11 ms·
If this becomes the trend (which in my opinon would be nice) it will become a big problem for companies that specialise in customer tracking e.g. for supermarke
by brunnsbe 12y ago
If this becomes the trend (which in my opinon would be nice) it will become a big problem for companies that specialise in customer tracking e.g. for supermarkets and big department stores. Previously it was quite easy to track a customer, how long he or she spends time in the store, which floors he or she visits, etc. by putting up dummy WiFI-networks that the customers phones find by giving out their MAC-addresses.
- pmorici 12y agoWhat stops them from switching to tracking via the hardware address of the cellular radio?
- gnu8 12y agoThe needed radio hardware would be more of an engineering and procurement challenge for the typical two-bit analytics startup than wifi radios.
- shaggyfrog 12y agoYou can only get that kind of information (e.g. IMEI) if you use IOKit, and you can't submit to the App Store if your app uses IOKit if you're not a part of the MFi (Made for iOS) program, i.e. a hardware manufacturer. Edit: I'm really getting confused with downvoting on HN. How exactly is this comment poor?
- lbotos 12y agoCorrect me if I'm wrong, but $tracking_co would just need to get their instore-tracker5000 approved by apple and then they are back to their old ways? I know that may not be cheap/easy for them, but still reasonably within reach.
- JackC 12y agoI'm pretty sure the post you're replying to isn't talking about an iOS app, so IOKit doesn't have anything to do with it. They're saying that a store could install their own cell antenna to listen to nearby cell phones, record unique identifiers, and track customers that way. Apple is anonymizing MAC addresses to stop a similar form of tracking, but it won't work if there are other radio signals they can't anonymize. Apologies if you knew that and I'm just not understanding your point.
- wmf 12y agoGreat idea; if public outrage forces police to stop using Stingrays then grocery stores can start buying them instead.
- tlrobinson 12y agoProbably the fact that IMSI-catchers are illegal.
- LoganCale 12y agoGood. It should be a problem for them.
- shurcooL 12y agoI'm genuinely curious, how does it being a problem for them benefit you? (I'm assuming you're not saying that out of indifferent malice but because you have personal gains, which is normal.) Can you please elaborate on your point?
- colechristensen 12y agoMost people, if it explained to them, would be generally uncomfortable with the idea of their movements in a public place being so specifically logged. How would you feel if every time you were in a store, an employee followed you around and took notes on your actions?
- shurcooL 12y agoThanks for a constructive response to my question. I'm simply trying to gain a better understanding of the situation. > How would you feel if every time you were in a store, an employee followed you around and took notes on your actions? Most people would feel uneasy/bothered by that. But are those emotions warranted? If we did not get such emotions, would the same scenario be okay? Or are the emotions a consequence of the true reason why we're against such behavior. It's also worth noting that the employee following you around is a visible behavior, while being tracked via Wi-Fi mac addresses is much less intrusive.
- nitrogen 12y agoIt's also worth noting that the employee following you around is a visible behavior, while being tracked via Wi-Fi mac addresses is much less intrusive. It's less visibly intrusive, but the effect is the same. Our instincts aren't very good at reacting to effects we can't see, having evolved in a world where there were no undetectable ways for someone to follow us. Thus, we should consider what our natural reactions would be to a person doing the thing we want to use technology to do, before we create the technology to do it.
- pjc50 12y agoThat's the whole reason to do it. Do Not Track for the physical world.
- mwfunk 12y agoI don't get it, defeating that kind of tracking sounds...awesome? Isn't that the point? EDIT: sorry, I've had too little coffee today for proper reading comprehension. Clearly you think it'd be nice too and are not empathizing with the snoops and marketers.
- kmfrk 12y agoPrivacy is inversely proportional to utility. It's basically the first rule of privacy.
- josephlord 12y agoStrongly disagree. The relationship, while it can exist in some areas is by no means universal and certainly not linear. In many cases privacy may be invaded for no end user utility and in others utility may be possible without any privacy costs. Of course some things cannot be offered with privacy fully preserved.
- praseodym 12y agoThe MAC address is stable once a device is authenticated (connected) to the network. With the trend of providing 'free' wifi access within stores, making sure that users connect to that network is enough to continue tracking them.
- mikeash 12y agoHow will you make sure of that, though? Only a tiny fraction of smartphone users will bother to connect to your wifi, and it'll be a skewed sample.
- 7952 12y agoBut the device is still visible on wifi even if it does not connect. Some phones tend will try to connect to known networks pro-actively and will leak the SSID of those networks.
- praseodym 12y agoBy making sure your steel-reinforced concrete mall walls are thick enough to block proper 3G/4G reception (no, really, reception is pretty bad in a lot of indoor places). But still, I agree, it would be very hard to have everyone connect to your wifi.
- notatoad 12y agoit's hard to get everybody, but it's easy to get a significant sample. just set up an open network called Starbucks WiFi and watch all the iPhones connect to it
- AnthonyMouse 12y ago> The MAC address is stable once a device is authenticated (connected) to the network. That is necessary to keep the gateway from having to issue a thousand ARP requests (one for every packet you send from a different MAC), but there is no reason why the MAC chosen to connect to the network couldn't change every time you disconnect and reconnect. That would at least prevent you from being tracked between visits to the store [using this tracking method], even if you actually use the network.
- chimeracoder 12y agoNomi[0] is one startup that does this, tracking locations of customers across participating stores without customers' consent. It's opt-out for consumers, and in order to opt-out, you must register your MAC address with them[1][2]. I really hope that cycling MAC addresses becomes easier on mobile devices, if not automatic. [0] http://nomi.com http://nomi.com [1] http://nomi.com/privacy/ http://nomi.com/privacy/ [2] Assuming you even know that this service exists (which most consumers don't, because why would the store owner tell them that they're doing this?)
- eli 12y agoAre retail stores actually using cell phones to track people at the individual level? I mean, I know the technology exists and all, but it just doesn't seem like it'd actually be all that useful to the stores. My guess is that the stores that are using this tech are mostly concerned about how long the average person has to wait in the checkout line, not whether Joe Blow is was in the store.
- dag11 12y agoLarge stores use it to positionally track unique customers. They can analyze the paths they take and ultimately what they buy. This is powerful because the can optimize the layout of their stores to maximize sales based on hard data. This will now become much more difficult to do.
- eli 12y agoI'm genuinely curious: is there data on how many or which retailers do this?
- atmosx 12y agoIsn't that suppose to be illegal in first place? I mean without actual consent, tracking a device... Doesn't sound extremely ethical. That said in some airports, changing MAC address is illegal. Now that the iPhone will support the feature and most owners will have no idea what's happening, I guess these airports will have to change policy :-)
- ehPReth 12y ago> That said in some airports, changing MAC address is illegal. Would you mind providing some links? I'm interested to see how it's laid out
- macspoofing 12y ago>If this becomes the trend (which in my opinon would be nice) it will become a big problem for companies that specialise in customer tracking e.g. for supermarkets and big department stores. That's terrible! Poor them!
- btgeekboy 12y agoPerhaps it's not quite that bad. Places like Home Depot use AT&T, so the AP is called attwifi. If you've ever used the wireless at a Starbucks or McDonald's, you've likely already approved your phone to connect to attwifi.
- userbinator 12y agoIt's disturbingly creepy to think that stores would even think of doing this, but on the other hand it's also an indication of how clueless the general population is about the amount of identifiable data they're unconsciously "leaking" through personal, (nearly) always-on devices. My laptop is setup with a random MAC precisely to prevent this sort of tracking. Interestingly, the unbranded Android phones I have (one looks very much like an iPhone, ironically enough) all came with this "feature" of a random MAC every time the WiFi is turned on/off, although that was more likely the manufacturer not bothering to give each one a unique MAC. All the more reason to keep the WiFi turned off unless you're actually using it, and this might be a bit on the paranoid side, but I do the same for the cell radio (airplane mode) - it's on only when I'm expecting a call or making one. At the other end of the scale, this tracking via MAC almost invites making them think several million customers have suddenly entered the store...
- elarkin 12y agoWithout being too specific, you should assume that Large stores already do this. Any store claiming to have "in store wifi" is almost guaranteed to be tracking you through your mac address. The system that I'm familiar with only tracks where you're going. It didn't (as of a couple months ago) have any way of linking your mac back to a consumer profile.
- meepmorp 12y agoI was in a shopping mall recently, where the free wifi required your name and an email address before letting you use it. Fuck that.
- lucaspiller 12y agoThat's pretty standard for all free wifi in the UK.
- alister 12y agoName and email, you say? Check out the form you need to fill in to use free wifi at Brazilian airports: http://brazilsense.com/index.php?title=Wi-Fi_and_Internet_service_in_Brazil#Internet_at_airports http://brazilsense.com/index.php?title=Wi-Fi_and_Internet_se... They want your: name sex marital status nationality place of birth profession identity document type identity document number street address city state country cellular phone number name of cellular provider landline phone number email address barcode from your boarding pass If you think that this is an April Fool's joke, I can assure you that it's real. Some of the above are optional on the form that's shown, but other airport ISPs in Brazil do insist that you fill in a lot of fields like the above. I'm happy to say that the trend in the United States and Canada has been toward less or zero information for using wifi. Less than 10 years ago, it was quite common to see all sorts of questions to use wifi. And Internet cafes used to demand ID in the United States and Canada (and they still do in Brazil).
- speleding 12y agoAs nice as this may be for privacy, there is too much at stake here commercially, so this will likely be just a step in the cat and mouse game. Face recognition comes to mind as a technology that can replace this, and perhaps as a result of the MAC scrambling we will see a bigger push for face recognition in stores.
- criley2 12y agoHave the stores release apps (or one app that works for the system they use) that trades a percentage off, coupons, etc, for location data. "We'd like to learn a little about your shopping habits, and that includes sending anonymized data about your time in our store. In exchange for this, we'd love to offer you 25% off this purchase and 10% off all future purchases".