cross-posted from: https://infosec.pub/post/51680197
Append “
_nomap” to the end of your SSIDs to instruct Google not to use your wi-fi access point for their mapping services.
To do the same for Apple, add “_optout” to the end of your SSIDs¹.To boycott both, the rumor is that Google’s “
_nomap” must be last, but Apple’s “_optout” flag must be in the penultimate position if and only if Google’s token is at the end. So you might have an SSID like “boycottCloudflare_optout_nomap” to boycott the baddies, for example. But note that “boycottCloudflare” is merely symbolic, to raise awareness of the web’s most harmful enshitifier.¹ sorry to say I have no reference to cite for the Apple rules. It’s just a rumor.
update
The Apple opt-out procedure has apparently changed to align with Google. Someone refers to this page for Apple.
update 2
Mapquest is suddenly gaining popularity.
19 Comments
markz@suppo.fi · 56 pts · 2d
What a spectacularly shit opt-out system.
Lemmchen@feddit.org · 12 pts · 2d
Microsoft: https://account.microsoft.com/privacy/location-services-opt-out
ZC3rr0r@piefed.ca · 10 pts · 2d
For once, Microsoft actually has the more sensible approach. I don't love having the self-report your MAC address for several reasons, but to add some arbitrary nonsense to your SSID (which is intended to help identify the networks you are broadcasting) is somehow worse.
brackled@lemmy.world · 50 pts · 2d
It is such bullshit that this is even opt out. The level of non-consensual data gathering is infuriating and disappointing.
einkorn@feddit.org · 12 pts · 2d
On the one hand I can understand it. Default wireless settings amount to your router screaming "I AM HERE, YOU CONNECTIONLESS IDIOTS" down the whole street. Simply writing this information down that is constantly broadcasted by your device is not an inherently bad thing to do.
But yes, connecting all these hundreds of dots across multiple devices, systems and whatnot is where it gets terrifying. Just like HTTP, WLAN protocols have not been developed with security as a top priority. They are simply not made to protect from tech-surveillance companies. They are meant as utilities for everyone to share freely.
Davel23@fedia.io · 5 pts · 2d
You're not wrong, but in this one instance you're not entirely right, either. If your SSID is set to broadcast then you're sending it out there for anyone to see and use however they see fit. You're basically opting in by that alone. The fact that most WIFI routers are set to broadcast by default and most users have no idea how to change it is another argument entirely.
daveyOsborn@infosec.pub · 10 pts · 2d
Apple seems to say hiding your SSID will not protect you:
So IIUC, if you hide your SSID and an Apple spy (read: normal iOS user) connects to it, their device will ignore the
_nomaptoken and report your AP to the mothership. And note as well that a hidden SSID only makes your AP invisible in the absence of traffic. iOS devices can probably see and process traffic that happens to be in motion when they are in range.undu@discuss.tchncs.de · 5 pts · 2d
If a SSID is set to hidden, clients in that network will broadcast the name of the network, so it's usually not hidden at all. I don't buy the argument that broadcasting the SSID means to allow opting in to anything.
https://wifi.report/blog/hidden-ssids-security-myth-vs-reality.html
henfredemars@infosec.pub · 4 pts · 1d
I’m glad that opting out is available, but there is no practical, technical enforcement. Who is to say that they don’t collect the data anyway? Google is exactly the type of business to ask for forgiveness.
daveyOsborn@infosec.pub · 1 pts · 21h
What sort of technologically-enforced mechanism might you envision that does not rely on legal enforcement?
Lately I practice the only tech-enforced option I know of: wholly pull the plug on wi-fi. Indeed, this means I only have ethernet in my house and wifi radios are disabled. It also means for my smartphone to reach the cloud, I am reverse tethering over USB. Try getting a crowd of people to do that. I will praise you if you can get 10 people to do that.
There is such a thing as bluetooth routers. So a middle ground would be to pull the plug on wi-fi and use bluetooth instead. Though it’s a compromise because we cannot¹ be certain that Google does not also harvest bluetooth. But at least the limited range would mean fewer cases where the signal reaches the street. Of course you would have to be okay with the slower speed.
If Google violates their own policy, it’s legally actionable. So if you are going to run wi-fi you can do your part in helping grow the legal liability that Google has signed up for.
¹ well strictly speaking, we might know from the location data whether Google uses bluetooth. But if it’s not part of the location data it would not be an absolute indicator that it’s not collected.
noxypaws@pawb.social · 3 pts · 2d
apologies for my repeated comment here from your other post, but your info for Apple seems wrong. This support article says it uses "_nomap" just like Google says:
https://support.apple.com/en-us/102515
daveyOsborn@infosec.pub · 2 pts · 2d
Glad to hear Apple has aligned with Google on that.
noxypaws@pawb.social · 2 pts · 2d
me too! from your post I added an SSID to my APs with _nomap suffixed. which might not be sufficient, admittedly, it's not clear if any SSID without it will be used, or if an "opted out" SSID with the same hardware ID as an SSID without the prefix will also cause non-"opted out" SSIDs to be disregarded as well
daveyOsborn@infosec.pub · 3 pts · 2d
What I would expect to happen is when an AOS or iOS device falls in your range in the future, it will not report the AP to the mothership. But the motherships will still remember the history and perhaps be able to continue exploiting it. To have more certainty, I would change the MAC address on the AP if it lets you, and perhaps also change the prefix of the SSID for good measure. If your AP gives no means for changing the MAC, you could investigate replacing the firmware with openwrt -- but probably not worth the effort just to change the MAC.
When I setup an AP, I chose the same SSID as a neighbor but then added the suffix for fun.. to confuse things. Then they changed their SSID (perhaps in fear that something dodgy was going on).
A_norny_mousse@piefed.zip · 1 pts · 1d
Surely this only applies to devices logged into a Google account? (as Android phones must be these days I believe)
What about LineageOS, Graphene etc.?
daveyOsborn@infosec.pub · 4 pts · 1d
It has nothing to do with your phone. If you have wi-fi at home and the wireless signal reaches the road, then it’s relevant.
A_norny_mousse@piefed.zip · 1 pts · 16h
So it's independent of any Google account, they can just use any wifi access point to - do what exactly? Not sure I understand this at all.
daveyOsborn@infosec.pub · 1 pts · 15h
I lost the link but the research was done by: Douglas J. Leith, School of Computer Science & Statistics, Trinity College Dublin, Ireland, 25th March, 2021 in a paper titled “Mobile Handset Privacy: Measuring The Data iOS and Android Send to Apple And Google”.
Every Android device owner is a Google spy. Every iOS device owner is an Apple spy. They don’t know it, generally. Android and iOS devices
constantly¹ harvest the radio data of their surroundings and they send the data home to their respective mothership. This is hard-wired into the platforms and has nothing todo with accounts. An arbitrary person randomly walks/drives by your house with their iPhone or android powered on, and it collects your SSID, MAC, GPS position, etc and sends it to Google or Apple, unwittingly, because people are oblivious as to what’s going on.¹ The phone user may need to have location services enabled for the phoning-home to occur.. not sure if turning on location services enables the data sharing in both directions or just one. Guess I need to re-read the research.
A_norny_mousse@piefed.zip · 1 pts · 14h
Thanks for explaining.