41 comments

  • NoSalt1 hour ago
    &gt; <i>&quot;The standard response to privacy concerns is usually &#x27;nothing to hide, nothing to fear.&#x27;&quot;</i><p>&gt; <i>&quot;But here’s the thing: even if you have nothing to hide, you’re still giving away information you probably don’t intend to.&quot;</i><p>Whenever I see talk like this, I always like to post this quote that not only still rings true, but rings even louder today.<p>&gt; <i>&quot;If you give me six lines written by the hand of the most honest of men, I will find something in them which will hang him.&quot;</i><p>~ Cardinal Richelieu (Cardinal and former Secretary of State for Foreign Affairs of France)
  • trashb1 day ago
    &gt; We’ve normalised the idea that Bluetooth is always on. Phones, laptops, smartwatches, headphones, cars, and even medical devices constantly broadcast their presence. The standard response to privacy concerns is usually “nothing to hide, nothing to fear.”<p>I guess anything you send out can be used to profile you.<p>Some of my friends live on a farm near a semi busy road, however far enough from other farms to not be able to receive their wifi. They showed me their router logging all the wifi accesspoints that appear&#x2F;disappear. There where A LOT of access points named &quot;Audi&quot;, &quot;BMW&quot;, &quot;Tesla&quot; etc. similar to those devices leaking bluetooth data. We had a discussion that it would be easy to determine who was passing by at what times due to these especially when you can &quot;de-anonymize&quot; the data for example link it to a numberplate.<p>I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.
    • luma21 hours ago
      You can do this for much cheaper - all four of your tires are broadcasting a unique ID to report tire pressure, the radio to pick it up is cheap (because cars), and TPMS has no facility to randomize or otherwise secure this.
      • Gigachad20 hours ago
        It’s actually even easier, your car has a plate on the front with a unique ID that a camera scans, often to automatically track your park time for ticketing.<p>I can’t really care about obscure Bluetooth tracking when every business has CCTV doing facial recognition.
        • wolvoleo18 hours ago
          Yeah exactly, with a car I would no longer be expecting any type of privacy, sadly.<p>Here in Holland we must even have a mobile phone module in every car so it can call the emergencies in case of a crash.
          • sneak16 hours ago
            It’s all of the EU. It’s literally illegal to sell new cars without a radio transceiver in them.
          • ErroneousBosh8 hours ago
            I&#x27;m in two minds about this. Yes, there are severe privacy implications.<p>But also this happened, just a couple of hour&#x27;s drive from where I live, about ten years ago:<p><a href="https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-scotland-tayside-central-33505854" rel="nofollow">https:&#x2F;&#x2F;www.bbc.co.uk&#x2F;news&#x2F;uk-scotland-tayside-central-33505...</a><p>and similar things have happened about once a year ever since. Now in the news article I linked to a huge part of the problem was that the police didn&#x27;t follow it up correctly, went to where the accident had been reported rather than where it had occurred, didn&#x27;t see anything, and then gave up.<p>But if the car had rung from where it had actually crashed then the incident would have EISEC[1] data tagged to it, which would have given them actual co-ordinates to hit.<p>[1] <a href="https:&#x2F;&#x2F;www.derbyshire.police.uk&#x2F;SysSiteAssets&#x2F;foi-media&#x2F;derbyshire&#x2F;disclosure_2025&#x2F;emergency-call-guidance-booklet-extract---eisec--aml.pdf" rel="nofollow">https:&#x2F;&#x2F;www.derbyshire.police.uk&#x2F;SysSiteAssets&#x2F;foi-media&#x2F;der...</a> (first hit on google)
        • userbinator17 hours ago
          Also, you can read the plate from much farther away than the TPMS sensors.
        • throwaway274486 hours ago
          The plate is pretty trivial to fake though. For one thing you can just remove it, but it&#x27;s trivial to alter with just spray paint. Or using an outdated plate, or someone else&#x27;s plate, etc. it&#x27;s identifying sort of how an phone number is supposed to be identifying: nominal, but not secure and trivially abused for fraud
          • franga20005 hours ago
            It&#x27;s trivial if you&#x27;re concealing your conceal your identity when committing a crime, but a huge pain in the ass and a crime itself if you just want to protect yourself from creeps tracking you.
          • ale424 hours ago
            &gt; The plate is pretty trivial to fake though.<p>Sure it is, but people can&#x27;t realistically think to randomize their plate numbers to avoid tracking... IANAL but is it probably a criminal offense to do so.
          • Asmod4n5 hours ago
            In Europe and the US all new vehicles now have a visible ID under their front window glass, it’s called a VIN. It’s even standardized where it must be.
            • Barbing2 hours ago
              I wonder what the first vehicle to have the VIN under the windshield was. I believe I saw that for the first time maybe 20 years ago (USA).
              • wlesieutre51 minutes ago
                This says 1969<p><a href="https:&#x2F;&#x2F;scholarlycommons.law.case.edu&#x2F;cgi&#x2F;viewcontent.cgi?article=2549&amp;context=caselrev#:~:text=For%20cars%20manufactured%20after%201969,windshield%2C%20from%20outside%20the%20vehicle." rel="nofollow">https:&#x2F;&#x2F;scholarlycommons.law.case.edu&#x2F;cgi&#x2F;viewcontent.cgi?ar...</a>
            • caseyohara5 hours ago
              Are there cameras that can actually read VINs on moving vehicles?
              • ale424 hours ago
                I&#x27;m pretty sure it should be possible if one really wants to do it. Think of a high-power IR flash and a high-res camera synchronized with the flash, with fixed focus on where the VIN would be passing. If the flash pulse is short but strong enough, it should be possible to read the VIN. Maybe some polarizing filters to remove glass reflections are needed.
        • bell-cot4 hours ago
          A camera has quite a few failure modes (bad lighting, fog, dirty lens, obscured by plant growth, privacy laws, etc.) which a TPMS receiver &amp; directional antenna don&#x27;t.
        • hammock15 hours ago
          Wait they use this for parking meters?! Which cities?
          • omgmajk5 hours ago
            Here in Sweden it&#x27;s uncommon. Especially in big parking lots&#x2F;houses.
          • harrall15 hours ago
            I think they’re pretty common.<p>Only reason I know is because I wondered if I could walk to the booth and press the button for a new parking ticket and pay for 5 minutes instead of 4 hours..
        • stinkbeetle10 hours ago
          Even easier, electromagnetic radiation can be used to detect the presence and exact location and movements of not just automobiles, but also people! Many people have detectors for these things that can literally see through transparent material that makes up large sections of the walls of many houses and apartments.
      • everdrive7 hours ago
        I believe that every morning someone in the tech industry wakes up and devises a new place to cram some sort of radio. And it&#x27;s appealing enough the the unwashed masses such that it becomes widely adopted and then unavoidable. I don&#x27;t want TPMS in my tires. It&#x27;s not as if checking tire pressure is difficult. No one will consider moving away from TPMS. You&#x27;ll only hear technologists say &quot;yes, but we could improve the standard! Perhaps encrypt it.&quot; They only know how to solve technological problems with more technology.
      • spockz20 hours ago
        Not all cars have active TPMS. my Volvo xc90 had them but in later models they switched back to passive ones. So it is not even a given for higher end models.
        • ssl-319 hours ago
          That&#x27;s not quite the end of the road, though: The tires themselves often have RFID tags embedded.<p><a href="https:&#x2F;&#x2F;rfid.michelin.com&#x2F;what-is-rfid&#x2F;" rel="nofollow">https:&#x2F;&#x2F;rfid.michelin.com&#x2F;what-is-rfid&#x2F;</a>
          • m-s-y17 hours ago
            much harder to read rfid at a distance
            • ssl-316 hours ago
              It is.<p>My read through this document suggests that the maximum usable range may be as far as 5 meters, or as little as 1 meter: <a href="https:&#x2F;&#x2F;rfid.michelin.com&#x2F;wp-content&#x2F;uploads&#x2F;2024&#x2F;07&#x2F;dataSheet-TireTag-muRata.pdf" rel="nofollow">https:&#x2F;&#x2F;rfid.michelin.com&#x2F;wp-content&#x2F;uploads&#x2F;2024&#x2F;07&#x2F;dataShe...</a><p>That&#x27;s not as far as BLE or TPMS can work at, but it&#x27;s not exactly like the NFC arrangement in a credit card, either. 5 meters is enough for a motivated attacker to do some undetected bulk data collection.
      • stirfish19 hours ago
        I&#x27;ve had trouble reading these from more than a few feet away, but I concede that I have no idea what I&#x27;m doing
    • officeplant1 day ago
      &gt;There where A LOT of access points named &quot;Audi&quot;, &quot;BMW&quot;, &quot;Tesla&quot; etc.<p>That&#x27;s one of the funniest things about wardriving with Wigle on your phone. I can often see the SSID of &quot;Jennifer&#x27;s Equinox&quot;, &quot;Jacks Suburban&quot; right after I get cut off by someone in said vehicle. The vast majority of car bluetooth&#x2F;wifi I see tends to have varying amounts of identifying information. It&#x27;s almost as bad as the fact that apple still defaults to Jacks iPhone&#x2F;iPad etc with no option to rename the device until you&#x27;ve finished setting it up.<p>Companies are not out to protect us with default settings and the majority of users need to wake up to this fact.
      • saghm1 day ago
        This might just be me being uninformed as someone who doesn&#x27;t drive but how are you seeing what wifi networks are available so quickly right after being cut off? My very naive instinct is that looking at your phone or opening up a menu with the available wifi networks on your car&#x27;s display seems like it would require a noticeable decrease in attention to the road, so I&#x27;d almost expect an uptick in being cut off from other people who are annoyed with your driving.
        • officeplant23 hours ago
          Small town, phone is on a dash mounted holder. Sometimes I leave Wigle up just to eye every now and then to see how much crap I&#x27;m picking up while war driving.<p>I am not without sin when it comes to driving a car.
      • reactordev22 hours ago
        What would be next level wardriving would be to break into their Bluetooth and have a conversation about their driving habits.<p>It <i>can</i> be done, relatively easily.
    • Fnoord1 day ago
      Don&#x27;t worry about Tesla&#x27;s being tracked. Via Bluetooth this has existed for at least 7 years [1] (was mentioned on HN as well). Tesla know (also for 7 years), Musk doesn&#x27;t care &#x27;since license plates can also be tracked&#x27;.<p>I used it in train stations, and get hits when passing highways via train or bus. Esp. fun if you stand still due to traffic lights or traffic jam, since you can try to get a visual.<p>The only lesson to be learned here is that it allowed one to learn in 2019 Musk is overrated. But you can also learn that lesson from the book The PayPal Wars which predates this by 15 years.<p>&gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.<p>Not allowed in EU.<p>[1] <a href="https:&#x2F;&#x2F;www.teslaradar.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.teslaradar.com&#x2F;</a>
      • nandomrumber11 hours ago
        &gt; Not allowed<p>This phrasing needs to die.<p><i>Not allowed</i> is something your parents imposed on you when you were a child.<p>You’re not allowed to have an ice cream, or you’re not allowed to hang out with that boy.<p>Laws don’t <i>not allow</i> anything, they only <i>sometimes</i> impose penalties if you’re caught breaking them.
        • palata8 hours ago
          &gt; This phrasing needs to die.<p>If we&#x27;re being annoying about language for no valid reason, I would say that a &quot;phrasing&quot; cannot &quot;die&quot;, because a &quot;phrasing&quot; is not a living creature.<p>&gt; Laws don’t not allow anything, they only sometimes impose penalties if you’re caught breaking them.<p>How does it work with your parents? Do they cast a spell that prevents you from hanging out with that boy? Nobody was &quot;allowed&quot; to smoke, and yet...
          • nandomrumber5 hours ago
            Fortunately for me, words <i>are allowed</i> to have more than one meaning.<p>die &#x2F;dī&#x2F;<p>intransitive verb<p>2. To cease existing, especially by degrees; fade.
            • palata4 hours ago
              I explicitly said I was being annoying for no valid reason. If you want to justify something here, you should probably justify that you weren&#x27;t annoying for no valid reason.<p>Does your dictionary say that &quot;not allowed&quot; is specific to parents and children?
              • nandomrumber26 minutes ago
                From the HN guidelines:<p><i>Please respond to the strongest plausible interpretation of what someone says, not a weaker one that&#x27;s easier to criticize. Assume good faith.</i><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html</a>
      • xaldir21 hours ago
        &gt; Not allowed in EU.<p>I&#x27;m surprised, I know for a fact that some stores definitely have the ability to do that on their hardware.
        • Fnoord3 hours ago
          Only under strict rules, i.e. anonymized one way hash not relatable to a legal person. It isn&#x27;t allowed to track a person that way.
        • thenthenthen16 hours ago
          Utrecht Central Station does this, there are stickers at the entrance notifying the ‘public’ of this. Or its just a sticker;p
        • m-s-y17 hours ago
          and i can commit crimes with my kitchen knives, yet they’re still legal
      • sneak16 hours ago
        It’s done in Europe’s second busiest airport, Amsterdam Schiphol. I saw the advisory signs (so they can pretend that you gave informed consent by walking out of the jetbrige) up just last week.<p><a href="https:&#x2F;&#x2F;media.licdn.com&#x2F;dms&#x2F;image&#x2F;v2&#x2F;D4D12AQHCyctOFz_EJg&#x2F;article-cover_image-shrink_720_1280&#x2F;B4DZonJzLHIgAI-&#x2F;0&#x2F;1761593472707?e=2147483647&amp;v=beta&amp;t=easLfBT1M-7aPM9mT3Xf9VN-APJYv4EUXBwLPt5R28E" rel="nofollow">https:&#x2F;&#x2F;media.licdn.com&#x2F;dms&#x2F;image&#x2F;v2&#x2F;D4D12AQHCyctOFz_EJg&#x2F;art...</a>
        • Fnoord3 hours ago
          The URL which explains the technicalities [1].<p>[1] <a href="https:&#x2F;&#x2F;www.linkedin.com&#x2F;pulse&#x2F;what-wi-fi-bluetooth-tracking-schiphol-really-does-bas-van-der-leij--xd5ef" rel="nofollow">https:&#x2F;&#x2F;www.linkedin.com&#x2F;pulse&#x2F;what-wi-fi-bluetooth-tracking...</a>
    • jorvi21 hours ago
      &gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at<p>In the EU this is forbidden unless they explicitly ask your permission. They can still gather aggregate stats but they cannot build a profile on <i>you</i>.
      • stevage13 hours ago
        I find it curious that the EU, despite it having such a complex parliamentary structure, is able to consistently enact such laws that are good for ordinary people. Are the two connected, I wonder...
        • brigandish10 hours ago
          That&#x27;s the outcome of cherry picking the good things and ignoring the bad, not their decision making structure. Try asking critics of the EU what they don&#x27;t like (a quick search on here will provide plenty of examples) and you&#x27;ll see laws that are not good for ordinary people. Repeat with any jurisdiction, making sure to choose the opposite of your preconception (e.g. ask proponents of the USA&#x27;s system what they like about it) and you&#x27;ll get a better, less biased and more challenging view.
      • wolvoleo18 hours ago
        True but I wouldn&#x27;t put it past them tbh. It&#x27;s very easy to hide or claim a &#x27;misconfiguration&#x27;.<p>Even the airports here track everyone. They say it&#x27;s for public safety but I&#x27;m sure they use it for market analysis for their expensive sandwich shops too.
    • jasonfrost1 day ago
      There&#x27;s an Android app that can find devices, make profiles, and you can track location for as long as they&#x27;re connected. So you can profile passerbys and even get notified when the profile passes through again. I forgot what is was called
      • RunningDroid22 hours ago
        Are you thinking of BLE Radar?<p><a href="https:&#x2F;&#x2F;github.com&#x2F;BLE-Research-Group&#x2F;MetaRadar" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;BLE-Research-Group&#x2F;MetaRadar</a><p><a href="https:&#x2F;&#x2F;f-droid.org&#x2F;packages&#x2F;f.cking.software" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;packages&#x2F;f.cking.software</a>
      • dylan60422 hours ago
        Years ago when BT beacons were newish, I was talking to an AdTechBro that wanted to create the ability from Minority Report where the kiosk recognizes a user, not by eye scans but by recognizing mobile device, so they could offer a personalized whatever. The creepiness wasn&#x27;t something they eased into. It was pretty much instant.
    • tskulbru1 day ago
      &gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.<p>Yes, I remember Cisco had a product like this all the way back in 2011. They could pinpoint a customer to an exact position inside a store using triangulation, they would know which shelf you spent time in front of etc. In the 15 years since then, I expect the technology is much scarier and intrusive.
      • nofunsir21 hours ago
        iBeacon. They know what shelf you&#x27;re standing in front of. What products you touch and read.<p>Ever been in an Apple store? Look up. In the dark voids between the edge-to-edge backlit ceiling. There are secrets there. Watching you.
        • astafrig17 hours ago
          Not what iBeacon does but an entertainingly dramatic description nonetheless.
          • pests13 hours ago
            The only step missing from their description is having the app- or company- specific app installed. For Apple, that is the Apple Store app which everyone has. If you have BT enabled, it can detect the iBeacon and Apple Store can send that back for tracking.
          • nofunsir12 hours ago
            Wrong.<p>&quot;products visitors pick up&quot; [1]<p>[1] <a href="https:&#x2F;&#x2F;itechcraft.com&#x2F;blog&#x2F;ibeacon-for-retail-store&#x2F;" rel="nofollow">https:&#x2F;&#x2F;itechcraft.com&#x2F;blog&#x2F;ibeacon-for-retail-store&#x2F;</a>
        • reaperducer21 hours ago
          Macys pioneered it before there even were Apple Stores. Back when most people didn&#x27;t even know their phones had Bluetooth.
          • shafoshaf20 hours ago
            Macy&#x27;s has Santa clause since 1947 because that is when Miracle on 24th Street came out. And he even knows when you are sleeping.
    • scottlamb22 hours ago
      &gt; We had a discussion that it would be easy to determine who was passing by at what times due to these especially when you can &quot;de-anonymize&quot; the data for example link it to a numberplate.<p>You could also read the numberplate directly with OpenALPR. It can be finicky to set up a camera to do this reliably in all conditions (particularly at night and high speed) but once done you could detect any car passing, not just ones with wifi access points.<p>When the law requires us to have numberplates, I think this just has to be considered public information for anyone who is nearby or can leave a camera nearby. It&#x27;s not ideal to leak it in additional forms that might be easier for people to grab (say, with an ESP32), but it&#x27;s a matter of degree rather than of kind.<p>But yeah, I&#x27;m with you on some of these others, particularly the medical devices. That&#x27;s not great.
      • AlotOfReading21 hours ago
        There&#x27;s a difference between public and Public. I go outside with my face visible and I don&#x27;t mind if my neighbors see me. I <i>do</i> mind if my neighbors stand outside my door with a notepad sketching faces every time they see me or anyone else, especially if they&#x27;re selling the data. Systematic tracking that isn&#x27;t subject to the constraints of human memory and apathy fundamentally changes the equation.
        • scottlamb19 hours ago
          &gt; Systematic tracking that isn&#x27;t subject to the constraints of human memory and apathy fundamentally changes the equation.<p>I definitely don&#x27;t approve of mass collection across many cameras, accessible to who-knows-who with minimal if any privacy controls (Flock). But it wouldn&#x27;t surprise or bother me if my next-door neighbor had ALPR enabled, as long as it&#x27;s not part of that cloud. YMMV.<p>Full disclosure: I develop an open source home&#x2F;hobbyist-oriented NVR, although it doesn&#x27;t have an ALPR feature or any other analytics today.
        • thedrexster21 hours ago
          &gt; constraints of human memory and apathy<p>i like that a lot, brother, thank you!
    • SoftTalker1 day ago
      I disable bluetooth on my phone, though periodically I find that it&#x27;s back on.<p>Edit: iOS
      • craftkiller1 day ago
        I have the opposite experience: GrapheneOS has an option to automatically turn your bluetooth off after a configurable period of not being used. So when I need to use bluetooth, I turn it on like normal. Then, without thinking about it, it automatically turns off. The end result is my bluetooth is only ever on for a couple hours each month when I&#x27;m making phone calls.
        • 999115 hours ago
          Your problem is that you chose an OS that respects you and treats you with dignity.
        • rationalist22 hours ago
          I only see an option to turn back on tomorrow. How do you find this option?
          • craftkiller18 hours ago
            It&#x27;s under Settings &gt; Security and Privacy &gt; Exploit Protection &gt; Turn off bluetooth automatically<p>Definitely not the most obvious location. I would have expected to find this under the bluetooth settings.
            • rationalist14 hours ago
              Awesome, thank you.<p>I don&#x27;t recall that being there when I first installed GrapheneOS. I need to go through the settings more often I guess.<p>It might be a cool feature if settings were highlighted or had a red dot or something until it was viewed (like an unread notification).
        • littlecorner23 hours ago
          Did not realize I could do that! Thank you!
      • joemi18 hours ago
        I used to fervently keep my bluetooth off on iOS, and I learned that if you turn it off via the Control Center, then it automatically gets turned back on the next day. But if you turn it off via Settings, then it only gets turned back on when the system software updates. (I stopped doing this a couple iOS versions ago, though, so it may have changed since then.)
        • jerlam17 hours ago
          Bluetooth (and wifi) aren&#x27;t turned off at all through the Control Center - they changed the wording to say &quot;disconnected&quot;, meaning that your phone only disconnects from known devices. But both are still turned on for other purposes such as CarPlay, Handoff, and Location Services (via wifi). For the purposes of this discussion, they are potentially still transmitting a known identifier.<p>Apple reconnects to known devices and networks at 5am:<p><a href="https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102412" rel="nofollow">https:&#x2F;&#x2F;support.apple.com&#x2F;en-us&#x2F;102412</a><p>Bluetooth and Wi-Fi Aren&#x27;t Fully Disabled When Off in iOS 11 Control Center<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15297387">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15297387</a> (2017, 143 comments)
      • dylan60422 hours ago
        I miss wired headphones for this purpose. It&#x27;s the only reason I even have BT enabled.
        • poolnoodle10 hours ago
          Wired headphones do still exist. :-) I often use a pair of cheap USB C Apple earpods with my Google Pixel.
      • officeplant23 hours ago
        With iOS the easiest way to make sure it off and stays off is to build a shortcut to cut off wifi&#x2F;bluetooth. Otherwise it&#x27;s typically off until you get geolocated as being back home&#x2F;work and wifi comes back on.<p>I have a &quot;store mode&quot; button that just kills wifi&#x2F;bt that I hit before I go into any store.
        • mcosta21 hours ago
          what do you gain doing this?
          • officeplant20 hours ago
            Peace of mind that I&#x27;m not being tracked around the store by wifi&#x2F;bt, and&#x2F;or having my device fingerprinted for further identification on future visits.
      • silon421 day ago
        Android now has an option to enable it every day.. (I have it disabled).
    • wolvoleo18 hours ago
      &gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall<p>They do but most phones rotate the mac adress these days. So while they can still track you through the store (sadly) they don&#x27;t have the ability to track your recurring visits.<p>I wish phones had the option to constantly spam broadcasts with random MAC ids. That would make the practice useless.
    • KolibriFly8 hours ago
      Even when they claim it&#x27;s &quot;anonymous,&quot; the value is in aggregate behavioral patterns: dwell time, repeat visits, path through the space, etc.
    • bryanrasmussen11 hours ago
      &gt;I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is. They know what section of the store you spend most of your time in and what storefronts you stall at.<p>hmm, I wonder if there is anything about using this to combat shoplifting... short google later, seems there is, but mostly everything I&#x27;m finding is just brochures and breathless corporate announcements.<p>found this uni project <a href="https:&#x2F;&#x2F;capstone.cse.msu.edu&#x2F;2020-01&#x2F;projects&#x2F;meijer&#x2F;" rel="nofollow">https:&#x2F;&#x2F;capstone.cse.msu.edu&#x2F;2020-01&#x2F;projects&#x2F;meijer&#x2F;</a>
    • chasil22 hours ago
      The GrapheneOS variant of Android will disable both Bluetooth and WiFi after a set period of inactivity.<p>There is also a Bluetooth shutoff app on F-Droid.<p><a href="https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;packages&#x2F;com.mystro256.autooffbluetooth&#x2F;" rel="nofollow">https:&#x2F;&#x2F;f-droid.org&#x2F;en&#x2F;packages&#x2F;com.mystro256.autooffbluetoo...</a><p>I have also put an Airtag clone in my car (Loshall in iOS mode). That is probably leaking my arrival times. My water meter is also now bluetooth.
    • King-Aaron15 hours ago
      &gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is.<p>I worked for a company about 18 years ago where we did just this. We also sold the technology to car dealerships who were very interested in our silent salesman stuff where you could tie interactions with your web campaign directly to the person walking past the dealership and preload the salesman with all their details.<p>Grubby stuff nearly two decades ago.
    • autoexec1 day ago
      &gt; I believe shopping malls often use such signals (wifi, bluetooth) to track what your travel pattern through the mall is.<p>Many places do this. The department stores in the mall, target, even grocery stores do it.
    • voidmain000118 hours ago
      Sure, stores use WiFi access points and BT to track MAC addresses and BT device IDs. Google does something similar with location and it provides in real time how busy a location is which I find super convenient. It’s a shame that shaping data into useful information also means it can weaponized.
    • jlarocco2 hours ago
      I was researching bluetooth low energy for a project, and discovered &quot;Beacons&quot;: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bluetooth_Low_Energy_beacon" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bluetooth_Low_Energy_beacon</a><p>What&#x27;s more insidious than just tracking people through the store is that the beacons can collect the bluetooth IDs of the devices they&#x27;ve seen and send it off to advertisers, who can use the UUID to connect a person&#x27;s offline shopping with the online advertising profile they&#x27;ve built up for the person.
    • pixl971 day ago
      &gt; even medical devices constantly broadcast their presence<p>I mean yes, said medical devices are a whole lot less useful to me if they are not transmitting data. For some of this stuff you can&#x27;t have your cake and eat it too.
      • 0x1ch1 day ago
        I was wardriving my neighborhood and realized my elderly neighbor&#x27;s CPAP machine is broadcasting some type of BT signal 24&#x2F;7. I imagine it&#x27;s transmitting some important stats, but it did make me have a 2nd thought about medical devices being IoT or BT enabled.
        • kccqzy23 hours ago
          &gt; being IoT or BT enabled<p>Please don’t conflate these two. I have lots of BLE wearables and other sensors. They only send data to my own computer which I control, unlike IoT devices which by definition send to a third party on the Internet. To me it is far more important to protect against strangers on the Internet versus someone wardriving the neighborhood.<p>On a related note, did you know that EU has a Radio Equipment Directive (RED 2014&#x2F;53&#x2F;EU) that came into effect in 2025. It all but guarantees that such Bluetooth communication will be encrypted.
          • bigiain19 hours ago
            &gt; I have lots of BLE wearables and other sensors. They only send data to my own computer which I control<p>That&#x27;s perhaps technically correct, but a naive interpretation of the risk. I don&#x27;t need to see the data your BLE devices are sending you, all I need is traffic analysis and meta data from the signals they are broadcasting - and they broadcast that to anyone within detection range which includes attackers with much higher gain antennas than you who can likely pick up those broadcasts at ten times the distance any of your devices will communicate at.<p>&quot;Flying helicopters low and slow over the Tucson desert in Arizona, the FBI has been using &quot;signal sniffers&quot; to try to locate Nancy Guthrie&#x27;s pacemaker.<p>As the search for the 84-year-old mother of US Today show anchor Savannah Guthrie entered its third week, investigators took to the sky with advanced bluetooth technology.<p>They were hoping to pick up signals emitted from the device implanted in Ms Guthrie&#x27;s chest to help trace her whereabouts, US media outlets NewsNation and Fox News reported.&quot;<p><a href="https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-02-16&#x2F;nancy-guthrie-pacemaker-signal-sniffer-suspected-kidnapping-fbi&#x2F;106348848" rel="nofollow">https:&#x2F;&#x2F;www.abc.net.au&#x2F;news&#x2F;2026-02-16&#x2F;nancy-guthrie-pacemak...</a>
        • wolvoleo18 hours ago
          Yeah I always keep my cpap on airplane mode. It even had 5G. The therapist complains they can&#x27;t monitor it but I have to come in with the machine and SD card every few months so they can check it then. They don&#x27;t need 24&#x2F;7 access.<p>What bothers me more is that my sex toys broadcast on Bluetooth even when I&#x27;m using them through WiFi. It even says the brand in the device name.<p>Not that I give a fuck what the neighbours think but it&#x27;s just none of their business. And some toys are for discreet outdoor use too. Though that&#x27;s not my thing.<p>In the past I renamed one of my phones to &quot;Lovense Hush&quot; to troll, though I&#x27;ve never seen anyone looking suspiciously. I guess most people aren&#x27;t creeps like me who check stuff like that :)
      • xanrah1 day ago
        There’s a middle ground here. There is no technical reason a pacemaker constantly broadcasts itself - there is ways to allow communication to such devices without yelling your name all the time. And there is definitely no reason for such a name to be a unique identifier.
        • just697915 hours ago
          That middle ground has been eroded by cost-cutting.<p>Example: my mother had a cardic resynchronization device, and it had some kind of NFC type thing to enable the full wireless comms mode: wave a wand over her shoulder and the device&#x27;s radio wakes up for a set time to send data or receive adjustments. So it wasn&#x27;t always transmitting, but it did require the doctor&#x27;s office or hospital to have that NFC wand to initiate any kind of data aquisition or reconfiguration. If it has an always-on BLE radio, the provider would just needs the phone&#x2F;tablet&#x2F;laptop with appropriate software that is already required.<p>Since any device like is already going to have a radio equivalent to a BLE radio, then removing the NFC parts from the device (and especially from the provider side) is some amount of cost savings. I think most patients would disagree that this privacy trade-off is NOT worth it, but you have remember that the patients aren&#x27;t usually the actual customers in the US health care system. (And most manufacturers are going to have the US market as a target at least somewhat.) The most common actual customer is actually the insurance companies, and they&#x27;ll take every single fraction of a penny, along with &quot;an arm and a leg&quot;.
        • ssl-319 hours ago
          There are technical reasons, though.<p>Let&#x27;s suppose we have a pacemaker, and it has data that is beneficial to read -- maybe even in real-time on their pocket computer, or opportunistically as the patient walks by their reader-device, or however that is done.<p>So we want this data, and we want it over RF. It probably seems obvious that it should only transmit when it is told to do so, right?<p>So how do we tell the pacemaker to transmit? On its face, that problem seems solved by integrating a receiver that sits and waits for a valid instruction.<p>Except: That receiver takes power to run. And since changing batteries inside of a person is problematic, we want them to last as long as they can while still performing the desired task.<p>Now we get to the not-obvious part: In terms of power, it&#x27;s often less costly to intermittently transmit a string of data than to continuously operate a radio receiver. And maybe it&#x27;s a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway.<p>But a transmit-only radio? Good luck hacking that.<p>So... we do intermittent transmission, and this works for pacemakers. It also works for the cheap Zigbee thermometer I have (wherein I don&#x27;t normally <i>request</i> the temperature; it just delivers it periodically, and it runs for years and years on a coin cell).<p>(Now: Should that pacemaker data be encrypted? Yes, of course. And so should the ID. In fact, the whole transmission should be indistinguishable from background noise by unrelated devices. In this way, authorized devices can then use pre-shared keys to receive and decode these messages and others receive nothing. That kind of cuts BLE and thus also the pocket computer out of the monitoring mix, but tradeoffs are tradeoffs.)
          • palata8 hours ago
            &gt; In terms of power, it&#x27;s often less costly to intermittently transmit a string of data than to continuously operate a radio receiver.<p>The fair comparison would be intermittently transmitting a string of data versus <i>intermittently</i> operating a radio receiver, wouldn&#x27;t it?<p>Maybe it&#x27;s still less costly to transmit, that I don&#x27;t know. But I am interested about it :-).<p>&gt; And maybe it&#x27;s a bad idea to have an implanted pacemaker that has an open receiver for anything nearby to try to fuck with, anyway.<p>This part resonates more with me.
        • pixl971 day ago
          I mean if not a name, how would a mac id be any different?
      • dietr1ch1 day ago
        What forces devices to constantly stream data? You can batch updates and probably save power thanks to it.
        • kccqzy23 hours ago
          Because these BLE devices are so cheap that they don’t have storage. And BLE transmission is already very power efficient: the power consumption of BLE is probably the same order of magnitude as powering flash storage.
  • WaitWaitWha16 hours ago
    I am personally aware that Washington DC, same areas of Maryland, Virginia and Delaware have been tracking car Bluetooth (and EZ-Pass) for decades for &quot;traffic management&quot;. The more BT detected the heavier tracking. The longer time between detectors for the unique BT&#x2F;EZ-Pass, the slower the traffic. Adjust traffic lights down the road to improve traffic flow. (when I write Ez-Pass, i mean the toll transponder, but <i>not</i> detected by a toll booths or overhead arches.)
  • moontear11 hours ago
    Introducing the „are they home“ device to assist burglars. Just slap that miniature device somewhere non-suspicious on the place of your potential marks and let it run for the battery life of 7 days. Afterwards you collect it and know movements patterns.<p>Features automatic notifications if no movement detected for more than two days.
    • KolibriFly8 hours ago
      To be fair, that&#x27;s basically a variation of techniques that have existed long before Bluetooth
      • moontear8 hours ago
        I don&#x27;t disagree, nothing new to see here. I just thought that this would be a nifty device to sell via nefarious shops. Include some more passive tracking of WiFi and bob&#x27;s your uncle. Maybe add mesh functionality via LoRaWAN and track the whole neighborhood.
  • KolibriFly8 hours ago
    Bluetooth, Wi-Fi, even things like tire pressure sensors... they were designed primarily for convenience and interoperability, not adversarial environments. Now we&#x27;re retrofitting privacy onto systems that were never really built with that as a first principle
  • TheSilva1 day ago
    Tangential, sort of: in the early days of mobile phones for the masses, when there was no WiFi&#x2F;3G in the underground, I will often enable Bluetooth in my phone, look for nearby devices and try to match names and looks.<p>That was before everyone had their &quot;John&#x27;s IPhone&quot; or &quot;Samsung A55&quot; boring names everywhere and some of us cared to personalise our device&#x27;s name.<p>Anyone else played this game?
    • herghost23 hours ago
      hmmmmm...<p>2006, sat in a job interview. Interviewer says he&#x27;ll Bluetooth over a file to me - what&#x27;s by phone&#x27;s name?<p>2006, the year that Tool&#x27;s 10,000 Days had been released, which I was enjoying and, being a bit of an Edge Lord, I&#x27;d named my device after a lyric from Vicarious - which, IIRC fit perfectly into the name space and made me very happy:<p>&gt; ILikeToWatchThingsDie<p>Excellent. Still got the job though!
    • jjkaczor1 day ago
      Hah, I change my device name and wifi hotspot all the time...<p>&quot;[Agency-acronym] Surveillance Van #43&#x2F;44&#x2F;etc..&quot;
    • fer18 hours ago
      What I remember is that you could push OBEX calendar objects without much refusal from the phones and make people have alarms ringing at 3am, fun times!
    • keraf8 hours ago
      When I set up my iPhone and it asked who&#x27;s iPhone it is, I thought it would be funny to put in Kim Jong Un. Now it shows up as &quot;Kim Jong Un&#x27;s iPhone&quot; when I enable my hotspot. Or even better, it says it out loud when I connect to some Bluetooth speakers.
    • styfle1 day ago
      Did you ever try to communicate with them?<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bluejacking" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Bluejacking</a>
    • oarla1 day ago
      Yeah, but it stopped pretty soon stores figured out that they could flood you with advertisements over Bluetooth. In some places it was bad enough that I had to turn off Bluetooth.
      • patja1 day ago
        How did this play out? Were the ads from an app from the store that you had installed? Or did they spam you over SMS because they associated your bluetooth info with an account you have with the store, or contact info they bought from a third party?
        • dylan60422 hours ago
          &gt; Were the ads from an app from the store that you had installed?<p>This is my main concern over installing apps in general but specifically store apps. I&#x27;ve noticed that grocery stores are moving past existing loyalty cards and want you to use their apps for exclusively available digital coupons. The prices I&#x27;m seeing are very compelling and are on top of existing loyalty card discounts, and I could see lots of people using the app because of it. The assumed amount of abuse keeps me from lemminging my way through the store.
          • nonamenoslogan18 minutes ago
            Kroger here has done that with their app. The loyalty card&#x2F;phone number still works for many of the specials, but the &quot;digital deals&quot; thing by using the app and scanning a QR code on the price sticker gives BIGGER discounts. Its not the most convenient way to shop, but I am willing to save 15-20% more usually.
        • edent19 hours ago
          Neither. They used to discover your device and then send a Bluetooth push. &quot;Would you like to receive a file from …&quot;<p>It was usually an image, movie, or audio file.
          • patja17 hours ago
            Wow that is wild. Thanks for explaining.<p>I&#x27;ve never seen a prompt like that on my phone and would not have guessed this.
        • oarla16 hours ago
          As someone explained it below in this thread, walk into a mall with Bluetooth turned on and phone starts chiming with multiple &quot;... wants to send you a media&#x2F;audio&#x2F;image etc.&quot; Not just ads, some bad actors would try to infect the phone with malware. Luckily never happened to me, but I heard from my acquaintances.
    • Yep 100% did the same.<p>It was interesting to see what people named stuff as even back then I figured you could use that metadata for tracking devices...but even more interesting was looking at the Mac address to see the manufacturer and try and find some rare or cool device.
    • I do the reverse. I set my wifi hotspot or bluetooth to &quot;MetPoliceUnit355&quot; and I look for people making faces or looking around.
  • nine_k1 day ago
    This is not very different from collecting visual cues. You can notice a delivery van arriving. You can see the driver&#x27;s face, same with passers-by. The biggest difference is that a camera needs to be more conspicuous, while a BT receiver can be invisible and undetectable. Much cheaper, too.
    • bigiain19 hours ago
      I have an ESP32 Cam in front of me right now. I think I paid maybe 8 bucks for it. If I wanted to, I could very easily hide the tiny camera in my front door, and use it to both collect bluetooth and wifi metadata (including MAC addresses) and correlate images&#x2F;faces to MAC addresses when people pass by close enough so that I can identify them later from longer range wifi&#x2F;ble detections.<p>(I actually do plan to install this at my front door, but aimed mainly to detect when a deliver&#x2F;parcel in on my doorstep, and I don&#x27;t (yet?) plan on sniffing bluetooth&#x2F;wifi with it)
      • nine_k17 hours ago
        A decent optical part is comparably expensive, and somehow visible.
  • dalemhurley21 hours ago
    Ring: thank you for the idea, &quot;Introducing Ring Face-Off, face masks covering faces during a break-in is no an issue for Ring, we will track the thieves until they reveal their face to our Ring network.&quot;
    • bigiain19 hours ago
      For immediate release: BLE N95 Facemasks Inc (YCombinator Summer 2025) is proud to come out of stealth mode and announce our acquisition by Ring. This follows a major private angel investment by Palintir with a post money valuation of $500 million.
  • clarabennett2623 hours ago
    The part about passively detecting delivery driver patterns from a home office is wild. I knew BLE was chatty but being able to correlate device pairs (phone + watch) to build movement profiles with just a Pi is genuinely unsettling. Makes me want to audit which of my devices are broadcasting when they don&#x27;t need to be.
    • thenthenthen16 hours ago
      I mean.. these services have apps right? It is, mostly, pretty trivial to track drivers and it would not surprise me if they have a fixed ID.
  • anonymousiam13 hours ago
    Within the past two years, I began leaving BT turned off on all of my devices unless I needed it. It means that I need to pause a moment to turn it on when I get in the car, use my headphones&#x2F;airpods, or other BT devices.<p>For me, it&#x27;s worth the extra trouble because I noticed a significant reduction in battery life on my mobile devices. The reduction coincided with the rollout of Apple&#x27;s &quot;Find My&quot; service, which was followed by Google&#x27;s &quot;Find Hub&quot; service. (I have devices in both ecosystems.)<p>I wish there was a separate way to opt out of the &quot;Find&quot; services, but AFAIK, even if you opt out, your device may still relay traffic from other nearby devices. So it seems that the only way to preserve device battery life is to just shut off the BT.
    • chii11 hours ago
      &gt; I began leaving BT turned off on all of my devices unless I needed it<p>i&#x27;ve been doing that since the inception of BT being available on my devices. I&#x27;m just surprised at so many people&#x27;s cavalier attitude to security and privacy. And then later, it is too late to reverse course.
      • GordonS11 hours ago
        Same. Security aside, I also didn&#x27;t want to waste the battery when I knew I was unlikely to use Bluetooth.
  • gruez1 day ago
    Bluetooth desperately needs mac randomization. Wifi mac randomization is welcome, but it doesn&#x27;t do much when many (most?) people have bluetooth accessories broadcasting a persistent identifier whenever they&#x27;re on.
    • avidiax23 hours ago
      &gt; Bluetooth desperately needs mac randomization.<p>Bluetooth already has a well developed MAC randomization scheme.<p>Lookup &quot;resolvable private address&quot;. The short of it is, your phone can find your headphones or vice-versa, despite one or both having random addresses. The addresses can be regenerated or rotate at an interval (say 15 minutes). The first part of the address is a nonce (pRand), and the rest of the address is a 24-bit hash of pRand with an identity resolving key (IRK). So the other party just listens passively for addresses, and sees if any of them happen to have the right hash.<p>I don&#x27;t think this is as airtight as people think it is. Certainly, if you are following somebody and one address disappears right as another appears (rotation), it&#x27;s quite easy to infer the new&#x2F;old addresses belong to one device. I tried briefly to convince the Android developers to synchronize that rotation globally.<p>You can also probably infer that if you see a pair of random MACs arrive, and they have a certain pattern of timing and payload size, you can say with some certainty that they are particular devices, say an iPhone and an Apple Watch. But that requires sophisticated equipment since most Bluetooth LE communication is over a non-cryptographic frequency hopping arrangement.<p>Lastly, radio fingerprinting is widely known in academia, but requires special equipment.
      • bigiain19 hours ago
        &gt; Lookup &quot;resolvable private address&quot;. The short of it is, your phone can find your headphones or vice-versa, despite one or both having random addresses.<p>Is that just for the connection phase? Or does it then start publicly broadcasting a persistent MAC onced it&#x27;s connected, so if you earbuds or watch are connected and communicating with your phoine, would a sniffer see a persisten MAC address or the session randomised one?<p>That&#x27;s a problam (one of many problems) with WiFi MAC address randomisation - you can sniff the network names a phone is trying to connect to, then stand up a wifi access point with one of those names and the phone will reveal its real MAC address when it connects. I experimented a long time back with having a raspi that broadcast itself as a McDonalds free wifi access point, a huge number of phones would try to connect while I was out in public with it.
        • gruez19 hours ago
          &gt;That&#x27;s a problam (one of many problems) with WiFi MAC address randomisation - you can sniff the network names a phone is trying to connect to, then stand up a wifi access point with one of those names and the phone will reveal its real MAC address when it connects.<p>That&#x27;s not how mac address randomization works now for both android and ios. Both connects with a randomized mac as well, which might be persistent per-network, but it still heavily hampers data collection. For ios specifically, it also seems to have some sort of heuristic to detect which network names are common&#x2F;guessable, and use a rotating mac for those. Moreover &quot;you can sniff the network names a phone is trying to connect to&quot; isn&#x27;t really a thing unless the network is using hidden ssid, which isn&#x27;t the default for almost all routers.
          • bigiain19 hours ago
            Oh cool, thanks. My last time playing with this was pre covid, possibly 5 or more years pre covid.<p>I do know for sure that my iOS devices connect with persistent MAC addresses on both my home and work wifi networks - I&#x27;d _assumed_ it was the same MAC address on both networks, but I&#x27;ll be curious to see if that&#x27;s correct next time I&#x27;m in the office.
            • gruez18 hours ago
              You don&#x27;t even need to be in the office to see it. Just go to wifi -&gt; edit, and it&#x27;ll bring up a list of saved networks. Tap on one of them and it&#x27;ll show the mac address used.
    • neilalexander1 day ago
      Random Bluetooth MACs are already possible. iOS devices have been doing it for years alongside the random Wi-Fi MACs.
  • electrosphere2 hours ago
    This gives me a homebrew project idea - to create something portable that would allow me to sniff Bluetooth devices on my daily train commute into the office.<p>Has anyone done this or can give me ideas where to start?
  • cm-t7 hours ago
    Parisians Métro &#x27;s ads screen are equiped with BT scanner, with a hidden sticker on the side to link you with a qrcode to a RGPD output website, where you have to log your private data to register your devices to be not scanned...<p>What a world to be alive..
  • jeena1 day ago
    About 10 years ago i had HomeAssistant running and thacking my bluetooth devices. It does so per default by jus memorizing a mac adress an recording when it&#x27;s visible and when not. No need for pairing or anythung. It also stores the custom name if available.<p>Anyway, the default dashboard also automatically generated a view when my neighbours &quot;Katie&#x27;s iPhone&#x27; was at home and when not, until I actively deleted it and the data it stored.
    • avel1 day ago
      Similar story - &quot;Home assistant picked up my neighbours Bluetooth toothbrush and now I can see when they brush their teeth&quot;<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;homeassistant&#x2F;comments&#x2F;1306pcw&#x2F;home_assistant_picked_up_my_neighbours_bluetooth&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;homeassistant&#x2F;comments&#x2F;1306pcw&#x2F;home...</a>
  • RockRobotRock12 hours ago
    The AI written blog posts will continue until morale improves.
    • stingraycharles7 hours ago
      &gt; The Problem Nobody Talks About<p><i>head explodes</i><p>do these people writing these blog posts not recognize just how super bad their blog posts look with this slop?
  • stevage14 hours ago
    Years ago I was interested to discover that my local road authority uses Bluetooth tracking of drivers to monitor traffic speed on certain major roads. Detect a particular Bluetooth ID at one point, pick it up again 2km down the road, you know how fast the traffic is going. Pretty useful for getting an immediate alert if traffic speed suddenly plummets.
  • ggm14 hours ago
    Heard a talk in Paris about a guy who &quot;war drove&quot; around town using a higher layer Mobile IP ap which could sweep up open SSID, connect, and (ab)use the bandwidth to maintain a link &quot;above&quot; it (I guess like an agile VPN)<p>he was getting 100mbit class speeds routinely. Also patches of nothing, but it was interesting. That was over 5 years ago.
  • keraf8 hours ago
    Over a decade ago, I already saw a music festival using Bluetooth tracking to monitor crowd movements [0]. There&#x27;s an assumption that people just leave their Bluetooth on out of convenience.<p>[0] <a href="https:&#x2F;&#x2F;actu.epfl.ch&#x2F;news&#x2F;using-bluetooth-to-track-crowds-at-the-paleo-music&#x2F;" rel="nofollow">https:&#x2F;&#x2F;actu.epfl.ch&#x2F;news&#x2F;using-bluetooth-to-track-crowds-at...</a>
  • cadamsdotcom23 hours ago
    This could be used for a truly eye-opening art installation: a screen that as you walk by it, tells you when you were last there..<p>Even wilder would be to buy data on you in real time and display that.
    • supertrope22 hours ago
      The Hollywood movie Minority Report has a scene where an advertising display personalizes the ad by your name. <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=7bXJ_obaiYQ" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=7bXJ_obaiYQ</a>
  • SUDEEPSD251 hour ago
    Weirdly intriguing!
  • bpoyner1 day ago
    &quot;We agreed on a 150-day disclosure window&quot;. Isn&#x27;t that longer than Google Project Zero gives to release fixes?
  • ifh-hn1 day ago
    Wonder what the difference is between this and: <a href="https:&#x2F;&#x2F;github.com&#x2F;ArgeliusLabs&#x2F;Chasing-Your-Tail-NG" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;ArgeliusLabs&#x2F;Chasing-Your-Tail-NG</a>
    • RamRodification22 hours ago
      That one doesn&#x27;t seem to do bluetooth at all, I think?
  • dwedge10 hours ago
    Something about them saying they use Proton pass so they don&#x27;t need to have secrets in pipelines as an example of being into privacy rubbed me the wrong way
  • haberlerm18 hours ago
    BLE Tire pressure sensors are great vehicle identification devices. Static MAC adress gives 4 unique keys to a vehicle when actively scanning.
  • jjbiotech1 day ago
    I suspect the e-scooters left around town (Lime, Bird, etc) are massive Bluetooth &#x2F; LoRa dragnets. You pay them to increase coverage or visibility to social hot spots.
    • thenthenthen16 hours ago
      There is a startup (in Stuttgart i believe?) that adds camera ms to these scooters.. this is 100% illegal (and I think the ccc is filing lawsuits?). Some of the earlier Tier model scooters even had a dedicated space for a camera in their head tubes.
    • hammock1 day ago
      Wow e-scooter wardriving is something I hadn’t thought of. Could be happening somewhere
  • f0r3st21 hours ago
    you said &quot; blocking ads network-wide with AdGuard&quot;. It&#x27;s better to block it with a Pihole.
  • bigbuppo20 hours ago
    I can assure you this has been talked about and is known and it&#x27;s why you still find a headset port on devices handed out to government officials, though most of them ignore the advice to not use bluetooth.
  • catsquirrel2821 hours ago
    &gt; This isn’t about paranoia. It’s about understanding the trade-offs<p>&gt; Bluetooth mesh networks—no internet required, no servers, no phone numbers<p>LLM slop. Both the article and the Python script
    • the-anarchist16 hours ago
      I second that. This website, including its look and layout, appears to be a copy of some more prominent indieweb ones that have been frequently featured here, filled with what seems to be almost entirely copied and&#x2F;or LLM generated content.
  • farkanoid12 hours ago
    Somewhat related - I&#x27;ve been working on a design using Nordic&#x27;s NRF52840 SOC for work; Intensely focusing for the past few weeks on antenna tuning for maximum BLE range.<p>Part of the testing involves using the &#x27;nRF Connect&#x27; app, which lists all nearby Bluetooth devices, plots signal strengths, and allows for some rudimentary communication. It doesn&#x27;t seem to be Nordic-specific.<p>I&#x27;d frequently leave the app open scanning during development late in the evening, and rarely, an unidentified Bluetooth LE device would pop up for a few minutes then disappear.<p>Turns out it was my dad&#x27;s pacemaker, which sends telemetry via Bluetooth to a 4G gateway they gave him (this only happens after he lies down with little movement apparently).<p>This prompted me to look into pacemakers and deactivation after death of course. I wish I hadn&#x27;t, it turns out they leave it in the corpse unless it&#x27;s scheduled for cremation.<p>Because of the aforementioned research, and the open field tests I was performing, it somehow devolved into me having a nightmare where I was RF testing at a graveyard, and the app suddenly displaying a bunch of pacemakers underground.<p>...I really hope this isn&#x27;t possible - The signal through 6ft of dirt and concrete would be marginal but still detectable.
    • Footprint05213 hours ago
      Random question, but will this be open sourced at any point? Just asking as a curious party who just bought one for exploration lol<p>Also super random question but would you happen to have any idea&#x2F;advice on how to get a Raytac MDBT50Q-CX Nordic nRF52840 Dongle (<a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B0DP6MVDZQ" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B0DP6MVDZQ</a>) flashed with ButteRFly (<a href="https:&#x2F;&#x2F;github.com&#x2F;whad-team&#x2F;butterfly" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;whad-team&#x2F;butterfly</a>)?<p>I got it flashed through nrfutil with sniffer and sweyntooth, but butterfly has not been working no matter what I try and do…<p>Thanks for even taking the time to read this :)
  • kevincloudsec1 day ago
    ran something similar on a home network once and was surprised how many of my neighbors&#x27; devices showed up with full manufacturer names and model numbers. you don&#x27;t even need to try hard.
    • wolvoleo18 hours ago
      Yeah here in the city I scan for 2 minutes and I know half the neighbours names and what phones, computers and TVs they use.
  • rsync23 hours ago
    The project describes - and shows - a web interface.<p>Is there a simple CLI interface that can be redirected or pipelined into other tools ?
    • kccqzy23 hours ago
      The article says the data is in a SQLite database.
      • rsync23 hours ago
        Yes I see that and I wonder if the project includes a CLI tool.
  • webdoodle1 day ago
    Doesn&#x27;t HackRF with Cha0s do something similar?
  • fennec-posix19 hours ago
    Emit at your own peril
  • dncornholio8 hours ago
    FYI WiFi leaks the same metadata, so turn that off too if you disable BT.
  • 0xdeadbeefbabe21 hours ago
    Wait doesn&#x27;t BLE randomize the UUIDs?
    • nmstoker16 hours ago
      Yes, I was surprised there would be enough to go on with the MAC addresses rotating and I had assumed the UUID would too, but it sounds like there&#x27;s enough to go on to identify targets.
  • I read an article in 2012 about the feds (DHS?) placing Bluetooth enabled devices along I5 in Seattle. They were able to make profiles of people based on what Bluetooth devices they had in their cars. Is anyone familiar with this? I&#x27;ve periodically tried to Google it and can&#x27;t find anything about it
    • Spooky2323 hours ago
      Possible, but they buy data from the carriers with similar profile possibilities. The DEA operates long standing and pervasive surveillance in “drug corridors” like I-95 from Maine to Miami. They do things like LPR and grabbing passenger pictures.<p>If Bluetooth is used, it may be a way to get a count of passengers or if the passengers change. I know based on newspaper accounts that they are particularly interested in cars that stop in Philly or Baltimore.<p>This stuff is frequently used against cops too so they may use the tech in similar ways. If you’re someone worried about getting raided, spotting a large number of new signals at the front door is an early warning potentially.
    • parpfish1 day ago
      I remember an art exhibit by an online privacy activist made where it’d ping people’s phones to get a list of “known WiFi networks” and then display them on a screen in a room.<p>Each person would get a unique fingerprint of named network locations
    • coldbrewed1 day ago
      <a href="https:&#x2F;&#x2F;www.kuow.org&#x2F;stories&#x2F;privacy-advocates-flag-a-potentially-dark-side-to-quicker-commutes" rel="nofollow">https:&#x2F;&#x2F;www.kuow.org&#x2F;stories&#x2F;privacy-advocates-flag-a-potent...</a>
    • angus-g19 hours ago
      There are realtime systems for traffic analysis. I know of Addinsight, e.g. <a href="https:&#x2F;&#x2F;news.addinsight.com&#x2F;bluetooths-leap-forward-the-evolution-of-probe-data-collection" rel="nofollow">https:&#x2F;&#x2F;news.addinsight.com&#x2F;bluetooths-leap-forward-the-evol...</a>
    • post_break1 day ago
      I believe Houston used bluetooth to measure congestion on 45.
  • ck223 hours ago
    Has anyone ever studied what happens with Bluetooth contention where thousands of people are gathered in a small space?<p>Like a marathon mass-start with 10,000 sometimes 20,000 or more people<p>How does bluetooth handle that? Or it doesn&#x27;t?
    • username_here21 hours ago
      In my experience, just fine. I recently ran a large (~30k) marathon and my AirPods and watch never glitched once, streaming the whole time including in the packed start corrals. I had the same thought about RF contention, but Bluetooth didn&#x27;t seem to care.
      • just697914 hours ago
        <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Frequency-hopping_spread_spectrum" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Frequency-hopping_spread_spect...</a>, combined with the inverse square law, is pretty amazing.<p>The amount of data needed to send audio to your ear-buds is quite small compared to the spectrum available, so only needs tiny slices of spectrum and for relatively tiny slices of time. And also relatively tiny amounts of power since it&#x27;s only going max 100 feet, hence a pretty small chunk of space.<p>If all those 10K-30K devices are constantly jumping around the frequency band to transmit tiny payloads a tiny distance, then a whole metric fuck-ton of them can interoperate in what seems to us to be very tight quarters. But to those specialzied radios it probably seems like a fairly wide open field.
    • supertrope22 hours ago
      Even licensed wireless stops functioning. All circuits are busy.
  • efilife13 hours ago
    I am fucking sick of seeing this everywhere. I gave this article a benefit of the doubt until:<p>&gt; Bluehood isn’t a hacking tool. It’s an educational demonstration of what’s possible with commodity hardware and a bit of patience.<p>&gt; This isn’t about paranoia. It’s about understanding the trade-offs we make when we leave wireless radios enabled on our devices.<p>This LLM spam needs to end. Tons of people on HN got tired of this, and it often shows in the comments. Let&#x27;s maybe start adding [LLM] to the titles of AI generated submissions?
  • kittbuilds2 hours ago
    [dead]