35 ms·
US cell carriers are selling access to real-time phone location data
- ataturk 8y agoIt's so strange--I never would have expected the boot of tyranny to come from private corporations, but here we are. And what all this proves is that technology is value-neutral and can wipe us all out, or just make us incredibly miserable, if we let it. Hopefully there will be a way to opt out. Otherwise, I should start selling faraday bags for devices. Probably should anyways.
- emodendroket 8y agoWhy wouldn't you have expected that?
- wpietri 8y agoI think it depends a lot on the kind of capitalism you have. There's what I think of as small-business capitalism, where business owners in a community naturally take the community's interest into account because that's where they live. I think that's distinct from American MBA capitalism, which is the increase-shareholder-value, up-and-to-the-right, maximize-short-term-cash-gains kind. The former is positive-sum, the latter can easily be negative sum. And I think the latter, because it doesn't include any humanity in its calculus, is perfectly capable of profitable tyrrany.
- rectang 8y agoThis tracking abomination is an emergent phenomenon of the merger of private industry and government in the US. See for example both legalized bribery (a.k.a. unlimited campaign contributions by corporations thanks to Citizens United) and outright bribery (Cohen) by telecoms like AT&T, ensuring that they will have the flexibility to perpetrate such garbage as this tracking data sale. Why not distrust both government and industry? The rule "power corrupts" holds in either case.
- emodendroket 8y agoAlright, but distrusting all parties doesn't suggest a way forward.
- rectang 8y agoWhy not? Both government and private industry bring innumerable benefits to humanity. But we can and should view them both with constant skepticism and exercise vigilance. Why should holding one accountable mean that we can't hold the other accountable? If you're looking for someone to root for, I'd suggest the individual citizen.
- emodendroket 8y agoThe individual citizen has practically no power against large institutional actors.
- rectang 8y agoThat's like saying voting is pointless because individual votes don't matter. https://en.wikipedia.org/wiki/Paradox_of_voting https://en.wikipedia.org/wiki/Paradox_of_voting
- emodendroket 8y agoAll voting can do is steer the course of the government, which you've just cast as nothing more than a villain.
- rectang 8y agoSince I said that government brings "innumerable benefits to humanity", and you've characterized that as "nothing more than a villain", I think we're done with this thread.
- 18pfsmt 8y ago
- fixermark 8y ago> Hopefully there will be a way to opt out Don't use a cellphone. See also: the FBI can't wiretap your phone lines if you never use a telephone.
- emodendroket 8y agoLive in a cabin in the woods and never have contact with anyone. Now your surveillance worries are solved.
- brewdad 8y agoWe have satellites to monitor those people.
- dredmorbius 8y agoGo read some history. Power is Power, and will wear any damned guise it wants. Corporations, criminals, monarchies, democracies, Fascists, Communists, Catholics, Protestants, Jews, Muslims, Hindus, Confucists, Goths, Huns, Romams, Macedonians, Persians, Greeks, Trojans, Hittites, Israelites, etc., etc., etc., have slaughtered, sacked, enslaved, oppressed, or dehumanised others, all in the name of temporary gain. The British East India company had armies. Wyoming cattlemen funded a mercenary army in the Johnson Count War. Coal wars in Apallachia and Colorado. U.S. Steel, Standard Oil, the Pullman Company, the L.A. Times, Union Carbide in Bhopal, oil companies throughout the US, Middle-east, Indonesia, and Africa. Fruit companies in Latin America. Sugar, tobacco, and cotton plantations. Coal mines in Wales. The Kochs today.
- braunshedd 8y agoPreviously discussed yesterday, and again two days before that: https://news.ycombinator.com/item?id=17069459 https://news.ycombinator.com/item?id=17069459 This is one of the reasons I use a public-facing Twilio number, which forwards to a private number which I never hand out. This isn't something that people should have to do to opt-out of tracking like this, but it doesn't seem like there are many other reliable options.
- rando444 8y agoIf you take that cell phone home with you regularly and don't live in a multi-unit building, it would be relatively trivial to figure out your identity using this data.
- braunshedd 8y agoUndoubtably. Not a strong protection against doxxing, but might offer some semblance of protection from 'drive-by-lookups'. With a modern smartphone and location services, there's only so much you can do.
- fapjacks 8y agoJust a heads up: Twilio now offers a metric fuckton of services geared towards SIM-enabled IoT. You can order SIM cards by the pile and then bind them to a Twilio number by activating it in the UI (or via API). So now instead of (or in addition to) simply forwarding traffic from garbage numbers to your real number, you can get Twilio numbers that are registered on T-Mobile's network via an actual SIM card, making it much easier to send from your Twilio number than it used to be without it bound to a SIM card. Fairly good price, too. Unfortunately, I'm not sure what happened to Twilio's API as it's now as opaque and awkward as any AWS API (almost as though someone on Twilio's engineering team made the decision to model their API after the way AWS builds their APIs), but the services they offer are as compelling as they always were. I'd give Twilio a solid D for what the API has turned into, but A+ for service innovation.
- reustle 8y ago
- assblaster 8y agoThe most obvious use of the data appears to be by credit card companies to detect fraudulent use of a card and decline those transactions. This is something I'm relatively comfortable with, though it's plainly in the interests of the bank and I only indirectly benefit from the tracking.
- pdkl95 8y agoThe most obvious use is insurance companies looking for excuses to deny claims.
- dspillett 8y agoAs blocking fraudulent claims could remove a reason for my premiums to he higher, I can't say I'm against that. With the caveat, for course, that people are not always where their phone is so this taken on its own would be circumstantial evidence: one would hope decisions are not made directly based on this information.
- nojvek 8y agoIt’s not in the interest of insurance companies to lower premiums. They only do it if competition is eating them alive. Geico has been raising their margins ever so slightly. I bet they are also the purchasers of ungodly amounts of data for targeting marketing. Insurance companies #1 goal is to make maximum profits for their shareholders without getting caught with their pants down.
- mostlyskeptical 8y agoMine go down fairly regularly. I have even been cut a check for adding cars to my insurance.
- brewdad 8y agoAre you changing insurance companies regularly? Why would an insurance company have any reason to reduce your rates unless legally required to? Even if they've been overcharging you for years compared to competitors, if you aren't calling them up and threatening to change insurers, why would they ever give you money back?
- gpvos 8y ago> the Electronic Communications Privacy Act only restricts telecom companies from disclosing data to the government. It doesn't restrict disclosure to other companies Clearly the US has their priorities completely the wrong way.
- RubenSandwich 8y agoPart of the American mythology is that government involvement is always bad. It's hard for me to know if this developed because of the myths of the America Revolution, that a small colony won it alone and not because of external factors, and how much is due to people preaching small government politics. Regardless a distrust of the government seems to be ingrained in the American psyche IMO.
- stevehawk 8y agoAhaha what? There's no myth that we won it alone. Elementary school texts on the subject lay it out fairly clearly that we did it with the French.
- lostcolony 8y agoThere are a worrying number of people in the US who believe in American exceptionalism. When the French are brought up by them, it's generally in the context of "We saved their asses in WWII", not "They were vital in our war of independence".
- adventured 8y agoTrump just spent his formal state visit with Macron repeatedly extolling the role the French played in American independence. Trump addresses almost everything he does to the same audience that elected him (the same people that your premise would imply don't understand how vital France was to US independence). It's blatantly clear that average Americans for two centuries have understood the very important role France played. It is taught in all schools in the US. Just about all nations believe in their own exceptionalism. Ask a person from Scandinavia what the best nations on earth are sometime. You really don't need to ask, they'll start all of their replies with: in Sweden we are bestest. Ask a French person how glorious their culture is. Ask a person from China how extraordinary their nation is and about how it's going to dominate the world in the future. Ask a German who makes the best cars on earth (they'll volunteer that, you know, Americans should make better cars if they want to fix the trade deficit, snark snark, chortle). Ask a Canadian if their country provides for a superior way of life vs the US - they won't hesitate for a second to proclaim that as a matter of fact their way of doing things is superior. Ask a Japanese person, off the record, if they're superior to the Chinese. America's exceptionalism, is that it's the only nation aggressively called out for believing it's exceptional.
- lolc 8y agoThe way I understood it is that the requester of the location is trusted to have gotten consent from the subject of the query. The providers will answer any queries. So Securus works on the "we're sure our customers are getting consent for their inquiries" presumption. What are the consequences if a company is found to not have gotten consent? Business sense dictates there to be no consequence at all if Securus can avoid it. The way this should work is that the carriers can get permission to share location data with third-parties. They should not do it without having gotten permission from their customer. But then they probably get that when you sign the contract. Or do they just not mention it?
- kurthr 8y agoI wondered how the spam callers knew what area code I was in while traveling out of state. I would assume that through clustering analysis (eg coworkers/friends travel together) even fairly coarse position data can allow you to construct relationships. Then they can spam/fish both you end your coworkers with the same fake number. That makes it seem more important to answer and more organic.
- wpietri 8y agoA friend of mine just got back from NYC and then received a fake call from an NYC area code. I get several every day from random area codes, and we had to wonder whether it was coincidence or not.
- baxtr 8y agoWhat if I as an European visit the states? Am I protected by through some agreements with my local provider or even GDPR?
- einfach 8y agoMaybe [1]. I wouldn't count on being protected while outside the EU. Art. 3 GDPR Territorial scope Article 3(1) This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: Article 3(2)(a) - the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or Article 3(2)(b) - the monitoring of their behaviour as far as their behaviour takes place within the Union. Article 3(3) This Regulation applies to the processing of personal data by a controller not established in the Union, but in a place where Member State law applies by virtue of public international law. [1] https://gdpr-info.eu/art-3-gdpr/ https://gdpr-info.eu/art-3-gdpr/
- John_KZ 8y agoPractically you're just going to get extra tracked because you're a foreigner. Also if the articles about TSA borrowing your phone to clone it real quick or forcing you to log into facebook are true, I wouldn't expect them to abide to GDPR.
- emodendroket 8y agoI doubt you get extraterritorial protection.
- a_imho 8y agoWhy do you assume European carriers do not do the same?
- chillingeffect 8y agoThrough FISA, all foreigners are legal monitorable, no matter what. This is part of how US mass surveillance works. We record everything and if it turns out to be a citizen, we're supposed to throw it out. Of course in reality, it goes to the Parallel Construction Department who uses the information to build a case against someone through other means, knowing the answer in advance.
- kevcampb 8y agoCarriers have been providing these services to 3rd party providers since at least 2006 https://www.theguardian.com/technology/2006/feb/01/news.g2 https://www.theguardian.com/technology/2006/feb/01/news.g2 A few points to note: * Obtaining consent is entirely left to the provider to implement. It does not appear to have any auditing. A provider can query any number they like. * The opt-in process used by many providers is easy to exploit, by spoofing SMS replies or abusing the SMS template so that the surveillance target does not get notified * The providers have are well aware of the potential to exploit this and have been for some time. It has never been resolved in over 10 years.
- kevcampb 8y agoI just discovered this treasure trove from the UK house of commons in 2006 https://publications.parliament.uk/pa/cm200506/cmhansrd/vo060314/debtext/60314-12.htm https://publications.parliament.uk/pa/cm200506/cmhansrd/vo06... "To extend that to adults, The Guardian journalist Ben Goldacre showed recently that someone needs possession of another person's mobile phone for only a couple of minutes to appear to give the consent required under mobile phone companies' current procedures. The person he was tracking never got any of the warning messages that were meant to have been sent to her. Even more scarily, a hacker's website has recently published information telling how to spoof consent without even having to have temporary possession of the target's phone; all that is needed is the number. If someone has a person's number, he can track them. It is not a problem. I know where the website is, but I am not going to tell Members. It is possible to track people just through their phone numbers."
- fixermark 8y agoIs it even considered an exploit? It's a cell carrier providing data about the radio communications between hardware they own and someone else. At a moral level, seems somewhat equivalent to a web server providing data about clients that access the server. To opt out, stop using some third-party corporation's owned hardware to route your communications near lightspeed around the world. Hey, the Amish communities may have something in their overall philosophy of "Don't be beholden to strangers who aren't part of your community."
- Qwertie 8y agoThe worst part is there isn't any possible way I know of to defend yourself against this other than not having a phone.
- rinze 8y agoA while ago I thought of a very neat 'future job': you walk around town with somebody else's phone. So if you 'need to be' somewhere, you just hire this service, deliver your phone, which will be returned to you, and there goes your track record.
- metalliqaz 8y agoyeah but... then the customer doesn't have their phone I need my phone, especially when I'm out
- cpeterso 8y agoUse a drone to fly your primary phone to the location and relay the call to your secondary phone on your person.
- eximius 8y agoThat's fairly easily detectable through analysis, though.
- gm-conspiracy 8y agoNot if you use a clowder of feral cats.
- pavel_lishin 8y agoIt would probably be more detectable, since a cat's movement pattern would likely be very different from you or a stranger you hired.
- xfitm3 8y ago
- itchyjunk 8y agoI am starting to wonder what all have I consented to? Every week I learn I have consented to this and that because of a news article as I never read those contracts or TOS. I wonder if there will be a way to phrase long contracts into bullet list of ideas for someone simple minded like me in the near future.
- emodendroket 8y agoIs that possible? Yes, but it's not in their interest to do.
- itchyjunk 8y agoMaybe by some 3rd party then? Maybe an application of all the fancy natural language processing or some other ML. I visit the site, paste the TOS or maybe there is a list of TOS that has been translated and i get a nice gist.
- emodendroket 8y agoI think a more realistic option is Congress imposing a requirement on them, the way the terms of a loan have to be presented in a standard form.
- Sharlin 8y agoOne of the things that GDPR requires is real informed consent, small print hidden inside a thirty-page EULA is not acceptable.
- mtgx 8y agoAnd unlike some of the recent proposals in the U.S., it's generalized to all industries.
- xexers 8y agoYou would need 76 work days per year to keep up with reading all of your TOS http://techland.time.com/2012/03/06/youd-need-76-work-days-to-read-all-your-privacy-policies-each-year/ http://techland.time.com/2012/03/06/youd-need-76-work-days-t...
- emodendroket 8y ago> Kevin Bankston, director of New America's Open Technology Institute, explained in a phone call that the Electronic Communications Privacy Act only restricts telecom companies from disclosing data to the government. It doesn't restrict disclosure to other companies, who then may disclose that same data to the government. It seems like intelligence services spend a lot of their time dreaming up ways to do an end-run around the law. This is the same reason US intelligence does partnerships with foreign intelligence services.
- dwighttk 8y agoI'd rather them try to do end-runs around the law than run it up the gut... (If I had to choose)
- wmeredith 8y agoFalse dichotomy. There are a million choices.
- risotto_groupon 8y agoJust think of how amazing the museum will be for your great grandkids when we completely dismantle them when, inevitably, their stated mission goals supersede common sense and a responsible relationship to the American public.
- nojvek 8y agoI doubt any of the privacy invasions are going anytime soon. The big tech cos pull in ~100B in revenue precisely because they can capitalize on the data. As long as there is crazy amount of money to be made, it will keep on getting worse. Having hope on the US govt to do anytime is wishful thinking. Govt and corporations are hell bent on knowing everything about you. It gives them the power.
- risotto_groupon 8y agohttp://www.stasimuseum.de/en/enindex.htm http://www.stasimuseum.de/en/enindex.htm
- yosito 8y agoHas anyone suggested a practical way that people can avoid being tracked? (Aside from Airplane Mode or keeping your phone in a Faraday Cage)
- emodendroket 8y agoDon't use a cell phone, I guess.
- John_KZ 8y agoThere's no way to do this without using your own antenna network. Even then, you need encryption just to anonymize your calls, but if you end up talking to people subscribed to the same carriers you're trying to avoid, you can trivially be de-anonymized by timing attacks. So there's no good solution, unless you're willing to turn your calls to voice mail. More practical solutions would include: -(physically) Powered off radio unless you want to make a call. A clear drawback is that you can't receive calls. -Satphones. I'm pretty sure satellite phone providers aren't in this yet. They could be, but my guess is that they wouldn't want to waste bandwidth triangulating their users. Also satellite-based triangulation would be much harder and less accurate, and if you use your own directional antenna and sat-tracking mount, you can avoid this altogether. Until they start installing phased array antennas or something. -Finding a provider that doesn't sell your data to third parties. Probably the hardest of all, and you have to rely on their word.
- yosito 8y agoIt used to be possible to buy prepaid SIM cards with cash and not have to provide any identification. AFAIK, this isn't possible anymore. Does anyone know for sure?
- John_KZ 8y agoThe providers in our country require ID. I think there was an EU directive in 2006 that gradually forced all providers to require identification. Of course this doesn't stop criminals in the slightest, they just get second hand SIMs registered by homeless or just SIMs from outside the EU, so it was a pointless law with regards to reducing crime, but if the goal was more surveillance they did ok.
- random6547545 8y agoThrowaway account. I work in location / mapping / geo. Some of us have been waiting for this to blow (which it hasn't yet). The public has zero idea how much personal location data is available. It's not just your cell carrier. Your cell phone chip manufacturer, GPS chip manufacturer, phone manufacturer and then pretty much anyone on the installed OS (android crapware) is getting a copy of your location data. Usually not in software but by contract, one gives gps data to all the others as part of the bill of materials. This is then usually (but not always) "anonymized" by cutting it in to ~5 second chunks. It's easy to put it back together again. We can figure out everything about your day from when you wake up to where you go to when you sleep. This data is sold to whoever wants it. Hedge funds or services who analyze it for hedge funds is the big one. It's normal to track hundreds of millions of people a day and trade stocks based on where they go. This isn't fantasy, it's what happens every day. Almost every web/smartphone mapping company is doing it, so is almost everyone that tracks you for some service - "turn the lights on when I get home". The web mapping companies and those that provide SDKs for "free". It's a monetization model for apps which don't need location. That's why Apple is trying hard to restrict it without scaring off consumers.
- tekstar 8y agoIs this happening with iPhone as well, or primarily android due to the third party nature of the hardware?
- matwood 8y agoThe problem is once it's at the cell carrier level it doesn't even matter if you use a dumb phone. They know roughly where you are based on tower triangulation.
- crankylinuxuser 8y agoAs an amateur radio operator, I would expect nothing less for carrying a highly networked radio transceiver with loads of sensors including geopositioning. Simply put: don't want to be tracked? Put your phone in a lead sealed box or leave it at home. Tracking only tracks the phone , not your person.
- knodi 8y agoCarriers are also selling your billing records. They offer a service to return the carrier billing address/name based on the mobile number. Not only this but late last year all 4 of the major US carriers are offering APIs to convert mobile IP to a billing record (name/address/phone number).
- cascom 8y agoThis is even more disconcerting - just out of curiousirty what does this cost?
- knodi 8y ago9c on the high end, under a 1c on the low end (with volume/long term commitment)
- bscphil 8y ago>Not only this but late last year all 4 of the major US carriers are offering APIs to convert mobile IP to a billing record (name/address/phone number). That's terrifying. Do you have a source I can look at for this? It might be time to always-on VPN my phone.
- draw_down 8y agoOther companies are selling access to this and other info too. Check out Urban Airship’s Connect product.
- cyanbane 8y agoDoes anyone know of a way you can request consent status from your service provider?
- erikpukinskis 8y agoSend a letter to their legal department requesting the information.
- wmeredith 8y agoAnyone have a link to jeans with faraday pockets?
- deleted 8y ago[deleted]
- dhimes 8y agoWould airplane mode work?
- metalliqaz 8y agoAirplane mode would work, yes. But it only works against the cell provider. The on-phone GPS can still work and sync the data later.
- hanspeter 8y agoI would imagine the airplane mode deactivates GPS signal recipience?
- gm-conspiracy 8y agoWhy? Would it only prevent transmission of radio signals, not reception of them. Just the TX, not the RX.
- ThinkingGuy 8y agoI can confirm that it doesn't, at least on the iPhone 7. I recently took one on an overseas trip and left it in airplane mode the whole time. The photos I took during the trip were all properly geotagged.
- deleted 8y ago[deleted]
- paulmd 8y agoGPS is passive, so there's no need to disable it in airplane mode.
- thr0waway999 8y agoIsn't this how teralytics.net gets the data it sells?
- deleted 8y ago[deleted]
- m3kw9 8y agoIsn’t carrier IQ been always doing that?
- Someone1234 8y agoCarrier IQ was far more invasive than just location. Their "Experience Manager" was supposedly tracking every app launch, time spent in that app, metrics on key & button presses within that app, and other misc interactions. They got accused of being a "keylogger" which they rightly said they weren't, but that ignores how invasive and creepy Experience Manager was (is?). Their whole argument was that carriers can use this app data to see what apps are draining battery, which is kind of bs since carriers are in no position to resolve battery issues or advise customers. The reality is that carriers wanted more information on how customers were using their devices, Carrier IQ provided that raw data, and both got rich. They survived the scandal because the critics focused on keylogging, instead of the highly invasive usage analytics which it really was.
- addflip 8y agoIt's funny that this is coming up now. The other day I was on the phone with Geico's roadside assistance and they wanted to know my location. I told them I didn't have their app downloaded, they said it wasn't a problem and they could get it without it. Sure enough they could. I checked their disclaimers [1] and they purchase the data from my cell carrier. They didn't even have to know which one. [1] https://www.geico.com/web-and-mobile/mobile-apps/roadside-assistance/ https://www.geico.com/web-and-mobile/mobile-apps/roadside-as... (see disclaimers at the bottom)
- limsup 8y agoWow. The fact that they can just get this with "oral approval" (relayed by them to your carrier) is shocking to me. This is ridiculous.
- jellicle 8y agoThey don't need oral approval or any approval. GEICO is only asking so that their customers won't freak out when GEICO magically knows where they are. The customer service rep probably had the data up on their screen already when they asked.
- trendia 8y agoI wonder if they use this data to price insurance -- they would easily know when their drivers are going over the speed limit (or, if such data is not so precise, if their average speed over 10 minutes exceeded the speed limit).
- addflip 8y agoThat was my concern.
- ThrustVectoring 8y agoMore likely is approximating number of miles driven and price discriminating based off that. More miles driven = more risk of an auto accident. Basically pay-per-mile car insurance, but hidden.
- 0xb8000 8y agoWe don’t have a problem when google does it ?
- goda90 8y agoYou don't have to use a Google powered phone. But the modern economy almost demands you have a cell phone.
- dredmorbius 8y ago1. Whatabboutism. 2. Yes, we do. https://plus.google.com/104092656004159577193/posts/foKDxbyhYUF https://plus.google.com/104092656004159577193/posts/foKDxbyh...
- Negative1 8y agoI've just started using Signal and was surprised by how good the call quality is. For those that aren't aware, Signal calls are encrypted, so you effectively give nothing to the cell carrier when you make a call through it (except that you used some data).
- goda90 8y agoUnless I misunderstood, this has nothing to do with what apps you use to communicate. It has to do with connecting to the cellular network at all. I think the only way around this would be to run airplane mode with wifi only, and then taking lots of steps to keep your wifi use private too.
- faitswulff 8y agoWhile it is true that Signal's call quality is great, this doesn't seem relevant to the fact that cell providers can track you regardless of what apps you use.
- privong 8y ago> Signal calls are encrypted, so you effectively give nothing to the cell carrier when you make a call through it (except that you used some data). Maybe not to your carrier, but presumably Google could capture some form of metadata.
- Spooky23 8y agoI’m shocked that anyone is shocked about this! Transportation departments have been buying this data since the late 90s. More creepy are the planning solutions for commercial development. You can buy datasets that will tell you the average income of drivers on larger highways in hourly buckets.
- forgottenpass 8y agoWe don't _all_ work in adtech, you know?
- trophycase 8y agoAnd thank god for that...
- jobigoud 8y agoThe article mentions banks tracking your credit card usage to detect fraud. Are there known instances of banks reselling this location data?
- jhowell 8y ago> Cook: What would he do if he were Facebook CEO Mark Zuckerberg? His answer: “I wouldn’t be in this situation.” Sounds like one of those situations to me...
- OnlyRepliesToBS 8y agoClass Action Status: One dollar for every minute per person per conversation captured.
- arca_vorago 8y agoOne of these days, most of you will finally understand just how right RMS was and is... It's just a shame so many can't see it, and worse, give those of us who do shit.
- noetic_techy 8y agoRMS = Richard Stallman?
- reustle 8y agoCorrect
- wilsonnb 8y agoStallman is not a prophet and there are many valid arguments against his views.
- pathseeker 8y agoNot really "valid arguments" but differing opinions. If you are fine with closed systems and surveillance states then everything RMS says against these systems will sound wrong to you.
- OldSchoolJohnny 8y agoYeah him and every tin foil hat guy have been ranting about this for years. Doesn't make it not true, but RMS? Really? That guys is a certifiable nut job and we would all do well to let him lapse into the dust of history.
- fixermark 8y agoSo as a private citizen, I can pool some money and get the same level of tracking that American intellignece services have of individual cell hardware? Sounds like a win for the citizens.
- mastofaces 8y agoI tried location smart website said location accuracy was up to 14 miles off. They were really 4 miles off. So not that accurate. If it was 2 blocks like other poster I'd be worried.
- Rjevski 8y agoThis exploits a vulnerability in the SS7/MAP protocols that power mobile networks worldwide; the cooperation of the carrier isn't even required (even if carriers were against this; bad actors can and will get this data anyway).
- deleted 8y ago[deleted]
- willstrafach 8y agoYou are referring to the command used to request where to route an SMS message, I assume? If so, carriers can (and have been albeit very slowly) restrict this activity so it is less of a free-for-all. That said, it seems they are intentionally selling this data as well, which is a whole new issue.
- code4tee 8y agoI was aware the cell phone companies were selling anonymized data for some time (not revealing the numbers and adding some jitter to the location data to avoid identifying users). This is the first I’m hearing that they’re releasing detailed personal tracking by phone number. When I sat in on a recent presentation with Verizon execs they flat out said they were not doing this. Oops.
- wpdev_63 8y agoWhen are we going to wake up and reform privacy laws?! This cannot be the new norm. Something about this has to be illegal.
- 8_hours_ago 8y agoI believe the relevant T-Mobile privacy policy (that I definitely read before signing up...) is: "With your consent. We may provide location-based services or provide third parties with access to your approximate location to provide services to you." https://www.t-mobile.com/company/website/privacypolicy.aspx https://www.t-mobile.com/company/website/privacypolicy.aspx That is why a text message confirmation is required to get a cell phone's location from https://www.locationsmart.com/try/ https://www.locationsmart.com/try/ For those on T-Mobile, there are privacy settings that can be adjusted here: https://my.t-mobile.com/profile/privacy_notifications/advertising https://my.t-mobile.com/profile/privacy_notifications/advert... I already had all of them disabled, and I was still able to get the location of my cell phone from LocationSmart. I chatted with T-Mobile support yesterday to see if I could opt-out of them sharing my data. Not surprisingly, the support agent was less than helpful. "Don't worry, your data is secured" Are there any US carriers that respect privacy and do not share private information with 3rd parties? Or is that a pipe dream?
- mohaine 8y agoWell, the locationsmart fails completely on my Google fi phone.
- byproxy 8y agoI imagine Google wants sole access to your location.
- drbawb 8y ago... well now I'm wondering if I should have stuck w/ my Pixel + Fi instead of the S9 + T-Mobile plan I signed up for today. Whoops.
- tomaskafka 8y agoYou are chosing between spyphone on spynet and spyphone on spynet.
- dylz 8y ago
- g8oz 8y agoI assume this is how we get real-time road traffic information, is it not?
- kylehotchkiss 8y agoDon't banks use this data when you create an account nowadays too? I just created a capital one account and they were actually pretty transparent that they'd be checking the location of my phone via carrier.
- 5064364100 8y agoVery much a tangent, but this song is the perfect soundtrack for privacy / tracking articles like these: https://www.youtube.com/watch?v=8ttTf8N7Bwg https://www.youtube.com/watch?v=8ttTf8N7Bwg "The Hymn Of Acxiom" Somebody hears you. you know that. you know that. Somebody hears you. you know that inside. Someone is learning the colors of all your moods, to (say just the right thing and) show that you’re understood. Here you’re known. Leave your life open. you don’t have. you don’t have. Leave your life open. you don’t have to hide. Someone is gathering every crumb you drop, these (mindless decisions and) moments you long forgot. Keep them all. Let our formulas find your soul. We’ll divine your artesian source (in your mind), Marshal feed and force (our machines will) To design you a perfect love— Or (better still) a perfect lust. O how glorious, glorious: a brand new need is born. Now we possess you. you’ll own that. you’ll own that. Now we possess you. you’ll own that in time. Now we will build you an endlessly upward world, (reach in your pocket) embrace you for all you’re worth. Is that wrong? Isn’t this what you want? Amen.
- jiveturkey 8y ago> one of the biggest gaps in US privacy law. Gaps? How about lack of? https://content.next.westlaw.com/6-502-0467?transitionType=Default&firstPage=true&bhcp=1&contextData=(sc.Default) https://content.next.westlaw.com/6-502-0467?transitionType=D... General Laws: Not Applicable. Sectoral Laws: There is no national law. ---- How outrageous and disgusting that congress can make a big show of questioning facebook over privacy, when they don't have the courage to pass even moderate data privacy laws. How much do you want to bet this location data will be ignored by congress?
- AlexCoventry 8y agoDoes disabling the location data via the settings make any difference, and is there an app which will turn off location data after a set period?
- thsowers 8y agoNo, I tried with my number, all location data off. GPS landed right on my house, very room phone was in.
- swerveonem 8y agoHow do I get into this business? PM me if you want to collaborate.
- JudasGoat 8y agoIt is very tempting to go full "tin foil hat" at this point. I am seriously considering removing my cell battery and powering it up semi hourly to check for messages.
- dredmorbius 8y agoHow much do you typically move in 30 minutes?
- mancerayder 8y agoThe individual rights under the Constitution have been deemed, in the U.S., to only apply to government and government institutions. The private companies are exercising their free market rights, unfettered by inconveniences like privacy rights, and thus can (as per the article and the random65... whistleblower user at the top of this thread at the time of this writing) track behavior and sell the data. Therefore, does it follow that government canNOT be the buyer of such data? That police departments or the FBI or others cannot access this data? Is there a Chinese Wall in place to prevent such things from happening. Or...?
- turdnagel 8y agoI met a high-level executive at Ericsson who told me that he had met with Tim Armstrong (CEO of AOL) could make $5 billion more a year if he had access to location data with <50m accuracy.
- deleted 8y ago[deleted]
- Steeeve 8y agoIt's funny to me that this is news to anyone. This has been going on for quite some time - at least the length of my career. For the longest time it was wide open for anyone to access who had an inkling of knowledge about how mobile devices worked. Did this _never_ come up at defcon or in an issue of 2600? Are people really _that_ focused on web security?
- noobermin 8y agoTurns out that Stallman was right.
- toetied 8y agoi havent read all 504 comments, and dont plan to, but this should come as no suprise to anyone, unfortunatly it does. cogress, dc, will not help there is too uch to gain, posting the info in real time of the ones in power, will shine a light on the issue, they will make it look like this has been taken care of-while it continues. the ONLY solution in my opinion its a revolt-against big data/tech, not a boycott, and exodus to DIY open source tech.
- 8bitsrule 8y agoOnce the books are all burned, there will be no more book-burnings.
- Horatio9000 8y agoThere was mild discontent when the Data Retention laws [1] were being rolled out across the EU in the early 2010s. This was a legal harmonization of existing collection practices for law enforcement purposes. It did receive a lot of press coverage and some small protests (even though in reality the collection was already widespread). In 2009, Malte Spitz (German Green Party politician) sued his telecom provider for all the information they had stored on him in the last 6 moths. He and others made a good (and spooky) visualization showing how it tracked his entire life [2]. He did a TED talk about it [3], which received a spirited applause and unfortunately minor press coverage. I think many naively bought the idea that all this detailed data was only for LE (maybe a side effect of all the reporting on the Data Retention Laws?), despite constantly seeing clauses in their EULA's saying their data will be shared with third parties. ---- People only care about these issues once they become evident and widespread, and they personally are affected. I remember the shock my friends had when Google Maps released the location history feature. Up until then, its just a theoretical concern. Good demonstrations, hard hitting expositions and good press coverage are essential. ---- [1] - https://en.m.wikipedia.org/wiki/Data_retention https://en.m.wikipedia.org/wiki/Data_retention [2] - https://www.zeit.de/digital/datenschutz/2011-03/data-protection-malte-spitz https://www.zeit.de/digital/datenschutz/2011-03/data-protect... [3] - https://youtu.be/Gv7Y0W0xmYQ https://youtu.be/Gv7Y0W0xmYQ
- TangoTrotFox 8y agoAnother 'fun' implication of this are the increasingly large number of sites that try to obtain your phone number either through SMS messages during account setup, two factor authentication, or any other number of ways. The accounts you have on those sites link directly to your physical presence. Taking it one small step further, any accounts on other sites you have linked to those accounts are similarly effected. Taking it one step even your dynamic IP address at any given moment can end up working as a physical identifier. The amount of information the NSA has on people is going to be phenomenal. It'd be interesting to be able to glimpse the data just to see how much we all give away. Here's to hoping we never once ever end up putting a 'bad' person in high office because the amount of targeted damage somebody could do with this information is just staggering to even consider.
- entrypoint0 8y agoTwo related stories: I went to a recruiting event in 2013, or 14 perhaps, for a major telecom network in Canada. They were proudly showcasing their ability and interest to analyze people's data. I was shocked, so I spoke to the hiring manager: "You should be concerned about google and Microsoft, they have much more data" he said. They do, but much less sensitive data. And I am paying you! And google gives me free excellent services. You are an expensive oligopoly with not the best customer protection track record. 2. I had a free modem from a major network that came with the internet. I used the modem at another location while I was away. I got charged for my usage! The modem was not just a modem, it was sensing more information to their system. That is how they tracked my usage, if that is the only thing they tracked. Their technical customer service avoided any form of discussion. Cancelled my internet line with them, and using VPN for trackable stuff ever since. I am seriously considering cancelling my cell phone until their practices changes.
- _o_ 8y agoI think that Snowden comment fits here: "Arguing that you don't care about the right to privacy because you have nothing to hide is no different than saying you don't care about free speech because you have nothing to say,"
- BigBalli 8y agoAfter reading this post a couple hours ago, I was able to play around with LocationSmart's API. Indeed seems quite powerful/comprenhensive. As of an hour or so, they took down their try/demo webpage and related open API.
- yawz 8y agoIsn't this covered under CPNI [1]? Something that consumers can opt out? [1] https://www.wikiwand.com/en/Customer_proprietary_network_information https://www.wikiwand.com/en/Customer_proprietary_network_inf...
- deleted 8y ago[deleted]