cross-posted from: https://infosec.pub/post/50218987

Karcher DAB radios are broadcasting an SSID for open Wi-Fi access. It doubles as an Internet radio, but AFAICT from the manual it’s only expected to act as a client.

So WTF is going on?

It seems like a really bad idea for consumers to connect this radio to their LANs to use to play Internet radio and podcasts when there is an always available Wi-Fi AP that enables anyone in proxity to connect to the radio. What’s the point? There is no way to disable the SSID broadcasting and it remains on even when the radio is “off” (but plugged in).

The manual shows that there is a remote control. Is the remote using wi-fi? I don’t have the remote so I have no way of verifying. In any case, this design seems like a recipe for disaster. Karcher should perhaps just stick to making pressure washers.

Google and Apple use Wi-Fi SSIDs for navigation. I boycott both companies. As such, I prefer not to have any wi-fi APs. And when I decide to run an AP, I ensure the SSID ends in _optout_nomap to opt-out of giving uncompensated help to the nav systems of Apple and Google.

Does this violate the GDPR? I cannot change the SSID, so it’s like I am being forced to share with the general public the fact that there is a Karcher radio in my home. That does not respect data minimisation.

  • Corporal_Punishment@feddit.uk
    link
    fedilink
    English
    arrow-up
    2
    ·
    8 days ago

    It seems like you’ve already decided this is a breach of GDPR based on your reply to the other guy.

    Firstly - definition of personal data. Data is only personal data if it can be used to directly or indirectly identify an individual.

    An SSID doesn’t do that. It might allow someone in the general vicinity the ability to identify which house the SSID originates from but that still doesnt reveal the identity of the person inside.

    The EDPB goes further - for data to be personal data:

    A natural person is “identified or identifiable” if they can be distinguished from others in a given context using means reasonably likely to be used and in a way that makes it possible to treat them differently. “Means” should be interpreted broadly and may include means that are only accessible through a third party. Whether they are reasonably likely to be used will depend on the relevant entity’s perspective and should be assessed in light of all objective factors

    So several tests need to be applied. First test -

    Does the information relate to a natural person? Is the natural person identifiable?

    If the answer to either question is no, then it isnt personal data.

    Second test.

    Is it reasonably possible for someone to establish your identity and are they likely to bother trying.

    So, in a world swimming with SSID hot-spots, is a person going to be able to reasonably ascertain the identity of a single individual living in your house using reasonable means accessible to them, and if so are they likely to even attempt to do so?

    Using a WiFi analyser I’m picking up 152 SSIDs within 100 metres of my house. Only 4 of them have a reognisable name attached. What do you think I’d actually be able to do with this data?

    You could probably make noise and try and prove some kind of point I suppose, but to what end? Karcher will be selling the fact that the device is WiFi enabled, and they will argue that if a broadcast SSID does meet the criteria of personal data it is irrelevant because you willingly consented to it (or entered into a contract) by buying the product and you can easily withdraw your consent by not using the product anymore.

    • one_old_coder@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      8 days ago

      Only 4 of them have a reognisable name attached

      Actually according to the GDPR, it would be useful IF the serial number and SSID of the device was attached to the name of the person who bought the device. And I severely doubt OP gave his name to the Karcher company along the serial number of that speaker after he bought it.

      I like GDPR because it gives more power to the customers, but I don’t think his case is valid.

      • daveyOsborn@infosec.pubOP
        link
        fedilink
        arrow-up
        1
        arrow-down
        1
        ·
        8 days ago

        And I severely doubt OP gave his name to the Karcher company along the serial number of that speaker after he bought it.

        It’s profoundly naive to assume that product registration is the only way to collect data. Data brokers and surveillance advertisers are smarter than that.

        I like GDPR because it gives more power to the customers, but I don’t think his case is valid.

        You could benefit from reading Art.5-1©. Data minimisation is obligatory.

        • one_old_coder@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          8 days ago

          You could benefit from reading Art.5-1©.

          Once again “personal data.” You haven’t told us how Karcher knows that the device belongs to you. Everything else is irrelevant.

          Local storage is subject to GDPR if: The organization maintains control … The data is personal

          Did you log on the device using an email or any personal data? You have to consult a lawyer for that because I doubt you fall in that case.

          A MAC address is unique

          Absolutely not, and it can be changed.

          And again, are you European?

          • daveyOsborn@infosec.pubOP
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            edit-2
            8 days ago

            Once again “personal data.” You haven’t told us how Karcher knows that the device belongs to you. Everything else is irrelevant.

            Nonsense. Karcher doesn’t need to know /who/ the personal data belongs to in order to be accountable for designs that violate Art.25.

            Local storage is subject to GDPR if: The organization maintains control … The data is personal

            Did you log on the device using an email or any personal data? You have to consult a lawyer for that because I doubt you fall in that case.

            wtf, stop making up quotes.

            A MAC address is unique

            Absolutely not, and it can be changed.

            Citation needed. Karcher does not even allow users basic access to change the SSID. Please point to the page in the Karcher user guide showing how to change the MAC address on their appliance.

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      edit-2
      8 days ago

      An SSID doesn’t do that. It might allow someone in the general vicinity the ability to identify which house the SSID originates from but that still doesnt reveal the identity of the person inside.

      Google and/or Apple already has that. They have maps. They know where people live.

      And to be clear, it’s not the SSID but rather the MAC address that’s unique enough to make this possible. Although the SSID alone could do it in aggregate with other local SSIDs.

      A natural person is “identified or identifiable” if they can be distinguished from others in a given context using means reasonably likely to be used and in a way that makes it possible to treat them differently.

      Google often knows who bought the Karcher radio. GAFAM is interested enough in who is buying what that they go as far as buying data from local shops in order to find out who buys what offline.

      Does the information relate to a natural person?

      Of course, when the radio is owned by a natural person.

      Is the natural person identifiable?

      They are identifiable to the entity who the SSID & MAC is shared with.

      Is it reasonably possible for someone to establish your identity and are they likely to bother trying.

      The machinery of surveillance advertisers like Google and Apple is designed to require no effort. They put effort into the infra, but from there the infra automatically identifies and grows profile data for further sales (read: privacy exploits).

      Karcher will be selling the fact that the device is WiFi enabled,

      Irrelevant. A wi-fi client does not need to broadcast an SSID.

      and they will argue that if a broadcast SSID does meet the criteria of personal data it is irrelevant

      They will want to avoid talking about MAC addresses for sure.

      because you willingly consented to it (or entered into a contract) by buying the product

      So you believe the legal basis is “consent” or “contract”? I don’t see how either apply. There is no contract to speak of. The purchase literature is on the box which does not mention SSID broadcasting.

      “Consent”-based legal basis requires being informed in the very least, according to the EDPB. And it cannot just be some fine print stashed somewhere. It requires explicit informed consent. They don’t have that. Consumers don’t even necessarily know this broadcast is occurring.

      and you can easily withdraw your consent by not using the product anymore.

      It must be unplugged. And the data subject must be informed in the first place. Which is the crux of the problem. It’s not art.5 (data minimisation) compliant, and data subjects are not being informed.

      • Corporal_Punishment@feddit.uk
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 days ago

        You’re making lots of assumptions and leaps about Google. Like anyone else all they can do is map SSID to a general locality. They still dont know who you are based on that single piece of information.

        The question is - is an SSID personal data.

        No. It isnt.

        Is a MAC? Potentially but only to a very specific and small number of entities. And then as I said for it to be personal data the link between that device and you has to be realistically and reasonably likely to occur.

        Like I said, you’ve already decided you’re correct and this is a breach. I look forward to reading the result of your court case against Karcher in 3 years time, so don’t forget to come back and let us know how you get on

        • daveyOsborn@infosec.pubOP
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          8 days ago

          You’re making lots of assumptions and leaps about Google.

          Amid Apple and Google’s opacity, you’re making lots of assumptions and leaps about Google that a Google spokesperson would praise you for. It’s unwise not to assume surveillance advertisers are collecting all profitable data possible.

          Like anyone else all they can do is map SSID to a general locality. They still dont know who you are based on that single piece of information.

          You’ve apparently not read Douglas Leith’s research. It’s the MAC address that is sent along with other telemetry data.

          The question is - is an SSID personal data.

          No. It isnt.

          We’re talking about MAC addresses that are linked to an individual natural person. Think of the SSID as the bait by which the uniquely identifying MAC address is discovered and collected.

          Is a MAC? Potentially but only to a very specific and small number of entities.

          Nonsense. A MAC address is unique and the box emitting it is owned by a particular person. In residential areas most such devices are owned by natural individuals.

          And then as I said for it to be personal data the link between that device and you has to be realistically and reasonably likely to occur.

          It’s automated. Apple collects the MAC addresses along with telemetry data. Apple also collects other data which can be aggregated. Data aggregation is profitable. It enables advertisers to know the most about their ad targets.

          I look forward to reading the result of your court case against Karcher in 3 years time.

          Woah, hold on. I never claimed the GDPR is actually enforced. The GDPR is widely disregarded. No, I do not have the confidence you seem to think I have in the GDPR being enforced. We can’t even get the most bluntly egregious indefensible GDPR violations enforced, much less any kind of nuanced scenario like this.

          The GDPR is just a prop… a façade to make the population comfortable with engaging with digital commerce (and for this purpose the GDPR works wonders on people). The discussion is whether there is a violation, not whether there would be justice. We can probably agree that Karcher will never face justice or be compelled to actually respect Art.5 and Art.32.

          • Corporal_Punishment@feddit.uk
            link
            fedilink
            English
            arrow-up
            1
            ·
            8 days ago

            I agree MAC addresses can be personal data - if it can be linked in some way.

            So a mobile phone? Sure - it links to you through subscriber info etc.

            A router? Sure - links to you via your ISP (although im both cases technically it links to the person paying the bills)

            But a DAB radio? Like others have said, unless you registered it under your name then its MAC is not linked to you.

            We then go back to the tests of whether it actually is personal data, and one of those tests is whether a person can determine who you are by taking reasonable steps and also whether they are likely to try.

            In both cases, in the real world the answer is arguably no.

            • daveyOsborn@infosec.pubOP
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              8 days ago

              But a DAB radio? Like others have said,

              Others? You mean the person who thinks data is only collected by product registrations? Who thinks “smart” devices have no GDPR relevance? And who thinks MAC addresses are not unique and who also thinks a MAC address on a DAB radio can be changed by consumers apparently without breaking an anti-reverse engineering terms of use? Who also thinks Karcher would become GDPR compliant through a MAC changing mechanism if it were to exist. Who then tried to establish credibility by claiming to endorse the GDPR. Indeed… not a good source.

              unless you registered it under your name then its MAC is not linked to you.

              You cannot really know what Google and Apple do with their data collection as opaque as they are. But the data is there. They have enough to link people to MAC addresses on a large scale in an automated fashion. The data collection is proven by Douglas Leith’s research.

              At the same time, we need not rely on assumptions. I could unwittingly place my Karcher within view of my front window while my neighbors who know exactly who I am. I might also be the sole person in hundreds of meters who has a Karcher that emits a unique MAC address. Any arbitrary owner of a Karcher radio would not necessarily even be aware of the reckless emissions. My neighbor would realistically have a great degree of certainty that the MAC address relates to me as they can see the signal strength increase ast they approach my dwelling and decrease as they walk away from it.

              To make this more interesting, replace “neighbor” with “stalker” in the above paragraph. Then when I move to get away from the stalker, the DBs of Apple or Google could reveal¹ my new location. Or the stalker can war drive if they know I didn’t move far.

              ¹ Note that research showed that Ukranian troops were trackable using Apple’s map tool that all ordinary Apple consumers have access to.

              • Corporal_Punishment@feddit.uk
                link
                fedilink
                English
                arrow-up
                1
                ·
                7 days ago

                It’s all a bit thin mate.

                You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.

                Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.

                As a thought experiment I’ll concede that you might have a point. But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio. It just isn’t a realistic scenario which is something a data protection authority would need to consider as well.

                • daveyOsborn@infosec.pubOP
                  link
                  fedilink
                  arrow-up
                  1
                  ·
                  edit-2
                  7 days ago

                  You’re likening the ability of apple/Google to see devices moving around in Ukraine to someone figuring out who you are because you have a DAB radio transmitting an SSID and a MAC address - that only people within a hundred or so metres can see.

                  Of course. Apple does not distinguish a DAB radio from a smartphone from an access point. It just blindly collects all SSIDs and MACs. Why do you think a soldier in Ukraine would get not only different treatment, but in fact more compromising treatment? That’s absurdly unrealistic. It costs Apple money to pay engineers to write tailored code and filters that then get deployed to all iOS devices at the risk of the exceptional logic doing the wrong thing. Of course iOS devices indiscriminantly send all data just the same.

                  The Ukraine soldier tracking was a scandalous embarrassment, so it stands to reason that adjustments have been made since then – and most likely by Ukraine not Apple. But if it were Apple, the change would obviously be to /not/ collect the compromising data of soldiers. A war fighter has a higher expectation for privacy than a DAB radio listener.

                  It’s not Apple who tracked the Ukrainian soldiers. The exploit was demonstrated by an end user who was simply making use of available data from Apple. IOW, some avg. Joe tinkering in their basement could do it. And they could do it with LESS information to start with. The person who demonstrated the tracking was much further than 100 meters. They were not even in Ukraine IIRC. They did not know where the soldiers were to begin with (IIRC). Unlike a Karcher scenario, where an adversary could very well have the victim’s starting location. It’s trivial track the victim from there in this case.

                  Again, I bring you back to the test laid out by the EDPB. For indirect identifiers like this to be considered personal data you have to consider the technical ability and the liklihood of someone converting that indirect identifier into something that actually identifies you as a natural person.

                  Do stalker victims have to prove the likelihood that their threat agent will attack? It’s already clear to me that the GDPR is mostly a failure. If judges and GDPR practitioners were to require proof that excessive data would likely lead to misuse as a precondition to corrective action against art.5-1© infringements, it would be yet another failure of the GDPR. The whole point to Art.5-1© (data minimisation) is to improve privacy generally without anticipation of particular threats. That’s the whole point of it. What you suggest is a purpose-defeating abuse of interpretation and discretion.

                  But in the real world, I don’t believe you do. You mention a stalker - a stalker isn’t going to find you by driving around using a WiFi scanner looking for a DAB radio.

                  If I ever have a stalker, I hope they are as unmotivated and undevoted as you suggest. But I have to say you have a strangely optimistic or flippant view of the psychology of a stalker.

  • one_old_coder@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    edit-2
    9 days ago

    Is the SSID linked to your identity? Then it’s not GDPR. Also you mistook that brand with Kärcher.

    Anyway, get a refund and stop complaining.

    • daveyOsborn@infosec.pubOP
      link
      fedilink
      arrow-up
      3
      arrow-down
      2
      ·
      edit-2
      9 days ago

      Is the SSID linked to your identity? Then it’s not GDPR.

      Nonsense. “Personal data” is not just your identity. All data the relates to you is your personal data. That includes your home address. When your home address becomes aggregated with a unique MAC address, that MAC address also becomes personal data that relates to you.

      And because the SSID does not include the string _optout_nomap, Google and Apple can use the SSID and MAC to track you and to keep tabs on where you relocate to so long as the Karcher radio moves with you.

      Anyway, get a refund and stop complaining.

      What EU country do you live in that you can get a refund on this basis (which according to you does not violate law)? Why do you think it would it be sensible to solve the problem for one person with respect to a manufactured product with likely tens or hundreds of thousands of consumers who are subject to the same abuse?

      • one_old_coder@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        8 days ago

        All data the relates to you is your personal data

        How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen. You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR. Random data linked to no one does not fit.

        Last but not the very least, are you European?

        • daveyOsborn@infosec.pubOP
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          edit-2
          8 days ago

          How does a single number relates to you? Is it linked to your purchase? If not, it’s not GDPR. You’re severely mistaken. Or you gave your first and last name when you bought the device, but I’m pretty sure it did not happen.

          A purchase is orthoganol to the GDPR. Even if I dug the Karcher out of a dumpster, the MAC address can still be linked to me by aggregating other data. A purchase transaction is irrelevant.

          You bought a piece-of-shit “smart device” and it’s sad, but it’s irrelevant to the GDPR.

          “Smart devices” are most certainly not irrelevant to the GDPR. The Article 29 Working Party devoted a 30-page guideline (opinion 02/2013 tagged WP202) entirely to the relevancy of smart devices to the EU privacy law just prior to the GDPR, which is now viewed through the lens of the GDPR.