USD
41.24 UAH ▼0.28%
EUR
43.47 UAH ▼2.52%
GBP
52.24 UAH ▼2.55%
PLN
10.02 UAH ▼2.9%
CZK
1.72 UAH ▼2.62%
American researchers are convinced that WPS Apple can be monitored even by peopl...

Under threat of the Armed Forces: Apple Wi-Fi technology allows you to track people around the world

American researchers are convinced that WPS Apple can be monitored even by people who do not use Apple devices. This threatens the Ukrainian military who use Starlink terminals. Scientists at the University of Maryland (USA) have conducted research and concluded that using Wi-Fi-based positioning systems can be monitored by people and any objects, reports The Register.

Postgraduate Student Eric Paradise and Dave Levin of Maryland University in their scientific article described how WPS Apple facilitates even those who do not use Apple devices. For example, people who do not have Apple gadgets can have a access point in WPS Apple, just if Apple's devices are in the Wi-Fi area, researchers explained.

Apple is one of several companies, along with Google, Skyhook and others, which uses WPS standard (Wi-Fi Protected Setup, WPS-a standard of semi-automatic creation of Wi-Fi wireless network, created by Wi-Fi Alliance,-ed. ). It offers customer devices an effective way to determine location than using a global positioning system (GPS). WPS also consumes less energy than GPS that makes it popular.

Mobile devices that use GPS to determine the location are transmitted with Mac addresses and Wi-Fi access points, which are identifiers of base services (BSSID). After that, other GPS mobile devices can receive location data by asking WPS service. Devices' requests include sending a list of closest BSSID and their level of their signal in WPS.

WPS usually reacts in one of two ways: either it calculates the client's position and returns these coordinates, or returns the geolocation of the BSSID sent (which are related to access equipment) and enables the client device to perform calculations to determine the location. Google's WPS reacts the first way and WPS from Apple is second. However, according to scientists, the Apple system is "exceptionally talkative".

"In addition to the BSSID geolocation sent by the client, API Apple promptly returns the geolocation of several hundred BSSIDs, which are near the quoted geolocation," the article reads. Eric Rai explained The Register that WPS Google and Apple operates fundamentally differently and that Apple has been opened with openness. "In the case of Apple, you send BSSID for geolocation, and it returns a geolocation in which, in her opinion, there is BSSID," Paradise said.

- "Standard also returns up to 400 geolocations that were not requested and which are nearby. These additional data have allowed us to accumulate a large number of geolocated BSSID in a short period of time. In addition can be used for free. " According to him, WPS Google simply returns the calculated location and is authenticated, has a speed limit and is paid, which makes it impossible to conduct research of this kind.

The design of the Apple system has made it possible to collect a database of 490 million BSSIDs around the world, which they could then use to track the movement of individuals and groups of people for some time. According to the researchers, it is quite possible to use the methods described in the article to determine the personality of individuals or groups of people, to obtain data such as names, residence addresses, places of work and training, military units, etc.

The document considers various scenarios that provide the use of location data obtained from the collection of BSSID from tourist routers GL. INET and Starlink terminals. The last scenario is a threat to the Ukrainian military who actively use Starlink on the front and in the rear. Researchers say that Apple, Starlink and GL.

INET have reported their findings, and indicate that you can make it impossible to get BSSID's use of WPS databases by adding _nomap string to the Wi-Fi Access Point Name, or to SSID. SSID is installed by the user and BSSID is the ID ID (SSID is the symbolic name of Wi-Fi's wireless access point, which serves to identify it among other points by users or devices that connect to the network. SSID is a line up to 32 bytes in size broadly in the air - ed. ).

Apple added _Nomap support in the update of March 27, 2024 on the reference page of its privacy services and location. WPS and WIGLE from Google Support _Nomap since 2016. The publication reported that the iPhone offers additional measures to prevent the described tracking. The SpaceX Product Security Team introduced BSSID randomization into its products in 2023. GL-ETE, a manufacturer of road routers, said it did not plan to deploy BSSID randomization.

BSSID randomization is the most reliable protection against WPS tracking, since the generation of a random ID every time the device is loaded (or moves the location) will make it look like a completely different device in WPS. BSSID randomization in Wi-Fi standard has not yet been implemented, but scientists hope that their research is prompting IEEE technical experts to deal with this question how they did. with randomization of MAC address in the past.