Avatar

GamingChairModel

GamingChairModel@lemmy.world
Joined
2 posts • 359 comments
Direct message

Apple’s got one, so does Google, and Microsoft.

They’ve got beacon location data, yes, but Apple is the only one that gives up that information without first conforming that the query is coming from someone who sees that BSSID. As OP notes:

In this respect, Apple’s Wi-Fi database also differs fundamentally from other Wi-Fi databases, such as the one operated by Google.

If you click through to the paper, it describes 2 approaches for using BSSIDs to identify location:

  1. Client submits a query listing each BSSID and its signal strength, and the server calculates position and returns where it believes the query is coming from.
  2. Client submits a query listing each BSSID it’s interested in, and the server responds with the location of each BSSID so that the client can calculate its own position.

See the problem there? Approach 2 gives more raw information away, by outsourcing the positioning calculation to untrusted clients.

And the paper outlines how Apple goes even further than that:

Apple’s Wi-Fi geolocation API [4] works in the latter manner, but with an added twist: In addition to the geolocations of the BSSIDs the client submits, Apple’s API opportunistically returns the geolocations of up to several hundred more BSSIDs nearby the one requested. These unrequested BSSID geolocations are presumably then cached by the client, which no longer needs to request the locations of the nearby BSSIDs it may soon encounter, e.g., as the user walks down a city street.

It goes on later:

Apple’s WPS API is free and places few restrictions on its use. It requires neither an API key, authentication, nor an Apple device; our measurement software is written in Go and runs on Linux. Moreover, Apple appears to make no attempt to filter physically impossible queries. The BSSIDs submitted to the WPS need not be physically proximate to each other nor to the device submitting the query; Apple’s WPS will respond with geolocations for BSSIDs on two different continents in the same request to a querier on a third.

That’s the discussion here. Apple keeps a large database, like many other big tech/mapping firms, but does nothing to keep that database hard for strangers to scrape in bulk.

In contrast, Google uses the first approach and keeps the information a bit more restricted by performing the location calculation at the server:

Han et al. reverse-engineered Google’s WPS’s method of operation [17]. Google’s WPS functions differently than Skyhook’s and Apple’s insofar as Google’s service attempts to geolocate the device submitting the query, providing it with only the device’s computed position given a list of BSSIDs from the client.

So it’s possible to run this type of service with this type of database, without sharing BSSID locations with anyone else who asks.

permalink
report
parent
reply

My kids have a book called “solitary animals,” explicitly framed as introverts in nature, and from what I remember of it, it mentions pumas, octopuses, sloths, and eagles.

permalink
report
reply

I don’t think that site would be problematic. After all, we’re just talking about custom interfaces to analyze public data.

A big part of the solution is that users should have an awareness that their activity is public. Every once in a while someone gets burned not knowing that anyone can view what a specific Twitter user or Instagram user liked (like politicians liking risque thirst trap photos).

Another is easy alts and throwaways, with tips to avoid correlations:

  • Don’t use the same verified email address
  • Don’t reuse usernames, including across platforms
  • Try not to use the same instances, such that instance admins can see whether login activity is coming from the same place, unless you absolutely trust that the admins won’t analyze your data OR inadvertently leak their records.
  • Be aware of the techniques used to correlate users: analysis of timestamps, linguistic/grammatical quirks, etc.

This is a public place, so people should be aware that this is a public place. That means they can still find this useful space, as with many other public places, but should be aware that the more they do on this platform, the easier it is to correlate with a real life identity.

permalink
report
reply

Generates a realistic-looking scene that didn’t actually occur

Doesn’t this describe, like, every mainstream live action film or television show?

permalink
report
parent
reply

Even before that, Apple owes its very existence to an acquisition. Acquiring Next allowed them to abandon their dying OS and start anew with OS X, and brought back in founder Steve Jobs (who Apple had previously fired). With Steve Jobs at the helm, they made the computers cool again to buy some time before the iPod completely turned the company around.

permalink
report
parent
reply

Put another way, this means that a malicious coffee shop or hotel can eavesdrop on all VPN traffic on their network. That’s a really big fucking deal.

permalink
report
parent
reply

I’m glad that The Atlantic is covering this issue. Nothing groundbreaking here for anyone who follows these issues, but the Atlantic’s audience overlaps a lot with actual policymakers and their staffs. The tech companies don’t want to be regulated by the government, so coverage by these types of publications may be a good starting point for reform (whether voluntary or regulated).

permalink
report
reply

The agency’s manager sent me a background memo about the woman I’d be playing, a purported 21-year-old university student blessed with physical proportions that are in vogue these days.

In vogue these days? That just reminds me of how every generation thinks they invented sex. Or the Simpsons quote where Mr. Burns describes a past encounter: “We expressed our love physically, as was the style at the time.”

permalink
report
reply

I disagree with your premise. The 111th Congress got a lot done. Here’s a list of major legislation.

  • Lily Ledbetter Act made it easier to recover for employment discrimination, and explicitly overruled a Supreme Court case making it harder to recover back pay.
  • The ARRA was a huge relief bill for the financial crisis, one of the largest bills of all time.
  • The Credit CARD Act changed a bunch of consumer protection for credit card borrowers.
  • Dodd Frank was groundbreaking, the biggest financial reform bill since probably the Great Depression, and created the Consumer Finance Protection Bureau, probably one of the most important pro-consumer agencies in the federal government today.
  • School lunch reforms (why the right now hates Michelle Obama)
  • Children’s Health Insurance Program (CHIP or SCHIP): healthcare coverage, independent of Obamacare, for all children under 18.
  • Obamacare itself, which also includes comprehensive student loan reform too.

That’s a big accomplishment list for 2 years, plus some smaller accomplishments like some tobacco reform, some other reforms relating to different agencies and programs.

Plus that doesn’t include the administrative regulations and decisions the administrative agencies passed (things like Net Neutrality), even though those generally only last as long as the next president would want to keep them (see, again, Net Neutrality).

permalink
report
reply

Our heads are just loaded with sensory capabilities that are more than just the two eyes. Our proprioception, balance, and mental mapping allows us to move our heads around and take in visual data from almost any direction at a glance, and then internally model that three dimensional space as the universe around us. Meanwhile, our ears can process direction finding for sounds and synthesize that information with our visual processing.

Meanwhile, the tactile feedback of the steering wheel, vibration of the actual car (felt by the body and heard by the ears), give us plenty of sensory information for understanding our speed, acceleration, and the mechanical condition of the car. The squeal of tires, the screech of brakes, and the indicators on our dash are all part of the information we use to understand how we’re driving.

Much of it is trained through experience. But the fact is, I can tell when I have a flat tire or when I’m hydroplaning even if I can’t see the tires. I can feel inclines or declines that affect my speed or lateral movement even when there aren’t easy visual indicators, like at night.

permalink
report
parent
reply