cross-posted from: https://infosec.pub/post/50218987

Karcher DAB radios are broadcasting an SSID for open Wi-Fi access. It doubles as an Internet radio, but AFAICT from the manual it’s only expected to act as a client.

So WTF is going on?

It seems like a really bad idea for consumers to connect this radio to their LANs to use to play Internet radio and podcasts when there is an always available Wi-Fi AP that enables anyone in proxity to connect to the radio. What’s the point? There is no way to disable the SSID broadcasting and it remains on even when the radio is “off” (but plugged in).

The manual shows that there is a remote control. Is the remote using wi-fi? I don’t have the remote so I have no way of verifying. In any case, this design seems like a recipe for disaster. Karcher should perhaps just stick to making pressure washers.

Google and Apple use Wi-Fi SSIDs for navigation. I boycott both companies. As such, I prefer not to have any wi-fi APs. And when I decide to run an AP, I ensure the SSID ends in _optout_nomap to opt-out of giving uncompensated help to the nav systems of Apple and Google.

Does this violate the GDPR? I cannot change the SSID, so it’s like I am being forced to share with the general public the fact that there is a Karcher radio in my home. That does not respect data minimisation.

  • Corporal_Punishment@feddit.uk
    link
    fedilink
    English
    arrow-up
    2
    ·
    16 days ago

    You’re making lots of assumptions and leaps about Google. Like anyone else all they can do is map SSID to a general locality. They still dont know who you are based on that single piece of information.

    The question is - is an SSID personal data.

    No. It isnt.

    Is a MAC? Potentially but only to a very specific and small number of entities. And then as I said for it to be personal data the link between that device and you has to be realistically and reasonably likely to occur.

    Like I said, you’ve already decided you’re correct and this is a breach. I look forward to reading the result of your court case against Karcher in 3 years time, so don’t forget to come back and let us know how you get on

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      15 days ago

      You’re making lots of assumptions and leaps about Google.

      Amid Apple and Google’s opacity, you’re making lots of assumptions and leaps about Google that a Google spokesperson would praise you for. It’s unwise not to assume surveillance advertisers are collecting all profitable data possible.

      Like anyone else all they can do is map SSID to a general locality. They still dont know who you are based on that single piece of information.

      You’ve apparently not read Douglas Leith’s research. It’s the MAC address that is sent along with other telemetry data.

      The question is - is an SSID personal data.

      No. It isnt.

      We’re talking about MAC addresses that are linked to an individual natural person. Think of the SSID as the bait by which the uniquely identifying MAC address is discovered and collected.

      Is a MAC? Potentially but only to a very specific and small number of entities.

      Nonsense. A MAC address is unique and the box emitting it is owned by a particular person. In residential areas most such devices are owned by natural individuals.

      And then as I said for it to be personal data the link between that device and you has to be realistically and reasonably likely to occur.

      It’s automated. Apple collects the MAC addresses along with telemetry data. Apple also collects other data which can be aggregated. Data aggregation is profitable. It enables advertisers to know the most about their ad targets.

      I look forward to reading the result of your court case against Karcher in 3 years time.

      Woah, hold on. I never claimed the GDPR is actually enforced. The GDPR is widely disregarded. No, I do not have the confidence you seem to think I have in the GDPR being enforced. We can’t even get the most bluntly egregious indefensible GDPR violations enforced, much less any kind of nuanced scenario like this.

      The GDPR is just a prop… a façade to make the population comfortable with engaging with digital commerce (and for this purpose the GDPR works wonders on people). The discussion is whether there is a violation, not whether there would be justice. We can probably agree that Karcher will never face justice or be compelled to actually respect Art.5 and Art.32.

      • Corporal_Punishment@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 days ago

        I agree MAC addresses can be personal data - if it can be linked in some way.

        So a mobile phone? Sure - it links to you through subscriber info etc.

        A router? Sure - links to you via your ISP (although im both cases technically it links to the person paying the bills)

        But a DAB radio? Like others have said, unless you registered it under your name then its MAC is not linked to you.

        We then go back to the tests of whether it actually is personal data, and one of those tests is whether a person can determine who you are by taking reasonable steps and also whether they are likely to try.

        In both cases, in the real world the answer is arguably no.

        • daveyOsborn@infosec.pubOP
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          15 days ago

          But a DAB radio? Like others have said,

          Others? You mean the person who thinks data is only collected by product registrations? Who thinks “smart” devices have no GDPR relevance? And who thinks MAC addresses are not unique and who also thinks a MAC address on a DAB radio can be changed by consumers apparently without breaking an anti-reverse engineering terms of use? Who also thinks Karcher would become GDPR compliant through a MAC changing mechanism if it were to exist. Who then tried to establish credibility by claiming to endorse the GDPR. Indeed… not a good source.

          unless you registered it under your name then its MAC is not linked to you.

          You cannot really know what Google and Apple do with their data collection as opaque as they are. But the data is there. They have enough to link people to MAC addresses on a large scale in an automated fashion. The data collection is proven by Douglas Leith’s research.

          At the same time, we need not rely on assumptions. I could unwittingly place my Karcher within view of my front window while my neighbors who know exactly who I am. I might also be the sole person in hundreds of meters who has a Karcher that emits a unique MAC address. Any arbitrary owner of a Karcher radio would not necessarily even be aware of the reckless emissions. My neighbor would realistically have a great degree of certainty that the MAC address relates to me as they can see the signal strength increase ast they approach my dwelling and decrease as they walk away from it.

          To make this more interesting, replace “neighbor” with “stalker” in the above paragraph. Then when I move to get away from the stalker, the DBs of Apple or Google could reveal¹ my new location. Or the stalker can war drive if they know I didn’t move far.

          ¹ Note that research showed that Ukranian troops were trackable using Apple’s map tool that all ordinary Apple consumers have access to.

          • Corporal_Punishment@feddit.uk
            link
            fedilink
            English
            arrow-up
            1
            ·
            15 days ago

            It’s all a bit thin mate.

            You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.

            Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.

            As a thought experiment I’ll concede that you might have a point. But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio. It just isn’t a realistic scenario which is something a data protection authority would need to consider as well.

            • daveyOsborn@infosec.pubOP
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              15 days ago

              You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.

              Of course. Apple does not distinguish a DAB radio from a smartphone from an access point. It just blindly collects all SSIDs and MACs. Why do you think a soldier in Ukraine would get not only different treatment, but in fact more compromising treatment? That’s absurdly unrealistic. It costs Apple money to pay engineers to write tailored code and filters that then get deployed to all iOS devices at the risk of the exceptional logic doing the wrong thing. Of course iOS devices indiscriminantly send all data just the same.

              The Ukraine soldier tracking was a scandalous embarrassment, so it stands to reason that adjustments have been made since then – and most likely by Ukraine not Apple. But if it were Apple, the change would obviously be to /not/ collect the compromising data of soldiers. A war fighter has a higher expectation for privacy than a DAB radio listener.

              It’s not Apple who tracked the Ukrainian soldiers. The exploit was demonstrated by an end user who was simply making use of available data from Apple. IOW, some avg. Joe tinkering in their basement could do it. And they could do it with LESS information to start with. The person who demonstrated the tracking was much further than 100 meters. They were not even in Ukraine IIRC. They did not know where the soldiers were to begin with (IIRC). Unlike a Karcher scenario, where an adversary could very well have the victim’s starting location. It’s trivial track the victim from there in this case.

              Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.

              Do stalker victims have to prove the likelihood that their threat agent will attack? It’s already clear to me that the GDPR is mostly a failure. If judges and GDPR practitioners were to require proof that excessive data would likely lead to misuse as a precondition to corrective action against art.5-1© infringements, it would be yet another failure of the GDPR. The whole point to Art.5-1© (data minimisation) is to improve privacy generally without anticipation of particular threats. That’s the whole point of it. What you suggest is a purpose-defeating abuse of interpretation and discretion.

              But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio.

              If I ever have a stalker, I hope they are as unmotivated and undevoted as you suggest. But I have to say you have a strangely optimistic or flippant view of the psychology of a stalker.