Is Dublin Airport tracking passenger phones without their permission?(medium.com)
medium.com
Is Dublin Airport tracking passenger phones without their permission?
https://medium.com/@roryireland/is-dublin-airport-tracking-passenger-phones-without-their-permission-8a779453a6d7
3 comments
Considering that they're tracking time spent in queues, and (presumably) also recording video for security purposes, it's possible to associate a MAC address with a person's face, and possibly a person's passport (if they're leaving the arrivals area and passing through passport control). Doesn't this constitute the very conjunction to which the guidance refers?
Having passed through Dublin Airport many hundreds of times, I think it would be an interesting technical challenge mapping one MAC address to one individual given the hundreds of people milling around the security area at times.
That is to say that, while possible, such a mapping is by no means easy or automatic, and it would have to be very calculated and deliberate and even then couldn't be 100% accurate without a whole lot of engineering. In such a case of deliberate and specific design to gather and associate MACs and identities, then yes, the law applies to such a conjunction.
That is to say that, while possible, such a mapping is by no means easy or automatic, and it would have to be very calculated and deliberate and even then couldn't be 100% accurate without a whole lot of engineering. In such a case of deliberate and specific design to gather and associate MACs and identities, then yes, the law applies to such a conjunction.
> challenge mapping one MAC address to one individual given the hundreds of people milling around the security area at times.
You don’t have to work on a static set of MAC addresses and individuals, rather, you can dynamically track arrivals and departures from your crowd of individuals. So instead of hundreds of people being more or less stationary you get movement data on the few new members of the set and on those who left, including whereto or wherefrom they moved.
After tracking not just one crowd but five, it should be possible to map out trajectories for both faces and MAC addresses. The larger the area or surveillance per traveller and differences in e.g. movement speed, the stronger the useful correlation between these trajectories should be.
You don’t have to work on a static set of MAC addresses and individuals, rather, you can dynamically track arrivals and departures from your crowd of individuals. So instead of hundreds of people being more or less stationary you get movement data on the few new members of the set and on those who left, including whereto or wherefrom they moved.
After tracking not just one crowd but five, it should be possible to map out trajectories for both faces and MAC addresses. The larger the area or surveillance per traveller and differences in e.g. movement speed, the stronger the useful correlation between these trajectories should be.
Were I doing it I'd stick APs at the static bottlenecks, so pretty much at the xray scanners. That maximizes the ability to single out individuals.
If I was really serious about it, I'd tie detection timing to the visual signals on the xray machines that tell security agents whether or not you can pass and whether to perform a secondary check.
If I was really serious about it, I'd tie detection timing to the visual signals on the xray machines that tell security agents whether or not you can pass and whether to perform a secondary check.
Funny that this article comes out just as I wrote this:
http://blog.higg.so/2015/11/03/look-at-my-invention/
> I just want to bust open the false narratives surrounding phone culture and speak about the long term implications of having a computer in your pocket at all times that talks to the public Internet.
It's as if the article was designed for the likes of what I wrote in my article. The Big Brother narrative is a false narrative.
> Big Brother gets the brunt of the blame, and not the citizen. In the worst case, the citizen identifies with the aggressor and feeds the narrative: "I am not in control, Big Brother is. I willingly submit my data to third parties". But, you are in control, and you should never forget that. Perhaps you need to work hard at being in control, or challenge more assumptions about that, but in a free and democratic society, we are in control (and empowered) more than we have ever been.
http://blog.higg.so/2015/11/03/look-at-my-invention/
> I just want to bust open the false narratives surrounding phone culture and speak about the long term implications of having a computer in your pocket at all times that talks to the public Internet.
It's as if the article was designed for the likes of what I wrote in my article. The Big Brother narrative is a false narrative.
> Big Brother gets the brunt of the blame, and not the citizen. In the worst case, the citizen identifies with the aggressor and feeds the narrative: "I am not in control, Big Brother is. I willingly submit my data to third parties". But, you are in control, and you should never forget that. Perhaps you need to work hard at being in control, or challenge more assumptions about that, but in a free and democratic society, we are in control (and empowered) more than we have ever been.
How is my device's MAC address not personal information? It is unique and belongs to me, how much more personal can you get?
[my device's MAC address] is unique and belongs to me, how much more personal can you get?
Regardless of its uniqueness, it can't be used by that data controller to identify you because the collector does not have additional information.
I can't identify you by reading your car licence plate, even though that information can be used to identify you by others who have access to a database of cars-to-owners. The point of the law is that I can't use it to identify you, therefore I don't have to notify you when I collect that information.
Regardless of its uniqueness, it can't be used by that data controller to identify you because the collector does not have additional information.
I can't identify you by reading your car licence plate, even though that information can be used to identify you by others who have access to a database of cars-to-owners. The point of the law is that I can't use it to identify you, therefore I don't have to notify you when I collect that information.
> The point of the law is
Is? Or was?
Was the law written when mass tracking of inidivuals by unique serial numbers was common, possible, or feasible?
Is? Or was?
Was the law written when mass tracking of inidivuals by unique serial numbers was common, possible, or feasible?
Well, imo you can argue that it belongs to the device and it's only tracking how the device moves through customs/security/whatever and if they don't attach that info to your name/picture/whatever-other-info then they aren't actually tracking you, just your device.
But I wouldn't be worried about just MAC tracking, you get far better and accurate information by tracking probe requests. Just by capturing probe requests you can at times guess where the target lives, works and even where they spend their free time.
But I wouldn't be worried about just MAC tracking, you get far better and accurate information by tracking probe requests. Just by capturing probe requests you can at times guess where the target lives, works and even where they spend their free time.
Because they don't know who you are from it - the MAC address is not a person, and you can't know who that person is without another database containing the actual personal information.
I just can't get outraged by this. You are walking around literally shouting out a personal identifier and demanding that no one listens.
People need to take responsibility for themselves. If you have a problem with this, TURN YOUR WI-FI OFF.
People need to take responsibility for themselves. If you have a problem with this, TURN YOUR WI-FI OFF.
But I am broadcasting identifiers everywhere I go. The oldest means of recognition in the world is my face, and I don't cover that up wherever I go. I've also got a recognizable smell[1], a recognizable gait[2], a recognizable voice[3], and doubtless many other things that can be used individually or in aggregate to identify me, and that's before we get to contact-based or invasive techniques involving fingerprints, iris recognition, or DNA tests.
Suggesting that people "need to take responsibility for themselves" is tantamount to victim blaming when it comes to broadcasting identities for gathering by third parties. The responsibility for correctly using data should really lie with those that collect the data, and that's what data protection acts in Europe tend to target.
[1] http://www.livescience.com/5188-odor-unique-fingerprint.html
[2] http://www.wired.com/2011/09/walking-biometric-identificatio...
[3] https://en.wikipedia.org/wiki/Speaker_recognition
Suggesting that people "need to take responsibility for themselves" is tantamount to victim blaming when it comes to broadcasting identities for gathering by third parties. The responsibility for correctly using data should really lie with those that collect the data, and that's what data protection acts in Europe tend to target.
[1] http://www.livescience.com/5188-odor-unique-fingerprint.html
[2] http://www.wired.com/2011/09/walking-biometric-identificatio...
[3] https://en.wikipedia.org/wiki/Speaker_recognition
This sounds like a judgement on those who carry phones and don't think too hard about this but then call out those who go phoneless because they (the phone-equipped) don't understand the hardware. This is not a judgement. It's simply challenging the false narratives and assumptions citizens have when they carry a phone around: DO you feel empowered or enfeebled (weakened) by a phone?
These sort of solutions (Wi-Fi and/or Bluetooth based) are already growing in popularity amongst the retail sector (esp. large shopping malls), so no surprise that an airport is doing likewise.
And to be clear, this in no way implies that I am okay with this state of affairs.
And to be clear, this in no way implies that I am okay with this state of affairs.
So maybe we should start randomizing MAC adresses whenever Wifi is turned on.
(Would it be a privacy problem if MAC adresses were very short-lived? I really don't know.)
(Would it be a privacy problem if MAC adresses were very short-lived? I really don't know.)
There would be at least service gaps if you changed MAC on the fly while connected to a network. At worst your packets would go to another device, unless your device announced it's MAC change, which would render the whole operation pointless.
And sniffing for probe requests is way more revealing than just sniffing MAC addresses. Only real solution is to turn off all WiFi and bluetooth devices, latter is getting harder and harder with smart watches, wireless headphones and other stuff.
That being said I'm not worried about being tracked while I move through an airport, since they already have cameras. Also your ticket is pretty telling, they know when it gets printed out, when it gets scanned in security and when it's scanned in the boarding, so you have always been tracked. This just brings more accurate data how long it takes for you to get from point A to B.
And sniffing for probe requests is way more revealing than just sniffing MAC addresses. Only real solution is to turn off all WiFi and bluetooth devices, latter is getting harder and harder with smart watches, wireless headphones and other stuff.
That being said I'm not worried about being tracked while I move through an airport, since they already have cameras. Also your ticket is pretty telling, they know when it gets printed out, when it gets scanned in security and when it's scanned in the boarding, so you have always been tracked. This just brings more accurate data how long it takes for you to get from point A to B.
I think the bigger point is that the roll out of MLA systems is happening in public spaces without any real public debate or knowledge that these things are happening. CCTV is obvious and normally sign posted in a public area, MLA is not...
Apple is already doing it on iOS devices: http://www.techtimes.com/articles/8233/20140612/apple-implem...
But I think it turned out to be ineffective because it doesn't kick in on real world configurations or something? http://m.imore.com/closer-look-ios-8s-mac-randomization
Thank you, I didn't know that
The data protection law exists for the protection of personal data, defined as "data relating to a living individual who is or can be identified either from the data or from the data in conjunction with other information that is in, or is likely to come into, the possession of the data controller"[1]
If the airport authority is not gathering any other information beyond the device MAC address, and is not connecting that information to other information sources (such as MAC addresses gathered from WiFi registrations) then the MAC address cannot be used to identify a living individual.
Now, we all know that there is a correspondence between such a MAC address and a single individual, just as there is with DNA or fingerprints or footfall pattern or voice analysis or facial recognition, or car registration numbers or any of a number of other identifying characteristics. However, the law does not concern the gathering of data (however unique), merely the gathering of personal data that identifies someone in conjunction with other data in the possession of the data controller.
Just because that data could be used to identify someone (in a different system) does not mean that it is covered under data protection obligations in this system.
[1] https://www.dataprotection.ie/docs/What-is-Personal-Data-/21...