Lawrence D'Oliveiro wrote: >> Those scripts proved I could collect a list of every single access >> point in Apple's database, just as researchers Eric Rye and Dave >> Levin did, using a simple perl script which proved the results of >> their paper, and which went further to prove that my own >> hidden-broadcast SSIDs were in that database. > > I don't understand what you're complaining about, exactly. Your wi-fi > network broadcasts its existence to all and sundry, and yet you feel > upset when somebody collects that information and passes it on. > > And hiding SSIDs is a complete waste of time, which gains you nothing > in security or privacy. Don't do it.
Hi Lawrence, I respect you, but I have to teach you so that you learn what you do not know, as you don't even know that you don't know what you said is wrong. Rest assured, I know what I'm talking about. :) I've discussed this issue with Brian Krebs and Daniel Veditz (of the Mozilla Security Team) so it's quite well understood by professionals. The problem is most people who are NOT Wi-Fi pros, are stuck in the stone age when it comes to thinking about what a hidden broadcast actually does. Worse, I've had to have this discussion a billion times because almost nobody else in the world outside of tech people knows anything about it. The facts is you're thinking about security. Not about privacy. They're not even close to the same thing. This is about privacy. Not security. Apple literally manually removed my SSIDs from their database, as a result of my RADAR bug report and Apple literally changed their documentation. <https://support.apple.com/en-ie/102515> That's new. That's solely because of me. As I had reported months ago, Apple at first pulled the stalling legal trick of saying it's "not reproducible" but the person I had submit that RADAR bug report is an executive in the Apple Maps division who happens to be my next-door neighbor, and he knows full well I know my stuff. They eventually told me "don't use a hidden SSID", which is the wrong answer, and they KNOW it's the wrong answer because they literally manually removed my hidden SSID (but only mine!) from their public WPS database. The entire reason for a hidden SSID is privacy. If the SSID is hidden, it tells everyone you want to be private a. Google respects that b. Mozilla respects that c. Everyone respects that d. Except Apple There's a HUGE difference in what happens to privacy between these events: A. You set the SSID to null B. You append _nomap to your SSID -- Of the million things people need to know about privacy, most know 3. -- https://mail.python.org/mailman3//lists/python-list.python.org
