3 ms·
This has been the case since around 2004 at least. I reported it to the press at the time, without much fanfare. Things to note with the SMS opt-in. * You can
by kevcampb 8y ago
This has been the case since around 2004 at least. I reported it to the press at the time, without much fanfare.
Things to note with the SMS opt-in.
* You can abuse the opt-in message of "Real Name wants to track..” by registering with a real name of 160 blank letters (depends on provider) so the recipient only gets a blank SMS
* You can spoof the reply opt-in as th confirmation as they all use is a fixed string. Spoofing SMS sender is mostly trivial.
* Few services appeared to implement the regular notification to the tracked party
* As I understand it, implementation of opt-in was the responsibility of the service provider, not the telco, and the telcos did not seem to audit this in any way.
If anyone cares to investigate further, happy to give more details.
- pietroglyph 8y agoI just tried this, and the opt-in message didn't include the name I gave (so no possibility of a blank message.) It did everything else mentioned in the parent. The opt-in message did provide an option to text "STOP", so someone really on the lookout for this service could potentially stop tracking with this specific method. Still an excellent reminder of how much information we share.
- confounded 8y agoDo you happen to know if there are any carriers which prevent this from happening, either by not entering into commercial arrangements, or requesting warrants? I have read good things about CREDO mobile in the EFF's Who's Got Your Back? report[1], but I'm not sure if it would cover things like this, as the service is white-labeled from Sprint/Verizon. In other words, is it the 'MVNO' (company you pay) or the MNO (company they pay for the network) that would fullfil the request? [1]: https://www.eff.org/who-has-your-back-2017#credo-report https://www.eff.org/who-has-your-back-2017#credo-report
- zkms 8y ago> If anyone cares to investigate further, happy to give more details. I'm quite interested in looking into this further; any details you have would be much appreciated.
- kevcampb 8y agoHave a look at https://www.theguardian.com/technology/2006/feb/01/news.g2 https://www.theguardian.com/technology/2006/feb/01/news.g2 This news article was about a year later than the original once, from what I remember. It misses the part that you can replace the name and spoof the SMS though. The SMS quoted in the article does demonstrate the vulnerabilities mentioned though "Ben Goldacre has requested to add you to their Buddy List! To accept, simply reply to this message with 'LOCATE'" Interesting to re-discover this now, I had no idea who Ben Goldacre was at the time. If you find services still vulnerable, let me know. I'm still friends with the journalist who initially spoke to Vodafone before publishing in the first place. I remember them not being too pleased, but as I say, it never got fixed.