Originally Posted By: wfaulk
What kind of information do you think could possibly be gleaned from that data? There's nothing that identifies anything about you in your MAC address and SSID (unless you specifically put personal information in your SSID). It's merely being used as a beacon. That said, if you're really that concerned about it, stop transmitting radio waves into public areas.


That's not my point, actually. My point is that pieces of info I created locally for my personal local use - my SSID - is being sent over to some other organization who uses it to provide a service to me. This is perfectly fine with me, and possibly a great idea, provided I am told before, and I agree in doing this (which I would do, in this case). Instead, i don't seem to see any sort of information sheet, or clear disclaimer anywhere, in my iPad2, that tells me this.

Also, the fact that my SSID is being bradcasted locally, within the range of my WAPs, is not a good justification to send that info via the internet to somebody else, as that is not my intended use of that piece of info.

The issue I personally see here is not technical, but rather ethical. And legal as well.

The fact that, as usual, the legal system is lagging behind tech development and failing to understand it is in this and all similar privacy-related cases proving a de facto privacy risk for people. If Apple can take the SSID and use it without asking the consumer (which, pratically means whitout a **very** significant liability risk for Apple), then why can't Apple get the brand and model of my router for marketing research, which is still pretty ok, or for profiling, which is possibly less ok depending on what type of profiling, or my firmware version to find out if I am vulnerable to this or that bug / backdoor, or what not?

Again, I am using Apple as an example. I don't intend to make this a brand-centered discussion. I am talking in general.

Here in Italy we've had some scaldals related to phone companies working for secret services gathering a lot of intel from citizens' phone calls and ip traffic without any legal justifications, and they got away with the IP-related part because actually no law existed to make that type of "tapping" actually illegal. Not that a law can prevent this type of abuse completely but at least I would make it clearly illegal.
_________________________
= Taym =
MK2a #040103216 * 100Gb *All/Colors* Radio * 3.0a11 * Hijack = taympeg