4 ms·
"With a court order, this data can be used to identify and track an individual... ... which means that it is stored de-anonymized in the carrier servers" No, i
by diego 7y ago
"With a court order, this data can be used to identify and track an individual...
... which means that it is stored de-anonymized in the carrier servers"
No, it does not mean that it's stored de-anonymized. It means that it can be de-anonymized if required by a court order.
EDIT because all the downvotes, this is not nitpicking. The deanonymizing data is ELSEWHERE, not on the servers. It takes a court order to obtain it, employees cannot use it. It's an important point.
- the_svd_doctor 7y agoIsn't that the same? If it was properly anonymized, it couldn't be de-anonymized. Which implies it's not anonymized, i.e., it's store de-anonymized.
- diego 7y agoNo, it's not the same. It could be stored anonymized, and the de-anonymizing data is somewhere else, and it can ONLY be accessed with a court order. I don't know why my original comment is being downvoted, it's an important distinction. Edit: stop with the downvotes please. Whether you agree or not, anonymizing something does not always mean it cannot be de-anonymized. And who can do it (and under what circumstances) is important.
- matheusmoreira 7y agoIf the de-anonymizing data exists at all, then the anonymized data was never truly anonymized in the first place.
- diego 7y agoAnonymizing does not mean that it has to be one-way. You can give other people an anonymized version of your data, but you can keep the key to deanonymize that data (and hand it out selectively). I don't know who is assuming that anonymizing means the information has to be thrown away and lost to EVERYONE.
- morganherlocker 7y agoThis does not work for most location datasets. It is easy to Re identify users in this type of dataset with a few lines of code. The identifying information is embedded in the locations and time stamps themselves. Research shows 4 randomly selected location points from a phone is all that is needed to uniquely identify 95% of the population.
- matheusmoreira 7y agoIf someone can use that information to identify you, then the data is by definition not anonymized. It doesn't matter how exceptional the circumstances where that's allowed to happen are. "Fully 100% anonymous, unless we label you a terrorist" is not the same as anonymous.
- diego 7y agoIf you're going to nitpick like that, then no data is ever anonymized if it contains any information at all. When you start combining pieces of data, they all contribute information that helps you narrow down individuals until there is only one possible match.
- matheusmoreira 7y agoIt's not nitpicking. Your definition of "anonymized" leads people to believe they are anonymous when they are not. That can lead to serious consequences.
- diego 7y agoIt’s not my definition. You’re twisting words. Location data is just not “anonymizable” at all because it’s always possible to combine it with other sources.
- morganherlocker 7y agoRead up on differential privacy and k-anonymization. There are commonly implemented best practices for measuring and preserving anonymity in a dataset in non-reversible ways. It usually involves aggregating clusters of data and dropping clusters with too few unique contributions. These techniques have a long track record in the private sector and with public entities such as the US Census, with a lot of formal research to back it up.
- Allower 7y agothere is no functional difference from a security standpoint
- fortytw2 7y agoIn order to de-anonymize it, the data needed to do so would have to be stored somewhere, very little difference between something split and that.
- Eldt 7y agoAre you just being nitpicky or does that actually make a difference?
- diego 7y agoIt does, see my other comment. It means employees CANNOT deanonymize the data. If done properly, the key is off network and off premises, only retrievable with a lot of red tape.
- salawat 7y agoThen it isn't anonymized. It can't be unmaskable by any procedure and anonymous at the same time. You need to stop calling it anonymous and call it what it is: Bound to an individual, but not actionable via the collecting agency without outside input.
- ryanlol 7y agoSo how many carriers do you know that do this properly?
- aivisol 7y agoCan you explain this to the layman? How does it work? Does it mean they store IMSI hashes with location data in one database and customer names and their IMSI in another and nobody supposedly should have access to both databases at the same time?
- wastedhours 7y agoThat's the explanation I'd expect the answer to be. In Europe it'd be classified as pseudo-anonymous, and would still be personally identifiable data in the legal sense, and therefore not truly "anonymised".
- mytailorisrich 7y agoThe network stores the location of connected users at cell level (group of cells, sometimes) because that information is required to page (ie receive calls) and then to route traffic.
- jamescontrol 7y agoThat sounds like the same thing. What would you say if a SaaS told you that they store your password hashed, but that they can reverse it and get it out in plain text, if someone with authority asks?
- zaphod4prez 7y agoThe idea that 24/7 minute-by-minute location data can somehow truly be "anonymized" is beyond ridiculous. It's easy for any organization (or even a single researcher who has cash to spend) to deanonymize it by merging w any number of other datasets that are available for purchase. "Anonymizing" this kind of data is really just saying "for some of these users, it'll be somewhat expensive to unmask them. for others it will be trivial." https://www.researchgate.net/publication/220926571_Anonymization_of_location_data_does_not_work_A_large-scale_measurement_study https://www.researchgate.net/publication/220926571_Anonymiza...
- myrryr 7y agoIf you read the original, it is aggregated on an hourly based by cell tower, at the Telco level, before it hits the stats department. Also New Zealand did it first, using exactly the same model. The stats department don't get unit record.
- deogeo 7y agoDepends on your definition of "the data". If they store all the data, split it in two, and you only count one half as "the data", and the other half as... something else, then yes, it can be both anonymized and de-anonymizable. But I think privacy advocates (myself included) count everything collected and stored as "the data", and don't find some red tape securing it particularly reassuring.
- caconym_ 7y agoIf you can de-anonymize so-called "anonymous" data through some well-known (intended, even) procedure then said data is not anonymous. This is trivially, definitionally true.
- stjohnswarts 7y agoThen that isn't anonymized at all. Anyone who thinks it is is a fool. It's just 2 step identification, and pretty typical of overreaching governments. No one should be tracked unless a warrant is issued and at that point meta data can start being collected.