8 ms·
Tracking devices hidden in London's recycling bins are stalking your smartphone
- buro9 13y agoOn one of the forums I am on, the debate has moved to whether a MAC address is an identifying piece of information. Especially given the high likelihood that a phone is not a shared device. They're also using the MAC address to identify the device, and I suspect from that to estimate the demographic: http://new.pitchengine.com/pitches/60f7865a-f3ac-4167-920c-52faeea0564a http://new.pitchengine.com/pitches/60f7865a-f3ac-4167-920c-5... This seems to be echoed by some legal people: http://www.huntonprivacyblog.com/2011/05/articles/article-29-working-party-opines-on-geolocation-services/ http://www.huntonprivacyblog.com/2011/05/articles/article-29... > Unique identifiers (such as MAC addresses) should only be stored for a maximum period of 24 hours, and should subsequently be deleted or anonymized. And they have an opt-out page: http://www.presenceorb.com/optout.aspx http://www.presenceorb.com/optout.aspx But how many people would opt-out of something they didn't know was tracking them?
- voltagex_ 13y agoI wonder how long it would take you to POST all the possible iPhone and Android MAC addresses to that opt out page.
- buro9 13y agoAnd to do it in a random order to ensure they couldn't just ignore the opt-outs based on sequence.
- baruch 13y agoYou'd also need to do it from multiple ips to avoid hellbanned or effectively filtered later on (presumably they log from which IP the request came from).
- Karunamon 13y agoGet on Tor, send a random number of requests between 1 and 3, wait a few seconds, regenerate the tor circuit, do it again.
- sjtgraham 13y ago…and make yourself into Weev II.
- krichman 13y agoYeah, there is no way you'd be able to do that in the US without getting charged with wire fraud at least.
- cheald 13y agoGiven that this is about London, being tracked in public is already a forgone conclusion.
- buro9 13y agoI never really buy into the idea that just because there is some tracking (for any definition of `some`) that we should accept all other tracking. Anyone with a credit/debit card has been tracked since the day they got it, but it doesn't mean that every subsequent intrusion should blithely accepted.
- deleted 13y ago[deleted]
- cheald 13y agoMy comment posted as a reply to the wrong comment. Oops. Anyhow, I agree. My reply was in response to another comment which seemed to imply that this program was the difference between being tracked or not, which is a silly sentiment in London. I agree in principle that this kind of tracking isn't okay. I'm just not sure that the implications are worse than the status quo in this case.
- harrytuttle 13y agoLow tech solution: fire. When a couple have gone up, it will no longer be cost effective. I really don't like the idea of tracking such things. It's bad enough in the internet but being stalked outside is not acceptable.
- moocowduckquack 13y agoI wonder how it would cope with a raspberry pi with wifi cycling through random cloned mac addresses.
- marshray 13y agoI wonder how many write cycles its flash memory is good for.
- quarterto 13y agoYeah, you try setting fire to a bin in the City of London. See how far you get.
- jlgreco 13y agoYou'd probably be best off burning them by "recycling" some sort of timed firebomb. Ideally this would be done with something that has some plausible deniability (have somebody "recycle" some crumbled newspaper before you, then "recycle" a (modified?) cigarette butt). Of course firebombing the cans is probably very more illegal than just dumping a can of lighter fluid into it and throwing in a match... I mean, even that is arson, nothing to sneeze at. You would have to balance the possibility of being caught with the punishment if you are caught.
- DanBC 13y agoArson is a serious criminal offence! You'd do better to steal the entire bin.
- protomyth 13y agoI would supposed wrapping it with a little tinfoil might get you down to littering.
- linker3000 13y agoYou can just imagine a future press release from those involved, citing an 'enhanced...experience' - which is general marketing speak for "we're going to try and squeeze more money from you with targeted advertising". What a shitty way to contribute to society.
- krichman 13y agoThere's a commenter on HN who thinks so; https://news.ycombinator.com/item?id=6196981 https://news.ycombinator.com/item?id=6196981 I tend to disagree, I don't think tracking my habits to more effectively manipulate and target me is an enhanced experience.
- casca 13y agoThis has some interesting legal implications. The UK has a Data Protection Act that requires organisations to register with the ICO (Information Commissioners Office) and comply with a number of requirements. Renew London is not registered with the ICO, nor is any company with a similar name at their postcode [1]. So either they believe that they're exempt, or that it's under a different name. The ICO has a self-assessment tool [2] to work out whether an organisation is required to register. I'd suggest that the big question is: "Are you processing personal information?". The definition is: ‘Processing’ means doing any of the following with the information: obtaining it recording it storing it updating it sharing it ‘Personal information’ means any detail about a living individual that can be used on its own, or with other data, to identify them. So based on that, they're processing personal information and are legally required to register and comply. The ICO is not seen as an overly strong regulator, but they might be convinced to investigate after the inevitable headlines in the papers. [1] http://www.ico.org.uk/esdwebpages/search http://www.ico.org.uk/esdwebpages/search. Postcode is E1 6DY from their website in the press release [2] http://www.ico.org.uk/for_organisations/data_protection/registration/self-assessment http://www.ico.org.uk/for_organisations/data_protection/regi...
- sjtgraham 13y agoIt's not clear that a MAC address is personal information. The ICO's own guidance [1] gives the example of telephone number being personal information if the number is in the telephone directory, making a reverse lookup to identify the owner possible. Is such a directory available for MAC addresses possible? Given a hypothetical MAC address 0c:fd:c3:de:00:d5, could you identify a person with that alone? [1] http://www.ico.org.uk/upload/documents/library/data_protection/detailed_specialist_guides/personal_data_flowchart_v1_with_preface001.pdf http://www.ico.org.uk/upload/documents/library/data_protecti...
- knowaveragejoe 13y agoNot in a public directory similar to a telephone book, no. At most you could learn the make/model of their nic.
- 13y ago
- ColinWright 13y agoThere is further discussion over here: https://news.ycombinator.com/item?id=6194160 https://news.ycombinator.com/item?id=6194160 (arstechnica.com) In addition, here are some other sources for the same story: https://news.ycombinator.com/item?id=6181893 https://news.ycombinator.com/item?id=6181893 (qz.com) https://news.ycombinator.com/item?id=6183485 https://news.ycombinator.com/item?id=6183485 (qz.com) https://news.ycombinator.com/item?id=6184423 https://news.ycombinator.com/item?id=6184423 (theatlanticcities.com) https://news.ycombinator.com/item?id=6187750 https://news.ycombinator.com/item?id=6187750 (vice.com)
- borplk 13y agoI'm no fan of fighting these things with technology and workarounds as I believe these issues need to be addressed at the legal level and the technology battle is just an arms race that you can never win. However, might be a good idea to write a mobile app that changes your MAC address periodically (not sure how hard it is)
- ivix 13y agothirty üyyyQWJ
- deizel 13y agoUpdate 18:15 09/08/2013-- "[We collect anonymised and aggregated MAC data -- we don't track individuals or individual MACs. The ORBs aggregate all footfall around a pod for three minutes and send back one annonymised aggregated report from each site so the idea that we are tracking individuals again is more style than substance," says Memari in an email. "There are applications in the future which Quartz focused on but during the trial period we are only looking at anonymised and aggregated MAC data". He adds, "as some of the technology we will be testing will be on the boundaries of what is regulated and discussed it is our intention to discuss it publicly and especially collaborate with privacy groups like EFF to make sure we lead the charge on [adding necessary protections] as we are with the implementation of the technology"
- doctorstupid 13y agoThat is not consistent with their stated intention of targeting individuals with ads. They made that quite clear in the video.
- newser1337 13y agoThis is nothing to the security problems that will arise with the upcoming Google Glass.
- ihsw 13y agoOne can only wonder when it will be illegal to not have a tracking device (smartphone) attached to you.
- fauigerzigerk 13y agoLong before before that it will become suspicious.
- ZeroMinx 13y agoStupid question; can I not opt out of this by turning wifi off while walking around these places?
- cylinder714 13y agoYes--if you turn WiFi off, your phone won't broadcast its MAC address, so there's nothing for them to track. Nordstrom stores in the US were caught tracking shoppers via their phones' MAC addresses earlier this year. All the more reason to turn off WiFi if you're not actively using it.
- anigbrowl 13y agoAll the more reason why the US needs a robust data protection act, despite the howls of outrage this will cause in Silicon Valley.
- lelandbatey 13y agoReading through these comment, I get the feel that many people feel that this kind of observation is wrong in some way. I'm confused about this, since it seems like it's built on the solid social contract that we are free to observe anything that happens I'm a public space. I actually just wrote about this subject this morning.[0] The possibility that I might be observed in public has never bothered me, and I'm curious to hear what other people have to say. [0] - http://xwl.me/md/erj28mbe62ap193 http://xwl.me/md/erj28mbe62ap193
- krichman 13y agoIt's because when we say being observed in public, we assume it to be someone looking at us and then basically forgetting all about us. We don't think about security cameras watching us and having a single party aggregate all of that. And we don't know our cell phones are broadcasting a unique barcode to everything even if we do know the cell towers can triangulate and log our location. (By we I mean our family members, not us on HN.) Adding technology to the observation makes it so much stronger that I think there should be a new discussion about it by our various governments.
- lo_fye 13y agoHilariously, all 3 "unique" MAC addresses in that marketing image are identical: 00-14-22-01-23-45 They changed the font colour of the word "Mac", but not the actual address. Plus, Mac should be MAC. McFail.
- skeletonjelly 13y agoYeah I think their point still remains though. They referred to it as "MAC" in the text of the article at least. Probably just the designer.
- cupcake-unicorn 13y agoThis is very interesting. So I never was much of a network analyst, forgive me - is there any way to guard against this while still leaving your wifi on, without something like cycling MACs? I wasn't aware that when you scan for Networks, that you're actually exchanging some packets with those networks - I thought you were just picking up on a broadcast one way. Shouldn't there be some sort of "stealth mode" where you're not leaking packets everywhere? It actually seems like if this was the case, I'm surprised it hasn't been used in other ways. Say a burglar breaks into my house with his iPhone in his pocket. Could I later prove it was him by pulling up some log on my router that was picking up MAC addresses going by? And why isn't there some software (to my knowledge) that does the same thing for surveillance - logging all the MAC addresses and creating alerts if a new one comes into the area?
- lutusp 13y ago> is there any way to guard against this while still leaving your wifi on, without something like cycling MACs? No -- the adaptor's MAC is an essential part of the transaction, while cycling MACs would be a dead giveaway and would increase attention paid to that system and its travels. Turning off the adaptor is the only meaningful way to avoid tracking. > Say a burglar breaks into my house with his iPhone in his pocket. Could I later prove it was him by pulling up some log on my router that was picking up MAC addresses going by? Yes, but only in a society that would allow this kind of tracking of people, each of whom is presumed to be innocent. Usually a person is first identified as a suspect, after which a technical track can be made. But a person who is not already regarded as a suspect can't be (legally) subjected to this kind of surveillance. > And why isn't there some software (to my knowledge) that does the same thing for surveillance - logging all the MAC addresses and creating alerts if a new one comes into the area? Because this is privileged information having to do with privacy, and violating it would confront certain well-established civil rights that vary from country to country.
- cupcake-unicorn 13y agoI get and agree with your last two answers, but if that's the case, why has this kind of thing started popping up on a commercial scale? They certainly would have more to answer for, legally, if privacy laws were violated. And just because an app like that may violate privacy rights, I mean, you still see things like Firesheep, packet sniffing, network surveillance tools, all published with the caveat to just use for "testing". It seems to me that the laws are somewhat murky, as evidenced by this article, and I would be surprised if there was any law in the US against me keeping track of MACs that came into the range of my router. With your argument I couldn't set up a surveillance camera outside my house either.
- nns 13y agoAs someone living and working in London, I pass more than a couple of these 'bins' every single day. These bins are quite strategically placed (1) in the heart of the square mile - the prime financial district and tourist hub of London city (2) especially around bus stops and city squares in this area - which have some form or other of free city wide wifi networks - where one would be waiting for enough time (consuming lunch, waiting for bus, meeting a friend, shopping...) to be an ideal consumer for targeted advertisement. They also have an extremely amusing design which makes them look slick - but extremely unlike waste bins - infact you have to look at them closely to find where you need to dispose off your waste. This was one thing that amused me extremely when I first saw them - the strange inconspicuous design - but things make much more sense in the light of this article. As someone who's targeted more than once a day by these things, I see this as a breach of privacy and expect to be informed that data about me is being collected and stored and maybe used for commercial purposes in the future (irrespective of the ICO technicalities and loop holes). As a human, its a fundamental breach of trust and I would personally not see these things with the same inconspicuousness they have been designed with to deceptively integrate and blend into our daily environment.
- gasull 13y agoGreenPower for Android turns off your wifi when you're not using it. It's meant for battery life. Now it's also good for privacy. https://play.google.com/store/apps/details?id=org.gpo.greenpower&hl=en https://play.google.com/store/apps/details?id=org.gpo.greenp...
- will_ 13y agoI had a little start-up idea a while ago .. albeit only tangentially related to this one. Make a deal with JC Decaux, or some similar out-of-home advertising company to place cameras (strategically) around the City of London. Nominally to provide personally tailored advertising, the significant secondary purpose is to use face recognition to identify individuals-of-interest: specific traders, fund managers and so on. This enables us to analyse facial expression, gait, maybe body temperature to determine mood, then look for correlations in the stocks and markets that these individuals trade. I think that this will be legal, since all the information that you are using is (nominally, at least) legal, and gained in a public place. After all, if it is OK for the authorities to place the whole population under close surveillance, they cannot possibly object if we turn around and do the same thing to their paymasters, can they?
- swamp40 13y agoPeople have been waiting for this technology infrastructure to get in place for years. It's a shame the recent NSA fiasco will scare people away now and set this back another 5 years. There are some phenomenal experiences possible.
- krichman 13y agoI don't understand this viewpoint. It seems to me like advertisers are more likely to use extra data to be more manipulative, the same way they do it by targeting ads on the internet. What kind of improved experience are are imagining?
- zxcdw 13y agoDo you find that marketing/advertising is about creating experiences? I find it is about bullshitting people as much as you can, change my view please.
- swamp40 13y ago100+ years of radio and 60+ years of television shaped the lives of almost everyone alive on the planet. Brought to you free by advertising. Closing in on a million free apps available at both Apple and Android marketplaces. Brought to you free by advertising. Skype. How many poor families scattered across the world has Skype helped? Those are significant, life changing experiences - not bullshit.
- swamp40 13y agoGoogle, Google Maps, Google Street View. Those are experiences. Free to the world, paid for by advertising.
- marshray 13y agoI think I even took a picture of one of those when I was in London last Fall: https://twitter.com/marshray/status/321038712735690754 https://twitter.com/marshray/status/321038712735690754 EDIT: That may not have been my own picture in that tweet. But still ISTR having snapped a similar one.