4 ms·
This idea is cool, but there are some issues with their privacy claim. They say they are hashing the MAC address (presumably on the device). However, they can'
by Robin_Message 13y ago
This idea is cool, but there are some issues with their privacy claim.
They say they are hashing the MAC address (presumably on the device). However, they can't be salting the hash (else they wouldn't be able to match across different stores).
Since there is no salt (or a fixed salt), it is trivial to de-anonymise a specific MAC address (just hash it and see if any server has it).
Worse, there are only 46 bits that are variable in a MAC address, and there is structure in there (3 bytes manufacturer, 3 bytes serial), so a complete mapping from MACs to the hashed MAC is very doable.
A secret per-device key for a HMAC would preserve privacy much better, but would stop them doing the cool stuff they plan — the usual trade off.
- silvertonia 13y agowhy not salt and store the salt with the hash?
- Robin_Message 13y agoThat seems like it would work, but it turns into a "open using crowbar found inside" problem: how do I know to use the same salt on a second density.io device unless I have already matched the MAC address.
- billyhoffman 13y agoThe whole point is the customers in your store have nothing on there phones. Their device simply sucking down the MAC that is broadcast. They are going to get the unprotected MAC.
- albertsun 13y agoThere's no point in trying to assess any privacy claims they make — it's not a technological thing. The only value they offer is violating people's privacy.
- MPetitt 13y ago> The only value they offer is violating people's privacy. I don't think reading a value being freely broadcast by a person in your building is an invasion of privacy, how is this any different from having security cameras with audio or anything else. Saying you have privacy to something you are broadcasting in public, even more specifically in this case a privately owned building is a little daft. Do you think it's an invasion of privacy if someone writes down your name and address if you were yelling it in the middle of a Starbucks?
- mixedbit 13y agoIf I enter Starbucks I indeed expect that everyone around knows about it. I don't expect that some system will store this information and will be able to associate it with my other activities.
- MPetitt 13y agoWell that is the capability of security cameras, loyalty cards, credit cards, scanning ID to get booze and a million other identification means. Unless you go to Starbucks wearing a ski-mask, a Faraday cage, and paying with cash you are possibly being tracked for marketing data. As much as I have an natural dislike against rampant corporate abuse, I am hard pressed to find a reason a privately owned merchant couldn't put one of these in their store. When I go to a hockey game I get my ticket checked, my ID checked, I have to empty my pockets, possibly even my bag, and I have to get scanned by a metal detector. But that is something I consent to so that I may go about enjoying the game. I feel as though eventually these types of Mac address scanners, loyalty cards, credit card tracking, and things of the like will just be terms that the stores set that we just sacrifice to be able to shop there. As for me I would just rather turn off my wifi and buy as much as I can off online stores.
- yread 13y agoYou could salt the hash with a constant secret
- Robin_Message 13y agohttp://en.wikipedia.org/wiki/Poe's_law http://en.wikipedia.org/wiki/Poe's_law – I can't tell if this is a serious suggestion or not... In case it is, a HMAC (which a salted hash effectively is, except keys are secret) helps in the case of them losing the database, but not if they also lose the key, and the NSA will get access to the key as well as the database, so it won't help there.