When a device passes the beacons, its non-personal unique ID—called a MAC address—is recorded, encrypted and time-stamped.
Blip, you make me laugh. You know this will raise privacy concerns and say the sweet nothings that placate the general public, but inspire no confidence in people who know what those words mean.
I'm not here to say that as a JFK traveler I'm unhappy with the privacy considerations. I just want to point out you're pretending your design is good on privacy when simple tweaks would show the security minded you gave half a shit. I don't mind this monitoring if it is limited to the uses described, your maneuvering simply makes me giggle.
A MAC may not be in whatever bucket you're calling "personal" but is certainly more personal than "non-personal" implies. Encryption is effectively a "we're doing it right" buzzword to the general public. What are your authorized uses for the data? What's your KMI? What data minimization techniques are employed? Do you purge old records? Replace the MAC with an identifier that can't be tied back to MAC once the target has left the line? Hash MACs on entry in a way that is both time-costly to bruteforce and results in a different hash every day?
Yeah that same line made me laugh a bit as well. "Your non-identifying, SUPER personal, burned onto your phones hardware, is never going to change Mac Address is recorded as you walk by."
I think the idea is a great one, it's unfortunate there isn't a better way (that I can think of atm) to do it, or like you said just some transparency on what they do with it. As simple as: "At the end of each day the encrypted mac addresses are completely erased from our system."
Seems like they do keep the info though, it says the Cincinnati airport kept it and used it for data analysis. In the end, I think this kind of thing most people will be okay with foregoing a bit of privacy for.
I work in the traffic industry and over the last 8 years I have seen the rise of WIFI and Bluetooth journey time monitoring kit and after looking at every solution, I have found that the method of "encrypting" the data has always been just a MD5 hash, or SHA if you are lucky. With with result Hash just been http'ed over to a server on the internet. This usually leads to to question, "OK, so I can just hash the victims MAC address and the look for that in the data stream to find out where the person is instead of just using the MAC directly?" The same is done for ANPR based systems. The word "encrypted" seems to be added to some how make it secure without the solution being secure.
I work in the traffic industry and over the last 8 years I have seen the rise of WIFI and Bluetooth journey time monitoring kit and after looking at every solution, I have found that the method of "encrypting" the data has always been just a MD5 hash, or SHA if you are lucky. With with result Hash just been http'ed over to a server on the internet. This usually leads to to question, "OK, so I can just hash the victims MAC address and the look for that in the data stream to find out where the person is insteadvof just using the MAC directly?"
I understand the concern, but isn't your face effectively just as personally identifiable, recorded in far more locations, and arguably much more personal because it can't be easily replaced/changed?
That doesn't make either situation okay for privacy-conscious people like you and I, but I personally feel like MAC address tracking is a relatively minor concern when it comes to privacy.
"supposed to be", but not really. There are no measures to prevent MAC collision other than a manufacturer assurance they won't duplicate the addresses.
I was under the impression that iOS devices now use a random MAC address when searching for WiFi access points - so although you could still make estimates, at least based on people not using iPhones, wouldn't this alleviate the privacy issues?
Blip, you make me laugh. You know this will raise privacy concerns and say the sweet nothings that placate the general public, but inspire no confidence in people who know what those words mean.
I'm not here to say that as a JFK traveler I'm unhappy with the privacy considerations. I just want to point out you're pretending your design is good on privacy when simple tweaks would show the security minded you gave half a shit. I don't mind this monitoring if it is limited to the uses described, your maneuvering simply makes me giggle.
A MAC may not be in whatever bucket you're calling "personal" but is certainly more personal than "non-personal" implies. Encryption is effectively a "we're doing it right" buzzword to the general public. What are your authorized uses for the data? What's your KMI? What data minimization techniques are employed? Do you purge old records? Replace the MAC with an identifier that can't be tied back to MAC once the target has left the line? Hash MACs on entry in a way that is both time-costly to bruteforce and results in a different hash every day?