'"Walmartwifi" isn't compatible with iCloud Private Relay' | Store demands privacy sacrifice to use internet in their cavernous dead zone of a building
This is after forcing login to a store account:
At least they don’t hide in their ToS that:
“l agree to let Walmart monitor my use of Walmart WiFi, including to:
Determine my presence in Walmart stores
Associate information about me with my Walmart account
Improve products and services
Gather market insights about my in-store purchases and activities”
But that’s not enough, they need to monitor your internet activity further too.
For further reading, some greatest hits (the section headers on Wiki’s Criticism of Walmart):
Local communities
Allegations of predatory pricing and supplier issues
Labor relations
Poorly run and understaffed stores
No AEDs in stores (automated external defibrillators)
privacy sacrifice to use internet in their cavernous dead zone of a building
It was a worthwhile sacrifice, but I’m definitely gonna name & shame! Wouldn’t touch WiFi if it weren’t a dead zone.
Also gave me a chance to complain about some of their other business practices. (Certainly wouldn’t have shopped there if I hadn’t been asked to this one time.)
I’ve never seen this message before so they seem an outlier even in the greedy corporate world. Enough complaints and every once in a while a business changes their practices. Why not whine a little? 🙂
The privacy community and yourself have become the equivalent of windows UAC. It's tiresome and no sane person with an understanding of technology would ever have the expectation of privacy on a public WiFi network. There are legal and compliance obligations.
complaining about a lack of privacy on a public wifi node is like complaining that people are perverts for looking at your genitals when you run down the street naked.
No, cause you have an expectation of privacy in a shower. You don't have an expectation of privacy in public.
No reasonable person has an expectation of privacy on a public wifi, hell most people wont even connect to a public wifi because they dont want to take the unnecessary risk. Especially with a public wifi provided by such stellar companies like Walmart.
Which is why the entire argument is as stupid as getting angry at people looking at your junk when you're running around naked in public.
It's more like calling your neighbor a pervert when they force you to undress in front of them prior to showering, or force you to go out naked in public. There's no legitimate reason to block vpn tools aside from bathwidth or tracking issues, the former can be handled by QoS and the latter isn't an issue unless you're using your "free Wi-Fi" to harvest data.
How is allowing people to use a VPN a legal/compliance issue? If anything the traffic is exiting to the internet elsewhere and because it’s encrypted you can’t see what’s happening, essentially offloading responsibility to someone else while still providing access.
Every public WiFi is like this. iCloud relay doesn’t work on any airport or airplane WiFi. I need to always turn it off and other ‘hide IP’ settings. I have a Target with a dead zone and I’m sure T&C are the same. I just use it when I need it and don’t auto-connect. Walmart needs precise location to pick up from the app. Sam’s club app needs precise location for checkout form the app. Mcd app needs my precise location to give me deals.
I wouldn’t say this is asshole design. Our regulation let them design it this way. I turn off my NextDNS and iCloud relay when I’m having issues and then turn back on. Nothing else you can do about it, apart from not using the WiFi or app, unfortunately.
Would you say the same thing if they intercepted HTTPS connections? Or blocked popular DNS (edit: DNS over HTTPS/TLS) resolvers and required you to use the one advertised in DHCP?
I think if you're going to provide WiFi, just do it and stop spying on me.
The reason they want this is probably so they can tie your Walmart account to your position inside the store. And see which other sites you visit to find a better price, etc.
You're conflating the individual practice of having a pessimistic threat model with a corporation's entitlement to behave badly.
Of course I assume the worst from Walmart or any other public network — I just think they should have some class and provide a public good to their customers without creepy privacy invasion. Somehow they manage to provide free water in fountains without requiring me to scan my driver's license.
If they published a white paper explaining the Differential Privacy properties of their customer analysis tech, I might revise my opinion.
They aren't invading the privacy here. They are preventing a malicious actor from running an attack via VPN and ssh tunneling in addition to IP address, device, etc. At worst they are associating IP with browsing at competing stores. Preventing the VPN was likely required by a lawyer and auditor and a risky attack vector for a billion dollar company.
If Walmart was breaking https and inserting man in the middle games it would be in their policy. Other commentators went off into fantasy land edge cases where traffic is being decrypted. And it still doesn't change my expectation of privacy on a public hotspot.
Yes they are, they're forcing you to disable Private Relay.
They are preventing a malicious actor from running an attack via VPN and ssh tunneling in addition to IP address, device, etc.
This makes no sense. I could walk outside the store and do any of those things on my 5G connection. Private Relay does not enable these attacks and blocking it doesn't prevent them.
At worst they are associating IP with browsing at competing stores.
Wut? They are the ones assigning IP addresses. Not sure what you mean.
At worst, they're using your IP address to join your walmart.com session cookie with complete time series data on your store position, data from store cameras, etc. to build a creepy profile without consent.
Preventing the VPN was likely required by a lawyer and auditor and a risky attack vector for a billion dollar company.
It's not a problem for Starbucks. As long as the public facing network is separate from the internal store network, e.g. with a VLAN, what is the concern?
If Walmart was breaking https and inserting man in the middle games it would be in their policy.
Regardless, it would be shitty behavior.
If they were cracking crypto schemes and were decrypting your traffic, it's entirely possible this violates a "hacking" law in the US.
Other commentators went off into fantasy land edge cases where traffic is being decrypted. And it still doesn't change my expectation of privacy on a public hotspot.
It was a hypothetical to explore the extent of your "their house, their rules" viewpoint.
They aren't invading the privacy here. They are preventing a malicious actor from running an attack via VPN and ssh tunneling in addition to IP address, device, etc. At worst they are associating IP with browsing at competing stores. Preventing the VPN was likely required by a lawyer and auditor and a risky attack vector for a billion dollar company.
Then why do their ToS say they use this data for advertising purposes? If they really need to be able to track you to prevent malicious actors, they can do so without using the data for advertising.
Not entirely sure if this is possible but I'm increasingly suspicious that they started jamming outside networks within their warehouse. Of course it makes sense that mobile data doesn't really work inside a giant steel warehouse, so perhaps it's just confirmation bias, but I can't seem to recall not having any mobile data signal at all until my last walmart visit.
I used to keep to myself and look up the location of the item I was looking for online. If they want me to bother a floor person for it though, doing that is highly preferable to giving walmart my email to sell along with any information they can extrapolate from my usage of their network.
Multiple big-box stores in my area have poor cell reception in-house. I blame the giant metal roof overhead, which is probably acting like some kind of Faraday cage or RF filter.
Excuse me for not knowing the precise legal landscape involved in covertly blocking the use of outside networks inside of a private warehouse department store
For future reference, jamming radio equipment is illegal essentially everywhere on earth because it's banned by the ITU rules, which every country on earth has adopted with the sole exception of Palau. Palau isn't an exception here though, because they've also also adopted those rules in a roundabout "not-actually-joining the ITU" way.
Exactly. "Hey, we're gonna let you use our network. But if you do anything illegal or shady on our network, we'd be held liable. So we're gonna track what you do on our network to make sure if you do try something, we can remove you from the network and have proof."
I mean, yeah, they're also gonna collect advertising data, but do you really expect to have an expectation of privacy when using someone else's network? Just like they can film you in the building, they can monitor your network traffic on their network.
If this surprises you, maybe you should do some more research on how a network actually works. And get a VPN. And maybe don't connect to random public networks(you don't even want to know what OTHER PEOPLE can do to you on those networks, nevermind the company).
Also, you pay for your cellphone service, right? Are you paying for the wifi in the store? Nooooooo. They're giving it to you for free. Almost like they're offering you something in return for that data monitoring. Like they're offering you a service with a built in method to recoup costs... A service you voluntarily use and in doing so, agree to their terms.
Which is still their right, with it being their network. The cost of using their bandwidth is letting them watch what you do with it. Don't like it? Don't use it.
Lol why is this an opinion? If people want to vpn out of my network I don't give a fuuuuuuuuck. Now if you're raw doggin' that traffic or sucking down the bandwidth don't bitch when I filter or throttle, for sure, but surely you can at least empathize with people wanting to use privacy tools, ya tool.
THEY DONT EVEN LET ME USE DATA THO! Like they force me to use their wifi while inside the store and I HATE IT. I cant even call my mom cus it just murders any kind of single I had going in there.