How Apple Wi-Fi Positioning System can be abused to track people around the globe
ID: d7f9b216-0f07-5200-b679-b5559ae467d5
STIX ID: report--d7f9b216-0f07-5200-b679-b5559ae467d5
Feed Name: The Register (Security)
Researchers at the University of Maryland demonstrated that Apple's Wi‑Fi Positioning System (WPS) design allows opportunistic return of up to several hundred nearby BSSIDs and, because the API is unauthenticated and unrate‑limited, they were able to compile ~490 million geolocated BSSIDs worldwide; this capability can be abused for mass surveillance, tracking of individuals, groups, and sensitive sites. The paper documents scenarios (e.g., tracking homes, military movements, travel routers, Starlink terminals), reports coordinated disclosure to vendors, and recommends mitigations including appending _nomap_ to SSIDs and implementing BSSID randomization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
