‘iSniff GPS’ tool reveals locations of iOS users, prompts privacy concerns for Apple’s location services

A new proof of concept Python tool recently uploaded to GitHub aims to use data collected through Apple’s location services for iOS devices to reveal where users have been and potentially even their home address. Researcher Hubert Seiwert has taken advantage of previous discoveries that iOS devices often send out ARP requests that disclose previously joined WiFi networks when connecting to access points. Apple responded to concerns of it collecting a database of access points to provide more accurate GPS and wifi location services back in 2011, but that data isn’t supposed to be accessible to just anyone.

Seiwert says sending a single MAC address to Apple returns 400 in return based on recently joined access points and from there iSniff “submits MAC addresses to Apple’s WiFi location service (masquerading as an iOS device) to obtain GPS coordinates for a given BSSID.”

The new Github tool dubbed “iSniff GPS” will allow users to capture SSID probes, ARPs and MDNS (Bonjour) packets to access the location data, highlighting a serious privacy concern for Apple’s location services. Seiwert explained:

iOS devices transmit ARPs which sometimes contain MAC addresses (BSSIDs) of previously joined WiFi networks, as described in [1]. iSniff GPS captures these ARPs and submits MAC addresses to Apple’s WiFi location service (masquerading as an iOS device) to obtain GPS coordinates for a given BSSID. If only SSID probes have been captured for a particular device, iSniff GPS can query network names on wigle.net and visualise possible locations… By geo-locating multiple SSIDs and WiFi router MAC addresses, it is possible to determine where a device (and by implication its owner) is likely to have been.

Back in 2011, Google locked down its API for its own WiFi location services for Android devices after reports surfaced prompting similar privacy concerns. Seiwert noted that you “can’t query a single MAC address anymore, you have to give two or more MAC addresses which are close to other before Google will actually turn over location.”

Apple’s location services have a few times been the source of privacy concerns since the company dumped Google and Skyhook back in 2010 to run its own location services database.

Last year Seiwert talked about how the iSniff GPS tool works. You can check out the full talk in the video below around the 2:15:00 mark:

(via SCMagazine)

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel



Avatar for Jordan Kahn Jordan Kahn

Jordan writes about all things Apple as Senior Editor of 9to5Mac, & contributes to 9to5Google, 9to5Toys, & Electrek.co. He also co-authors 9to5Mac’s Logic Pros series.