PCWorld (USA)

How ‘free’ Wi-fi hotspots can track your location

Simple steps can protect your privacy and location data.

- BY DIETER HOLGER ILLUSTRATI­ON BY DANIEL DOWNEY

Before you join the Wi-fi hotspot at your local cafe, you might want to make sure it won’t follow your footsteps—literally—after you leave. Ostensibly “free” Wi-fi hotspots are in hundreds of thousands of businesses and public spaces across the United States. They’re in shopping malls. In airports. In chain restaurant­s. In local cafes. As a result, it’s easier than ever to get online. If your notebook or phone lacks a reliable data connection, you can still connect to a hotspot. But this convenienc­e often comes at a price: your personal data and privacy.

When you use “free” Wi-fi, there’s a good chance it’s managed by a third-party provider—which gets you online in exchange for your valuable sign-on data. The sign-on informatio­n that hotspots require will vary, but often includes your email address, phone number, social media profile, and other personal informatio­n. All can be used to target you with advertisin­g and gain insights on your habits.

As Emory Roane, policy counsel at Privacy Rights Clearingho­use ( go.pcworld. com/pvrt), told Pcworld: “Read through the Wi-fi Terms of Use for any of these businesses and you’ll almost certainly realize that there’s still no such thing as a free lunch.”

That’s probably not a surprise to most Wi-fi hotspot users. But what might surprise you is that some hotspot providers are taking data collection a step further, and quietly tracking millions of users’ whereabout­s even after they’ve left an establishm­ent. These hotspots are part of America’s burgeoning location-based Wi-fi marketing industry.

Pcworld spoke to privacy experts and Wi-fi location-analytics companies to learn more about how this technology works, and what you can do to avoid being tracked.

WI-FI LOCATION TRACKING AND YOU

Pcworld reviewed the privacy policies ( go. pcworld.com/pvdc) of a dozen Wi-fi hotspot providers and found that they commonly ask users to agree to location tracking when they sign on. Some phrases that tip off this practice are “location data,” “location history,” “your

location,” “device identifier­s,” and “MAC address” (more on this later).

We reached out to all of the Wi-fi companies, but only two with major operations in the United States responded to questions about tracking hotspot users. These networks, Zenreach ( go. pcworld.com/zenr) and Euclid ( go.pcworld.com/ ecld), log the locations of millions of smartphone and laptop owners who pass within range of their hotspots— even when these people don’t sign on.

According to Zenreach’s privacy policy, “Later, when the user’s device returns to this client location or enters the Wi-fi range of another Zenreach router (of any Zenreach client), we automatica­lly recognize the device and record the visit in our record for that device.”

According to Euclid’s privacy policy, “General Visit Informatio­n is collected as your mobile device moves across different Locations that use our technology.”

To give you an idea of a hotspot network’s scope, Zenreach counts Peet’s Coffee, Five Guys, IHOP, and KFC among its larger clients, according to its website ( go.pcworld.com/ znwb). KFC has nearly 4,500 locations nationwide, so these networks can span broad swaths of urban areas.

HOW IT WORKS: DATA COLLECTION BEGINS AT THE CAPTIVE PORTAL

When you connect to public Wi-fi, you’ll usually be greeted with a sign-in form, also known as a “captive portal.” This is where you provide personal informatio­n and consent to terms of service to get online.

In the case of Zenreach, “by clicking ‘go online,’ you agree to our terms of use and privacy policy,” allowing them to track your location over time. Euclid is more explicit, saying, “you agree to provide this device’s location” next to where you can tick a box to consent.

What distinguis­hes location-based marketing hotspot providers like Zenreach and Euclid from standard third-party hotspot providers is that the personal informatio­n you enter in the captive portal—like your email address, phone number, or social media

profile—can be linked to your laptop or smartphone’s Media Access Control (MAC) address. That’s the unique alphanumer­ic ID that devices broadcast when Wi-fi is switched on.

As Euclid explains in its privacy policy, “... if you bring your mobile device to your favorite clothing store today that is a Location—and then a popular local restaurant a few days later that is also a Location—we may know that a mobile device was in both locations based on seeing the same MAC Address.”

MAC addresses alone don’t contain identifyin­g informatio­n besides the make of a device, such as whether a smartphone is an iphone or a Samsung Galaxy. But as long as a device’s MAC address is linked to someone’s profile, and the device’s Wi-fi is turned on, the movements of its owner can be followed by any hotspot from the same provider.

“After a user signs up, we associate their email address and other personal informatio­n with their device’s MAC address and with any location history we may previously have gathered (or later gather) for that device’s MAC address,” according to Zenreach’s privacy policy.

This can reveal a detailed profile of someone’s daily habits. Where they shop, where they live, and what places they frequent at certain times could be laid bare by this data.

Stacey Gray, policy counsel at the Future of Privacy Forum ( go.pcworld.com/ftpf), told

Pcworld that associatin­g a MAC address with someone’s movements between locations reveals “highly sensitive” informatio­n.

“Analyzing MAC signals from mobile phones can be valuable for retailers and others to calculate wait times, understand peak versus off-hours, or assign staff,” Gray said. “However, location data is highly sensitive when linked to an individual over time and across venues.”

Neither Euclid or Zenreach would provide Pcworld with exact figures on how many people’s data they’re collecting. But Euclid claims more than 120 million monthly active devices ( go.pcworld.com/m120) globally and told Pcworld that the majority of its users are in the United States. Zenreach also told Pcworld that most of its hotspots are in the United States. It’s also the most well-funded of the location analytics companies, having raised $80 million for a $210 million valuation as of March 2017, according to Crunchbase ( go.pcworld.com/crnc).

When asked to respond to people who might find Wi-fi location tracking invasive, Zenreach cofounder Kai Umezawa highlighte­d the convenienc­e, pointing out how his company makes it easy to get online.

“After customers log in to the Wi-fi at a merchant location, we can recognize that device at any Zenreach network location,” Umezawa said. “The benefit for users is oneclick access to Wi-fi in any of these locations.”

All the hotspot providers Pcworld reviewed say they take data security seriously. A Euclid spokespers­on said the company immediatel­y anonymizes collected location data by “de-personaliz­ing” or “hashing” it in non-human readable format when stored. That said, Euclid still processes and provides identifiab­le data to businesses on someone’s visits between various locations they own.

Zenreach didn’t respond to multiple emails asking if they anonymize personal data collected over Wi-fi, and the company’s privacy policy makes no mention of doing so.

How the data is used differs from provider to provider, and where it might end up is another question entirely. Many promise never to share it. Others have more opaque policies, or, in the case of Zenreach, may

outright share data with clients, affiliates, and other third parties. Euclid may also share data with advertiser­s, but only in “hashed” form.

HOW TO PROTECT YOURSELF FROM BEING TRACKED BY ‘FREE’ WI-FI

If you’re concerned about data being collected by free Wi-fi hotspots, there are some simple steps you can take to protect your personal informatio­n.

Don’t use “free” Wi-fi: The most obvious solution to protecting your data from free Wi-fi networks is not to use them at all. Alternativ­es include using the data services from your cellular provider, or signing up for a more secure hotspot service like Boingo ( go. pcworld.com/bngo).

Disable Wi-fi when you’re not using it: Enabling Wi-fi lets these hotspots track you (and also drains your battery faster). There’s really no reason to keep your Wi-fi on unless you need to connect.

Read the privacy policy: It’s tempting to skip reading the privacy policy, but if you take a few minutes to do so, you can learn how the Wi-fi service is collecting your data and where it might end up. Keywords to look for are “MAC address,” “location,” “collect,” and “share.”

Opt-out of location tracking and delete your data: Location analytics companies let you opt-out of location tracking and delete your data, though some opt-outs are easier than others. How to opt out can be found in a privacy policy. You’ll be given a chance to review the policy before you sign in to a captive portal, or you can find it on the hotspot provider’s website.

You’ll need to get your MAC address to opt out of any location tracking. On an iphone, you can find it under Settings > General > About, where it’s listed as your Wi-fi Address. On Android, tap the menu key and go to Settings > Wireless & Networks or About Device. Press the menu key again and hit Advanced, and then you should see your device’s MAC address.

You can then provide your MAC address to opt out of many, but not all,

location-tracking services through the Future of Privacy Forum’s Smart Places web portal ( go.pcworld.com/smpv). This is a one-stop shop many location analytics companies work with voluntaril­y. (Companies should say in their privacy policies if they’re associated with the Future of Privacy Forum.)

Not all location analytics companies are associated with the Smart Places web portal, including Zenreach. In these cases, you’ll need to find a Wi-fi hotspot provider’s email in its privacy policy and contact the company directly with your MAC address on hand. You should be able to request to opt out, receive the data they have on you, and have it deleted. See the screenshot below from Zenreach’s policy:

Randomize your MAC address on Android: Since version P, Android has added a feature that allows you to randomize your smartphone’s MAC address to improve privacy. This lets you generate a new MAC address for every Wi-fi hotspot you connect to, effectivel­y stopping these companies from tracking you. You can switch on MAC randomizat­ion under Developer Options.

There’s no need to go through a similar process on iphones and ipads running IOS 11 and up, which automatica­lly randomize their MAC address when scanning for Wi-fi.

“Because a device’s MAC address now changes when disconnect­ed from a Wi-fi network, it can’t be used to persistent­ly track a device by passive observers of Wi-fi traffic, even when the device is connected to a cellular network,” according to Apple’s IOS Security Guide ( go. pcworld.com/apsg).

However, Apple also says “Wi-fi scans that happen while trying to connect to a preferred Wi-fi Network aren’t randomized,” meaning a hotspot a device has connected to previously will be able to detect the

device’s actual MAC address.

Don’t sign in with social media: It may be convenient and quicker to sign in with Facebook, Twitter, or Linkedin, but it’s also ideal for data harvesters. Your social profile, especially your Facebook “likes,” reveals a wealth of informatio­n about you.

A study published in 2015 by the National Academy of Sciences ( go.pcworld. com/nasc) found that it takes just 10 Facebook “likes” for a computer model to know your personalit­y better than a colleague does. In a previous 2013 study by the same researcher­s, also published by the NAS ( go.pcworld.com/pnas), the scientists used Facebook “likes” to predict whether someone was black or white with 95-percent accuracy, male or female with 93-percent accuracy, gay or straight with 88-percent accuracy, and Democrat or Republican with 88-percent accuracy.

WI-FI REGULATION­S ON THE HORIZON?

Unlike the United States, the European Union restricts individual, profile-based location tracking via Wi-fi hotspots under the General Data Protection Regulation (GDPR; go.pcworld.com/gdpr), which went into effect in May, 2018.

GDPR considers device identifier­s like MAC addresses “individual­ly identifiab­le informatio­n,” entitling people with rights to have their personal data processed securely and deleted, and requiring explicit user consent in the captive portal for location tracking.

“Exact location is considered as very sensitive informatio­n across Europe. Companies tracking user location need to, among others, provide easily understand­able notice and obtain explicit user consent,” Alja Poler De Zwart ( go.pcworld.com/zwrt), Eu-based privacy and data attorney at law firm Morrison Foerster, told Pcworld.

“Companies who do not abide by these rules, risk regulatory enforcemen­t action, including the GDPRstyle fines,” Poler De Zwart added.

Netherland­s-based Spoton ( go.pcworld. com/sp0t) Wi-fi, a hotspot provider

operating mostly in Europe, with some business in the United States, immediatel­y anonymizes MAC addresses it associates with personal info to comply with GDPR.

“Without associatin­g a MAC address to a social profile we wouldn’t be able to provide seamless roaming between cloudbased access points or create email campaigns that target guests with more than X visits,” Niek Giavedoni, founding director of Spoton Wi-fi, told Pcworld.

Giavedoni confirmed that the ability to track identified users via their devices is present in Spoton Wi-fi’s systems and other Wi-fi networks, but he said it would be a privacy violation to track the locations of individual profiles through Wi-fi in the EU.

“We are very much aware of the technical possibilit­ies, the competitor­s that use it, and privacy concerns that come along with it,” he said.

Similar restrictio­ns could make their way to the United States.

Government officials are grappling with how to safeguard personal data in the wake of Facebook’s Cambridge Analytica scandal ( go. pcworld.com/cmbr), creating an opportunit­y for Eu-like constraint­s on Wi-fi location tracking to enter law. U.S. Senators Richard Blumenthal (D-CT) and Edward Markey (D-MA) are working on a federal “privacy bill of rights” to provide people with more protection­s and controls over data given over the web. Their offices didn’t respond to questions about their positions on Wi-fi location tracking in time for publicatio­n.

States are taking action, too. California passed a sweeping privacy bill ( go.pcworld. com/b375) in June that goes into full effect in 2020. The bill guarantees California­ns the right to know what data is being collected about them and whether it’s being sold or disclosed, and to refuse the sale of their

personal informatio­n.

“Unique personal identifier­s” are among the data types the bill covers, which include MAC addresses. But the rights the bill guarantees California­ns are often already offered by companies voluntaril­y, and the bill still doesn’t restrict the location tracking that companies like Zenreach and Euclid employ.

Wi-fi privacy regulation­s have actually taken a step backward at the federal level since the election of president Donald Trump, former Federal Communicat­ions Commission (FCC) staffer Marc S. Martin told Pcworld.

“One of the first acts by the Republican­controlled Congress and the Trump administra­tion shortly after the president was inaugurate­d was to rely on the Congressio­nal Review Act to repeal the FCC’S Broadband Privacy Rules,” said Martin, currently a partner at law firm Perkins Coie ( go.pcworld.com/perk).

“Following that step, the Trump administra­tion FCC repealed the FCC’S 2015 net neutrality rules,” he added.

Martin said because of these two repeals, there are currently “no prescripti­ve federal privacy rules or regulation­s governing Wi-fi service providers in the United States.”

“It will take a new act of Congress, signed by the President, to adopt any new federal privacy rules governing public Wi-fi service providers,” Martin said.

 ??  ??
 ??  ??
 ??  ??
 ??  ?? Euclid tells businesses the location a customer visits the most and how likely they are to visit again.
Euclid tells businesses the location a customer visits the most and how likely they are to visit again.
 ??  ?? These templates from Zenreach’s captive portal builder show you how a Wi-fi hotspot’s sign-in form can appear.
These templates from Zenreach’s captive portal builder show you how a Wi-fi hotspot’s sign-in form can appear.
 ??  ?? Euclid’s captive portal notes they track location.
Euclid’s captive portal notes they track location.
 ??  ?? This panel from Euclid shows some of the data available to businesses on a customer traveling between their venues.
This panel from Euclid shows some of the data available to businesses on a customer traveling between their venues.
 ??  ?? Zenreach lets businesses send automated emails based upon how many times a customer has visited.
Zenreach lets businesses send automated emails based upon how many times a customer has visited.
 ??  ?? Like in the case of Zenreach’s privacy policy, you can usually find the email address for opting out of location data collection at the end of a company’s privacy policy.
Like in the case of Zenreach’s privacy policy, you can usually find the email address for opting out of location data collection at the end of a company’s privacy policy.
 ??  ?? You can take steps to protect your data while using ‘free’ Wi-fi hotspots.
You can take steps to protect your data while using ‘free’ Wi-fi hotspots.
 ??  ??
 ??  ?? Since 2018, the 28 members of the EU have tightened their data and privacy laws.
Since 2018, the 28 members of the EU have tightened their data and privacy laws.
 ??  ?? California is the first state to pass its own data privacy bill, which will go into full effect in 2020.
California is the first state to pass its own data privacy bill, which will go into full effect in 2020.

Newspapers in English

Newspapers from Australia