easLfBT1M-7aPM9mT3Xf9VN-APJYv4EUXBwLPt5R28E https://media.licdn.com/dms/image/v2/D4D12AQHCyctOFz_EJg/art...
- tskulbru 8mo ago> I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at. Yes, I remember Cisco had a product like this all the way back in 2011. They could pinpoint a customer to an exact position inside a store using triangulation, they would know which shelf you spent time in front of etc. In the 15 years since then, I expect the technology is much scarier and intrusive.
- nofunsir 8mo agoiBeacon. They know what shelf you're standing in front of. What products you touch and read. Ever been in an Apple store? Look up. In the dark voids between the edge-to-edge backlit ceiling. There are secrets there. Watching you.
- reaperducer 8mo agoMacys pioneered it before there even were Apple Stores. Back when most people didn't even know their phones had Bluetooth.
- shafoshaf 8mo agoMacy's has Santa clause since 1947 because that is when Miracle on 24th Street came out. And he even knows when you are sleeping.
- astafrig 8mo agoNot what iBeacon does but an entertainingly dramatic description nonetheless.
- pests 8mo agoThe only step missing from their description is having the app- or company- specific app installed. For Apple, that is the Apple Store app which everyone has. If you have BT enabled, it can detect the iBeacon and Apple Store can send that back for tracking.
- scottlamb 8mo ago> We had a discussion that it would be easy to determine who was passing by at what times due to these especially when you can "de-anonymize" the data for example link it to a numberplate. You could also read the numberplate directly with OpenALPR. It can be finicky to set up a camera to do this reliably in all conditions (particularly at night and high speed) but once done you could detect any car passing, not just ones with wifi access points. When the law requires us to have numberplates, I think this just has to be considered public information for anyone who is nearby or can leave a camera nearby. It's not ideal to leak it in additional forms that might be easier for people to grab (say, with an ESP32), but it's a matter of degree rather than of kind. But yeah, I'm with you on some of these others, particularly the medical devices. That's not great.
- AlotOfReading 8mo agoThere's a difference between public and Public. I go outside with my face visible and I don't mind if my neighbors see me. I do mind if my neighbors stand outside my door with a notepad sketching faces every time they see me or anyone else, especially if they're selling the data. Systematic tracking that isn't subject to the constraints of human memory and apathy fundamentally changes the equation.
- thedrexster 8mo ago> constraints of human memory and apathy i like that a lot, brother, thank you!
- scottlamb 8mo ago> Systematic tracking that isn't subject to the constraints of human memory and apathy fundamentally changes the equation. I definitely don't approve of mass collection across many cameras, accessible to who-knows-who with minimal if any privacy controls (Flock). But it wouldn't surprise or bother me if my next-door neighbor had ALPR enabled, as long as it's not part of that cloud. YMMV. Full disclosure: I develop an open source home/hobbyist-oriented NVR, although it doesn't have an ALPR feature or any other analytics today.
- chasil 8mo agoThe GrapheneOS variant of Android will disable both Bluetooth and WiFi after a set period of inactivity. There is also a Bluetooth shutoff app on F-Droid. https://f-droid.org/en/packages/com.mystro256.autooffbluetooth/ https://f-droid.org/en/packages/com.mystro256.autooffbluetoo... I have also put an Airtag clone in my car (Loshall in iOS mode). That is probably leaking my arrival times. My water meter is also now bluetooth.
- jorvi 8mo ago> I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at In the EU this is forbidden unless they explicitly ask your permission. They can still gather aggregate stats but they cannot build a profile on you.
- wolvoleo 8mo agoTrue but I wouldn't put it past them tbh. It's very easy to hide or claim a 'misconfiguration'. Even the airports here track everyone. They say it's for public safety but I'm sure they use it for market analysis for their expensive sandwich shops too.
- stevage 8mo agoI find it curious that the EU, despite it having such a complex parliamentary structure, is able to consistently enact such laws that are good for ordinary people. Are the two connected, I wonder...
- brigandish 8mo agoThat's the outcome of cherry picking the good things and ignoring the bad, not their decision making structure. Try asking critics of the EU what they don't like (a quick search on here will provide plenty of examples) and you'll see laws that are not good for ordinary people. Repeat with any jurisdiction, making sure to choose the opposite of your preconception (e.g. ask proponents of the USA's system what they like about it) and you'll get a better, less biased and more challenging view.
- luma 8mo agoYou can do this for much cheaper - all four of your tires are broadcasting a unique ID to report tire pressure, the radio to pick it up is cheap (because cars), and TPMS has no facility to randomize or otherwise secure this.
- spockz 8mo agoNot all cars have active TPMS. my Volvo xc90 had them but in later models they switched back to passive ones. So it is not even a given for higher end models.
- ssl-3 8mo agoThat's not quite the end of the road, though: The tires themselves often have RFID tags embedded. https://rfid.michelin.com/what-is-rfid/ https://rfid.michelin.com/what-is-rfid/
- m-s-y 8mo agomuch harder to read rfid at a distance
- ssl-3 8mo agoIt is. My read through this document suggests that the maximum usable range may be as far as 5 meters, or as little as 1 meter: https://rfid.michelin.com/wp-content/uploads/2024/07/dataSheet-TireTag-muRata.pdf https://rfid.michelin.com/wp-content/uploads/2024/07/dataShe... That's not as far as BLE or TPMS can work at, but it's not exactly like the NFC arrangement in a credit card, either. 5 meters is enough for a motivated attacker to do some undetected bulk data collection.
- Gigachad 8mo agoIt’s actually even easier, your car has a plate on the front with a unique ID that a camera scans, often to automatically track your park time for ticketing. I can’t really care about obscure Bluetooth tracking when every business has CCTV doing facial recognition.
- wolvoleo 8mo ago> I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall They do but most phones rotate the mac adress these days. So while they can still track you through the store (sadly) they don't have the ability to track your recurring visits. I wish phones had the option to constantly spam broadcasts with random MAC ids. That would make the practice useless.
- voidmain0001 8mo agoSure, stores use WiFi access points and BT to track MAC addresses and BT device IDs. Google does something similar with location and it provides in real time how busy a location is which I find super convenient. It’s a shame that shaping data into useful information also means it can weaponized.
- King-Aaron 8mo ago> I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. I worked for a company about 18 years ago where we did just this. We also sold the technology to car dealerships who were very interested in our silent salesman stuff where you could tie interactions with your web campaign directly to the person walking past the dealership and preload the salesman with all their details. Grubby stuff nearly two decades ago.
- bryanrasmussen 8mo ago>I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at. hmm, I wonder if there is anything about using this to combat shoplifting... short google later, seems there is, but mostly everything I'm finding is just brochures and breathless corporate announcements. found this uni project https://capstone.cse.msu.edu/2020-01/projects/meijer/ https://capstone.cse.msu.edu/2020-01/projects/meijer/
- KolibriFly 8mo agoEven when they claim it's "anonymous," the value is in aggregate behavioral patterns: dwell time, repeat visits, path through the space, etc.
- jlarocco 8mo agoI was researching bluetooth low energy for a project, and discovered "Beacons": https://en.wikipedia.org/wiki/Bluetooth_Low_Energy_beacon https://en.wikipedia.org/wiki/Bluetooth_Low_Energy_beacon What's more insidious than just tracking people through the store is that the beacons can collect the bluetooth IDs of the devices they've seen and send it off to advertisers, who can use the UUID to connect a person's offline shopping with the online advertising profile they've built up for the person.