evacide,
@evacide@hachyderm.io avatar

"Three years ago, Apple introduced a privacy-enhancing feature that hid the Wi-Fi address of iPhones and iPads when they joined a network. On Wednesday, the world learned that the feature has never worked as advertised."

https://arstechnica.com/security/2023/10/iphone-privacy-feature-hiding-wi-fi-macs-has-failed-to-work-for-3-years/

KraftTea,
@KraftTea@mastodon.social avatar

@evacide Reminds me of all those users on BlueSky, who somehow are oblivious that everything they post is completely open to anyone on the internet, whether it is locked or not...
https://mastodon.social/@badlogic@mastodon.gamedev.place/111246798273691553

vamp07,

@evacide This stuff is complicated. At least it got fixed eventually. It has been working since release except for more sophisticated packet sniffer. I'm not making excuses for Apple but bugs are bugs. What's important is that they get fixed when found and that happened.

dan,

@evacide I feel like that article is a little more provocative than it needed to be. “Apple hasn’t explained how a failure as basic as this one escaped notice for so long. “ - probably the same reason why it’s taken so long for anyone else to notice. It did work at the basic level of tracking through dhcp requests which was the primary vector. Wasn’t completely useless 😅

retiolus,
@retiolus@mamot.fr avatar
spla,
@spla@mastodont.cat avatar

@retiolus és curiós que ningú ho hagi descobert fins que la pròpia Apple ha alliberat l'actualització que ho soluciona.

retiolus,
@retiolus@mamot.fr avatar

@spla és "igual" que s'hagués "descobert" o no... el cas és que els aparells no eren anònims com Apple assegurava. Bàsicament, pagar per una funcionalitat inexistent i seguir sent rastrejat com tothom.

spla, (edited )
@spla@mastodont.cat avatar

@retiolus no hi ha evidències que s'hagi "rastrejat" cap dispositiu ja que ningú ho sabia fins que Apple ha aplicat l'actualització. Si Apple no hagués dit res cap mitjà hauria publicat "Apple enganya als seus usuaris".Parlar malament d'Apple genera visites...

retiolus,
@retiolus@mamot.fr avatar

@spla no cal que hi hagi evidències? El wifi públic que ja rastrejava per raons comercials els parells connectats a la seva xarxa doncs... ho haurà seguit fent?

I "no hi ha evidències" fins que es faci públic que durant 3 anys tal empresa o tal govern ho ha utilitzat. El que passa sempre bàsicament 😂

janxdevil,
@janxdevil@sfba.social avatar

@evacide Oh FFS, they were using the HW identifier in mDNS advertisements? That makes me extremely sad.

traumaphoenix,
@traumaphoenix@chaos.social avatar

@evacide oh that’s less impactful than i thought

if the feature that rotates the identifier when the device is unassociated and scanning for networks didn’t work, i’d actually be scared 🦋

gabehcuod,
@gabehcuod@ioc.exchange avatar

@evacide Shocker...I wouldn't be surprised if there are more Apple "privacy features" that have never worked as advertised.

ahltorp,
@ahltorp@mastodon.nu avatar

@evacide “From the get-go, this feature was useless because of this bug,”

This is incorrect.

“never worked as advertised” is correct, though. Passive MAC address snooping was prevented, but information was leaked when you connected to a network.

ahltorp,
@ahltorp@mastodon.nu avatar

@evacide ”In 2013, a researcher unveiled a proof-of-concept device that logged the MAC of all devices it came into contact with.”

This seems to refer to a Black Hat 2013 demonstration in the summer of 2013. We had already exhibited an artwork doing this at Art Hack Day in Stockholm in the spring, and we probably weren’t the first ones.

cuteprince,
@cuteprince@mastodon.social avatar

@evacide open source >>>> walled gardens

lobster2,

@evacide

Dear friends and fiends of privacy,
As we know Apple are liars and can not be trusted. Sad but true. Just like facebook and Google, Hex-twitter and mis-governments etc. they have turned us into data to be sold the latest set of 'Billionaires are your friends', 'War is for your welfare' and other ownership lies. They have failed. They are not fit to wank, swank or shank ... :ablobcatwave:

There are solutions, here is one in its early stages. :blobheart:
https://veilid.com/

Remember the lobster principles of :

  • Be Open about your closets
  • Breathe Garlic (good for vampires)
  • Be the revolting you want to sear
  • Be , and a menace

In the words of The Prisoner, Joseph Pat McGoohan, 'I'm not a number, I am a free lobster'

Have a great day everyone. Save the world if you can-can. Support the screaming if you are able. Join the silent, that will not be silenced And stay sane (if possible) It's a crazy .

matinmollapur,

@evacide awesome article

satyam,
@satyam@mastodon.online avatar

@evacide glad it’s finally fixed 🤞

theBurn,
@theBurn@mastodon.social avatar

@evacide @kuketzblog maybe relevant for your blog as well?

thumbone,

MAC Spoofing is a pain anyhow and killed effective MAC based access to a LAN.

Powerfromspace1,
@Powerfromspace1@mstdn.social avatar

@evacide hello are you listening opportunities comes a knocking

daniel,

@evacide I would see this on my iDevices and always thought it seemed too good to be true!

Galletasalada,

@evacide lol how did nobody find this before

reconbot,
@reconbot@toot.cafe avatar

@evacide at least it wasn't so obvious that pre-existing stalking tech would have kept working

martinicat,
@martinicat@mastodon.social avatar

@evacide Well, at least “in the last 7 days Safari has prevented 71 trackers from profiling me” 🍸😹 And they fixed the MAC address disclosure?🍸😺

swetland,
@swetland@chaos.social avatar

@evacide That is just kind of embarrassing.

I mean I can absolutely see how it could happen -- the decision of what MAC to stuff in the source address could easily come from a slightly different path than the information stuffed in the discovery packet, etc.

But you'd also think for a Serious Security/Privacy Feature, one might do a bit more extensive testing, and just observing beacon/discovery/arp/etc traffic to see if all is well would be a pretty reasonable thing.

hod,

@evacide believe at your own peril

nateb,

@evacide I'm not one of those hyper Apple hater types, but it's getting pretty exhausting seeing that so much of their alleged privacy-preserving innovations have turned out to be cosmetic theater. App labels, the "do not track" toggle, now this. /sigh

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • ngwrru68w68
  • rosin
  • GTA5RPClips
  • osvaldo12
  • love
  • Youngstown
  • slotface
  • khanakhh
  • everett
  • kavyap
  • mdbf
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • anitta
  • InstantRegret
  • normalnudes
  • tacticalgear
  • cubers
  • ethstaker
  • modclub
  • cisconetworking
  • Durango
  • provamag3
  • tester
  • Leos
  • megavids
  • JUstTest
  • All magazines