Skip to content

Comment on Apple: Android is a tracking device [pdf]

Comments

All smartphones are. There's only so much you can do to cover your track. There's most likely always someone knowing where you are if your phone is powered on (or even powered off with Apple Find My network).

https://9to5mac.com/2021/06/07/ios-15-find-my-network-can-fi...

Forget about all the app and OS, maybe they're clean and maybe not.

There's also the cell layer, which constantly negotiates with cell towers for sector and power as normal idling. So they know your location at least to tower (CGI), sector and delay (CGITA) and sometimes trilaterated (UTDOA) from ~1000m down to 10m accuracy. The towers' base station controllers need to keep logs anyway, so the cell company has records of your rough location.

Then there's bluetooth, wifi, audio beacons, optical, magnetic and inertial nav, all emitting or recieving you move through the world. None of this requires GPS, some requires app participation, some doesn't.

All phones are location and surveillance devices. Leave it home if you're serious.

The positive side to tracking and a cell layer anecdote - cell layer forensics are often utilized in search and rescue contexts. I have seen this data accessed (through legal procedure in the US) and utilized to save lives of the missing and to provide closure to the families/friends of the missing.

On the flipside e.g. in Germany this has been used to track down creators of illegal graffiti, using a law that is intended for terrorism and other heavy crimes. We can allow search and rescue missions without having to also accept abuse of power.

All this and the parent comment means is that any tool that is useful, is equally useful for good or bad. It is yet another example showing how it's wrong to address something bad by attacking the tool used to do it.

Can you reference anywhere where that happened because I've never heard of that and would expect huge pushback in Europe in general..

I think I found the talk I got most of the info from [0]. The interesting parts about the law and how it was abused start roughly at 25:03, though unfortunately it's only available in German (Edit: turns out it actually does have an English audio track).

A very short summary: the law is only supposed to be used for very severe crimes and only if the investigation would otherwise be significantly more difficult or impossible. Also the owners of the tracked phones have to be notified of the tracking as it is a violation of the person's rights. In reality (at the date of the talk) it had never been used for terrorism, about 5% of the time for crimes like murder and in over 70% of the time for theft (including a case of stolen empty beer barrels), and nobody was ever notified.

[0] https://media.ccc.de/v/35c3-9972-funkzellenabfrage_die_allta...

Thank you, those stats of the usage seem fine on paper, maybe worse than they should be, I'm still waiting to see what parent was talking about when he inferred abuse..

Europe does need a security authority, that doesn't depend on slow bureaucracy.

would expect huge pushback in Europe in general..

In general those things are not made public so that you don't have pushbacks.

And when the SIM card will be gone, isn’t it gone already in USA for iPhones, you won’t even have the ability to remove that SIM. And you can be tracked all the time. Because we are already there - your phone is switched of but not really switched off.

My understanding is that modern phones still connect to cell towers without a SIM card in the device to allow for emergency calls.

Find My doesn’t actually map the device to an individual. Someone might know where the device which is currently broadcasting an ID is, but that ID rotates frequently, and can only be resolved to you using keys held against your Apple ID. The entire thing is specifically designed such that objects being tracked by Find My can’t be resolved to individuals, because the network depends upon publicly broadcasting those object’s IDs via Bluetooth.

Yeah, the GPS location (of the finder device) is encrypted using the ID as encryption key before uploading to Apples servers, so unless the owner of the device actually looks for it, Apple doesn't even know who the encrypted blob they can't read belongs to.

It would be nice if the code on the device and server could be independently viewed and verified. Otherwise we need to trust the biggest corporation in the world. There are reasons why governments of the second and third great powers in the world, China and Russia, have banned Iphones for government use.

Can ID be mapped to IMEI and by extension SIM or mobile number? If yes, then it can be resolved to individuals.

It can not.

The master private key used by the system is generated locally and never leaves your Apple devices in a state that anyone except your devices can read it.

The master key is used to derive an AirTag specific private key which is provisioned to the AirTag and is in turn combined with an increasing counter which generates a third private key that's never stored anywhere. The ID broadcast is the public key of this third key. It changes every 30 minutes or 1 hour, I forget which.

Other devices see this key, use it to encrypt their own location, and upload that encrypted blob along with the public key to Find My, and in order for Apple to even know which account the encrypted blob they can't decrypt belongs to I have to actually request the location of my AirTag by locally deriving the keypair it used for a certain point in time.

No, the "Find My" identifiers cannot be mapped to an IMEI except by the user to whose account the device is registered.

Find My does not leak user or device location to Apple or other users. The greatest info leak is “there is a find my device near me”.

The greatest info leak is “there is a find my device near me”.

Which is anonymous and the identity changes every 30 minutes or an hour, I forget which.

Talk about a false equivalency. One has spying built into the business model itself. The other does not.

The thing about business models is they are in never-ending flux, always shifting, optimizing, and re-optomizing seeking the most profitable model(s).

If you have some business model either coincidentally or intentionally in alignment of consumer privacy, you're going to see marketing said alignment so long as it's a potential selling point (if it's not, it wont be advertised unless you can spin it).

It doesn't mean anything though. It doesn't mean that either or any business has your interests in mind. Apple executives do not care about your privacy, no matter what narrative they weave. Apple probably banked on older ideals of consumer privacy and didn't anticipate businesses that disregarded user privacy and found ways of making money out of that process would be so successful. They were behind the curve and found a way to spin the narrative that the reality is they're just here to protect consumers all along.

Perhaps they took a risk that differentiating on privacy would be more profitable years ago and are pushing it more now there's real consumer talk (a wise risk path IMHO). No matter what, it's all profit driven. At this point there could be a bit of a sunk cost fallacy and it would be pretty awkward for them to shift but that doesn't mean they won't . Consumers have shown by and large they just don't care about privacy or at least are willing to sacrifice it for other things. That's bad for Apple (and bad for consumers frankly, IMHO).

I don't buy these narratives from any business propaganda machine and you shouldn't either. When push comes to shove, if Apple is down and forced to compete and privacy protection isn't profitable or they're not in a position to explore an alternative truly competitive position, they will jump ship in an instant and mimic the rest of industry.

The only thing keeping these models at bay are a distribution of consumers that keep the competing models afloat. If Apple caves we'd rapidly go down the lack of privacy hole of spying functions until we reach legal protections. If Android caves, we'll see Apples continued model for awhile until the insatiable demand for revenue growth starts looking at initial principles like privacy as the last remaining revenue streams then we'll slowly start back with 2000s era advertising back to current and future dystopian levels of privacy invasion. The difference is just a time factor here, so long as large enough segments of the consumer market will cave to these ideals (which has already been proven).

I suppose some business could just add a line item "privacy tax" that you just pay for depending on the valuation of your privacy so to keep your privacy you clearly pay that tax so the business continues to get its expected revenue growth from said privacy invasion without actually invading your privacy. To some degree this is already baked into higher costs for many Apple products but as markets optimize I anticipate we'll eventually get to such a point, just like we have ad-free and ad-infested service options.

Maybe I don't understand your point, but isn't this similarly false equivalency? The business models are for-profit and subject to change. But despite that, right now, there is a material difference in privacy.

Also I think it a bit humorous - "privacy tax" to me is when services like Google offer services at a cost to my privacy.

The thing about business models is they are in never-ending flux, always shifting, optimizing, and re-optomizing seeking the most profitable model(s).

Googles hasn't since the start. It's ads. Which leads to abuse and spying.

All smartphones are.

My Librem 5 isn't.

Your carrier can follow your location by triangulating your position from your SIM ID.

Only if the modem hardware kill switch is on. I can always make sure I'm not tracked whenever I need it.

plus as anyone doing navigation with these open source phones knows, 3gpp location is embarrassingly low resolution without a supplemental source like WiFi SSID visibility, which has to be measured client-side. plus cell networks are asymmetric (SNR is higher from tower -> cell than from cell -> tower) so all else equal triangulation on the tower side should be even lower resolution.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.