Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
I don't understand what you're complaining about, exactly. Your wi-fi
network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.
And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. Don't do it.
Lawrence D'Oliveiro wrote:
On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote:
Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
I don't understand what you're complaining about, exactly. Your
wi-fi network broadcasts its existence to all and sundry, and yet
you feel upset when somebody collects that information and passes
it on.
And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. Don't do it.
The problem is most people who are NOT Wi-Fi pros, are stuck in the
stone age when it comes to thinking about what a hidden broadcast
actually does.
This is about privacy.
Not security.
The entire reason for a hidden SSID is privacy. If the SSID is
hidden, it tells everyone you want to be private
I donrCOt understand what yourCOre complaining about, exactly. Your wi-fi network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.
Your car broadcasts its license plate number to anyone in
sight of it, yet people are rightfully ticked off at Flock
cameras everywhere recording them.
On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote:
Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
I donrCOt understand what yourCOre complaining about, exactly. Your wi-fi network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.
And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. DonrCOt do it.
On 2026-09-03 10:09, Lawrence DrCOOliveiro wrote:
On Thu, 3 Sep 2026 16:30:15 +0930, Maria Sophia wrote:
Those scripts proved I could collect a list of every single access
point in Apple's database, just as researchers Eric Rye and Dave
Levin did, using a simple perl script which proved the results of
their paper, and which went further to prove that my own
hidden-broadcast SSIDs were in that database.
I donrCOt understand what yourCOre complaining about, exactly. Your wi-fi
network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.
I guess it is because the SSID is terminated in _nomap, which is
documented as a flag to Apple and others to not store this SSID in their maps. But Apple is/was mapping them all the same.
This is an update to the WPS scripts that I posted a few months ago.
This is about privacy.
Not security.
This is about the *perception* of privacy. Like telling people they
don't have to worry about closing their curtains, they just need to
close their eyes -- if they canot see the people outside looking in,
then those looking in can't see them!
Lawrence D'Oliveiro wrote:
This is about privacy.
Not security.
This is about the *perception* of privacy. Like telling people they
don't have to worry about closing their curtains, they just need to
close their eyes -- if they can-ot see the people outside looking in,
then those looking in can't see them!
Hi Lawrence,
I say with all respect that your statement is too wrong to accept as is.
What you just said, I've heard a thousand times before, from many people.
And yet, it's no different than what I've heard by asking the guy next to
me at the gas pump since the 1960's why he puts premium in a Honda Civic.
For over five decades, people have been parroting what someone told them. None of them actually understand a word that they're obviously parroting.
Same here...
Again, I respect you for your technical acumen which is greater'n mine.
But I can't tell if you know privacy differences between these situations:
a. iPhone owner happens to walk by my house
b. Android owner happens to walk by my house
Do you know the difference in terms of what happens, or not, with respect
to my unique AP BSSID & GPS location (both of which are exactly my house)?
I do.
A. So does Apple.
B. So does Mozilla. And Google.
Mozilla respects a hidden access point broadcast (i.e., it's set to null).
So does Google (surprisingly).
i. But not Apple.
ii. And yet, Apple loudly & vociferously proclaims to care about privacy.
That's the part that is the most hurtful.
Apple brazenly lies, with a huge "what me?" seemingly innocent smile.
Yet, Apple immediately removed my BSSID/GPS from their WPS database.
Because they know what I know about the lack of privacy in that regard.
It may well be I'm the only one in the world who is honored so by Apple.
But that's not my point as I care about everyone's privacy. Not just mine.
Another question for you, Lawrence, again, because I respect your acumen.
Do you know the difference between these two situations:
a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
b. Android owner happens to walk by my house & it uploads my BSSID/GPS?
What happens then?
Do you know?
I do.
Anyone who can't answer those queries, can't possibly understand the issue.
Anyone who can't answer those queries, can't possibly understand the issue.
Do you have any intention of letting anyone else know what the issue is?
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
Lawrence D'Oliveiro wrote:
This is about privacy.
Not security.
This is about the *perception* of privacy. Like telling people they
don't have to worry about closing their curtains, they just need to
close their eyes -- if they can-ot see the people outside looking in,
then those looking in can't see them!
Hi Lawrence,
I say with all respect that your statement is too wrong to accept as is.
What you just said, I've heard a thousand times before, from many people.
And yet, it's no different than what I've heard by asking the guy next to
me at the gas pump since the 1960's why he puts premium in a Honda Civic.
For over five decades, people have been parroting what someone told them.
None of them actually understand a word that they're obviously parroting.
Same here...
Again, I respect you for your technical acumen which is greater'n mine.
But I can't tell if you know privacy differences between these situations: >> a. iPhone owner happens to walk by my house
b. Android owner happens to walk by my house
Do you know the difference in terms of what happens, or not, with respect
to my unique AP BSSID & GPS location (both of which are exactly my house)? >>
I do.
A. So does Apple.
B. So does Mozilla. And Google.
Mozilla respects a hidden access point broadcast (i.e., it's set to null). >> So does Google (surprisingly).
i. But not Apple.
ii. And yet, Apple loudly & vociferously proclaims to care about privacy. >>
That's the part that is the most hurtful.
Apple brazenly lies, with a huge "what me?" seemingly innocent smile.
Yet, Apple immediately removed my BSSID/GPS from their WPS database.
Because they know what I know about the lack of privacy in that regard.
It may well be I'm the only one in the world who is honored so by Apple.
But that's not my point as I care about everyone's privacy. Not just mine. >>
Another question for you, Lawrence, again, because I respect your acumen.
Do you know the difference between these two situations:
a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
b. Android owner happens to walk by my house & it uploads my BSSID/GPS?
What happens then?
Do you know?
I do.
Anyone who can't answer those queries, can't possibly understand the issue.
Do you have any intention of letting anyone else know what the issue is?
Maria Sophia <mariasophia@comprehension.com> wrote:
This is an update to the WPS scripts that I posted a few months ago.
I was wondering how you got on with your "experiment" only the other day.
You said you had installed two routers in friends' houses downtown, move
them around and then track the movement in the database.
I'd like to see the results. How often did you move them, how far, and were the details tracked in the "apple database"?
In short, he knows NOTHING about Apple, iOS, iPhones or anything else
Your car broadcasts its license plate number to anyone in
sight of it, yet people are rightfully ticked off at Flock
cameras everywhere recording them.
Because machine data acquirement is more powerful.
Jon Ribbens wrote:
Anyone who can't answer those queries, can't possibly understand the
issue.
Do you have any intention of letting anyone else know what the issue
is?
Hi Jon,
Lil' ole' me can easily track a BSSID anywhere in the world, down to a
meter or so accuracy, if I want to under the common circumstances which
I've outlined in this thread (and in others).
I move my router around a lot, and I don't want just anyone being able
to track all my movements down to a meter accuracy when I do that. Do
you?
You were correct in your prior post to Carlos, when you said (verbatim):
"I got the impression they were claiming that their SSID was hidden,
which makes it irrelevant as to whether it has "_nomap" at the end
of it, but that Apple had somehow discovered and logged it nonetheless.
It seems highly implausible."
But, of course, there's more detail (which I provided in my responses).
I explained it in gory detail, and even provided a link to the research.
I provided some of the python scripts too (although they're not the point).
We've discussed this ad infinitum on the Apple & Android & Windows ngs in
the past, although I don't remember how much we brought in Python folks.
What's *new* is Apple told me in my email that there was no way to
have WPS privacy from Google/Mozilla if I wished to have WPS privacy
from Apple.
It's a catch-22 situation.
Which would you pick?
HINT: If we read the research paper, it's a no brainer which one to pick.
Heh heh heh...[SNIP]
While I realize Apple religious zealots will attack people personally
Do you know the difference between these two situations:
a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
b. Android owner happens to walk by my house & it uploads my BSSID/GPS?
Chris wrote:
Maria Sophia <mariasophia@comprehension.com> wrote:
This is an update to the WPS scripts that I posted a few months ago.
I was wondering how you got on with your "experiment" only the other day. >>
You said you had installed two routers in friends' houses downtown, move
them around and then track the movement in the database.
I'd like to see the results. How often did you move them, how far, and were >> the details tracked in the "apple database"?
Hi Chris,
Thanks for remembering that I ran a 3-router experiment early in the year.
That experiment was run in the first month of the year, which was before Apple changed their documentation saying that they will track us forever.
<https://support.apple.com/en-ie/102515>
Those BSSIDs are now in Apple's WPS database, so the experiment worked.
Now, anywhere in the world I move those routers, anyone can track them.
Instantly.
Down to a meter or so resolution.
With no controls whatsoever.
Think about that.
What if I were hiding from an ex-wife or disgruntled Apple poster?
Anyone on the planet can track my router location from anywhere in the
world down to meter-like accuracy, and I simply cannot stop them.
The only thing I can do, once my BSSID is in Apple's WPS database, is throw that router over the next bridge because I can't change the BSSID on it.
I can be tracked forever, if my location is associated with that router.
Just like the research paper said it would be.
I simply reproduced exactly what the research paper said was possible.
Worse, I proved hiding the BSSID broadcast was a catch-22 situation.
a. It kept the BSSID out of Google/Mozilla hands (they're well behaved)
b. Yet, it's permanently in the Apple WPS database
Which do you pick to be in, given you can't solve both issues at once?
HINT: Apple's WPS database has no protection whatsoever, as proved by:
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
My research *started* with that paper, and took it to the next level.
Anyone on the planet can track my router location from anywhere in the
world down to meter-like accuracy, and I simply cannot stop them.
The only thing I can do, once my BSSID is in Apple's WPS database, is throw that router over the next bridge because I can't change the BSSID on it.
I can be tracked forever, if my location is associated with that router.
Maria Sophia wrote:
Anyone on the planet can track my router location from anywhere in the
world down to meter-like accuracy, and I simply cannot stop them.
The only thing I can do, once my BSSID is in Apple's WPS database, is throw >> that router over the next bridge because I can't change the BSSID on it.
I can be tracked forever, if my location is associated with that router.
I don't remember whether you addressed this ... how does someone who
hasn't visited your address (i.e they already know where you live)
discover what the BSSID of your router is?
Lil' ole' me can easily track a BSSID anywhere in the world, down to a
meter or so accuracy, if I want to under the common circumstances which
I've outlined in this thread (and in others).
Ok. I think BSSID means "MAC address of the WiFi access point".
I don't know what circumstances you can track them, and you don't
seem to have said in this thread.
I move my router around a lot, and I don't want just anyone being able
to track all my movements down to a meter accuracy when I do that. Do
you?
I suppose if someone had reason to target me specifically, and they had
a real-time way of tracking BSSIDs, and for some reason I can't imagine
I was taking a WiFi access point with me, I... oh, wait. In that
circumstance I would not take a WiFi access point with me, for the
same reason I wouldn't have my mobile phone radio enabled, or would not
have a mobile phone with me at all, depending on the threat model.
You were correct in your prior post to Carlos, when you said (verbatim):
"I got the impression they were claiming that their SSID was hidden,
which makes it irrelevant as to whether it has "_nomap" at the end
of it, but that Apple had somehow discovered and logged it nonetheless. >> It seems highly implausible."
But, of course, there's more detail (which I provided in my responses).
I saw no response from you to that post. But from what you're saying
in the post I'm replying to now, I wasn't correct - I now think you're
saying that Apple store the BSSIDs of access points of WiFi networks
with hidden SSIDs, because they *don't* know the SSID and therefore
can't tell if it has "_nomap" appended, and so don't exclude it.
I'm not sure what I think about that, and I don't know what any of the
other companies that map SSIDs do in the same situation. I'm not sure
why Apple would store location data of BSSIDs with no visible SSID -
it doesn't seem like it would help the geolocation feature much, since
hiding the SSID is pretty rare.
I explained it in gory detail, and even provided a link to the research.
I provided some of the python scripts too (although they're not the point).
You haven't done any of that in this thread so far as I can see.
We've discussed this ad infinitum on the Apple & Android & Windows ngs in
the past, although I don't remember how much we brought in Python folks.
What's *new* is Apple told me in my email that there was no way to
have WPS privacy from Google/Mozilla if I wished to have WPS privacy
from Apple.
Sorry, what does WPS have to do with it? And why is it a binary option?
A non-hidden SSID with "_nomap" would presumably provide privacy from
all those companies? Or do some of them not support that? Or is having
a non-hidden SSID not acceptable to you? If so, what are the options
for privacy you are referring to?
It's a catch-22 situation.
Which would you pick?
I mean I literally do pick a non-hidden SSID without "_nomap" on it,
that I've kept constant for decades. I've never even seen a SSID with "_nomap" on it. There is no-one I regard as a threat, let alone someone
who would be a threat and who would know my SSID let alone my BSSIDs.
HINT: If we read the research paper, it's a no brainer which one to pick.
What research paper?
In particularly, there's in this thread nothing about Python or
Windows 10.
Do you know the difference between these two situations:
a. iPhone owner happens to walk by my house & it uploads my BSSID/GPS?
b. Android owner happens to walk by my house & it uploads my BSSID/GPS?
If there is any difference, it would not be wise to rely on it.
What if I were hiding from an ex-wife or disgruntled Apple poster?
Just get a different router.
Jon Ribbens wrote:
Lil' ole' me can easily track a BSSID anywhere in the world, down to a
meter or so accuracy, if I want to under the common circumstances which
I've outlined in this thread (and in others).
Ok. I think BSSID means "MAC address of the WiFi access point".
I don't know what circumstances you can track them, and you don't
seem to have said in this thread.
Hi Jon,
Thanks for your questions as it shows you're trying to understand this.
Your questions are all good questions, from someone who is encountering
this issue for the first time in their lives, but let's be clear that an entire course in networking for privacy is beyond my personal skill sets.
If you don't know what a BSSID is by now then it will take too much work
here to explain it "fully" to you. Suffice to say it's like a vehicle identification number on a car. It goes everywhere the router goes.
I suppose if someone had reason to target me specifically, and they had
a real-time way of tracking BSSIDs, and for some reason I can't imagine
I was taking a WiFi access point with me, I... oh, wait. In that
circumstance I would not take a WiFi access point with me, for the
same reason I wouldn't have my mobile phone radio enabled, or would not
have a mobile phone with me at all, depending on the threat model.
Read the paper which we referenced multiple times in this thread so that I don't have to re-hash over and over again how mass surveillance is possible with the Apple WPS database design.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975>
Anyone who can run a python script (which I will provide to them upon request) can track anyone in the world who moves from one place to another (and who happens to take their router with them to their new location).
Nobody disputes that fact, which is what the paper itself explained.
I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
It doesn't bother you that I can track the movements of billions of people
if they happen to move from one locale to another using the same router?
You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?
That's 1/2 the point of this thread.
1. Apple is doing NOTHING about it (as described in the paper)
2. So anyone in the world can track the movements of billions of routers
2. Worse, Apple isn't honoring the established meaning of the hidden
broadcast (which even Google honors, by way of stark contrast).
So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
There are two fundamental issues, only one of which is in this paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975>
I've summarized what's in that paper likely a half dozen times in this thread, and I've added a second issue that is not discussed in that paper.
I've talked that second issue over with security professionals like Brain Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims.
To summarize complex issues in a few simple sentences, they might be:
1. Apple allows anyone on the world to track the movements of everyone
in the world (if they take their router with them when they move).
2. Apple puts zero controls on that tracking by anyone, of everyone.
3. In addition, Apple does not respect the known meaning of a hidden
broadcast, and worse, Apple *refuses* to honor what even Google does.
4. Anyone can prove these statements are true on a Windows PC running
Python using the scripts I have provided for that express purpose.
I'm not sure what I think about that, and I don't know what any of the
other companies that map SSIDs do in the same situation. I'm not sure
why Apple would store location data of BSSIDs with no visible SSID -
it doesn't seem like it would help the geolocation feature much, since
hiding the SSID is pretty rare.
Remember the Apple trolls posted to this thread that changing the SSID
would solve the issue, but the main issue is about the BSSID, not the SSID.
a. The BSSId is unique (see above for rare exceptions).
b. The GPS location is also unique
c. The SSID only plays a role tangentially, and as such is a minor player
I explained it in gory detail, and even provided a link to the research. >>> I provided some of the python scripts too (although they're not the
point).
You haven't done any of that in this thread so far as I can see.
Did you read the paper?
What does that paper say?
Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?
I've explained both perhaps a half dozen times in this thread.
Explaining another half dozen times won't help until you do the above.
Google does one thing (which, surprisingly, is the right thing to do).
Apple does the opposite (and, not surprisingly, refuses to change it).
Chris wrote:
What if I were hiding from an ex-wife or disgruntled Apple poster?
Just get a different router.
Chris,
I realize your only goal is to defend Apple's honor to the death, no matter what, but I only needed to prove two things, both of which are now obvious.
1. Apple's WPS database can be used by anyone in the world to track the
location of a router AP (by BSSID/GPS) without any restrictions.
I don't remember whether you addressed this ... how does someone who
hasn't visited your address (i.e they already know where you live)
discover what the BSSID of your router is?
Apparently it's a complete invasion of privacy in the same way google maps having actual pictures of his house and the phone book having his name, address *and* phone number isn't.
1. Apple's WPS database can be used by anyone in the world to track the
location of a router AP (by BSSID/GPS) without any restrictions.
This is the same as:
5e) A few maggots are going at it eating an apple, and nearby there
is a pumpkin in the field.
Lane W wrote:
1. Apple's WPS database can be used by anyone in the world to track the
location of a router AP (by BSSID/GPS) without any restrictions.
This is the same as:
5e) A few maggots are going at it eating an apple, and nearby there
is a pumpkin in the field.
While I get your attempt to ridicule all that you can't comprehend, and I
can tell you haven't clicked on a single reference provided in this thread, all I want to ask you, to prove the absurdity of your ignorance, is this:
*Give me your home router AP BSSID.*
I will return, to you, in seconds, not only the location of your router,
but I will give you the next 400 nearest router AP locations to you.
Then, after that, I can track not only everywhere you take that router, forever, sans any restrictions, but those of your next 400 neighbors.
Take me up on that before you try to ridicule what you don't comprehend.
Q: What is your home router AP BSSID please?
A: ?
If you don't know what a BSSID is by now then it will take too much work
here to explain it "fully" to you. Suffice to say it's like a vehicle
identification number on a car. It goes everywhere the router goes.
Well, yes, it's the MAC address, like I already said.
I suppose if someone had reason to target me specifically, and they had
a real-time way of tracking BSSIDs, and for some reason I can't imagine
I was taking a WiFi access point with me, I... oh, wait. In that
circumstance I would not take a WiFi access point with me, for the
same reason I wouldn't have my mobile phone radio enabled, or would not
have a mobile phone with me at all, depending on the threat model.
Read the paper which we referenced multiple times in this thread so that I >> don't have to re-hash over and over again how mass surveillance is possible >> with the Apple WPS database design.
You hadn't referenced it at the time I wrote my post, or at least
by the time you wrote the post I was responding to.
It mostly seems to be an attack against people who don't realise
they are targets, or are not thinking about the implications - c.f.
soldiers who upload their daily runs to public web sites thus
revealing if/where they are deployed.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
Anyone who can run a python script (which I will provide to them upon
request) can track anyone in the world who moves from one place to another >> (and who happens to take their router with them to their new location).
Nobody disputes that fact, which is what the paper itself explained.
I simply reproduced their "billions of BSSID/GPS pairs" with thousands.
It doesn't bother you that I can track the movements of billions of people >> if they happen to move from one locale to another using the same router?
As I say that's a pretty unusual thing to do (travelling with a router). Google's API does seem more sensible though (give it MAC addresses, it
tells you where you probably are, rather than giving you the recorded individual locations of all those MAC addresses).
You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?
That's 1/2 the point of this thread.
1. Apple is doing NOTHING about it (as described in the paper)
Have you, er, read the paper? It says Apple *is* doing things about it
(page 14, section 10 paragraph 3).
2. So anyone in the world can track the movements of billions of routers
2. Worse, Apple isn't honoring the established meaning of the hidden
broadcast (which even Google honors, by way of stark contrast).
This is the bit I keep asking about and you keep not responding.
Is your actual/main complaint that Apple is storing BSSIDs that
correspond to hidden SSIDs? And you're saying only Apple do this,
not Google etc?
So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
Apple cares about the privacy of *its customers*.
There are two fundamental issues, only one of which is in this paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
I've summarized what's in that paper likely a half dozen times in this
thread, and I've added a second issue that is not discussed in that paper. >>
I've talked that second issue over with security professionals like Brain
Krebs and Daniel Veditz, so there is no doubt of the veracity of my claims. >>
To summarize complex issues in a few simple sentences, they might be:
1. Apple allows anyone on the world to track the movements of everyone
in the world (if they take their router with them when they move).
2. Apple puts zero controls on that tracking by anyone, of everyone.
I imagine the issue here is that if they change their API then older
devices that are no longer receiving updates will stop being able to do wifi-positioning.
3. In addition, Apple does not respect the known meaning of a hidden
broadcast, and worse, Apple *refuses* to honor what even Google does.
4. Anyone can prove these statements are true on a Windows PC running
Python using the scripts I have provided for that express purpose.
I'm not sure what I think about that, and I don't know what any of the
other companies that map SSIDs do in the same situation. I'm not sure
why Apple would store location data of BSSIDs with no visible SSID -
it doesn't seem like it would help the geolocation feature much, since
hiding the SSID is pretty rare.
Remember the Apple trolls posted to this thread that changing the SSID
would solve the issue, but the main issue is about the BSSID, not the SSID. >> a. The BSSId is unique (see above for rare exceptions).
b. The GPS location is also unique
c. The SSID only plays a role tangentially, and as such is a minor player
The "Apple trolls" are presumably correct inasmuch as if you change the
SSID to end in "_nomap" then it solves the issue.
I explained it in gory detail, and even provided a link to the research. >>>> I provided some of the python scripts too (although they're not the
point).
You haven't done any of that in this thread so far as I can see.
Did you read the paper?
What does that paper say?
You hadn't linked the paper at the time I wrote my post.
The paper doesn't quite say what you're claiming, I think,
although I see your general point (or at least, the paper's
authors' general point).
Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?
To waste power in client devices, as far as I can see, since it
means they have to be constantly pinging for the network rather
than just connecting to it when they see the SSID broadcast.
So in some senses it makes the user tracking problem *much worse*,
since it means the attacker can hang around public places watching
for client devices (which, unlike access points, tend to move around
with the user) that are pinging for the attack target's hidden SSID.
Hang around a diner near Langley, Virginia, watching for people
carrying devices pinging the hidden SSID "CIA UNCLASSIFIED"...
I've explained both perhaps a half dozen times in this thread.
Explaining another half dozen times won't help until you do the above.
I'm starting to think that by "this thread" you don't mean "the set
of Usenet articles referenced in the References headers" and are
including other historic threads...
Google does one thing (which, surprisingly, is the right thing to do).
Apple does the opposite (and, not surprisingly, refuses to change it).
I think you are still failing to explain what those two things are,
and I'm getting tired of guessing. If you are claiming the paper
describes this difference, please say where. If it doesn't, please
just say what it is.
Q: What is your home router AP BSSID please?I'm homeless and don't have a home router, so there's something further
A: ?
for you to laugh at me about.
Keith Thompson wrote:
In particularly, there's in this thread nothing about Python or
Windows 10.
The code supplied for you to run is Python which ran on Windows 10.
I know this because I got help in the code from Windows/Python ngs.
So, together, the Windows & Python newsgroup honed the working code.
Do you need me to supply the code for you again so you can run it?
Jon Ribbens wrote:
If you don't know what a BSSID is by now then it will take too much work >>> here to explain it "fully" to you. Suffice to say it's like a vehicle
identification number on a car. It goes everywhere the router goes.
Well, yes, it's the MAC address, like I already said.
Hi Jon,
To your credit, you are the first person who has responded, who has shown that he actually *read* the paper before trying to respond intelligently.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975>
That's good.
Nobody else even bothered to click on the link, before responding.
Hence, everyone else simply parroted their stone-age knowledge level.
You, at least, did *read* the paper, which I congratulate you for doing.
But you did not *understand* what the paper said by the BSSID.
See below where you completely whooshed on which BSSID is what matters.
I must be careful here not to fault you like I fault the Apple trolls, because I think you are sincerely trying to understand the problem set.
So I simply caution you, as I did Lawrence & Andy, all of whom I respect
for acumen, that you have to follow the trail of the *router* AP BSSID.
You can not "randomize the BSSID" of the router AP (except in the most expensive commercial routers, which are not the topic of this thread).
Think very deeply about that simple fact before responding, as the crux of the problem is no different than a governmment-issued identification
number.
You can't easily change your unique government-issued ID number just as you can't easily change the router-issued BSSID of your home router AP.
Think about that the same way the paper presented the mass surveillance.
1. I wrote a Python script that ran on Windows 10 that guessed at a set
of random government-issued identification numbers, e.g., 123.45.6789
2. Within minutes, I had a hit on a random government ID, which came
back with a GPS location and 400 nearby government IDs and locations.
3. Then, I ran another Python script on Windows 10 that extended that,
taking the furthest-away governemtn ID/location pair, and did it again.
4. Within an hour, I had thousands of government IDs and locations.
(the researchers gathered billions, as I recall, but I stopped there.)
Now that I have every government-issued ID and GPS location in the world in my 2TB database (which we calculated would be the size it would have been), what is the paper saying about "mass surveillance" possibilities?
HINT: I can track the future location of every one of those billions of government ID/GPS location pairs, without any restrictions on my scripts!
Want to prove that?
What's your home router BSSID?
I will not only tell you exactly where that router is located (I even wrote the Python code to give me a dot on an OSM map for your location) but I can trivially easily forever track that router's location forever, without any restrictions on my part (which is the point of the paper, after all).
It mostly seems to be an attack against people who don't realise
they are targets, or are not thinking about the implications - c.f.
soldiers who upload their daily runs to public web sites thus
revealing if/where they are deployed.
It's not "an attack" so much as explaining, with examples, of why we
should care that mass surveillance is so easy with the Apple WPS implementation.
Give me your BSSID.
Note: I don't expect you to do it, which alone proves the point.
As I say that's a pretty unusual thing to do (travelling with a router).
Google's API does seem more sensible though (give it MAC addresses, it
tells you where you probably are, rather than giving you the recorded
individual locations of all those MAC addresses).
I think your claim that it's "pretty unusual" for people to take their
router with them when they move from one apartment to another is skewed.
If I ask 100 people who recently moved, do you really think it would be
only 1 or 2 people who took their home router with them when they moved?
You think this tracking isn't happenging asa we speak?
You think Apple is doing something about it?
That's 1/2 the point of this thread.
1. Apple is doing NOTHING about it (as described in the paper)
Have you, er, read the paper? It says Apple *is* doing things about it
(page 14, section 10 paragraph 3).
See my first response to you in this post, where I want to be careful to
not chastise you for misunderstanding what that paragraph actually says.
You can NOT randomize the MAC address of the router AP, Jon.
2. So anyone in the world can track the movements of billions of routers >>> 2. Worse, Apple isn't honoring the established meaning of the hidden
broadcast (which even Google honors, by way of stark contrast).
This is the bit I keep asking about and you keep not responding.
Is your actual/main complaint that Apple is storing BSSIDs that
correspond to hidden SSIDs? And you're saying only Apple do this,
not Google etc?
First off, I don't have a complaint. That's absurd. I have facts.
The absurdity of this thread is nobody has read or understood the links
which were provided, and yet, they ask me (repeatedly) to explain them.
Why can nobody understand the point that Eric & Dave made in this paper?
*Surveilling the Masses with Wi-Fi-Based Positioning Systems* <https://arxiv.org/abs/2405.14975>
Why can nobody understand what's different about what Apple documented? <https://support.apple.com/en-ie/102515>
Why can nobody undestqand the concept inherent in a hidden-broadcast? <https://ichnaea.readthedocs.io/en/stable/api/geosubmit2.html>
"The BSSID of the Wifi network.
Hidden Wifi networks must not be collected."
Why is it that I feel it's trivial to understand that 1+1=2 when everyone else is trying to claim that I need to explain why 1+2=2 when, if they
simply read (and understood) what I've explained, they would understand?
So much for Apple "cares about your privacy" bullshit, huh?
It's shocking that google cares about privacy more than Apple does.
Apple cares about the privacy of *its customers*.
I realize you're trying to understand these concepts so I have to be
careful when I point out that this affects every single person in the
world who owns a router (and company, but let's restrict this to just people).
The issues are exactly the same no matter what company made that router.
I imagine the issue here is that if they change their API then older
devices that are no longer receiving updates will stop being able to do
wifi-positioning.
The issue is clearly obvious that the Apple WPS design is flawed.
I have dozens of emails from Apple, all of which show that they *know*
that their design is flawed.
They're simply trying to protect themselves legally with me by having
their emails redirected to their lawyers, who are whom I was
responding with.
They *know* what they're doing is wrong.
Remember the Apple trolls posted to this thread that changing theThe "Apple trolls" are presumably correct inasmuch as if you change the
SSID would solve the issue, but the main issue is about the BSSID,
not the SSID.
a. The BSSId is unique (see above for rare exceptions).
b. The GPS location is also unique
c. The SSID only plays a role tangentially, and as such is a minor player >>
SSID to end in "_nomap" then it solves the issue.
No it does not. Did you read any of the Mozilla references?
Simply *collecting* the BSSID is the starting point.
The problem exists no matter what the SSID is.
With my congratulations to you and with my appreciation that you are the
only one who has shown they have read the paper, I must point out that I think you misunderstood which BSSID the paper is talking about.
For most home routers, the owner has no way of changing the AP BSSID.
Do you know what a hidden broadcast SSID is?
What is the purpose of a hidden broadcast in your opinion?
To waste power in client devices, as far as I can see, since it
means they have to be constantly pinging for the network rather
than just connecting to it when they see the SSID broadcast.
No. Every mobile device has the on/off ability to NOT autoconnect.
Privacy never was something that everyone could understand, but let's
hope the people on this ng have the capacity to understand the
complexities.
I think you are still failing to explain what those two things are,
and I'm getting tired of guessing. If you are claiming the paper
describes this difference, please say where. If it doesn't, please
just say what it is.
Again, I have to first say that I appreciate that you read the paper, and I presume you read the Mozilla documentation I presented, and I presume you also read the Apple documentation which the Apple lawyers wrote after my discussions with them way back in December of last year (public knowledge).
The paper shows that Apple's WPS implementation is highly flawed.
If you've ever tried Google's WPS implementation, you'll see that it's
not. Nor is Mozilla's MLS implementation (now deprecated).
Chris wrote:
What if I were hiding from an ex-wife or disgruntled Apple poster?
Just get a different router.
Chris,
Q3: Would you kindly give me the BSSID of your home router AP please?
When/if you do so, not only will I provide the exact location of that
router
but I can track its movement, forever.
Firstly, I do not like crossposting to so many groups. What group
are you actually reading this thread in, so that I can limit the
crossposts please?
On 2026-09-05, Maria Sophia <mariasophia@comprehension.com> wrote:
Jon Ribbens wrote:
As I say that's a pretty unusual thing to do (travelling with a router). >>> Google's API does seem more sensible though (give it MAC addresses, it
tells you where you probably are, rather than giving you the recorded
individual locations of all those MAC addresses).
I think your claim that it's "pretty unusual" for people to take their
router with them when they move from one apartment to another is skewed.
If I ask 100 people who recently moved, do you really think it would be
only 1 or 2 people who took their home router with them when they moved?
I could quibble with that inasmuch as ISPs tend to provide the APs when
you order the connection, so a new connection usually implies a new AP
(in the UK, anyway). But I was talking about travelling with an AP,
e.g. on business, not moving house.
Maria Sophia <mariasophia@comprehension.com> writes:
[...]
Heh heh heh...
While I realize Apple religious zealots will attack people personally[SNIP]
Can you please restrict this to newsgroups where it's relevant?
In particularly, there's in this thread nothing about Python or
Windows 10.
On 2026-09-06 02:06, Jon Ribbens wrote:
Firstly, I do not like crossposting to so many groups. What group
are you actually reading this thread in, so that I can limit the
crossposts please?
I understand, but that could be a problem to people that are already
reading on a "different" group.
Your comments are easier to understand that Arlen (aka Maria) posts. He
is not clearly explaining the issues and wants people to read a lot of documentation, instead of just posting an actual summary of the
situation with explanations.
Ie, what was Apple doing, why is that bad, what have they changed, is
that enough and why, what are the actual dangers to people.
Complete, and short text.
On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
On 2026-09-06 02:06, Jon Ribbens wrote:
Firstly, I do not like crossposting to so many groups. What group
are you actually reading this thread in, so that I can limit the
crossposts please?
I understand, but that could be a problem to people that are already
reading on a "different" group.
Your comments are easier to understand that Arlen (aka Maria) posts. He
is not clearly explaining the issues and wants people to read a lot of
documentation, instead of just posting an actual summary of the
situation with explanations.
Ie, what was Apple doing, why is that bad, what have they changed, is
that enough and why, what are the actual dangers to people.
Complete, and short text.
Ok, well to summarise what I have gathered then, which may or may not
be Maria's opinion but reflects my opinion at this point: there are two completely separate issues here, which are unrelated except that they
are both to do with WiFi location databases.
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Multiple organisations are gathering and storing the physical
co-ordinates of the MAC addresses ("BSSIDs") of WiFi Access Points
around the world, whenever they are seen transmitting by, e.g. mobile
phones. (Any WiFi-enabled device can see this information; it does not
need to be connected to the network in question, nor does it need to
know its password.)
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There is broad agreement that these databases should not include BSSIDs
which are broadcasting WiFi network names ("SSIDs") which end in the
string "_nomap".
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such "hidden" networks.
My complete speculation: older Apple software, written before they added
the "_nomap" exclusion, doesn't care at all about the SSID, so just
reports from the phone to the central database the BSSID and location.
The database thus has no way of excluding "hidden" networks, without excluding all reports from older devices. The "_nomap" exclusion is
achieved by later software versions reporting the SSID if it is seen,
and any BSSIDs associated with "_nomap" SSIDs then being blacklisted,
maybe for 6 months or something like that. The likelihood of any
particular BSSID *only* being seen by old Apple devices and *never* new
ones is very low, and hence the "_nomap" exclusion more-or-less works.
My opinion: this failure to exclude "hidden" networks is unfortunate and should be fixed, and maybe Apple are indeed fixing it, but it's possible
it may take some years to achieve due to the multitude of devices
running old software.
2. Apple's API is trivial to abuse.
(My opinion: high priority.)
The Apple API to query their BSSID location database is remarkably unrestricted. It has little or no rate limiting, doesn't ask for an API
key, and reports not only the location of the BSSID but also potentially
a great many other BSSIDs in the locality. It is not beyond even an individual person's ability to get a list of most of the Access Points
in the world and all their locations.
This makes it very easy for people to abuse this data in various ways,
from stalkers tracking victims to state actors tracking military
targets.
Google's API by contrast essentially reverses the process, and instead
of the phone asking "Where is BSSID <x>?", it says "I can see BSSIDs
<x>, <y>, and <z>, where am I?".
My opinion: the lack of restrictions on the Apple API is unacceptable,
and if Apple are unwilling to do something about it then governments
should pass laws (or enforce existing laws) to make them to do so.
My opinion: it would be difficult for Apple to rapidly switch completely
to using an API more similar to Google's API, since this would remove functionality from devices running old software. However they could
certainly aim to do this eventually, and there are steps they could take immediately to improve the situation (e.g. rate limiting, and not
providing so many additional answers when asked about an individual
BSSID). I cannot see any obvious reason why they couldn't make
significant improvements almost immediately.
I don't remember whether you addressed this ... how does someone
who hasn't visited your address (i.e they already know where you live) discover what the BSSID of your router is?
So, together, the Windows & Python newsgroup honed the working code.
Do you need me to supply the code for you again so you can run it?
You haven't supplied it once. If you did, I personally would not be interested in running it, but it might at least be topical in comp.lang.python *if* anyone actually discusses the code.
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
12/17/2025 02:28 PM 2,934 bssid.bat.txt
12/17/2025 02:28 PM 4,309 bssidcheck.bat.txt
12/17/2025 02:28 PM 1,979 bssidcompare.bat.txt
12/17/2025 02:28 PM 316 bssidgenerate.bat.txt
12/17/2025 02:28 PM 4,312 bssidgenerate.ps1.txt
12/17/2025 02:28 PM 1,348 bssidplot.py.txt
12/17/2025 02:28 PM 27,527 bssid_results.txt
I will not only tell you exactly where that router is located (I even wrote >> the Python code to give me a dot on an OSM map for your location) but I can >> trivially easily forever track that router's location forever, without any >> restrictions on my part (which is the point of the paper, after all).
Yes, I know that too now, after reading the paper. I downloaded the
code at https://github.com/darkosancanin/apple_bssid_locator (which
was originally uploaded in 2015) and ran it locally with my own AP
MAC address and confirmed it showed my home location very accurately.
HINT: I can track the future location of every one of those billions of government ID/GPS location pairs, without any restrictions on my scripts!
Want to prove that?
What's your home router BSSID?
I will not only tell you exactly where that router is located (I even wrote the Python code to give me a dot on an OSM map for your location) but I can trivially easily forever track that router's location forever, without any restrictions on my part (which is the point of the paper, after all).
Keith Thompson wrote:
So, together, the Windows & Python newsgroup honed the working code.
Do you need me to supply the code for you again so you can run it?
You haven't supplied it once. If you did, I personally would not be
interested in running it, but it might at least be topical in
comp.lang.python *if* anyone actually discusses the code.
Hi Keith Thompson,
Thank you for bringing up your point of view, as all points are valid here. This is Usenet where we welcome deep detailed discussion of tech topics.
Jon Ribbens clearly ran the code so we have proof that it was referenced properly enough for him to have run it on his machine to prove the point.
Nonetheless, it's good you're *asking* for the Python code, which I only
ran on Windows 10, and which I'm happy to supply to you for all to review.
Please keep in mind the progression of this topic started with this paper:
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
As Jon Ribbens did, I simply ran the Python code in that article on my PC.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to remove
all hidden and _nomap entries, or that they removed only his entry?
On 09/06/2026 2:23 PM, Carlos E.R. wrote:
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
He achieved nothing.
It's all weasel words.
-a- nothing but a vague attempt(regardless of the size of multiple missives) to sound impressive and/or meaningful without any concrete proof.
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
2. Apple's API is trivial to abuse.
(My opinion: high priority.)
My opinion: the lack of restrictions on the Apple API is unacceptable,
and if Apple are unwilling to do something about it then governments
should pass laws (or enforce existing laws) to make them to do so.
My opinion: it would be difficult for Apple to rapidly switch completely
to using an API more similar to Google's API, since this would remove functionality from devices running old software. However they could
certainly aim to do this eventually, and there are steps they could take immediately to improve the situation (e.g. rate limiting, and not
providing so many additional answers when asked about an individual
BSSID). I cannot see any obvious reason why they couldn't make
significant improvements almost immediately.
On 2026-09-06 17:37, Jon Ribbens wrote:
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Only Apple?
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.
And if it is hidden they would not see if the SSID ends in _nomap.
But is there a consensus that hidden SSIDs should not be listed? In
writing? Maybe there is such a consensus now.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
On 2026-09-06 17:37, Jon Ribbens wrote:
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Only Apple?
I think that is what Maria is saying, and I have no information to the contrary.
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.
And if it is hidden they would not see if the SSID ends in _nomap.
But is there a consensus that hidden SSIDs should not be listed? In
writing? Maybe there is such a consensus now.
To me it's fairly intuitive that if someone has taken the unusual step
of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
(Snipping for brevity for inline replies, sorry that this removes the context, but in this case it probably is preferrable, please refer to
the parent post for the full context:)
(And thanks for the post, Jon, it does indeed make things clearer to understand at least for me.)
On 2026-09-06, Jon Ribbens wrote:
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There was already a mechanism to do this at least since "3G" using
mobile data connections, right?
2. Apple's API is trivial to abuse.
(My opinion: high priority.)
(I think this is one of the aspects that was made only implicit in most
of the thread, and it would have helped if it was made more explicit...)
[...]
My opinion: the lack of restrictions on the Apple API is unacceptable,
and if Apple are unwilling to do something about it then governments
should pass laws (or enforce existing laws) to make them to do so.
I'm leaning towards existing laws being more than sufficient, in
developed countries.
My opinion: it would be difficult for Apple to rapidly switch completely
to using an API more similar to Google's API, since this would remove
functionality from devices running old software. However they could
certainly aim to do this eventually, and there are steps they could take
immediately to improve the situation (e.g. rate limiting, and not
providing so many additional answers when asked about an individual
BSSID). I cannot see any obvious reason why they couldn't make
significant improvements almost immediately.
Not to mention Apple is not necessarily known for allowing older systems
to remain in use, so it'd be curious if they chose precisely a situation
like this to behave differently.
After having read the prior responses in this Jon/Carlos tangent...
I apologize if I haven't explained the situation to the liking of people
who haven't clicked on the references, but I am happy that Jon and Carlos (and Andy and Lawrence, all of whom I respect) are trying to understand.
I especially wish to thank Jon Ribbens and Carlos & any others who have bothered to read the links provided, because they explain the issue well.
If people haven't read the references, then they're stuck in the stone age
of understanding, which, well, which I'm not the one to drag them out of.
I just don't have the skills to explain that an SSID is not a BSSID
(as witnessed by those who claimed changing the SSID changes the BSSID).
These are basic networking concepts.
Regarding locations, I don't have the skills to explain what a set of GPS coordinates means, if people claim it's "just a map". I don't even know
_how_ to _begin_ to explain that your home address is NOT "just a map".
I don't even know how to explain to people who claim that the router never travels as their belief system is so absurd as to warn me that if they
don't understand that people take their routers with them when they move, then that kind of person will never be able to understand, well, anything.
I apologize that I don't have the skills set to bring folks out of the
stone age, when they claim a home address is "just a location on a map".
When I brought it up to my next-door neighbor, who runs Apple Maps, he said he'd check it out, which, after a few weeks of emails back and forth, we found out that Apple has no intention of honoring the intent of a hidden broadcast (even as we know Google & Mozilla certainly honor that intent).
The Apple lawyers made that very clear to me, as I was shut out from
talking to the engineers once the lawyers were informed of the issue.
I had given up, but recently, I happened to look at Apple's documentation, and I realized Apple proved they had no intent of honoring the long-held intention of a hidden broadcast, by simply changing their documentation.
<https://support.apple.com/en-ie/102515>
Clearly, I know what I'm talking about, so my well informed assessment,--
based on those verifiable facts, is Apple doesn't care about our privacy.
On 2026-09-06, Jon Ribbens wrote:
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There was already a mechanism to do this at least since "3G" using
mobile data connections, right?
On 2026-09-07 11:47, Nuno Silva wrote:
(Snipping for brevity for inline replies, sorry that this removes the
context, but in this case it probably is preferrable, please refer to
the parent post for the full context:)
(And thanks for the post, Jon, it does indeed make things clearer to
understand at least for me.)
On 2026-09-06, Jon Ribbens wrote:
The purpose of these databases of BSSID locations is to assist devices
such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that
GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There was already a mechanism to do this at least since "3G" using
mobile data connections, right?
Yes. It was possible since GSM was invented, but somebody had to figure
out that, and design a methodology. Initially, it involved a written
request to the mobile network provider to do calculations using dumps of logs from each tower that could be involved.
And at some time it was automated, and phones could find their rough location instantly.
I donot understand what youore complaining about, exactly. Your wi-fi
network broadcasts its existence to all and sundry, and yet you feel
upset when somebody collects that information and passes it on.
I guess it is because the SSID is terminated in _nomap, which is
documented as a flag to Apple and others to not store this SSID in their
maps. But Apple is/was mapping them all the same.
I got the impression they were claiming that their SSID was hidden,
which makes it irrelevant as to whether it has "_nomap" at the end
of it, but that Apple had somehow discovered and logged it nonetheless.
It seems highly implausible.
On 2026-09-07 13:34, Carlos E.R. wrote:
On 2026-09-07 11:47, Nuno Silva wrote:
On 2026-09-06, Jon Ribbens wrote:
The purpose of these databases of BSSID locations is to assist devices >>>> such as mobile phones in locating themselves. Maybe the device is
indoors and cannot get a GPS signal, but also my understanding is that >>>> GPS can fix an accurate location much faster if it starts already
knowing vaguely where on the planet it is.
There was already a mechanism to do this at least since "3G" using
mobile data connections, right?
Yes. It was possible since GSM was invented, but somebody had to
figure out that, and design a methodology. Initially, it involved a
written request to the mobile network provider to do calculations
using dumps of logs from each tower that could be involved.
And at some time it was automated, and phones could find their rough
location instantly.
I asked ChatGPT for more info. Take with a pinch of salt.
These are basic networking concepts.
We didn't ask to have it explained. Knowing this is not about skills, though. A mathematician can have very high skills, yet know nothing
about networks. Even a skilled computer programmer may not know about
them, and be a world master on IBM big iron assembler programming (and
being paid handsomely - a tiny fact I happen to know) and not know
offhand what the BSSID is.
I don't even know how to explain to people who claim that the router never >> travels as their belief system is so absurd as to warn me that if they
don't understand that people take their routers with them when they move,
then that kind of person will never be able to understand, well, anything.
No, we don't travel with our routers.
My router belongs to the ISP and I have to return it when I move, then I will get a new one at my destination. You should be intelligent enough
to accept this. Maybe doesn't happen in your nook of the world, but you
must understand that you are posting to an international medium.
I had given up, but recently, I happened to look at Apple's documentation, >> and I realized Apple proved they had no intent of honoring the long-held
intention of a hidden broadcast, by simply changing their documentation.
<https://support.apple.com/en-ie/102515>
Ok, finally. The crux of the issue.
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Only Apple?
I think that is what Maria is saying, and I have no information to the
contrary.
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.
And if it is hidden they would not see if the SSID ends in _nomap.
But is there a consensus that hidden SSIDs should not be listed? In
writing? Maybe there is such a consensus now.
To me it's fairly intuitive that if someone has taken the unusual step
of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
AH! Understood.
And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. Donot do it.
Yep.
Carlos E.R. wrote:
These are basic networking concepts.
We didn't ask to have it explained. Knowing this is not about skills,
though. A mathematician can have very high skills, yet know nothing
about networks. Even a skilled computer programmer may not know about
them, and be a world master on IBM big iron assembler programming (and
being paid handsomely - a tiny fact I happen to know) and not know
offhand what the BSSID is.
Hi Carlos,
The facts are incontrovertible, where only Jon went to the trouble to reproduce them (AFAwK). Everyone else simply used their stone-age knowledge of networking (which we all knew decades ago) to apply to this thread.
Winston just did that, multiple times in this thread, as if stating his own stone-age knowledge of networking has anything to do whatsoever with the topic. Franklin Slootweg tried the same worthless trolling as Winston did.
Please note that there's nothing wrong with people's stone-age knowledge of networking, but their stone-age knowledge, while true, doesn't apply here.
If all they can do in response to the facts posted in this thread is repeat their stone-age thought processes, then they can't possibly add value.
Then you have the trolls like Keith Thompson claiming that running python
on Windows to prove what Apple & Android devices do by default with respect to Wi-Fi protocols has absolutely nothing to do with running python on windows to prove how Apple & Google devices differ from how they handle
Wi-Fi metadata.
WTF?
These people are all applying their stone-age knowledge of networking, but without taking into account the verified *new* information in this thread.
Not a single person who trolled this thread shows any understanding of it.
I don't even know how to explain to people who claim that the router never >>> travels as their belief system is so absurd as to warn me that if theyNo, we don't travel with our routers.
don't understand that people take their routers with them when they move, >>> then that kind of person will never be able to understand, well, anything. >>
My router belongs to the ISP and I have to return it when I move, then I
will get a new one at my destination. You should be intelligent enough
to accept this. Maybe doesn't happen in your nook of the world, but you
must understand that you are posting to an international medium.
WTF?
What kind of absurd arguments are you claiming Carlos?
I don't like broccoli, so nobody on the planet likes broccoli?
More to the point, I don't bring the paintings on my wall with me when I move, but that doesn't mean that nobody brings their paintings with them.
The fact you get your access point from the ISP, while true, is an absurd
way of your attempt to refute the facts proposed in this respected paper.
*Surveilling the Masses with Wi-Fi-Based Positioning Systems*
<https://arxiv.org/abs/2405.14975>
I do take my many access points with me, Carlos. Dozens of them.
And even if I didn't, it would still refute NOTHING in that research paper.
The fact that's your major rebuttal indicates you haven't read the paper. Read it. Please.
I had given up, but recently, I happened to look at Apple's documentation, >>> and I realized Apple proved they had no intent of honoring the long-held >>> intention of a hidden broadcast, by simply changing their documentation. >>> <https://support.apple.com/en-ie/102515>
Ok, finally. The crux of the issue.
It's not hidden.
It is, after all, in the SUBJECT line of this thread, Carlos.
Every person who tried it, found out every single statement to be true.
Carlos E.R. wrote:...
And hiding SSIDs is a complete waste of time, which gains you nothing
in security or privacy. DonN++t do it.
Yep.
There are two fundamental issues which are making this task more difficult:
1. The common trolls are *desperate* to infest this thread
(and yet, not a single one of the trolls can possibly add value),
2. And, people who are NOT trolls, like Carlos above, still do not
(yet) understand the topic because they're applying old knowledge.
On 2026-09-06, Carlos E.R. <robin_listas@es.invalid> wrote:
On 2026-09-06 17:37, Jon Ribbens wrote:
1. Apple are storing the location of "hidden" WiFi Access Points.
(My opinion: low priority.)
Only Apple?
I think that is what Maria is saying, and I have no information to the contrary.
Allegedly: Apple are adhering to this exclusion, but are not also
excluding BSSIDs which are not broadcasting any SSID at all (i.e.
"hidden" networks). Other organisations (e.g. Google) do exclude such
"hidden" networks.
And if it is hidden they would not see if the SSID ends in _nomap.
But is there a consensus that hidden SSIDs should not be listed? In
writing? Maybe there is such a consensus now.
To me it's fairly intuitive that if someone has taken the unusual step
of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
Then you have the trolls like Keith Thompson claiming that running python[...]
on Windows to prove what Apple & Android devices do by default with respect to Wi-Fi protocols has absolutely nothing to do with running python on windows to prove how Apple & Google devices differ from how they handle
Wi-Fi metadata.
WTF?
Keith Thompson argues that your post is off topic in comp.lang.python, because you are not discussing python code. You simply posted a link
that contains a reference to a Python program and said you run it. You
are not discussing the code itself or making any question about it.
And he is right, IMNSHO.
More to the point, I don't bring the paintings on my wall with me when I
move, but that doesn't mean that nobody brings their paintings with them.
I did not say "nobody". That's you reading what is not in what I said.
The fact you get your access point from the ISP, while true, is an absurd
way of your attempt to refute the facts proposed in this respected paper.
I don't refute anything, except that you can only track a minority of
users worldwide.
The fact that's your major rebuttal indicates you haven't read the paper.
Read it. Please.
No.
Every person who tried it, found out every single statement to be true.
It is good Usenet manners to explain the subject in the body.
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
That's purely a correlation. It could be a coincidence. And is there any evidence that the documentation did change? We only have his say so.
The point we are saying is not what you claim it to be. It is not about Apple storing and publishing BSSIDs of hidden SSIDs. This is bad
behaviour by them. Ok. But our point is that you gain nothing by making
your AP hidden in the first place.
I don't remember whether you addressed this ... how does someone
who hasn't visited your address (i.e they already know where you live)
discover what the BSSID of your router is?
What you mention there has been explained to him in the thread here
[Tutorial: Query the Apple database with Python for your access point BSSID] <10h1qmr$2alo$1@nnrp.usenet.blueworldhosting.com>
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:
To me it's fairly intuitive that if someone has taken the unusual step
of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
I guess the challenge here is how can they know not to add the MAC
address if the SSID with the "_nomap" request invisible.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
That's purely a correlation. It could be a coincidence. And is there
any evidence that the documentation did change? We only have his say so.
On 2026-09-07, Chris <ithinkiam@gmail.com> wrote:
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:
To me it's fairly intuitive that if someone has taken the unusual step
of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
I guess the challenge here is how can they know not to add the MAC
address if the SSID with the "_nomap" request invisible.
That's the core of the issue - I would guess that Android devices are
only uploading BSSIDs to the Google database when they see that Access
Point broadcast an SSID, and that SSID doesn't end with "_nomap".
iPhones on the other hand, I would guess are uploading BSSIDs to the
Apple database as soon as they see that Access Point broadcasting
anything, regardless of whether they have seen an SSID from it.
If it works the way I am suggesting, then it means that Google's
database would automatically exclude "hidden" networks, and Apple's
wouldn't - and not only that, Apple would have no way of immediately excluding them. They would need to issue updated iPhone software,
and then wait until almost all iPhones in the world that were still
in use were using the new software.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them,
Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
That's purely a correlation. It could be a coincidence. And is there
any evidence that the documentation did change? We only have his say so.
We can't prove what prompted Apple to change their documentation, but
we certainly can prove that it did indeed change, using archive.org.
In December 2025 the page did not mention hidden networks, and today
it does.
https://web.archive.org/web/20251221213139/https://support.apple.com/en-ie/102515
https://support.apple.com/en-ie/102515
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:
On 2026-09-07, Chris <ithinkiam@gmail.com> wrote:
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:
To me it's fairly intuitive that if someone has taken the unusual step >>>> of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact
that the "_nomap" SSID method doesn't work for "hidden" networks.
I guess the challenge here is how can they know not to add the MAC
address if the SSID with the "_nomap" request invisible.
That's the core of the issue - I would guess that Android devices are
only uploading BSSIDs to the Google database when they see that Access
Point broadcast an SSID, and that SSID doesn't end with "_nomap".
iPhones on the other hand, I would guess are uploading BSSIDs to the
Apple database as soon as they see that Access Point broadcasting
anything, regardless of whether they have seen an SSID from it.
If it works the way I am suggesting, then it means that Google's
database would automatically exclude "hidden" networks, and Apple's
wouldn't - and not only that, Apple would have no way of immediately
excluding them. They would need to issue updated iPhone software,
and then wait until almost all iPhones in the world that were still
in use were using the new software.
Related: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his
entry?
My impression is that as a result of Maria's communications with them, >>>> Apple updated their documentation to note that "hidden" networks are
still listed in their database, and removed Maria's own BSSID(s) from
the database.
That's purely a correlation. It could be a coincidence. And is there
any evidence that the documentation did change? We only have his say so.
We can't prove what prompted Apple to change their documentation, but
we certainly can prove that it did indeed change, using archive.org.
In December 2025 the page did not mention hidden networks, and today
it does.
https://web.archive.org/web/20251221213139/https://support.apple.com/en-ie/102515
https://support.apple.com/en-ie/102515
I agree. And I did the same. The fact that Arlen couldn't very easily evidence his assertion, despite my challenge above, speaks volumes.
I agree. And I did the same. The fact that Arlen couldn't very easilyWhy do you call him/her Arlen if his/her preferred name is Maria? Are
evidence his assertion, despite my challenge above, speaks volumes.
you from the 70s?
Why do you call him/her Arlen if his/her preferred name is Maria? Are
you from the 70s?
I strongly dislike that he is using a woman's name, so I refuse to call
him by that.
But aggregators "can" track your posts across the Internet.
I post to many (many!) forums (web forums like XDA, Telegram, etc.)
Why do you call him/her Arlen if his/her preferred name is Maria?
Are you from the 70s?
Lane,
Why do you call him/her Arlen if his/her preferred name is Maria?
Arlen Holder is a so-called nym-shifter, who changes his nym
once-in-a-while - ostensibly so he cannot be tracked (by the people who scrape the newsgroups for information).
Although you jumped on the gender identity bandwagon, Arlens current name
has got zero to do with it. Current, as in the last number of years he has gone thru a number of them. Male as well as female ones.
Something you could have known if you would either have visited these newsgroups a bit longer or just had asked for it.
Are you from the 70s?
You know what a hypocrite is ? Thats someone who tells someone not to do {something}, while doing that {something} themselves. You know, the "do
as I say, not as I do" kind of person.
Carlos E.R. wrote:
I strongly dislike that he is using a woman's name, so I refuse to call
him by that.
Hi Carlos,
Since almost nobody on these technical newsgroups are females, IMHO, I
think I'll use Maria only for a few years and change it to, oh, Sally.
That would be another clear and obvious indication that I'm not hiding for even a moment FROM YOU, but from robot header aggregation tools, which is more and more of a problem even as I recognized the issue two decades ago.
And while I get why you associate nymshifting with the disgusting trolls,
you need to take an elementary course in Logic (or Occam's Razor at least).
A person has to rob a bank to be called a disgusting bank robber, right?
Just putting a mask on his face for privacy does not make him a criminal.
In fact, your disgusting habit of absurdly claiming everyone who uses a
fake name is a troll is starting to grate on me as it's disingenuous.
R.Wieser wrote:
Lane,
Why do you call him/her Arlen i
I've found that people who mangle transwomen by calling them male
pronouns are the manure of the earth. It's a repeating pattern that I've noticed.
On Tue, 8 Sep 2026 19:51:29 +0300, Maria Sophia <mariasophia@comprehension.com> wrote:
But aggregators "can" track your posts across the Internet.
I post to many (many!) forums (web forums like XDA, Telegram, etc.)
"Ads You See Online Are Now Police Surveillance" <https://www.youtube.com/watch?v=cq36YXrfyJE>
"This video explores how advertising data became a powerful
surveillance tool."
We're all doomed.
But aggregators "can" track your posts across the Internet.
I post to many (many!) forums (web forums like XDA, Telegram, etc.)
"Ads You See Online Are Now Police Surveillance" <https://www.youtube.com/watch?v=cq36YXrfyJE>
"This video explores how advertising data became a powerful
surveillance tool."
We're all doomed.
How would I have asked for this information differently than I did,
Are you from the 70s?
You know what a hypocrite is ? Thats someone who tells someone not to
do {something}, while doing that {something} themselves. You know, the >> "do as I say, not as I do" kind of person.
I've found that people who mangle transwomen by calling them male pronouns are the manure of the earth. It's a repeating pattern that I've noticed.
Chris wrote:
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:Why do you call him/her Arlen if his/her preferred name is Maria? Are
On 2026-09-07, Chris <ithinkiam@gmail.com> wrote:
Jon Ribbens <jon+usenet@unequivocal.eu> wrote:
To me it's fairly intuitive that if someone has taken the unusual step >>>>> of explicitly marking their network as "hidden", then its location
should not be included in these databases - especially given the fact >>>>> that the "_nomap" SSID method doesn't work for "hidden" networks.
I guess the challenge here is how can they know not to add the MAC
address if the SSID with the "_nomap" request invisible.
That's the core of the issue - I would guess that Android devices are
only uploading BSSIDs to the Google database when they see that Access
Point broadcast an SSID, and that SSID doesn't end with "_nomap".
iPhones on the other hand, I would guess are uploading BSSIDs to the
Apple database as soon as they see that Access Point broadcasting
anything, regardless of whether they have seen an SSID from it.
If it works the way I am suggesting, then it means that Google's
database would automatically exclude "hidden" networks, and Apple's
wouldn't - and not only that, Apple would have no way of immediately
excluding them. They would need to issue updated iPhone software,
and then wait until almost all iPhones in the world that were still
in use were using the new software.
We can't prove what prompted Apple to change their documentation, butRelated: What did Arlen (aka Maria) achieve? That Apple agreed to
remove all hidden and _nomap entries, or that they removed only his >>>>>> entry?
My impression is that as a result of Maria's communications with them, >>>>> Apple updated their documentation to note that "hidden" networks are >>>>> still listed in their database, and removed Maria's own BSSID(s) from >>>>> the database.
That's purely a correlation. It could be a coincidence. And is there
any evidence that the documentation did change? We only have his say so. >>>
we certainly can prove that it did indeed change, using archive.org.
In December 2025 the page did not mention hidden networks, and today
it does.
https://web.archive.org/web/20251221213139/https://support.apple.com/en-ie/102515
https://support.apple.com/en-ie/102515
I agree. And I did the same. The fact that Arlen couldn't very easily
evidence his assertion, despite my challenge above, speaks volumes.
you from the 70s?
Jeff Liebermann wrote:
But aggregators "can" track your posts across the Internet.
I post to many (many!) forums (web forums like XDA, Telegram, etc.)
"Ads You See Online Are Now Police Surveillance"
<https://www.youtube.com/watch?v=cq36YXrfyJE>
"This video explores how advertising data became a powerful
surveillance tool."
We're all doomed.
Hi Jeff,
I was wondering where you've been as you seem to have retired from the >Internet service business in recent years.
I see you on the electronics
repair ng sometimes, but rarely here nowadays.
I still remember you proved how the router transmit power claims are >completely bogus, much as Apple's claims of battery efficiency were.
You, of all people, have my true identity as we've conversed a few times
over the years in email and on Usenet about our shared WISP experiences, >e.g., surfnet, ridge, etheric, hilltop, xfinity, et al., and you and I both >personally know most of the local operators, e.g., mike, loren, dave.
When I moved to the Santa Cruz Mountains from flatland in San Jose, I was >shocked there was no wired services, so people only had satellite or WISP.
I ended up inviting the local WISP team to serve me, for free, and as a >result, they serve the whole mountain as I have a repeater on my rooftop.
For years, I provided them with good business by setting up all my
neighbors with 2.4GHz radios and eventually the 5GHz rocket dishes.
At some point they started doing the installations themselves, so I no
longer had to log into every neighbor's router to update the firmware.
I want to THANK YOU for teaching me a LOT of what I know about Wi-Fi >networking, particularly you're pretty clear on how they lie about
decibels, where we have control over our transmit strength if we like.
You also taught me a lot about changing the BSSID, or not, which was well >before Google became big so it's fundamental knowledge you imparted to me.
I very much APPRECIATE all the help you've provided over the decades.
You haven't posted much lately, so I'm happy to know you're still around!
I think we're almost the same age, where I'm an octogenarian, while you're >most likely still a young kid in your 70's, as I recall (but maybe not).
In summary, I love the sagacious sharpness of your sarcasm, which is, like >Paul's, well honed by decades of experience finding things out the hard
way.
I'm HAPPY you're still around, as you, & maybe Jon, & perhaps Lawrence, & >maybe even Andy, are the only ones seemingly capable of understanding this >topic, where if we follow the breadcrumb of the BSSID:GPS pair, the way
Apple does it is COMPLETELY DIFFERENT from the way everyone else does it.
Apple claims "we care about your privacy"... except when they don't.
I moved to the hills in about 1974(?). There were enough lines and
phone numbers for everyone. Near the end of the 1970's, the BBS's
(bulleting board services) and garage ISP's arrived. Available phone
lines and numbers suddenly became scarce. In about 1994, the BBS and
garage ISP's moved into problem office buildings, which freed up quite
a few phone lines, which were immediately consumed by a student
population increase inspired by rapidly rising real estate costs. <https://www.biggestuscities.com/city/santa-cruz-california>
On 9/10/2026 10:46 AM, Jeff Liebermann wrote:
I moved to the hills in about 1974(?). There were enough lines and
phone numbers for everyone. Near the end of the 1970's, the BBS's
(bulleting board services) and garage ISP's arrived. Available phone
lines and numbers suddenly became scarce. In about 1994, the BBS and
garage ISP's moved into problem office buildings, which freed up quite
a few phone lines, which were immediately consumed by a student
population increase inspired by rapidly rising real estate costs.
<https://www.biggestuscities.com/city/santa-cruz-california>
Dear Jeff,
Did you get a ...00 phone number for your landline?
Somehow, I managed
to get a home /landline/ number in Iceland that ends in 00, and you can
give me a call. As I don't live in Iceland anymore, this number is now >S.I.P. and I'll have to turn the "phone" on so give me some advance no-
tice before you attempt at calling me.
Alternatively, I can give you a call using my U.S. based S.I.P. number
and you'll merely have to tell me when is a good time to call you.
Best wishes, and happy phone numbers!--
On Fri, 25 Sep 2026 23:43:07 +0800, Johann 'Myrkraverk' Oskarsson <johann@myrkraverk.invalid> wrote:
On 9/10/2026 10:46 AM, Jeff Liebermann wrote:
I moved to the hills in about 1974(?). There were enough lines and
phone numbers for everyone. Near the end of the 1970's, the BBS's
(bulleting board services) and garage ISP's arrived. Available phone
lines and numbers suddenly became scarce. In about 1994, the BBS and
garage ISP's moved into problem office buildings, which freed up quite
a few phone lines, which were immediately consumed by a student
population increase inspired by rapidly rising real estate costs.
<https://www.biggestuscities.com/city/santa-cruz-california>
Dear Jeff,
Did you get a ...00 phone number for your landline?
No. I've had the same phone number since about 1974. It's in the
signature. However, it's no longer a "land line" using copper wires
from Ma Bell. It's been an Ooma VoIP number since Apr 2022. I use
Xfinity for internet connectivity. I've been retired since the end of
2020 and therefore do not need a reliable service. Best effort is sufficient.
Somehow, I managed
to get a home /landline/ number in Iceland that ends in 00, and you can
give me a call. As I don't live in Iceland anymore, this number is now
S.I.P. and I'll have to turn the "phone" on so give me some advance no-
tice before you attempt at calling me.
Ooma uses SIP (session initiation protocol). To make a SIP call, I
need to connect one of my SIP phones or adapters, and call direct.
However, I have ports 5060-5062 blocked because I got tired of having
my SIP phones probed and crashed.
Alternatively, I can give you a call using my U.S. based S.I.P. number
and you'll merely have to tell me when is a good time to call you.
At this time, I don't want to talk to anyone, especially if I need to reconstruct my SIP phone setup. I've been working on projects that
are going too slowly but which hopefully will end by November (or
December).
Best wishes, and happy phone numbers!
However, I have ports 5060-5062 blocked because I got tired of
having my SIP phones probed and crashed.
On Fri, 25 Sep 2026 13:14:48 -0700, Jeff Liebermann wrote:
However, I have ports 5060-5062 blocked because I got tired of
having my SIP phones probed and crashed.
Are SIP phones that easy to crash?
Have you thought of interposing some kind of intermediary SIP server,
which should be more robust? Kamailio and Asterisk come to mind.
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 74 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 120:00:18 |
| Calls: | 1,194 |
| Files: | 1,352 |
| Messages: | 289,833 |