
You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.
Of course. Apple does not distinguish a DAB radio from a smartphone from an access point. It just blindly collects all SSIDs and MACs. Why do you think a soldier in Ukraine would get not only different treatment, but in fact more compromising treatment? That’s absurdly unrealistic. It costs Apple money to pay engineers to write tailored code and filters that then get deployed to all iOS devices at the risk of the exceptional logic doing the wrong thing. Of course iOS devices indiscriminantly send all data just the same.
The Ukraine soldier tracking was a scandalous embarrassment, so it stands to reason that adjustments have been made since then – and most likely by Ukraine not Apple. But if it were Apple, the change would obviously be to /not/ collect the compromising data of soldiers. A war fighter has a higher expectation for privacy than a DAB radio listener.
It’s not Apple who tracked the Ukrainian soldiers. The exploit was demonstrated by an end user who was simply making use of available data from Apple. IOW, some avg. Joe tinkering in their basement could do it. And they could do it with LESS information to start with. The person who demonstrated the tracking was much further than 100 meters. They were not even in Ukraine IIRC. They did not know where the soldiers were to begin with (IIRC). Unlike a Karcher scenario, where an adversary could very well have the victim’s starting location. It’s trivial track the victim from there in this case.
Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.
Do stalker victims have to prove the likelihood that their threat agent will attack? It’s already clear to me that the GDPR is mostly a failure. If judges and GDPR practitioners were to require proof that excessive data would likely lead to misuse as a precondition to corrective action against art.5-1© infringements, it would be yet another failure of the GDPR. The whole point to Art.5-1© (data minimisation) is to improve privacy generally without anticipation of particular threats. That’s the whole point of it. What you suggest is a purpose-defeating abuse of interpretation and discretion.
But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio.
If I ever have a stalker, I hope they are as unmotivated and undevoted as you suggest. But I have to say you have a strangely optimistic or flippant view of the psychology of a stalker.



Any SSID broadcast is useful to Google and Apple spies (read: simple phone patrons) who feed the SSID to the mothership which is then used for mapping. There are security risks by that alone even if it’s blocked from my LAN, which I detail in these threads:
Apart from tracking my residency, I boycott both Google and Apple, so I object to feeding them in the slightest even when it’s innocuous to me. The map data enhances their location products and feeds their advertising surviellance machines.
Anyway, I appreciate your insight. I assumed it was a proactive act by Karcher and would not have thought that they were naive or lazy w.r.t. something baked-in upstream from them.