Tool Reveals iPad and iPhone User Locations
mask.of.sanity writes "A researcher has found that Apple user locations can be potentially determined by tapping into Apple Maps and he has created a Python tool to make the process easier. iSniff GPS accesses Apple's database of wireless access points, which is collected by iPhones and iPads that have GPS and Wi-Fi location services enabled. Apple uses this crowd-sourced data to run its location services; however, the location database is not meant to be public. You can download the tool via Giuthub."
GUITHUB????
The divorce rate will increase dramatically if Apple doesn't fix this ...
Slashdot, fix the reply notifications... You won't get away with it...
And this is why your iDevice should never be set to automatically join wifi networks.
Actually, NO device should be configured to automatically join wifi networks.
(For those who didn't read the docs that go with the software, this relies upon running an access point with no DHCP, which is what forces the iDevice to send ARPs for the last DHCP server it used).
Also, this means that if you want to "hide" your home network, don't run DHCP on your WiFi router, use another device.
Hmmm, "it can be used to find where people live", so can a phone book. ;) A lot of the time summaries take a very specific issue (quoting from Thornburg) "this relies upon running an access point with no DHCP, which is what forces the iDevice to send ARPs for the last DHCP server it used" and escalating it to a more dramatic issue. Sometimes with a very simple partial solution (again from Thornburg) "NO device should be configured to automatically join wifi networks," and a general attack with the open source vs closed or apple vs anyone fighting. Grated the dry description isn't as eye catching but its much more logical.
For the record yes I have an iPhone and no I am not setup to automatically join new wifi networks.
-Xen
-Xen
Taping into a system that is not ment to be public is illegal, right?
As seen in the picture in TFA, there was a (lightning?) talk about this on the 29c3, this was over 5 months ago If they haven't fixed it since, why should the fix it now?
From the github page: "Written by @hubert3 / . Presented at Blackhat USA July 2012, code published on Github 2012-08-31"
Slashdot, News of Last year, today! ;)
But yes, it is a rather cool hack that still works....
http://unfix.org
iOS devices (and many other devices) use the known locations of wireless access points to determine their own location. (They check which wireless access points they can see, with which signal strength, and compare the results with a database of wireless access locations). What this guy found was that he could access the same database. So he can find locations of wireless access locations, which are _not_ iPads or iPhones, and there is no reason to assume that they would be owned by Mac or iOS device owners.
That said, the information should not be available to anything but the operating system on a device.
The "Wi-fi never works again" bug^h^h^h feature is the fix.
Just update you iDevice, or get it warm, or get it cool, or bump it, or don't update it and your Wi-FI might drop off WiFi forever. Fixing the problem! Apple, it just works!
Now you can find that troll and punch him/her in the face... All you have to do is hack their computer, sniff the traffic until you see something from the WiFi router, use this database to find the approximate location of the user then knock on every door withing a 100 meter radius and punch the people that answer... I'm sure one of them will be the troll.
There's a glaring flaw in the summary. In order for this tool to work, the iPad owner has to have used Apple Maps.
Who actually uses Apple Maps? Haven't most of those people already been eaten by kangaroos in the desert or driven into canals?
#DeleteChrome
When is his trial date?
http://arstechnica.com/tech-policy/2013/03/auernheimer-aka-weev-sentenced-to-41-months-for-attipad-hack/
No, Giuthub. Learn to read, asshole.
I hovered over the "download the tool via Giuthub" link and noticed it is pointing to some site called "github" instead of Giuthub, so obviously it is a trap. DO NOT CLICK ON IT!
the only tool here is the person who goes out of way to set up a Linux box and WiFi point to track people. If you consider that the average WiFi has to be reasonably close to the target, then you must already have some general idea about where the target is, a lot of trouble for almost nothing.
There was an unknown error in the submission.
I read this as '''''[The Band] Tool