Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.python > #197902 > unrolled thread

Apple changed their documentation at my request but it proves they don't care about privacy

Started byMaria Sophia <mariasophia@comprehension.com>
First post2026-09-03 16:30 +0930
Last post2026-09-08 08:07 +0300
Articles 20 on this page of 95 — 18 participants

Back to article view | Back to comp.lang.python


Contents

  Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-03 16:30 +0930
    Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-03 08:09 +0000
      Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-04 02:27 +0930
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-03 20:46 +0000
          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 06:15 +0600
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 00:34 +0000
              Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:05 +0600
                Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 01:47 +0000
                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:00 -0300
                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-05 17:49 +0000
                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 16:14 -0300
                        Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-06 00:06 +0000
                          Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-06 13:39 +0200
                            Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-06 15:37 +0000
                              Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-06 20:23 +0200
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 02:16 +0300
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:42 +0200
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:06 +0300
                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 21:28 +0200
                                        Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 06:38 +0300
                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-07 15:28 -0700
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy "....winston" <winstonmvp@gmail.com> - 2026-09-07 02:01 -0400
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Hank Rogers <Hank@nospam.invalid> - 2026-09-07 01:47 -0500
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-07 10:18 +0000
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:30 +0200
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:22 +0300
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-07 22:28 +0000
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 07:22 +0300
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-08 10:44 +0000
                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-08 13:27 +0000
                                        Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-08 09:47 -0600
                                          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 19:51 +0300
                                            Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-08 10:23 -0700
                                              Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-08 18:12 +0000
                                              Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 22:18 +0400
                                                Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-09 19:46 -0700
                                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-25 23:43 +0800
                                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Jeff Liebermann <jeffl@cruzio.com> - 2026-09-25 13:14 -0700
                                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-26 04:41 +0800
                                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-25 22:17 +0000
                                                        Re: Apple changed their documentation at my request but it proves they don't care about privacy Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> - 2026-09-26 07:26 +0800
                                          Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 18:59 +0200
                                            Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 21:20 +0400
                                              Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 19:37 +0200
                                          Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-08 19:26 +0200
                                            Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-08 11:36 -0600
                                              Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-08 20:05 +0200
                                              Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-08 20:35 +0200
                                          Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-08 19:06 +0000
                              Re: Apple changed their documentation at my request but it proves they don't care about privacy Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-07 10:47 +0100
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 13:34 +0200
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 18:48 +0200
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Nuno Silva <nunojsilva@invalid.invalid> - 2026-09-07 18:46 +0100
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-07 14:04 +0000
                          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:47 +0300
              Re: Apple changed their documentation at my request but it proves they don't care about privacy Nick Charles <none@none.none> - 2026-09-05 01:11 +0000
                Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:24 +0600
                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-04 23:15 -0700
                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:18 -0300
                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-05 16:40 -0700
                        Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 02:40 +0300
                          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:09 +0300
                            Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:12 +0300
                              Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:13 +0300
                                Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:14 +0300
                                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:16 +0300
                                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 03:18 +0300
                                      Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 04:23 +0300
                          Re: Apple changed their documentation at my request but it proves they don't care about privacy Keith Thompson <Keith.S.Thompson+u@gmail.com> - 2026-09-06 19:03 -0700
                    Re: Apple changed their documentation at my request but it proves they don't care about privacy Frank Slootweg <this@ddress.is.invalid> - 2026-09-06 11:57 +0000
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Lawrence D’Oliveiro <ldo@nz.invalid> - 2026-09-05 06:44 +0000
              Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:35 -0300
      Re: Apple changed their documentation at my request but it proves they don't care about privacy Paul Rubin <no.email@nospam.invalid> - 2026-09-03 15:48 -0700
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Anton Shepelev <anton.txt@gmail.moc> - 2026-09-04 02:02 +0300
          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:46 +0600
      Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-04 10:28 +0200
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Jon Ribbens <jon+usenet@unequivocal.eu> - 2026-09-04 11:44 +0000
          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 20:28 +0300
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-07 21:45 +0300
          Re: Apple changed their documentation at my request but it proves they don't care about privacy "Carlos E.R." <robin_listas@es.invalid> - 2026-09-07 21:28 +0200
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 07:38 +0300
    Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-04 22:58 +0000
      Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 07:13 +0600
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-05 07:57 +0000
          Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 14:48 -0300
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-05 12:13 -0600
              Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 15:18 -0300
                Re: Apple changed their documentation at my request but it proves they don't care about privacy Lane W <cactus_DAC@yahoo.com> - 2026-09-05 12:25 -0600
                  Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 16:22 -0300
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-06 00:11 +0000
        Re: Apple changed their documentation at my request but it proves they don't care about privacy Andy Burns <usenet@andyburns.uk> - 2026-09-05 09:17 +0100
          Re: Apple changed their documentation at my request but it proves they don't care about privacy Chris <ithinkiam@gmail.com> - 2026-09-05 11:22 +0000
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-05 15:13 -0300
          Re: Apple changed their documentation at my request but it proves they don't care about privacy "R.Wieser" <address@is.invalid> - 2026-09-06 20:39 +0200
            Re: Apple changed their documentation at my request but it proves they don't care about privacy Maria Sophia <mariasophia@comprehension.com> - 2026-09-08 08:07 +0300

Page 1 of 5  [1] 2 3 4 5  Next page →


#197902 — Apple changed their documentation at my request but it proves they don't care about privacy

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-03 16:30 +0930
SubjectApple changed their documentation at my request but it proves they don't care about privacy
Message-ID<117b5u0$1q77$1@nnrp.usenet.blueworldhosting.com>
This is an update to the WPS scripts that I posted a few months ago.

Those scripts proved I could collect a list of every single access 
point in Apple's database, just as researchers Eric Rye and Dave 
Levin did, using a simple perl script which proved the results of 
their paper, and which went further to prove that my own 
hidden-broadcast SSIDs were in that database.

I complained to my next-door neighbor, who is a top-level exec 
at Apple Maps, where he (to his credit) pushed this wording 
through, but it proves, yet again, beyond any semblance of 
doubt, that Apple doesn't care about our privacy.

Even Google doesn't stoop this low.
And that's saying something.

https://support.apple.com/en-ie/102515

"The owner of a Wi-Fi access point can opt it out of Apple's 
Location Services by changing the access point's SSID (name)
 to end with _nomap.

For example, ´Access_Point¡ would be changed to ´Access_Point_nomap¡. 
This prevents devices from sending the access pointÿs location to 
Apple to include in Appleÿs crowd-sourced location database. 

This opt-out doesnÿt work for hidden networks because they make 
their network name only available to known devices, so other 
devices can't detect _nomap."

This last sentence is a bold lie, by the way, since they can 
certainly detect it, given the field has a null value. 
But they lie about that too.

Below is code reproducing my tests... from which the claims are made.

  @echo off
  setlocal EnableDelayedExpansion
  :: C:\app\os\python\apple_bssid_locator\bssid.bat
  :: Use: bssid.bat <Enter> (then enter desired BSSID to look up)
  :: Sample values:
  ::  00:18:f8:c1:4a:65 
  ::  00:07:89:d7:82:e8
  ::  04:09:A5:3B:34:67
  ::
  :: Logs up to 400 BSSID:GPS pairs from Apple's WPS public database
  :: Loop until user types q
  ::
  :: Changelog:
  :: v1p0 20251205 - Query Apple's highly insecure WPS database 
  :: v1p1 20251214 - Saves to time-date stamped results.txt log file
  :: v1p2 20251215 - Timestamp results.txt so it's not overwritten
  :: v1p3 20251219 - Limit the human-readable GPS to 6 decimal places
  :: v1p4 20251219 - Show original raw integers + converted decimals
  :: v1p5 20251219 - Tried to accomodate Google Maps query to new format
  :: v1p6 20251219 - Changed to block-aware parsing with debug output
  :: v1p7 20251219 - Enable delayed expansion to fix parsing inside loops
  
  set LOGDIR=%~dp0log
  if not exist "%LOGDIR%" mkdir "%LOGDIR%"
  
  :: Create a unique session log (YYYYMMDD_HHMMSS)
  for /f %%A in ('wmic os get localdatetime ^| find "."') do set dt0=%%A
  set "session_ts=%dt0:~0,8%_%dt0:~8,6%"
  set "session_log=%LOGDIR%\session_%session_ts%.log"
  
  echo === New BSSID lookup session started at %date% %time% === >> "%session_log%"
  
  echo.
  echo === Nearby Wi-Fi Networks ===
  netsh wlan show networks mode=bssid
  echo =============================
  
  :loop
  echo.
  set /p BSSID=Enter the BSSID (or q to quit): 
  
  if /I "%BSSID%"=="q" goto end
  
  :: --- Clean up input ---
  set "BSSID=%BSSID:"=%"
  set "BSSID=%BSSID: =%"
  
  :: --- Make filename-safe version ---
  set "safeBSSID=%BSSID::=-%"
  
  :: --- Generate timestamp for THIS lookup ---
  for /f %%A in ('wmic os get localdatetime ^| find "."') do set dt=%%A
  set "ts=%dt:~0,8%_%dt:~8,6%"
  
  :: --- Timestamped output file ---
  set "outfile=%LOGDIR%\bssid_%safeBSSID%_%ts%.txt"
  
  :: --- Clear previous coordinates ---
  set "LAT="
  set "LON="
  
  echo === Lookup started at %date% %time% === > "%outfile%"
  echo BSSID: %BSSID% >> "%outfile%"
  echo. >> "%outfile%"
  
  :: --- Run Python lookup ---
  python.exe apple_bssid_locator.py %BSSID% --all >> "%outfile%"
  
  :: --- Display results ---
  echo -----------------------------------------------
  type "%outfile%"
  echo -----------------------------------------------
  
  :: --- Block-aware parsing of coordinates (with delayed expansion) ---
  set "CAPTURE="
  set "LAT="
  set "LON="
  
  for /f "usebackq delims=" %%L in ("%outfile%") do (
      if /i "%%L"=="BSSID: %BSSID%" (
          set "CAPTURE=1"
          set "LAT="
          set "LON="
          echo [DEBUG] Found block start for %BSSID%
      ) else if defined CAPTURE (
          echo [DEBUG] Line in block: %%L
  
          echo %%L | findstr /i /c:"Latitude (degrees):" >nul
          if not errorlevel 1 (
              for /f "tokens=2 delims=:" %%A in ("%%L") do set "LAT=%%A"
              if defined LAT set "LAT=!LAT: =!"
              echo [DEBUG] Parsed LAT candidate = "!LAT!"
          )
  
          echo %%L | findstr /i /c:"Longitude (degrees):" >nul
          if not errorlevel 1 (
              for /f "tokens=2 delims=:" %%B in ("%%L") do set "LON=%%B"
              if defined LON set "LON=!LON: =!"
              echo [DEBUG] Parsed LON candidate = "!LON!"
          )
  
          if defined LAT if defined LON (
              goto :gotCoords
          )
  
          echo %%L | findstr /i /c:"BSSID:" >nul
          if not errorlevel 1 (
              set "CAPTURE="
          )
      )
  )
  
  :gotCoords
  echo [DEBUG] Final LAT = "!LAT!"
  echo [DEBUG] Final LON = "!LON!"
  
  :: --- Validate parsed coordinates ---
  if not defined LAT echo [DEBUG][ERROR] Latitude not captured. Check Python output format near "BSSID: %BSSID%".
  if not defined LON echo [DEBUG][ERROR] Longitude not captured. Check Python output format near "BSSID: %BSSID%".
  
  :: --- Save results --- 
  echo === Lookup finished at %date% %time% === >> "%outfile%"
  echo. >> "%outfile%"
  
  :: --- Append to session log ---
  echo [%date% %time%] BSSID: %BSSID% >> "%session_log%"
  echo Latitude: !LAT! >> "%session_log%"
  echo Longitude: !LON! >> "%session_log%"
  echo. >> "%session_log%"
  
  :: --- Append to master log ---
  echo [%date% %time%] BSSID: %BSSID% >> "%LOGDIR%\results.log"
  echo Latitude: !LAT! >> "%LOGDIR%\results.log"
  echo Longitude: !LON! >> "%LOGDIR%\results.log"
  echo. >> "%LOGDIR%\results.log"
  
  :: --- Open in Google Maps ---
  if defined LAT if defined LON start msedge "https://www.google.com/maps/search/?api=1&query=!LAT!,!LON!"
  
  goto loop
  
  :end
  echo Exiting. Goodbye!
  endlocal
  
  :: end of C:\app\os\python\apple_bssid_locator\bssid.bat

[toc] | [next] | [standalone]


#197903

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-09-03 08:09 +0000
Message-ID<117b9uu$3glj7$1@dont-email.me>
In reply to#197902
On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote:

> Those scripts proved I could collect a list of every single access
> point in Apple's database, just as researchers Eric Rye and Dave
> Levin did, using a simple perl script which proved the results of
> their paper, and which went further to prove that my own
> hidden-broadcast SSIDs were in that database.

I don’t understand what you’re complaining about, exactly. Your wi-fi
network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.

And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. Don’t do it.

[toc] | [prev] | [next] | [standalone]


#197904

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-04 02:27 +0930
Message-ID<117c8t3$ifv$1@nnrp.usenet.blueworldhosting.com>
In reply to#197903
Lawrence D'Oliveiro wrote:
>> Those scripts proved I could collect a list of every single access
>> point in Apple's database, just as researchers Eric Rye and Dave
>> Levin did, using a simple perl script which proved the results of
>> their paper, and which went further to prove that my own
>> hidden-broadcast SSIDs were in that database.
> 
> I don't understand what you're complaining about, exactly. Your wi-fi
> network broadcasts its existence to all and sundry, and yet you feel
> upset when somebody collects that information and passes it on.
> 
> And hiding SSIDs is a complete waste of time, which gains you nothing
> in security or privacy. Don't do it.

Hi Lawrence,

I respect you, but I have to teach you so that you learn what you do not
know, as you don't even know that you don't know what you said is wrong.

Rest assured, I know what I'm talking about. :)

I've discussed this issue with Brian Krebs and Daniel Veditz (of the
Mozilla Security Team) so it's quite well understood by professionals.

The problem is most people who are NOT Wi-Fi pros, are stuck in the stone
age when it comes to thinking about what a hidden broadcast actually does.

Worse, I've had to have this discussion a billion times because almost
nobody else in the world outside of tech people knows anything about it.

The facts is you're thinking about security. Not about privacy.
They're not even close to the same thing.

This is about privacy.
Not security.

Apple literally manually removed my SSIDs from their database, as a result
of my RADAR bug report and Apple literally changed their documentation.
 <https://support.apple.com/en-ie/102515>

That's new. 
That's solely because of me.

As I had reported months ago, Apple at first pulled the stalling legal
trick of saying it's "not reproducible" but the person I had submit that
RADAR bug report is an executive in the Apple Maps division who happens to
be my next-door neighbor, and he knows full well I know my stuff.

They eventually told me "don't use a hidden SSID", which is the wrong
answer, and they KNOW it's the wrong answer because they literally manually
removed my hidden SSID (but only mine!) from their public WPS database. 

The entire reason for a hidden SSID is privacy.
If the SSID is hidden, it tells everyone you want to be private
 a. Google respects that 
 b. Mozilla respects that
 c. Everyone respects that
 d. Except Apple

There's a HUGE difference in what happens to privacy between these events:
 A. You set the SSID to null
 B. You append _nomap to your SSID
-- 
Of the million things people need to know about privacy, most know 3.

[toc] | [prev] | [next] | [standalone]


#197905

FromLawrence D’Oliveiro <ldo@nz.invalid>
Date2026-09-03 20:46 +0000
Message-ID<117cmbk$1e7a$3@dont-email.me>
In reply to#197904
On Fri, 4 Sep 2026 02:27:07 +0930, Maria Sophia wrote:

> Lawrence D'Oliveiro wrote:
>>
>> On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote:
>>>
>>> Those scripts proved I could collect a list of every single access
>>> point in Apple's database, just as researchers Eric Rye and Dave
>>> Levin did, using a simple perl script which proved the results of
>>> their paper, and which went further to prove that my own
>>> hidden-broadcast SSIDs were in that database.
>>
>> I don't understand what you're complaining about, exactly. Your
>> wi-fi network broadcasts its existence to all and sundry, and yet
>> you feel upset when somebody collects that information and passes
>> it on.
>>
>> And hiding SSIDs is a complete waste of time, which gains you nothing
>> in security or privacy. Don't do it.
>
> The problem is most people who are NOT Wi-Fi pros, are stuck in the
> stone age when it comes to thinking about what a hidden broadcast
> actually does.

That’s their problem, though. Trying to offer some kind of sop to their
ignorance is not actually making them safer.

> This is about privacy.
> Not security.

This is about the *perception* of privacy. Like telling people they
don’t have to worry about closing their curtains, they just need to
close their eyes -- if they can’t see the people outside looking in,
then those looking in can’t see them!

> The entire reason for a hidden SSID is privacy. If the SSID is
> hidden, it tells everyone you want to be private

“Tells everyone” ... privacy is supposed to be something where you
don’t “tell everyone”!

[toc] | [prev] | [next] | [standalone]


#197911

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-05 06:15 +0600
Message-ID<117fmvs$27up$1@nnrp.usenet.blueworldhosting.com>
In reply to#197905
Lawrence D'Oliveiro wrote:
>> This is about privacy.
>> Not security.
> 
> This is about the *perception* of privacy. Like telling people they
> don't have to worry about closing their curtains, they just need to
> close their eyes -- if they can┤ see the people outside looking in,
> then those looking in can't see them!

Hi Lawrence,

I say with all respect that your statement is too wrong to accept as is.
What you just said, I've heard a thousand times before, from many people.

And yet, it's no different than what I've heard by asking the guy next to
me at the gas pump since the 1960's why he puts premium in a Honda Civic.

For over five decades, people have been parroting what someone told them.
None of them actually understand a word that they're obviously parroting.

Same here... 

Again, I respect you for your technical acumen which is greater'n mine.
But I can't tell if you know privacy differences between these situations:
   a. iPhone owner happens to walk by my house
   b. Android owner happens to walk by my house

Do you know the difference in terms of what happens, or not, with respect
to my unique AP BSSID & GPS location (both of which are exactly my house)?

I do.
   A. So does Apple.
   B. So does Mozilla. And Google.

Mozilla respects a hidden access point broadcast (i.e., it's set to null).
So does Google (surprisingly).
   i. But not Apple.
  ii. And yet, Apple loudly & vociferously proclaims to care about privacy.

That's the part that is the most hurtful.
Apple brazenly lies, with a huge "what me?" seemingly innocent smile.

Yet, Apple immediately removed my BSSID/GPS from their WPS database.
Because they know what I know about the lack of privacy in that regard.

It may well be I'm the only one in the world who is honored so by Apple.
But that's not my point as I care about everyone's privacy. Not just mine.

Another question for you, Lawrence, again, because I respect your acumen.

Do you know the difference between these two situations:
  a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
  b. Android owner happens to walk by my house & it uploads my BSSID/GPS?

What happens then?
Do you know? 

I do.
Anyone who can't answer those queries, can't possibly understand the issue.
-- 
Privacy is a million things, of which most people only understand about 3.

[toc] | [prev] | [next] | [standalone]


#197912

FromJon Ribbens <jon+usenet@unequivocal.eu>
Date2026-09-05 00:34 +0000
Message-ID<slrn119mosh.2a0.jon+usenet@raven.unequivocal.eu>
In reply to#197911
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
> Lawrence D'Oliveiro wrote:
>>> This is about privacy.
>>> Not security.
>> 
>> This is about the *perception* of privacy. Like telling people they
>> don't have to worry about closing their curtains, they just need to
>> close their eyes -- if they can¢t see the people outside looking in,
>> then those looking in can't see them!
>
> Hi Lawrence,
>
> I say with all respect that your statement is too wrong to accept as is.
> What you just said, I've heard a thousand times before, from many people.
>
> And yet, it's no different than what I've heard by asking the guy next to
> me at the gas pump since the 1960's why he puts premium in a Honda Civic.
>
> For over five decades, people have been parroting what someone told them.
> None of them actually understand a word that they're obviously parroting.
>
> Same here... 
>
> Again, I respect you for your technical acumen which is greater'n mine.
> But I can't tell if you know privacy differences between these situations:
>    a. iPhone owner happens to walk by my house
>    b. Android owner happens to walk by my house
>
> Do you know the difference in terms of what happens, or not, with respect
> to my unique AP BSSID & GPS location (both of which are exactly my house)?
>
> I do.
>    A. So does Apple.
>    B. So does Mozilla. And Google.
>
> Mozilla respects a hidden access point broadcast (i.e., it's set to null).
> So does Google (surprisingly).
>    i. But not Apple.
>   ii. And yet, Apple loudly & vociferously proclaims to care about privacy.
>
> That's the part that is the most hurtful.
> Apple brazenly lies, with a huge "what me?" seemingly innocent smile.
>
> Yet, Apple immediately removed my BSSID/GPS from their WPS database.
> Because they know what I know about the lack of privacy in that regard.
>
> It may well be I'm the only one in the world who is honored so by Apple.
> But that's not my point as I care about everyone's privacy. Not just mine.
>
> Another question for you, Lawrence, again, because I respect your acumen.
>
> Do you know the difference between these two situations:
>   a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
>   b. Android owner happens to walk by my house & it uploads my BSSID/GPS?
>
> What happens then?
> Do you know? 
>
> I do.
> Anyone who can't answer those queries, can't possibly understand the issue.

Do you have any intention of letting anyone else know what the issue is?

[toc] | [prev] | [next] | [standalone]


#197913

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-05 07:05 +0600
Message-ID<117fpti$18lf$1@nnrp.usenet.blueworldhosting.com>
In reply to#197912
Jon Ribbens wrote:
>> Anyone who can't answer those queries, can't possibly understand the issue.
> 
> Do you have any intention of letting anyone else know what the issue is?

Hi Jon,

Lil' ole' me can easily track a BSSID anywhere in the world, down to a
meter or so accuracy, if I want to under the common circumstances which
I've outlined in this thread (and in others).

I move my router around a lot, and I don't want just anyone being able to
track all my movements down to a meter accuracy when I do that. Do you?

You were correct in your prior post to Carlos, when you said (verbatim):
  "I got the impression they were claiming that their SSID was hidden,
   which makes it irrelevant as to whether it has "_nomap" at the end
   of it, but that Apple had somehow discovered and logged it nonetheless.
   It seems highly implausible."

But, of course, there's more detail (which I provided in my responses).

I explained it in gory detail, and even provided a link to the research.
I provided some of the python scripts too (although they're not the point).

We've discussed this ad infinitum on the Apple & Android & Windows ngs in
the past, although I don't remember how much we brought in Python folks.

What's *new* is Apple told me in my email that there was no way to have WPS
privacy from Google/Mozilla if I wished to have WPS privacy from Apple.

It's a catch-22 situation.
Which would you pick?

HINT: If we read the research paper, it's a no brainer which one to pick.
-- 
Of the million things to be considered for privacy, most people know 3.

[toc] | [prev] | [next] | [standalone]


#197918

FromJon Ribbens <jon+usenet@unequivocal.eu>
Date2026-09-05 01:47 +0000
Message-ID<slrn119mt6b.2a0.jon+usenet@raven.unequivocal.eu>
In reply to#197913
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
> Jon Ribbens wrote:
>>> Anyone who can't answer those queries, can't possibly understand the
>>> issue.
>> 
>> Do you have any intention of letting anyone else know what the issue
>> is?
>
> Hi Jon,
>
> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
> meter or so accuracy, if I want to under the common circumstances which
> I've outlined in this thread (and in others).

Ok. I think BSSID means "MAC address of the WiFi access point".
I don't know what circumstances you can track them, and you don't
seem to have said in this thread.

> I move my router around a lot, and I don't want just anyone being able
> to track all my movements down to a meter accuracy when I do that. Do
> you?

I suppose if someone had reason to target me specifically, and they had
a real-time way of tracking BSSIDs, and for some reason I can't imagine
I was taking a WiFi access point with me, I... oh, wait. In that
circumstance I would not take a WiFi access point with me, for the
same reason I wouldn't have my mobile phone radio enabled, or would not
have a mobile phone with me at all, depending on the threat model.

> You were correct in your prior post to Carlos, when you said (verbatim):
>   "I got the impression they were claiming that their SSID was hidden,
>    which makes it irrelevant as to whether it has "_nomap" at the end
>    of it, but that Apple had somehow discovered and logged it nonetheless.
>    It seems highly implausible."
>
> But, of course, there's more detail (which I provided in my responses).

I saw no response from you to that post. But from what you're saying
in the post I'm replying to now, I wasn't correct - I now think you're
saying that Apple store the BSSIDs of access points of WiFi networks
with hidden SSIDs, because they *don't* know the SSID and therefore
can't tell if it has "_nomap" appended, and so don't exclude it.

I'm not sure what I think about that, and I don't know what any of the
other companies that map SSIDs do in the same situation. I'm not sure
why Apple would store location data of BSSIDs with no visible SSID -
it doesn't seem like it would help the geolocation feature much, since
hiding the SSID is pretty rare.

> I explained it in gory detail, and even provided a link to the research.
> I provided some of the python scripts too (although they're not the point).

You haven't done any of that in this thread so far as I can see.

> We've discussed this ad infinitum on the Apple & Android & Windows ngs in
> the past, although I don't remember how much we brought in Python folks.
>
> What's *new* is Apple told me in my email that there was no way to
> have WPS privacy from Google/Mozilla if I wished to have WPS privacy
> from Apple.

Sorry, what does WPS have to do with it? And why is it a binary option?
A non-hidden SSID with "_nomap" would presumably provide privacy from
all those companies? Or do some of them not support that? Or is having
a non-hidden SSID not acceptable to you? If so, what are the options
for privacy you are referring to?

> It's a catch-22 situation.
> Which would you pick?

I mean I literally do pick a non-hidden SSID without "_nomap" on it,
that I've kept constant for decades. I've never even seen a SSID with
"_nomap" on it. There is no-one I regard as a threat, let alone someone
who would be a threat and who would know my SSID let alone my BSSIDs.

> HINT: If we read the research paper, it's a no brainer which one to pick.

What research paper?

[toc] | [prev] | [next] | [standalone]


#197924

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-05 14:00 -0300
Message-ID<117hhrg$1jqn$1@nnrp.usenet.blueworldhosting.com>
In reply to#197918
Jon Ribbens wrote:
>> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
>> meter or so accuracy, if I want to under the common circumstances which
>> I've outlined in this thread (and in others).
> 
> Ok. I think BSSID means "MAC address of the WiFi access point".
> I don't know what circumstances you can track them, and you don't
> seem to have said in this thread.

Hi Jon,

Thanks for your questions as it shows you're trying to understand this.

Your questions are all good questions, from someone who is encountering
this issue for the first time in their lives, but let's be clear that an
entire course in networking for privacy is beyond my personal skill sets.

If you don't know what a BSSID is by now then it will take too much work
here to explain it "fully" to you. Suffice to say it's like a vehicle
identification number on a car. It goes everywhere the router goes.

Every access point has a unique BSSID that stays with the router forever.

(Yes, I know in extremely expensive routers, not home routers, that the
BSSID can be changed, and yes, I know, in those extremely rare situations,
the BSSID may actually not be unique, but only one out of a million people
know those facts, so suffice to say for this thread the BSSID is unique).

The Apple trolls absurdly claimed that changing the SSID changes the BSSID,
but the fact remains the BSSID remains the same no matter what the SSID is.

>> I move my router around a lot, and I don't want just anyone being able
>> to track all my movements down to a meter accuracy when I do that. Do
>> you?
> 
> I suppose if someone had reason to target me specifically, and they had
> a real-time way of tracking BSSIDs, and for some reason I can't imagine
> I was taking a WiFi access point with me, I... oh, wait. In that
> circumstance I would not take a WiFi access point with me, for the
> same reason I wouldn't have my mobile phone radio enabled, or would not
> have a mobile phone with me at all, depending on the threat model.

Read the paper which we referenced multiple times in this thread so that I
don't have to re-hash over and over again how mass surveillance is possible
with the Apple WPS database design. 

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

Anyone who can run a python script (which I will provide to them upon
request) can track anyone in the world who moves from one place to another
(and who happens to take their router with them to their new location).

Nobody disputes that fact, which is what the paper itself explained.
I simply reproduced their "billions of BSSID/GPS pairs" with thousands.

It doesn't bother you that I can track the movements of billions of people
if they happen to move from one locale to another using the same router?

You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?

That's 1/2 the point of this thread.
 1. Apple is doing NOTHING about it (as described in the paper)
 2. So anyone in the world can track the movements of billions of routers
 2. Worse, Apple isn't honoring the established meaning of the hidden
    broadcast (which even Google honors, by way of stark contrast).

So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
 
>> You were correct in your prior post to Carlos, when you said (verbatim):
>>   "I got the impression they were claiming that their SSID was hidden,
>>    which makes it irrelevant as to whether it has "_nomap" at the end
>>    of it, but that Apple had somehow discovered and logged it nonetheless.
>>    It seems highly implausible."
>>
>> But, of course, there's more detail (which I provided in my responses).
> 
> I saw no response from you to that post. But from what you're saying
> in the post I'm replying to now, I wasn't correct - I now think you're
> saying that Apple store the BSSIDs of access points of WiFi networks
> with hidden SSIDs, because they *don't* know the SSID and therefore
> can't tell if it has "_nomap" appended, and so don't exclude it.

There are two fundamental issues, only one of which is in this paper.
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

I've summarized what's in that paper likely a half dozen times in this
thread, and I've added a second issue that is not discussed in that paper.

I've talked that second issue over with security professionals like Brain
Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.

To summarize complex issues in a few simple sentences, they might be:
 1. Apple allows anyone on the world to track the movements of everyone
    in the world (if they take their router with them when they move).
 2. Apple puts zero controls on that tracking by anyone, of everyone.
 3. In addition, Apple does not respect the known meaning of a hidden
    broadcast, and worse, Apple *refuses* to honor what even Google does.
 4. Anyone can prove these statements are true on a Windows PC running
    Python using the scripts I have provided for that express purpose.

> I'm not sure what I think about that, and I don't know what any of the
> other companies that map SSIDs do in the same situation. I'm not sure
> why Apple would store location data of BSSIDs with no visible SSID -
> it doesn't seem like it would help the geolocation feature much, since
> hiding the SSID is pretty rare.

Remember the Apple trolls posted to this thread that changing the SSID
would solve the issue, but the main issue is about the BSSID, not the SSID.
  a. The BSSId is unique (see above for rare exceptions).
  b. The GPS location is also unique
  c. The SSID only plays a role tangentially, and as such is a minor player

Assume, for an analogous purpose that a flock camera allowed anyone in the
world to track everyone in the world, not only by the license plate (which
can be changed) but by the VIN number, which cannot be changed.

Then assume Flock knows this, but refuses to add any security whatsoever.
 a. Worse, assume all the other camera outfits DO add security.
 b. Not only that, the other camera outfits add lookup protection.

That's a decent analogy of what's going on that is more easily understood.

> 
>> I explained it in gory detail, and even provided a link to the research.
>> I provided some of the python scripts too (although they're not the point).
> 
> You haven't done any of that in this thread so far as I can see.

Did you read the paper?
What does that paper say?

Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?

I've explained both perhaps a half dozen times in this thread.
Explaining another half dozen times won't help until you do the above.

It's unfair of you to claim I haven't provided you an entire courese in
basic networking, when you didn't even click on the links we provided.

>> We've discussed this ad infinitum on the Apple & Android & Windows ngs in
>> the past, although I don't remember how much we brought in Python folks.
>>
>> What's *new* is Apple told me in my email that there was no way to
>> have WPS privacy from Google/Mozilla if I wished to have WPS privacy
>> from Apple.
> 
> Sorry, what does WPS have to do with it? And why is it a binary option?
> A non-hidden SSID with "_nomap" would presumably provide privacy from
> all those companies? Or do some of them not support that? Or is having
> a non-hidden SSID not acceptable to you? If so, what are the options
> for privacy you are referring to?

Wrong WPS. 
Read the paper. 
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

>> It's a catch-22 situation.
>> Which would you pick?
> 
> I mean I literally do pick a non-hidden SSID without "_nomap" on it,
> that I've kept constant for decades. I've never even seen a SSID with
> "_nomap" on it. There is no-one I regard as a threat, let alone someone
> who would be a threat and who would know my SSID let alone my BSSIDs.

What you need to think about is what the paper explains about the SSID.
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

Then, you need to consider what happens when that SSID broadcast is hidden.

Only one out of a million people (or so) has thought about those two things
(but it goes further since now you need to consider what Google/Apple do).

Google does one thing (which, surprisingly, is the right thing to do).
Apple does the opposite (and, not surprisingly, refuses to change it).

If you don't follow the trail from your router to some guy in Russia who is
tracking the movements of everyone in the world, you can't understand it.

Read the paper (which explains half the issues brought up here).
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

>> HINT: If we read the research paper, it's a no brainer which one to pick.
> 
> What research paper?

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>
-- 
Most people can only parrot what clever marketing told them to believe.

[toc] | [prev] | [next] | [standalone]


#197928

FromJon Ribbens <jon+usenet@unequivocal.eu>
Date2026-09-05 17:49 +0000
Message-ID<slrn119oli2.8k8.jon+usenet@raven.unequivocal.eu>
In reply to#197924
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
> Jon Ribbens wrote:
>>> Lil' ole' me can easily track a BSSID anywhere in the world, down to a
>>> meter or so accuracy, if I want to under the common circumstances which
>>> I've outlined in this thread (and in others).
>> 
>> Ok. I think BSSID means "MAC address of the WiFi access point".
>> I don't know what circumstances you can track them, and you don't
>> seem to have said in this thread.
>
> Hi Jon,
>
> Thanks for your questions as it shows you're trying to understand this.
>
> Your questions are all good questions, from someone who is encountering
> this issue for the first time in their lives, but let's be clear that an
> entire course in networking for privacy is beyond my personal skill sets.
>
> If you don't know what a BSSID is by now then it will take too much work
> here to explain it "fully" to you. Suffice to say it's like a vehicle
> identification number on a car. It goes everywhere the router goes.

Well, yes, it's the MAC address, like I already said.

>> I suppose if someone had reason to target me specifically, and they had
>> a real-time way of tracking BSSIDs, and for some reason I can't imagine
>> I was taking a WiFi access point with me, I... oh, wait. In that
>> circumstance I would not take a WiFi access point with me, for the
>> same reason I wouldn't have my mobile phone radio enabled, or would not
>> have a mobile phone with me at all, depending on the threat model.
>
> Read the paper which we referenced multiple times in this thread so that I
> don't have to re-hash over and over again how mass surveillance is possible
> with the Apple WPS database design. 

You hadn't referenced it at the time I wrote my post, or at least
by the time you wrote the post I was responding to.

It mostly seems to be an attack against people who don't realise
they are targets, or are not thinking about the implications - c.f.
soldiers who upload their daily runs to public web sites thus
revealing if/where they are deployed.

>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
> <https://arxiv.org/abs/2405.14975>
>
> Anyone who can run a python script (which I will provide to them upon
> request) can track anyone in the world who moves from one place to another
> (and who happens to take their router with them to their new location).
>
> Nobody disputes that fact, which is what the paper itself explained.
> I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
>
> It doesn't bother you that I can track the movements of billions of people
> if they happen to move from one locale to another using the same router?

As I say that's a pretty unusual thing to do (travelling with a router).
Google's API does seem more sensible though (give it MAC addresses, it
tells you where you probably are, rather than giving you the recorded
individual locations of all those MAC addresses).

> You think this tracking isn't happenging asa we speak?
> You think Apple is doing something about it?
>
> That's 1/2 the point of this thread.
>  1. Apple is doing NOTHING about it (as described in the paper)

Have you, er, read the paper? It says Apple *is* doing things about it
(page 14, section 10 paragraph 3).

>  2. So anyone in the world can track the movements of billions of routers
>  2. Worse, Apple isn't honoring the established meaning of the hidden
>     broadcast (which even Google honors, by way of stark contrast).

This is the bit I keep asking about and you keep not responding.
Is your actual/main complaint that Apple is storing BSSIDs that
correspond to hidden SSIDs? And you're saying only Apple do this,
not Google etc?

> So much for Apple "cares about your privacy" bullshit, huh?
> It's shocking that google cares about privacy more than Apple does.

Apple cares about the privacy of *its customers*.

> There are two fundamental issues, only one of which is in this paper.
>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
> <https://arxiv.org/abs/2405.14975>
>
> I've summarized what's in that paper likely a half dozen times in this
> thread, and I've added a second issue that is not discussed in that paper.
>
> I've talked that second issue over with security professionals like Brain
> Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
>
> To summarize complex issues in a few simple sentences, they might be:
>  1. Apple allows anyone on the world to track the movements of everyone
>     in the world (if they take their router with them when they move).
>  2. Apple puts zero controls on that tracking by anyone, of everyone.

I imagine the issue here is that if they change their API then older
devices that are no longer receiving updates will stop being able to do
wifi-positioning.

>  3. In addition, Apple does not respect the known meaning of a hidden
>     broadcast, and worse, Apple *refuses* to honor what even Google does.
>  4. Anyone can prove these statements are true on a Windows PC running
>     Python using the scripts I have provided for that express purpose.
>
>> I'm not sure what I think about that, and I don't know what any of the
>> other companies that map SSIDs do in the same situation. I'm not sure
>> why Apple would store location data of BSSIDs with no visible SSID -
>> it doesn't seem like it would help the geolocation feature much, since
>> hiding the SSID is pretty rare.
>
> Remember the Apple trolls posted to this thread that changing the SSID
> would solve the issue, but the main issue is about the BSSID, not the SSID.
>   a. The BSSId is unique (see above for rare exceptions).
>   b. The GPS location is also unique
>   c. The SSID only plays a role tangentially, and as such is a minor player

The "Apple trolls" are presumably correct inasmuch as if you change the
SSID to end in "_nomap" then it solves the issue.

>>> I explained it in gory detail, and even provided a link to the research.
>>> I provided some of the python scripts too (although they're not the
>>> point).
>> 
>> You haven't done any of that in this thread so far as I can see.
>
> Did you read the paper?
> What does that paper say?

You hadn't linked the paper at the time I wrote my post.
The paper doesn't quite say what you're claiming, I think,
although I see your general point (or at least, the paper's
authors' general point).

> Do you know what a hidden broadcast SSID is?
> What is the purpose of a hidden broadcast in your opinion?

To waste power in client devices, as far as I can see, since it
means they have to be constantly pinging for the network rather
than just connecting to it when they see the SSID broadcast.

So in some senses it makes the user tracking problem *much worse*,
since it means the attacker can hang around public places watching
for client devices (which, unlike access points, tend to move around
with the user) that are pinging for the attack target's hidden SSID.

Hang around a diner near Langley, Virginia, watching for people
carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"...

> I've explained both perhaps a half dozen times in this thread.
> Explaining another half dozen times won't help until you do the above.

I'm starting to think that by "this thread" you don't mean "the set
of Usenet articles referenced in the References headers" and are
including other historic threads...

> Google does one thing (which, surprisingly, is the right thing to do).
> Apple does the opposite (and, not surprisingly, refuses to change it).

I think you are still failing to explain what those two things are,
and I'm getting tired of guessing. If you are claiming the paper
describes this difference, please say where. If it doesn't, please
just say what it is.

[toc] | [prev] | [next] | [standalone]


#197933

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-05 16:14 -0300
Message-ID<117hplp$oha$1@nnrp.usenet.blueworldhosting.com>
In reply to#197928
Jon Ribbens wrote:
>> If you don't know what a BSSID is by now then it will take too much work
>> here to explain it "fully" to you. Suffice to say it's like a vehicle
>> identification number on a car. It goes everywhere the router goes.
> 
> Well, yes, it's the MAC address, like I already said.

Hi Jon,

To your credit, you are the first person who has responded, who has shown
that he actually *read* the paper before trying to respond intelligently.

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

That's good. 
Nobody else even bothered to click on the link, before responding.

Hence, everyone else simply parroted their stone-age knowledge level.
You, at least, did *read* the paper, which I congratulate you for doing.

But you did not *understand* what the paper said by the BSSID.
See below where you completely whooshed on which BSSID is what matters.

I must be careful here not to fault you like I fault the Apple trolls,
because I think you are sincerely trying to understand the problem set.

So I simply caution you, as I did Lawrence & Andy, all of whom I respect
for acumen, that you have to follow the trail of the *router* AP BSSID.

You can not "randomize the BSSID" of the router AP (except in the most
expensive commercial routers, which are not the topic of this thread).

Think very deeply about that simple fact before responding, as the crux of
the problem is no different than a governmment-issued identification
number.

You can't easily change your unique government-issued ID number just as you
can't easily change the router-issued BSSID of your home router AP.

Think about that the same way the paper presented the mass surveillance.
 1. I wrote a Python script that ran on Windows 10 that guessed at a set
    of random government-issued identification numbers, e.g., 123.45.6789
 2. Within minutes, I had a hit on a random government ID, which came
    back with a GPS location and 400 nearby government IDs and locations.
 3. Then, I ran another Python script on Windows 10 that extended that, 
    taking the furthest-away governemtn ID/location pair, and did it again.
 4. Within an hour, I had thousands of government IDs and locations.
    (the researchers gathered billions, as I recall, but I stopped there.)

Now that I have every government-issued ID and GPS location in the world in
my 2TB database (which we calculated would be the size it would have been), 
what is the paper saying about "mass surveillance" possibilities?

HINT: I can track the future location of every one of those billions of
government ID/GPS location pairs, without any restrictions on my scripts!

Want to prove that?
What's your home router BSSID?

I will not only tell you exactly where that router is located (I even wrote
the Python code to give me a dot on an OSM map for your location) but I can
trivially easily forever track that router's location forever, without any
restrictions on my part (which is the point of the paper, after all).

That's what the paper says.
I went further (i.e., to hidden broadcast issues).

But that alone is what the paper says you can do, and I proved it, and I
supplied the python scripts (and will supply them to anyone who asks me).

>>> I suppose if someone had reason to target me specifically, and they had
>>> a real-time way of tracking BSSIDs, and for some reason I can't imagine
>>> I was taking a WiFi access point with me, I... oh, wait. In that
>>> circumstance I would not take a WiFi access point with me, for the
>>> same reason I wouldn't have my mobile phone radio enabled, or would not
>>> have a mobile phone with me at all, depending on the threat model.
>>
>> Read the paper which we referenced multiple times in this thread so that I
>> don't have to re-hash over and over again how mass surveillance is possible
>> with the Apple WPS database design. 
> 
> You hadn't referenced it at the time I wrote my post, or at least
> by the time you wrote the post I was responding to.
> 
> It mostly seems to be an attack against people who don't realise
> they are targets, or are not thinking about the implications - c.f.
> soldiers who upload their daily runs to public web sites thus
> revealing if/where they are deployed.

It's not "an attack" so much as explaining, with examples, of why we should
care that mass surveillance is so easy with the Apple WPS implementation.

The soldier part is just an example.
I have a more potent example.

Give me your MAC address of your home router AP.

Not only can I instantly tell you where that reouter is, but I can tell you
the location and BSSID of the nearest 400 routers to your location.

We proved that in the Python scripts I had provided and had run on WIn10.
Test me.

Give me your BSSID.

Note: I don't expect you to do it, which alone proves the point.

>>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> Anyone who can run a python script (which I will provide to them upon
>> request) can track anyone in the world who moves from one place to another
>> (and who happens to take their router with them to their new location).
>>
>> Nobody disputes that fact, which is what the paper itself explained.
>> I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
>>
>> It doesn't bother you that I can track the movements of billions of people
>> if they happen to move from one locale to another using the same router?
> 
> As I say that's a pretty unusual thing to do (travelling with a router).
> Google's API does seem more sensible though (give it MAC addresses, it
> tells you where you probably are, rather than giving you the recorded
> individual locations of all those MAC addresses).

I think your claim that it's "pretty unusual" for people to take their
router with them when they move from one apartment to another is skewed.

If I ask 100 people who recently moved, do you really think it would be
only 1 or 2 people who took their home router with them when they moved?

> 
>> You think this tracking isn't happenging asa we speak?
>> You think Apple is doing something about it?
>>
>> That's 1/2 the point of this thread.
>>  1. Apple is doing NOTHING about it (as described in the paper)
> 
> Have you, er, read the paper? It says Apple *is* doing things about it
> (page 14, section 10 paragraph 3).

See my first response to you in this post, where I want to be careful to
not chastise you for misunderstanding what that paragraph actually says.

You can NOT randomize the MAC address of the router AP, Jon.

Sure, for expensive commercial routers, with thousands of access points,
they can randomize their MAC addresses, but it's not on most home routers.

To be clear, it is on some (expensive) home routers. 
I am well aware of that. 

But we're talking about surveilling the masses, not the people who actually
know how networking works (which nobody on this thread so far has shown).

>>  2. So anyone in the world can track the movements of billions of routers
>>  2. Worse, Apple isn't honoring the established meaning of the hidden
>>     broadcast (which even Google honors, by way of stark contrast).
> 
> This is the bit I keep asking about and you keep not responding.
> Is your actual/main complaint that Apple is storing BSSIDs that
> correspond to hidden SSIDs? And you're saying only Apple do this,
> not Google etc?

First off, I don't have a complaint. That's absurd. I have facts.
This entire thread is people disputing those facts, without ever even
bothering to read the links which were provided for them to read.

The absurdity of this thread is nobody has read or understood the links
which were provided, and yet, they ask me (repeatedly) to explain them.

Why can nobody understand the point that Eric & Dave made in this paper?
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

Why can nobody understand what's different about what Apple documented?
 <https://support.apple.com/en-ie/102515>

Why can nobody undestqand the concept inherent in a hidden-broadcast?
 <https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html>
    "The BSSID of the Wifi network. 
     Hidden Wifi networks must not be collected."

Why is it that I feel it's trivial to understand that 1+1=2 when everyone
else is trying to claim that I need to explain why 1+2=2 when, if they
simply read (and understood) what I've explained, they would understand?

Can *nobody* actually read those references except me, and understand them?

> 
>> So much for Apple "cares about your privacy" bullshit, huh?
>> It's shocking that google cares about privacy more than Apple does.
> 
> Apple cares about the privacy of *its customers*.

I realize you're trying to understand these concepts so I have to be
careful when I point out that this affects every single person in the world
who owns a router (and company, but let's restrict this to just people).

The issues are exactly the same no matter what company made that router.

>> There are two fundamental issues, only one of which is in this paper.
>>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>> <https://arxiv.org/abs/2405.14975>
>>
>> I've summarized what's in that paper likely a half dozen times in this
>> thread, and I've added a second issue that is not discussed in that paper.
>>
>> I've talked that second issue over with security professionals like Brain
>> Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
>>
>> To summarize complex issues in a few simple sentences, they might be:
>>  1. Apple allows anyone on the world to track the movements of everyone
>>     in the world (if they take their router with them when they move).
>>  2. Apple puts zero controls on that tracking by anyone, of everyone.
> 
> I imagine the issue here is that if they change their API then older
> devices that are no longer receiving updates will stop being able to do
> wifi-positioning.

The issue is clearly obvious that the Apple WPS design is flawed.

I have dozens of emails from Apple, all of which show that they *know* that
their design is flawed. 

They're simply trying to protect themselves legally with me by having their
emails redirected to their lawyers, who are whom I was responding with.

They *know* what they're doing is wrong.

>>  3. In addition, Apple does not respect the known meaning of a hidden
>>     broadcast, and worse, Apple *refuses* to honor what even Google does.
>>  4. Anyone can prove these statements are true on a Windows PC running
>>     Python using the scripts I have provided for that express purpose.
>>
>>> I'm not sure what I think about that, and I don't know what any of the
>>> other companies that map SSIDs do in the same situation. I'm not sure
>>> why Apple would store location data of BSSIDs with no visible SSID -
>>> it doesn't seem like it would help the geolocation feature much, since
>>> hiding the SSID is pretty rare.
>>
>> Remember the Apple trolls posted to this thread that changing the SSID
>> would solve the issue, but the main issue is about the BSSID, not the SSID.
>>   a. The BSSId is unique (see above for rare exceptions).
>>   b. The GPS location is also unique
>>   c. The SSID only plays a role tangentially, and as such is a minor player
> 
> The "Apple trolls" are presumably correct inasmuch as if you change the
> SSID to end in "_nomap" then it solves the issue.

No it does not. Did you read any of the Mozilla references?
Simply *collecting* the BSSID is the starting point.

The problem exists no matter what the SSID is.

>>>> I explained it in gory detail, and even provided a link to the research.
>>>> I provided some of the python scripts too (although they're not the
>>>> point).
>>> 
>>> You haven't done any of that in this thread so far as I can see.
>>
>> Did you read the paper?
>> What does that paper say?
> 
> You hadn't linked the paper at the time I wrote my post.
> The paper doesn't quite say what you're claiming, I think,
> although I see your general point (or at least, the paper's
> authors' general point).

I appreciate that you're the only person in this thread who has ever shown
any indication that you actually clicked on the link, so I must be careful
to let you know that I understand that you went to that trouble to "try" to
understand what the paper actually said.

Remember, I go further than what the paper said, because the paper didn't
discuss hidden broadcast implications, but do keep in mind I wrote the
scripts so I can track any router AP anywhere in the world myself, just as
the paper claimed I could.

With my congratulations to you and with my appreciation that you are the
only one who has shown they have read the paper, I must point out that I
think you misunderstood which BSSID the paper is talking about.

For most home routers, the owner has no way of changing the AP BSSID.

>> Do you know what a hidden broadcast SSID is?
>> What is the purpose of a hidden broadcast in your opinion?
> 
> To waste power in client devices, as far as I can see, since it
> means they have to be constantly pinging for the network rather
> than just connecting to it when they see the SSID broadcast.

No. Every mobile device has the on/off ability to NOT autoconnect.

Privacy never was something that everyone could understand, but let's hope
the people on this ng have the capacity to understand the complexities.

> So in some senses it makes the user tracking problem *much worse*,
> since it means the attacker can hang around public places watching
> for client devices (which, unlike access points, tend to move around
> with the user) that are pinging for the attack target's hidden SSID.

That's why you set the mobile device to NOT autoconnect after all.

Remember, privacy doesn't mean you don't have to understand networking.
 
> Hang around a diner near Langley, Virginia, watching for people
> carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"...

I'm very happy you understand networking at that level, Jon.

This is an extremely well known phenomenon, which has been the topic of
discussion in numerous hackers' conferences, where the presenter puts on
the projector screen the names and locations of all such requests.

Anyone who doesn't understand what we're conversing about, can't really add
value to the conversation, so I'm glad you know it at that level.

>> I've explained both perhaps a half dozen times in this thread.
>> Explaining another half dozen times won't help until you do the above.
> 
> I'm starting to think that by "this thread" you don't mean "the set
> of Usenet articles referenced in the References headers" and are
> including other historic threads...

All the python scripts I wrote I put into the public domain so you're
welcome to ask for any of those scripts, which I posted to these ngs.

>> Google does one thing (which, surprisingly, is the right thing to do).
>> Apple does the opposite (and, not surprisingly, refuses to change it).
> 
> I think you are still failing to explain what those two things are,
> and I'm getting tired of guessing. If you are claiming the paper
> describes this difference, please say where. If it doesn't, please
> just say what it is.

Again, I have to first say that I appreciate that you read the paper, and I
presume you read the Mozilla documentation I presented, and I presume you
also read the Apple documentation which the Apple lawyers wrote after my
discussions with them way back in December of last year (public knowledge).

The paper shows that Apple's WPS implementation is highly flawed.

If you've ever tried Google's WPS implementation, you'll see that it's not.
Nor is Mozilla's MLS implementation (now deprecated).

This is known public information that I have to assume you already know, as
it would take me a while to write the Python scripts to query Google's
implementation, which also requires a key which is well known data.

SO, while I do appreciate that you're 'trying' to understand, to have me
document what Google has already documented, would be a waste of energy.

It's absurd for anyone to dispute what I say without actually looking up
the extremely well known fact that the Google lookup requires not only a
key from Google but also it's limited in what it outputs, and also it's
limited in how many lookups you can do in a certain time period.

Apple's WPS lookup is not.
That's why they wrote that paper, after all... :)
-- 
What is disconcerting is nobody seems to look anything up even as everyone
in the world knows what I'm explaining in this thread, over & over again.

[toc] | [prev] | [next] | [standalone]


#197936

FromJon Ribbens <jon+usenet@unequivocal.eu>
Date2026-09-06 00:06 +0000
Message-ID<slrn119pbka.8k8.jon+usenet@raven.unequivocal.eu>
In reply to#197933
Firstly, I do not like crossposting to so many groups. What group
are you actually reading this thread in, so that I can limit the
crossposts please?

On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
> Jon Ribbens wrote:
>>> If you don't know what a BSSID is by now then it will take too much work
>>> here to explain it "fully" to you. Suffice to say it's like a vehicle
>>> identification number on a car. It goes everywhere the router goes.
>> 
>> Well, yes, it's the MAC address, like I already said.
>
> Hi Jon,
>
> To your credit, you are the first person who has responded, who has shown
> that he actually *read* the paper before trying to respond intelligently.
>
>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
> <https://arxiv.org/abs/2405.14975>
>
> That's good. 
> Nobody else even bothered to click on the link, before responding.
>
> Hence, everyone else simply parroted their stone-age knowledge level.
> You, at least, did *read* the paper, which I congratulate you for doing.
>
> But you did not *understand* what the paper said by the BSSID.
> See below where you completely whooshed on which BSSID is what matters.
>
> I must be careful here not to fault you like I fault the Apple trolls,
> because I think you are sincerely trying to understand the problem set.
>
> So I simply caution you, as I did Lawrence & Andy, all of whom I respect
> for acumen, that you have to follow the trail of the *router* AP BSSID.
>
> You can not "randomize the BSSID" of the router AP (except in the most
> expensive commercial routers, which are not the topic of this thread).
>
> Think very deeply about that simple fact before responding, as the crux of
> the problem is no different than a governmment-issued identification
> number.
>
> You can't easily change your unique government-issued ID number just as you
> can't easily change the router-issued BSSID of your home router AP.

Yes, I do know all of the above.

> Think about that the same way the paper presented the mass surveillance.
>  1. I wrote a Python script that ran on Windows 10 that guessed at a set
>     of random government-issued identification numbers, e.g., 123.45.6789
>  2. Within minutes, I had a hit on a random government ID, which came
>     back with a GPS location and 400 nearby government IDs and locations.
>  3. Then, I ran another Python script on Windows 10 that extended that, 
>     taking the furthest-away governemtn ID/location pair, and did it again.
>  4. Within an hour, I had thousands of government IDs and locations.
>     (the researchers gathered billions, as I recall, but I stopped there.)
>
> Now that I have every government-issued ID and GPS location in the world in
> my 2TB database (which we calculated would be the size it would have been), 
> what is the paper saying about "mass surveillance" possibilities?
>
> HINT: I can track the future location of every one of those billions of
> government ID/GPS location pairs, without any restrictions on my scripts!
>
> Want to prove that?
> What's your home router BSSID?
>
> I will not only tell you exactly where that router is located (I even wrote
> the Python code to give me a dot on an OSM map for your location) but I can
> trivially easily forever track that router's location forever, without any
> restrictions on my part (which is the point of the paper, after all).

Yes, I know that too now, after reading the paper. I downloaded the
code at https://github.com/darkosancanin/apple_bssid_locator (which
was originally uploaded in 2015) and ran it locally with my own AP
MAC address and confirmed it showed my home location very accurately.

It does concern me that there is an attack model here which is that
a mildly technically-inclined stalker can very easily get the BSSID
of their victim and, as you say, find out where they've gone if they
move house to get away from them.

>> It mostly seems to be an attack against people who don't realise
>> they are targets, or are not thinking about the implications - c.f.
>> soldiers who upload their daily runs to public web sites thus
>> revealing if/where they are deployed.
>
> It's not "an attack" so much as explaining, with examples, of why we
> should care that mass surveillance is so easy with the Apple WPS
> implementation.

We should care because it enables attacks.

> Give me your BSSID.
>
> Note: I don't expect you to do it, which alone proves the point.

As above, I already tried it.

>> As I say that's a pretty unusual thing to do (travelling with a router).
>> Google's API does seem more sensible though (give it MAC addresses, it
>> tells you where you probably are, rather than giving you the recorded
>> individual locations of all those MAC addresses).
>
> I think your claim that it's "pretty unusual" for people to take their
> router with them when they move from one apartment to another is skewed.
>
> If I ask 100 people who recently moved, do you really think it would be
> only 1 or 2 people who took their home router with them when they moved?

I could quibble with that inasmuch as ISPs tend to provide the APs when
you order the connection, so a new connection usually implies a new AP
(in the UK, anyway). But I was talking about travelling with an AP,
e.g. on business, not moving house.

>>> You think this tracking isn't happenging asa we speak?
>>> You think Apple is doing something about it?
>>>
>>> That's 1/2 the point of this thread.
>>>  1. Apple is doing NOTHING about it (as described in the paper)
>> 
>> Have you, er, read the paper? It says Apple *is* doing things about it
>> (page 14, section 10 paragraph 3).
>
> See my first response to you in this post, where I want to be careful to
> not chastise you for misunderstanding what that paragraph actually says.
>
> You can NOT randomize the MAC address of the router AP, Jon.

Yes, I wasn't talking about randomizing the MAC addresses of APs,
I was talking about Apple taking steps to mitigate the attacks enabled
by their BSSID-lookup API. Apparently adding the "_nomap" exception was
one of the things Apple changed.

I agree that they shouldn't be storing BSSID data unless they see an
SSID broadcast without "_nomap" on the end (i.e. the SSID is not
hidden). And although I've briefly explored various lines of thought,
I can't immediately see why they would be reluctant to make that change.

But... it makes very little difference to the actual possible attacks.
Almost nobody hides their SSID, and even fewer append "_nomap". Anyone
who actually seriously cares about these things would take the trouble
to ensure that their BSSID does change if their location changes (even
if that means going as far as buying a new AP). The people who are
vulnerable are the people who don't know they're vulnerable.

>>>  2. So anyone in the world can track the movements of billions of routers
>>>  2. Worse, Apple isn't honoring the established meaning of the hidden
>>>     broadcast (which even Google honors, by way of stark contrast).
>> 
>> This is the bit I keep asking about and you keep not responding.
>> Is your actual/main complaint that Apple is storing BSSIDs that
>> correspond to hidden SSIDs? And you're saying only Apple do this,
>> not Google etc?
>
> First off, I don't have a complaint. That's absurd. I have facts.

You certainly don't seem to be happy with the status quo, which means
that by definition you have a complaint. My point is that for some
reason you are being opaque about what change you want to see.

> The absurdity of this thread is nobody has read or understood the links
> which were provided, and yet, they ask me (repeatedly) to explain them.
>
> Why can nobody understand the point that Eric & Dave made in this paper?
>  *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
> <https://arxiv.org/abs/2405.14975>
>
> Why can nobody understand what's different about what Apple documented?
> <https://support.apple.com/en-ie/102515>
>
> Why can nobody undestqand the concept inherent in a hidden-broadcast?
> <https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html>
>     "The BSSID of the Wifi network. 
>      Hidden Wifi networks must not be collected."
>
> Why is it that I feel it's trivial to understand that 1+1=2 when everyone
> else is trying to claim that I need to explain why 1+2=2 when, if they
> simply read (and understood) what I've explained, they would understand?

I think that many people understand that 1+1=2, but you are then going
on to make some further claim that you are explaining very badly.

Also, the links you are providing do not always back up what you are
saying, or it is not clear what conclusion you are expecting people to
draw from them. For example, that last quote about "Hidden WIFi networks
must be be collected" is simply a policy of the Mozilla Location Service.
It isn't any sort of law or agreed standard.

>>> So much for Apple "cares about your privacy" bullshit, huh?
>>> It's shocking that google cares about privacy more than Apple does.
>> 
>> Apple cares about the privacy of *its customers*.
>
> I realize you're trying to understand these concepts so I have to be
> careful when I point out that this affects every single person in the
> world who owns a router (and company, but let's restrict this to just
> people).
>
> The issues are exactly the same no matter what company made that router.

Yes, I think you missed my point, which is that Apple is not generally
the provider of the routers, so Apple is not primarily concerned with
the privacy of their owners. Apple is primarily concerned with the
privacy of its customers, in respect of them being its customers.
(i.e. does their use of an Apple product threaten their privacy?)

>> I imagine the issue here is that if they change their API then older
>> devices that are no longer receiving updates will stop being able to do
>> wifi-positioning.
>
> The issue is clearly obvious that the Apple WPS design is flawed.
>
> I have dozens of emails from Apple, all of which show that they *know*
> that their design is flawed. 
>
> They're simply trying to protect themselves legally with me by having
> their emails redirected to their lawyers, who are whom I was
> responding with.
>
> They *know* what they're doing is wrong.

I think all of the above is likely true, but there is some reason they
cannot (quickly) change their API, probably related to the millions of
devices out there which either can not or do not receive new software
updates.

>>> Remember the Apple trolls posted to this thread that changing the
>>> SSID would solve the issue, but the main issue is about the BSSID,
>>> not the SSID.
>>>   a. The BSSId is unique (see above for rare exceptions).
>>>   b. The GPS location is also unique
>>>   c. The SSID only plays a role tangentially, and as such is a minor player
>> 
>> The "Apple trolls" are presumably correct inasmuch as if you change the
>> SSID to end in "_nomap" then it solves the issue.
>
> No it does not. Did you read any of the Mozilla references?
> Simply *collecting* the BSSID is the starting point.
>
> The problem exists no matter what the SSID is.

Sorry, I don't get what you mean. If the broadcast SSID ends with
"_nomap" then Apple won't store the BSSID, and won't respond with
its location. Are you saying that isn't true? If it is true, then
what is "the problem"?

> With my congratulations to you and with my appreciation that you are the
> only one who has shown they have read the paper, I must point out that I
> think you misunderstood which BSSID the paper is talking about.
>
> For most home routers, the owner has no way of changing the AP BSSID.

I don't know why you think I misunderstood that.

>>> Do you know what a hidden broadcast SSID is?
>>> What is the purpose of a hidden broadcast in your opinion?
>> 
>> To waste power in client devices, as far as I can see, since it
>> means they have to be constantly pinging for the network rather
>> than just connecting to it when they see the SSID broadcast.
>
> No. Every mobile device has the on/off ability to NOT autoconnect.
>
> Privacy never was something that everyone could understand, but let's
> hope the people on this ng have the capacity to understand the
> complexities.

I think even fewer people are going to be manually connecting their
devices to a hidden-SSID WiFi network every time they come into range
than have hidden-SSID WiFi networks in the first place.

>> I think you are still failing to explain what those two things are,
>> and I'm getting tired of guessing. If you are claiming the paper
>> describes this difference, please say where. If it doesn't, please
>> just say what it is.
>
> Again, I have to first say that I appreciate that you read the paper, and I
> presume you read the Mozilla documentation I presented, and I presume you
> also read the Apple documentation which the Apple lawyers wrote after my
> discussions with them way back in December of last year (public knowledge).

I read the paper (albeit not in complete detail), and I skimmed the
Apple documentation, although I'm not clear on which bit you are saying
they added because of you - I assume the "This opt-out doesn’t work for
hidden networks" bit?

> The paper shows that Apple's WPS implementation is highly flawed.
>
> If you've ever tried Google's WPS implementation, you'll see that it's
> not. Nor is Mozilla's MLS implementation (now deprecated).

The paper discusses the difference between Apple and Google's
implementation, and I agree that Google's looks better.

[toc] | [prev] | [next] | [standalone]


#197938

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-09-06 13:39 +0200
Message-ID<mvvvmmxm4c.ln2@Telcontar.valinor>
In reply to#197936
On 2026-09-06 02:06, Jon Ribbens wrote:
> Firstly, I do not like crossposting to so many groups. What group
> are you actually reading this thread in, so that I can limit the
> crossposts please?

I understand, but that could be a problem to people that are already 
reading on a "different" group.

Your comments are easier to understand that Arlen (aka Maria) posts. He 
is not clearly explaining the issues and wants people to read a lot of 
documentation, instead of just posting an actual summary of the 
situation with explanations.

Ie, what was Apple doing, why is that bad, what have they changed, is 
that enough and why, what are the actual dangers to people.

Complete, and short text.


> 
> On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
>> Jon Ribbens wrote:

...

>>> As I say that's a pretty unusual thing to do (travelling with a router).
>>> Google's API does seem more sensible though (give it MAC addresses, it
>>> tells you where you probably are, rather than giving you the recorded
>>> individual locations of all those MAC addresses).
>>
>> I think your claim that it's "pretty unusual" for people to take their
>> router with them when they move from one apartment to another is skewed.
>>
>> If I ask 100 people who recently moved, do you really think it would be
>> only 1 or 2 people who took their home router with them when they moved?
> 
> I could quibble with that inasmuch as ISPs tend to provide the APs when
> you order the connection, so a new connection usually implies a new AP
> (in the UK, anyway). But I was talking about travelling with an AP,
> e.g. on business, not moving house.

Most people here get a free (rented, not purchased) router with AP from 
their ISP. When they move house, the old router has to be returned to 
the ISP (nominally), and they get a new router automatically when 
contracting a connection at the new location. So they don't have a problem.

Some of those might have a secondary AP of their own.

Only people that buy a router or AP have a problem. And most do not 
care. I don't. Only those that are using _nomap or perhaps those that 
hide the SSID.



...

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#197942

FromJon Ribbens <jon+usenet@unequivocal.eu>
Date2026-09-06 15:37 +0000
Message-ID<slrn119r24u.8k8.jon+usenet@raven.unequivocal.eu>
In reply to#197938
On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
> On 2026-09-06 02:06, Jon Ribbens wrote:
>> Firstly, I do not like crossposting to so many groups. What group
>> are you actually reading this thread in, so that I can limit the
>> crossposts please?
>
> I understand, but that could be a problem to people that are already 
> reading on a "different" group.
>
> Your comments are easier to understand that Arlen (aka Maria) posts. He 
> is not clearly explaining the issues and wants people to read a lot of 
> documentation, instead of just posting an actual summary of the 
> situation with explanations.
>
> Ie, what was Apple doing, why is that bad, what have they changed, is 
> that enough and why, what are the actual dangers to people.
>
> Complete, and short text.

Ok, well to summarise what I have gathered then, which may or may not
be Maria's opinion but reflects my opinion at this point: there are two
completely separate issues here, which are unrelated except that they
are both to do with WiFi location databases.


1. Apple are storing the location of "hidden" WiFi Access Points.
   (My opinion: low priority.)

Multiple organisations are gathering and storing the physical
co-ordinates of the MAC addresses ("BSSIDs") of WiFi Access Points
around the world, whenever they are seen transmitting by, e.g. mobile
phones. (Any WiFi-enabled device can see this information; it does not
need to be connected to the network in question, nor does it need to
know its password.)

The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.

There is broad agreement that these databases should not include BSSIDs
which are broadcasting WiFi network names ("SSIDs") which end in the
string "_nomap".

Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.

My complete speculation: older Apple software, written before they added
the "_nomap" exclusion, doesn't care at all about the SSID, so just
reports from the phone to the central database the BSSID and location.
The database thus has no way of excluding "hidden" networks, without
excluding all reports from older devices. The "_nomap" exclusion is
achieved by later software versions reporting the SSID if it is seen,
and any BSSIDs associated with "_nomap" SSIDs then being blacklisted,
maybe for 6 months or something like that. The likelihood of any
particular BSSID *only* being seen by old Apple devices and *never* new
ones is very low, and hence the "_nomap" exclusion more-or-less works.

My opinion: this failure to exclude "hidden" networks is unfortunate and
should be fixed, and maybe Apple are indeed fixing it, but it's possible
it may take some years to achieve due to the multitude of devices
running old software.


2. Apple's API is trivial to abuse.
   (My opinion: high priority.)

The Apple API to query their BSSID location database is remarkably
unrestricted. It has little or no rate limiting, doesn't ask for an API
key, and reports not only the location of the BSSID but also potentially
a great many other BSSIDs in the locality. It is not beyond even an
individual person's ability to get a list of most of the Access Points
in the world and all their locations.

This makes it very easy for people to abuse this data in various ways,
from stalkers tracking victims to state actors tracking military
targets.

Google's API by contrast essentially reverses the process, and instead
of the phone asking "Where is BSSID <x>?", it says "I can see BSSIDs
<x>, <y>, and <z>, where am I?".

My opinion: the lack of restrictions on the Apple API is unacceptable,
and if Apple are unwilling to do something about it then governments
should pass laws (or enforce existing laws) to make them to do so.

My opinion: it would be difficult for Apple to rapidly switch completely
to using an API more similar to Google's API, since this would remove
functionality from devices running old software. However they could
certainly aim to do this eventually, and there are steps they could take
immediately to improve the situation (e.g. rate limiting, and not
providing so many additional answers when asked about an individual
BSSID). I cannot see any obvious reason why they couldn't make
significant improvements almost immediately.

[toc] | [prev] | [next] | [standalone]


#197945

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-09-06 20:23 +0200
Message-ID<vln0nmxs7v.ln2@Telcontar.valinor>
In reply to#197942
On 2026-09-06 17:37, Jon Ribbens wrote:
> On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
>> On 2026-09-06 02:06, Jon Ribbens wrote:
>>> Firstly, I do not like crossposting to so many groups. What group
>>> are you actually reading this thread in, so that I can limit the
>>> crossposts please?
>>
>> I understand, but that could be a problem to people that are already
>> reading on a "different" group.
>>
>> Your comments are easier to understand that Arlen (aka Maria) posts. He
>> is not clearly explaining the issues and wants people to read a lot of
>> documentation, instead of just posting an actual summary of the
>> situation with explanations.
>>
>> Ie, what was Apple doing, why is that bad, what have they changed, is
>> that enough and why, what are the actual dangers to people.
>>
>> Complete, and short text.
> 
> Ok, well to summarise what I have gathered then, which may or may not
> be Maria's opinion but reflects my opinion at this point: there are two
> completely separate issues here, which are unrelated except that they
> are both to do with WiFi location databases.

Thanks.

> 
> 
> 1. Apple are storing the location of "hidden" WiFi Access Points.
>     (My opinion: low priority.)

Only Apple?

> 
> Multiple organisations are gathering and storing the physical
> co-ordinates of the MAC addresses ("BSSIDs") of WiFi Access Points
> around the world, whenever they are seen transmitting by, e.g. mobile
> phones. (Any WiFi-enabled device can see this information; it does not
> need to be connected to the network in question, nor does it need to
> know its password.)

Yes.

> The purpose of these databases of BSSID locations is to assist devices
> such as mobile phones in locating themselves. Maybe the device is
> indoors and cannot get a GPS signal, but also my understanding is that
> GPS can fix an accurate location much faster if it starts already
> knowing vaguely where on the planet it is.

Yes. And they can give an approximate location without using the GPS chip.

> 
> There is broad agreement that these databases should not include BSSIDs
> which are broadcasting WiFi network names ("SSIDs") which end in the
> string "_nomap".

Right.

> 
> Allegedly: Apple are adhering to this exclusion, but are not also
> excluding BSSIDs which are not broadcasting any SSID at all (i.e.
> "hidden" networks). Other organisations (e.g. Google) do exclude such
> "hidden" networks.

And if it is hidden they would not see if the SSID ends in _nomap.

But is there a consensus that hidden SSIDs should not be listed? In 
writing? Maybe there is such a consensus now.

> 
> My complete speculation: older Apple software, written before they added
> the "_nomap" exclusion, doesn't care at all about the SSID, so just
> reports from the phone to the central database the BSSID and location.
> The database thus has no way of excluding "hidden" networks, without
> excluding all reports from older devices. The "_nomap" exclusion is
> achieved by later software versions reporting the SSID if it is seen,
> and any BSSIDs associated with "_nomap" SSIDs then being blacklisted,
> maybe for 6 months or something like that. The likelihood of any
> particular BSSID *only* being seen by old Apple devices and *never* new
> ones is very low, and hence the "_nomap" exclusion more-or-less works.
> 
> My opinion: this failure to exclude "hidden" networks is unfortunate and
> should be fixed, and maybe Apple are indeed fixing it, but it's possible
> it may take some years to achieve due to the multitude of devices
> running old software.

Right.

Related: What did Arlen (aka Maria) achieve? That Apple agreed to remove 
all hidden and _nomap entries, or that they removed only his entry?


> 2. Apple's API is trivial to abuse.
>     (My opinion: high priority.)
> 
> The Apple API to query their BSSID location database is remarkably
> unrestricted. It has little or no rate limiting, doesn't ask for an API
> key, and reports not only the location of the BSSID but also potentially
> a great many other BSSIDs in the locality. It is not beyond even an
> individual person's ability to get a list of most of the Access Points
> in the world and all their locations.

Aha.

> 
> This makes it very easy for people to abuse this data in various ways,
> from stalkers tracking victims to state actors tracking military
> targets.

Well, only of the limited subset of people that carry their AP when they 
move.


> Google's API by contrast essentially reverses the process, and instead
> of the phone asking "Where is BSSID <x>?", it says "I can see BSSIDs
> <x>, <y>, and <z>, where am I?".

Ah. Yes, I can see this is better.

> 
> My opinion: the lack of restrictions on the Apple API is unacceptable,
> and if Apple are unwilling to do something about it then governments
> should pass laws (or enforce existing laws) to make them to do so.
> 

Ok.

> My opinion: it would be difficult for Apple to rapidly switch completely
> to using an API more similar to Google's API, since this would remove
> functionality from devices running old software. However they could
> certainly aim to do this eventually, and there are steps they could take
> immediately to improve the situation (e.g. rate limiting, and not
> providing so many additional answers when asked about an individual
> BSSID). I cannot see any obvious reason why they couldn't make
> significant improvements almost immediately.

Ok, yes.

Thank you for the explanation. Easy to understand, and I agree with your 
conclusions.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#197951

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-07 02:16 +0300
Message-ID<117ks8d$jjt$1@nnrp.usenet.blueworldhosting.com>
In reply to#197945
After having read the prior responses in this Jon/Carlos tangent... 

I apologize if I haven't explained the situation to the liking of people
who haven't clicked on the references, but I am happy that Jon and Carlos
(and Andy and Lawrence, all of whom I respect) are trying to understand.

I especially wish to thank Jon Ribbens and Carlos & any others who have
bothered to read the links provided, because they explain the issue well.

If people haven't read the references, then they're stuck in the stone age
of understanding, which, well, which I'm not the one to drag them out of.

I just don't have the skills to explain that an SSID is not a BSSID 
(as witnessed by those who claimed changing the SSID changes the BSSID).

These are basic networking concepts.

Regarding locations, I don't have the skills to explain what a set of GPS
coordinates means, if people claim it's "just a map". I don't even know
_how_ to _begin_ to explain that your home address is NOT "just a map".

I don't even know how to explain to people who claim that the router never
travels as their belief system is so absurd as to warn me that if they
don't understand that people take their routers with them when they move,
then that kind of person will never be able to understand, well, anything.

I apologize that I don't have the skills set to bring folks out of the
stone age, when they claim a home address is "just a location on a map".

People who make those claims will never be able to comprehend why it is so
trivial for Jon & me to surveil their movements using the Apple WPS db.

In summary, if people haven't read this paper, I don't have the skill set
to explain the very simple concepts which are described in that paper.
 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

The paper is about surveillance of masses (not individuals, per se),
knowing every single location of billions of router BSSIDs around the
world, from anywhere in the world, by anyone in the world, with zero
restrictions, which is only possible using Apple's WPS database (not
Google's, which has huge restrictions on both the input and output).

Apple has zero restrictions on the input.
And a restriction of the nearest 400 BSSIDs/GPS pairs on the output.

But... that restriction is meaningless, as I wrote and ran the Python code
on Windows that took the furthest away of those 400 to run it again. 

And again. And again. And again. I stopped at something like thousands.
So now I have the nearest ten thousand BSSIDs starting at my home.

Notice I have the GPS location of each of those unique ten thousand BSSIDs.

And, since apartments basically do not exist in this suburban area, I
actually know the names and address of the owners of record of those homes.

If any of those ten thousand people ever move, and take their router with
them, I will instantly know exactly where they moved to, within seconds.

Not only that, but I will instantly know the nearest 400 BSSIds, so if they
moved, oh, say, into someone else's home, I'll know exactly who that is.

To be very clear, this is only possible because of how Apple designed it.
Google and Mozilla designed their systems completely differently.

Only Apple's design is this bad in terms of privacy.

As for the hidden-BSSID issue, I was unaware of that until I found, to my
horror, my own hidden BSSIDs in Apple's WPS database. That was a shock!

At the time, I looked up Apple's public policy, and it was silent on the
issue of what Apple does when it encounters a hidden-broadcast BSSID.

When I brought it up to my next-door neighbor, who runs Apple Maps, he said
he'd check it out, which, after a few weeks of emails back and forth, we
found out that Apple has no intention of honoring the intent of a hidden
broadcast (even as we know Google & Mozilla certainly honor that intent).

The Apple lawyers made that very clear to me, as I was shut out from
talking to the engineers once the lawyers were informed of the issue.

I had given up, but recently, I happened to look at Apple's documentation,
and I realized Apple proved they had no intent of honoring the long-held
intention of a hidden broadcast, by simply changing their documentation.
 <https://support.apple.com/en-ie/102515>

Clearly, I know what I'm talking about, so my well informed assessment,
based on those verifiable facts, is Apple doesn't care about our privacy.
-- 
On Usenet we can have intelligent discussions with well-meaning people.

[toc] | [prev] | [next] | [standalone]


#197974

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-09-07 13:42 +0200
Message-ID<ghk2nmx99u.ln2@Telcontar.valinor>
In reply to#197951
On 2026-09-07 01:16, Maria Sophia wrote:
> After having read the prior responses in this Jon/Carlos tangent...
> 
> I apologize if I haven't explained the situation to the liking of people
> who haven't clicked on the references, but I am happy that Jon and Carlos
> (and Andy and Lawrence, all of whom I respect) are trying to understand.
> 
> I especially wish to thank Jon Ribbens and Carlos & any others who have
> bothered to read the links provided, because they explain the issue well.
> 
> If people haven't read the references, then they're stuck in the stone age
> of understanding, which, well, which I'm not the one to drag them out of.
> 
> I just don't have the skills to explain that an SSID is not a BSSID
> (as witnessed by those who claimed changing the SSID changes the BSSID).
> 
> These are basic networking concepts.

We didn't ask to have it explained. Knowing this is not about skills, 
though. A mathematician can have very high skills, yet know nothing 
about networks. Even a skilled computer programmer may not know about 
them, and be a world master on IBM big iron assembler programming (and 
being paid handsomely - a tiny fact I happen to know) and not know 
offhand what the BSSID is.


> Regarding locations, I don't have the skills to explain what a set of GPS
> coordinates means, if people claim it's "just a map". I don't even know
> _how_ to _begin_ to explain that your home address is NOT "just a map".
> 
> I don't even know how to explain to people who claim that the router never
> travels as their belief system is so absurd as to warn me that if they
> don't understand that people take their routers with them when they move,
> then that kind of person will never be able to understand, well, anything.

No, we don't travel with our routers.

My router belongs to the ISP and I have to return it when I move, then I 
will get a new one at my destination. You should be intelligent enough 
to accept this. Maybe doesn't happen in your nook of the world, but you 
must understand that you are posting to an international medium.

> 
> I apologize that I don't have the skills set to bring folks out of the
> stone age, when they claim a home address is "just a location on a map".

Don't be insulting. You can say the same things without insulting people 
or being patronizing.

...

> When I brought it up to my next-door neighbor, who runs Apple Maps, he said
> he'd check it out, which, after a few weeks of emails back and forth, we
> found out that Apple has no intention of honoring the intent of a hidden
> broadcast (even as we know Google & Mozilla certainly honor that intent).
> 
> The Apple lawyers made that very clear to me, as I was shut out from
> talking to the engineers once the lawyers were informed of the issue.
> 
> I had given up, but recently, I happened to look at Apple's documentation,
> and I realized Apple proved they had no intent of honoring the long-held
> intention of a hidden broadcast, by simply changing their documentation.
>   <https://support.apple.com/en-ie/102515>

Ok, finally. The crux of the issue.

> 
> Clearly, I know what I'm talking about, so my well informed assessment,
> based on those verifiable facts, is Apple doesn't care about our privacy.


-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#197979

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-07 21:06 +0300
Message-ID<117muff$1821$1@nnrp.usenet.blueworldhosting.com>
In reply to#197974
Carlos E.R. wrote:
>> These are basic networking concepts.
> 
> We didn't ask to have it explained. Knowing this is not about skills, 
> though. A mathematician can have very high skills, yet know nothing 
> about networks. Even a skilled computer programmer may not know about 
> them, and be a world master on IBM big iron assembler programming (and 
> being paid handsomely - a tiny fact I happen to know) and not know 
> offhand what the BSSID is.

Hi Carlos,

The facts are incontrovertible, where only Jon went to the trouble to
reproduce them (AFAwK). Everyone else simply used their stone-age knowledge
of networking (which we all knew decades ago) to apply to this thread.

Winston just did that, multiple times in this thread, as if stating his own
stone-age knowledge of networking has anything to do whatsoever with the
topic. Franklin Slootweg tried the same worthless trolling as Winston did.

Please note that there's nothing wrong with people's stone-age knowledge of
networking, but their stone-age knowledge, while true, doesn't apply here.

If all they can do in response to the facts posted in this thread is repeat
their stone-age thought processes, then they can't possibly add value.

Then you have the trolls like Keith Thompson claiming that running python
on Windows to prove what Apple & Android devices do by default with respect
to Wi-Fi protocols has absolutely nothing to do with running python on
windows to prove how Apple & Google devices differ from how they handle
Wi-Fi metadata.

WTF?

These people are all applying their stone-age knowledge of networking, but
without taking into account the verified *new* information in this thread.

Not a single person who trolled this thread shows any understanding of it.

>> I don't even know how to explain to people who claim that the router never
>> travels as their belief system is so absurd as to warn me that if they
>> don't understand that people take their routers with them when they move,
>> then that kind of person will never be able to understand, well, anything.
> 
> No, we don't travel with our routers.
> 
> My router belongs to the ISP and I have to return it when I move, then I 
> will get a new one at my destination. You should be intelligent enough 
> to accept this. Maybe doesn't happen in your nook of the world, but you 
> must understand that you are posting to an international medium.

WTF?
What kind of absurd arguments are you claiming Carlos?

I don't like broccoli, so nobody on the planet likes broccoli?

More to the point, I don't bring the paintings on my wall with me when I
move, but that doesn't mean that nobody brings their paintings with them.

The fact you get your access point from the ISP, while true, is an absurd
way of your attempt to refute the facts proposed in this respected paper.

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

I do take my many access points with me, Carlos. Dozens of them.
And even if I didn't, it would still refute NOTHING in that research paper.

The fact that's your major rebuttal indicates you haven't read the paper.
Read it. Please.

>> I had given up, but recently, I happened to look at Apple's documentation,
>> and I realized Apple proved they had no intent of honoring the long-held
>> intention of a hidden broadcast, by simply changing their documentation.
>>   <https://support.apple.com/en-ie/102515>
> 
> Ok, finally. The crux of the issue.

It's not hidden.
It is, after all, in the SUBJECT line of this thread, Carlos.

Every person who tried it, found out every single statement to be true.
-- 
My role on Usenet is to always add value that other people aren't aware of.

[toc] | [prev] | [next] | [standalone]


#197982

From"Carlos E.R." <robin_listas@es.invalid>
Date2026-09-07 21:28 +0200
Message-ID<nsf3nmxviq.ln2@Telcontar.valinor>
In reply to#197979
On 2026-09-07 20:06, Maria Sophia wrote:
> Carlos E.R. wrote:
>>> These are basic networking concepts.
>>
>> We didn't ask to have it explained. Knowing this is not about skills,
>> though. A mathematician can have very high skills, yet know nothing
>> about networks. Even a skilled computer programmer may not know about
>> them, and be a world master on IBM big iron assembler programming (and
>> being paid handsomely - a tiny fact I happen to know) and not know
>> offhand what the BSSID is.
> 
> Hi Carlos,
> 
> The facts are incontrovertible, where only Jon went to the trouble to
> reproduce them (AFAwK). Everyone else simply used their stone-age knowledge
> of networking (which we all knew decades ago) to apply to this thread.
> 
> Winston just did that, multiple times in this thread, as if stating his own
> stone-age knowledge of networking has anything to do whatsoever with the
> topic. Franklin Slootweg tried the same worthless trolling as Winston did.
> 
> Please note that there's nothing wrong with people's stone-age knowledge of
> networking, but their stone-age knowledge, while true, doesn't apply here.
> 
> If all they can do in response to the facts posted in this thread is repeat
> their stone-age thought processes, then they can't possibly add value.
> 
> Then you have the trolls like Keith Thompson claiming that running python
> on Windows to prove what Apple & Android devices do by default with respect
> to Wi-Fi protocols has absolutely nothing to do with running python on
> windows to prove how Apple & Google devices differ from how they handle
> Wi-Fi metadata.
> 
> WTF?

Wrong.

Keith Thompson argues that your post is off topic in comp.lang.python, 
because you are not discussing python code. You simply posted a link 
that contains a reference to a Python program and said you run it. You 
are not discussing the code itself or making any question about it.

And he is right, IMNSHO.

> 
> These people are all applying their stone-age knowledge of networking, but
> without taking into account the verified *new* information in this thread.
> 
> Not a single person who trolled this thread shows any understanding of it.
> 
>>> I don't even know how to explain to people who claim that the router never
>>> travels as their belief system is so absurd as to warn me that if they
>>> don't understand that people take their routers with them when they move,
>>> then that kind of person will never be able to understand, well, anything.
>>
>> No, we don't travel with our routers.
>>
>> My router belongs to the ISP and I have to return it when I move, then I
>> will get a new one at my destination. You should be intelligent enough
>> to accept this. Maybe doesn't happen in your nook of the world, but you
>> must understand that you are posting to an international medium.
> 
> WTF?
> What kind of absurd arguments are you claiming Carlos?

It is fact, Arlen.

> 
> I don't like broccoli, so nobody on the planet likes broccoli?
> 
> More to the point, I don't bring the paintings on my wall with me when I
> move, but that doesn't mean that nobody brings their paintings with them.
> 

I did not say "nobody". That's you reading what is not in what I said.

> The fact you get your access point from the ISP, while true, is an absurd
> way of your attempt to refute the facts proposed in this respected paper.

I don't refute anything, except that you can only track a minority of 
users worldwide.

> 
>   *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
>   <https://arxiv.org/abs/2405.14975>
> 
> I do take my many access points with me, Carlos. Dozens of them.
> And even if I didn't, it would still refute NOTHING in that research paper.
> 
> The fact that's your major rebuttal indicates you haven't read the paper.
> Read it. Please.

No.

> 
>>> I had given up, but recently, I happened to look at Apple's documentation,
>>> and I realized Apple proved they had no intent of honoring the long-held
>>> intention of a hidden broadcast, by simply changing their documentation.
>>>    <https://support.apple.com/en-ie/102515>
>>
>> Ok, finally. The crux of the issue.
> 
> It's not hidden.
> It is, after all, in the SUBJECT line of this thread, Carlos.
> 
> Every person who tried it, found out every single statement to be true.

It is good Usenet manners to explain the subject in the body.

-- 
Cheers, Carlos.
ES🇪🇸, EU🇪🇺;

[toc] | [prev] | [next] | [standalone]


#197986

FromMaria Sophia <mariasophia@comprehension.com>
Date2026-09-08 06:38 +0300
Message-ID<117nvvq$2j14$1@nnrp.usenet.blueworldhosting.com>
In reply to#197982
Carlos E.R. wrote:
> Keith Thompson argues that your post is off topic in comp.lang.python, 
> because you are not discussing python code. You simply posted a link 
> that contains a reference to a Python program and said you run it. You 
> are not discussing the code itself or making any question about it.
> 
> And he is right, IMNSHO.

People can't understand what the issue is if they don't understand the
breadcrumb trail from your router access point to my Win10 python runs.

They just can't. 
Their stone-age knowledge of networking doesn't prepare them for it.

Keith didn't understand that you have to run the python code that was
pointed to in the very first post, Carlos, which Jon found easily.

The instant I read the paper, I found and ran the Python code on Win10.
Why can Jon and I do it, but Keith complains he can't read the paper?

BTW, Keith can whine all he wants that Python code isn't python code.
But it's clear he's just whining about something he didn't even read.

>> More to the point, I don't bring the paintings on my wall with me when I
>> move, but that doesn't mean that nobody brings their paintings with them.
>> 
> 
> I did not say "nobody". That's you reading what is not in what I said.

Jesus Christ, Carlos. Have you never once taken a course in basic logic?

Because you don't own a red car, you claim (in effect) red cars can't
exist. Your entire rebuttal consist of that? WTF? It's ridiculous.

For some odd reason, your claim that because you do it one way, that you
think that refutes the fact that BILLIONS of people do it differently.

I wouldn't mind if you made that preposterous argument only once, as I'd
only need to point out your nonsensical bizarre point of view only once.

But you've been foisting that grotesque farcical rebuttal on us since we
started investigating this issue, oh, since way back in December 2026.

When will you stop proposing that absurd rebuttal that the fact you don't
own a red car, you think, negates the fact that billions of other people
can own red cars?

>> The fact you get your access point from the ISP, while true, is an absurd
>> way of your attempt to refute the facts proposed in this respected paper.
> 
> I don't refute anything, except that you can only track a minority of 
> users worldwide.

Clearly you did not read the paper. Read it Carlos. 

 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

Do not respond until you've shown you read the paper, please.


>> The fact that's your major rebuttal indicates you haven't read the paper.
>> Read it. Please.
> 
> No.

If someone hasn't read the paper, they can't possibly understand the issue.


 *Surveilling the Masses with Wi-Fi-Based Positioning Systems*
 <https://arxiv.org/abs/2405.14975>

>> Every person who tried it, found out every single statement to be true.
> 
> It is good Usenet manners to explain the subject in the body.

The subject says:
 a. Apple changed their documentation 
 b. at my request 
 c. but it proves they don't care about privacy

Since we provided the old documentation in the past, those trolls (like
Winston) who said there's no "proof", were simply trolling us, as they
didn't even read to know it never said that until after I contacted them.

At my request, would be hard for anyone here to verify, although the time
points all line up, as you all know I complained about this back in
December, and I stated then, that I had my neighbor file the RADAR report.

I also stated at that time, they removed my hidden BSSID, but I'm likely
the only one in the world who has had that favor (as far as we would know).

The part about privacy is harder for people on this group to comprehend
since they're all seemingly stuck in the stone age of wireless networking.

They don't know how to follow the BSSID/GPS breadcrumb trail from an iOS or
Android device (as it's very different!) to the Apple or Google database
(as that's different too!) and eventually to the Python code that Keith
says doesn't exist but which both Jon and I dutifully ran to confirm.

To put it bluntly, everyone but Apple will NOT distribute your BSSID if
it's hidden broadcast. Only Apple refuses to abide by that convention.

[toc] | [prev] | [next] | [standalone]


Page 1 of 5  [1] 2 3 4 5  Next page →

Back to top | Article view | comp.lang.python


csiph-web