Google’s “Passive Sniffing” Technique May Have Paved the Way for Wi-Fi Privacy Flap, Skyhook CEO Says

ask every Wi-Fi access point within range to respond. This happens very quickly. The downside is that if an in-range access point happens to be busy—say, helping its owner download e-mail—it won’t respond to the probe request, so the surveyors will miss that network.

The way around that problem is to use passive sniffing, which picks up all of the traffic traveling over active Wi-Fi networks, including key identifiers such as SSIDs (network names) and MAC addresses (similar to serial numbers, these are unique to each Wi-Fi router). The downside of passive sniffing is that it’s slower than active scanning, since routers may be broadcasting on any of a dozen channels, and each must be sniffed individually. “And you have to make sure you do not capture any of the network messages,” says Morgan.

Skyhook has never employed passive sniffing, in part because of the privacy challenges, Morgan says. “We have just found [active scanning] is more consistently reliable,” he says. “We feel very comfortable with the data we’re collecting, and it also keeps us from ever having to be perceived like we’re in the kind of situation that Google’s in. It’s actually impossible, with the approach we take right now, to observe or capture any private network data.”

Nor would it be possible for Google to record such data completely by accident, Morgan says. “At the engineering level it’s very easy to know whether you are capturing this data or not,” he says. So the error at Google, he says, probably happened “higher up the food chain…An engineer doesn’t care, and grabs whatever he can. But when there’s no one looking at it who’s got the broader perspective to understand the implications, that’s where the breakdown happens.”

Morgan says the choice to use active scanning at Skyhook was part of a sensibility about privacy concerns that was baked into the startup’s business model from the beginning. “It had to be, because early on, this was kind of an off-the-wall idea,” he says. “This was before there was such as thing as Street View cars, and people didn’t know what to make of it. So the first they would ask is, ‘What are you scanning for?’ We try to be very open about what type of data we collect and what we use it for so that we don’t get tripped up in situations like this.”

Eustace said in Friday’s post that Google will work with an outside party to review its Wi-Fi scanning software and confirm that the recorded payload data has been deleted appropriately. The company is also reviewing its procedures “to ensure that our controls are sufficiently robust to address these kinds of problems in the future,” Eustace wrote. He pointed out that payload data can be made inaccessible even to malicious passive sniffers by using the encryption features built into all modern Wi-Fi routers.

And he issued a dramatic apology. “The engineering team at Google works hard to earn your trust—and we are acutely aware that we failed badly here,” Eustace wrote. “We are profoundly sorry for this error and are determined to learn all the lessons we can from our mistake.”

Author: Wade Roush

Between 2007 and 2014, I was a staff editor for Xconomy in Boston and San Francisco. Since 2008 I've been writing a weekly opinion/review column called VOX: The Voice of Xperience. (From 2008 to 2013 the column was known as World Wide Wade.) I've been writing about science and technology professionally since 1994. Before joining Xconomy in 2007, I was a staff member at MIT’s Technology Review from 2001 to 2006, serving as senior editor, San Francisco bureau chief, and executive editor of TechnologyReview.com. Before that, I was the Boston bureau reporter for Science, managing editor of supercomputing publications at NASA Ames Research Center, and Web editor at e-book pioneer NuvoMedia. I have a B.A. in the history of science from Harvard College and a PhD in the history and social study of science and technology from MIT. I've published articles in Science, Technology Review, IEEE Spectrum, Encyclopaedia Brittanica, Technology and Culture, Alaska Airlines Magazine, and World Business, and I've been a guest of NPR, CNN, CNBC, NECN, WGBH and the PBS NewsHour. I'm a frequent conference participant and enjoy opportunities to moderate panel discussions and on-stage chats. My personal site: waderoush.com My social media coordinates: Twitter: @wroush Facebook: facebook.com/wade.roush LinkedIn: linkedin.com/in/waderoush Google+ : google.com/+WadeRoush YouTube: youtube.com/wroush1967 Flickr: flickr.com/photos/wroush/ Pinterest: pinterest.com/waderoush/