Lawrence D'Oliveiro wrote:
>> Those scripts proved I could collect a list of every single access
>> point in Apple's database, just as researchers Eric Rye and Dave
>> Levin did, using a simple perl script which proved the results of
>> their paper, and which went further to prove that my own
>> hidden-broadcast SSIDs were in that database.
> 
> I don't understand what you're complaining about, exactly. Your wi-fi
> network broadcasts its existence to all and sundry, and yet you feel
> upset when somebody collects that information and passes it on.
> 
> And hiding SSIDs is a complete waste of time, which gains you nothing
> in security or privacy. Don't do it.

Hi Lawrence,

I respect you, but I have to teach you so that you learn what you do not
know, as you don't even know that you don't know what you said is wrong.

Rest assured, I know what I'm talking about. :)

I've discussed this issue with Brian Krebs and Daniel Veditz (of the
Mozilla Security Team) so it's quite well understood by professionals.

The problem is most people who are NOT Wi-Fi pros, are stuck in the stone
age when it comes to thinking about what a hidden broadcast actually does.

Worse, I've had to have this discussion a billion times because almost
nobody else in the world outside of tech people knows anything about it.

The facts is you're thinking about security. Not about privacy.
They're not even close to the same thing.

This is about privacy.
Not security.

Apple literally manually removed my SSIDs from their database, as a result
of my RADAR bug report and Apple literally changed their documentation.
 <https://support.apple.com/en-ie/102515>

That's new. 
That's solely because of me.

As I had reported months ago, Apple at first pulled the stalling legal
trick of saying it's "not reproducible" but the person I had submit that
RADAR bug report is an executive in the Apple Maps division who happens to
be my next-door neighbor, and he knows full well I know my stuff.

They eventually told me "don't use a hidden SSID", which is the wrong
answer, and they KNOW it's the wrong answer because they literally manually
removed my hidden SSID (but only mine!) from their public WPS database. 

The entire reason for a hidden SSID is privacy.
If the SSID is hidden, it tells everyone you want to be private
 a. Google respects that 
 b. Mozilla respects that
 c. Everyone respects that
 d. Except Apple

There's a HUGE difference in what happens to privacy between these events:
 A. You set the SSID to null
 B. You append _nomap to your SSID
-- 
Of the million things people need to know about privacy, most know 3.
-- 
https://mail.python.org/mailman3//lists/python-list.python.org

Reply via email to