14 ms·
Your mobile data sold, without your knowledge
- soared 6y agoIsn’t data this granular illegal, at least in the US? Obviously trying to make the data anonymous does nothing if you can still see the same user over time - I’ve only ever seen this data with users put into groups, and data points fuzzed.
- ggggtez 6y ago>is granular location data illegal Generally speaking, there are no laws against merely possessing data, unless the data itself was the result of a crime. Maybe you mean selling the data? That's nuanced. It seems to be illegal for phone-companies to sell your real-time cellphone location... but historical data? App developers instead of phone companies? The devil is probably in the details in terms of what constitutes a crime and what is just shady business. See [1] where AT&T sells your location data but insists it's not technically illegal (but claims they stopped selling it anyway). Many companies try to anonymise this data anyway because it's good business to not piss off your customers. [1] https://www.theverge.com/2019/5/17/18629553/att-t-mobile-sprint-verizon-selling-user-location-data-illegal-fcc-letters-public https://www.theverge.com/2019/5/17/18629553/att-t-mobile-spr...
- PeterisP 6y agoThe article is about Norway, and there are laws against merely possessing data, namely the GDPR. To be specific, "merely possessing" private data (the granular movement data would qualify) by companies for business purposes is illegal by default - there are many options that give a legal basis for processing, and many of them do not require the user's consent, but it's upon the company to demonstrate what gives them the permission to do that, and having no justification (if the company "just has it") means that the processing is illegal. And even if the company has a legitimate reason for processing as such, doing so "without your knowledge" is generally illegal, as even where consent is not required, they are required to inform the data subject about the purposes of processing their private data. It's not about selling data - purchasing the data or having it or using it also are covered.
- ggggtez 6y agoThe above poster's question was specifically about the US. GDPR does not cover the US. Europe has more privacy laws than the US does.
- ggggtez 6y agoDespite the title, it was mostly an article about location data being (no surprise) identifying information.
- strombofulous 6y agoWow, this article is really interesting, but one thing I noticed is that the translation is generated and perfect! In fact if the header weren't there I'd have thought it was written by a native english speaker.
- partingshots 6y agoIt’s secretly an ad for Google Translate.
- jalk 6y agoThat is actually a pretty good translation with few mistakes
- vinay427 6y agoIt's alright but it's definitely not perfect. See the italics (emphasis mine) for a few quick examples in the first few sentences of the article. "Over the past year, his cellphone has revealed where he has been for almost 24 hours." "Nor do tens or thousands of other Norwegians." "Just before eight o'clock in the evening, a perfect little boy comes to the world at Stavanger University Hospital." EDIT: The rest of the article is littered with these minor errors every few sentences. I didn't bother including any more quotes here.
- mlthoughts2018 6y agoWhat I don’t get about this kind of thing is that it’s not just shady data resellers you’ve never heard of. It’s also overt, high profile, branded tech companies like Foursquare and Yelp, with huge amassed data sets of foot traffic, wifi scans, battery status, often paired with demographic info or data that can be joined by ad IDs or commercial device graphs. If these companies are able to keep on truckin’ with massive user bases who don’t seem to care that the entire business model rests on flagrant violation of data privacy and data reselling, why would you ever expect anyone to care about the long tail of scammy lesser known data resellers? Companies like Yelp or Foursquare are essentially as scammy as it can possibly be, with the scamminess shoved right in users’ faces, with lots of middle fingers and half-hearted sound bytes about respecting data privacy. If users don’t react in horror and delete accounts / stop contributing en masse in response to that, why would you ever think an expose about something a further ten degrees removed from the user’s immediate experiences is going to cause any reaction? People just don’t care.
- whoopdedo 6y agoWhen someone uses an app such as Yelp it's like valet parking. They know they're handing over something vital, but its with the expectation that the company will provide something of value in exchange, and trusting that they won't use it for more than that. Yes, you're allowing a company to track your movement (for the purpose of grading restaurants). And yes, you're allowing someone else to drive your car (for the purpose of finding a parking space). If you find out a third-party is tracking your location though, that would be as if someone other than the valet were driving your car. And when they use it for their own gain in a way that doesn't return anything of value to you, that would be considered joyriding.
- mlthoughts2018 6y ago“I hand over my data in exchange for the app handing over a valuable experience or service” is the hugest lie in the business. This is exactly what the disingenuous marketing doublespeak of Yelp and Foursquare says. In reality, most users really do not understand or consent to the level of data tracking and are very confused about terms of use or privacy settings in the app or just on their device. The big problem is that it is just not possible for the vast majority of people to have enough expertise or technical know-how to give anything resembling informed consent. Whatever the user is agreeing to, it emphatically is not anything like consent.
- milankragujevic 6y agoThe NY Times had a similar article recently: https://www.nytimes.com/interactive/2019/12/19/opinion/location-tracking-cell-phone.html https://www.nytimes.com/interactive/2019/12/19/opinion/locat...
- Cactus2018 6y agoPrevious short discussion about a "foot traffic" vendor https://news.ycombinator.com/item?id=22704138 https://news.ycombinator.com/item?id=22704138
- aritmo 6y agoMost likely the users installed one of those free apps that ask for location access. Those apps collected the location, even when not ruining and uploaded for sale. It is a pity they did not do better forensics on the installed apps. One or more were revealing the location.
- KMnO4 6y agoIt would be really interesting if each app was fed a slightly modified location as steganography. Then the sold data could be cross-referenced to determine which companies are selling the data.
- mortenjorck 6y agoI don’t know if AccuWeather is available in Norway, but in the US at least, it (in conjunction with location data company Reveal Mobile) has been one of the leading location-data trojan horses: https://www.zdnet.com/article/accuweather-caught-sending-geo-location-data-even-when-denied-access/ https://www.zdnet.com/article/accuweather-caught-sending-geo...
- indymike 6y agoMany of the apps that sell your location use location as a critical component of the experience. Apple and Google added a permission last year - only allow access to location when app is running (in the foreground). That change has made a dramatic reduction in the amount of location data available. Ultimately, free is the culprit. People like to navigate, buy stuff online, see things on a map, get local weather, and so on - especially if it is free. The old adage about if it is free, you are the product probably applies.
- aaomidi 6y agoThen allow me to pay if I want to? I don't get this argument when an alternative doesn't exist.
- gjs278 6y agoyou will pay. they will get $2. everyone else won’t pay. it wasn’t even worth setting up payment for you. oh and you actually wouldn’t have paid either
- nisse72 6y agoAnd even if you are able to pay and choose to do so, do you think this means they stop collecting your data? I very much doubt it.
- mayneack 6y agoSome do. I pay to remove ads from the wunderground app which IBM claims means they don't sell my data. Not sure if believe them, but at least I don't see ads. https://i.imgur.com/TlOo07T.png https://i.imgur.com/TlOo07T.png
- askvictor 6y agoI think the problem is developers/companies only have so much time/resources, and figure that x people might pay for an app/service, but 100x will use it if it's free (with other monetisation strategy), then why bother coding & interfacing with a payment system (and this starts to get convoluted and require and entire department handling payment and tax issues across different countries and jurisdictions) for just 1% of likely users? Not saying that's the right approach, but that's probably how the thinking goes. Billing is certainly easier than it used to be (that's what the 30% app store cut is for), but can still get convoluted, and might have the perception of being convoluted.
- pravda 6y agoA question for the Android experts: is it possible to block or spoof location data, through a custom build? Could I have an Android phone running a program that spoofs a long steady drive from Tampa to Butte?
- realharo 6y agoOn a custom ROM, sure. That's why games like Pokemon Go blocked them. Using it as a daily driver is not advisable though.
- Firerouge 6y agoAt worst, having root should be the most that's required, which only on some phones requires a custom rom. Android has built in support for location spoofing with the developer mode option, select mock location app.
- realharo 6y agoOther apps can easily check whether the location comes from a mock source and discard such data. https://developer.android.com/reference/android/location/Location#isFromMockProvider() https://developer.android.com/reference/android/location/Loc...
- mindslight 6y agoThese type of security vulnerabilities are due to the core OS/APIs being developed by a surveillance company that isn't concerned with user privacy, and they're countless. There isn't enough will in the Free world to mitigate even the most glaring ones either, such as LineageOS not incorporating the MicroG patches. The end result being more forks, more confusion, and groups of users remaining unprotected. Commoditize your complements, indeed.
- seibelj 6y agoYes, it’s very possible, I did similar work years ago patching functions on jail broken phones for seamless encryption.
- deleted 6y ago[deleted]
- jcchapm02 6y agoDoes anyone know what web framework they’re using to get the scrolling storytelling effect? Is this just parallax scrolling?
- sabujp 6y agoreal questions here: https://stackoverflow.com/questions/24239897/change-image-on-scroll-position https://stackoverflow.com/questions/24239897/change-image-on... , https://www.w3schools.com/howto/howto_css_bg_change_scroll.asp https://www.w3schools.com/howto/howto_css_bg_change_scroll.a... , https://www.geeksforgeeks.org/how-to-change-image-dynamically-when-user-scrolls-using-javascript/ https://www.geeksforgeeks.org/how-to-change-image-dynamicall... , https://codepen.io/fabuchao/pen/xwbRaa https://codepen.io/fabuchao/pen/xwbRaa
- saagarjha 6y agoThis is one of the reasons why I'm generally not OK with "anonymized" data collection without an explanation of how it's being anonymized. It's almost always easy, often trivially easy, to correlate the data together and basically get a perfect recreation of whatever the original data was back.
- meritt 6y agoAnonymization in the data reselling industry is often some form of md5(lower($email)). It's a joke. They even do that for extremely small search spaces like phone numbers. It's still provided at the individual user-level and even if the anonymization is done in a way that's irreversible, you only need to know a single event for a given person and you now have their entire history. For example, there's a popular email client that scrapes people's inboxes and sells their purchase history to anyone willing to pay. That purchase history is provided on an individual email level and is "anonymized". But if you know your target has this email client installed and you know a single purchase (e.g. a coworker saying "Oh, I bought this awesome coffee maker on Amazon last night!") you can now access their entire individual purchase history backward and forward.
- martimarkov 6y agoWait... WHAT?!?! I mean if I think about it, yeah that makes sense to have been built but WTF?!? Care to share which email client it is? It should be killed with fire!!!
- etrabroline 6y agoAssuming you're asking a genuine question, it's Gmail. https://mail.google.com/ https://mail.google.com/
- laegooose 6y agoDo you have a source for claims that (a) google parses emails for purchase histories and (b) sells it? https://myaccount.google.com/purchases https://myaccount.google.com/purchases is empty for me, and I sure do have a lot of email receipts on my gmail. It also says "Purchases made using Search, Maps, and the Assistant are organized to help you get things done, like tracking a package or reordering food". https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase-history-how-to-delete-it.html https://www.cnbc.com/2019/05/17/google-gmail-tracks-purchase... "Google says it doesn’t use this information to sell you ads." Google used emails for ad targeting which was mentioned in Microsoft "Scroogled" ad campaign in the US. But Google says it stopped doing so years ago. Do I miss something?
- fendmark 6y agoWhen I saw Foursquare transition from a B2C to a B2B focused company that is when I finally deleted the Swarm and Fourquare Apps. I still don't fully understand their decision to split Foursquare into 2 apps, but what I did/do understand is that there is alot of money to be made in location data. You just hope that the people in these businesses are ethical people.
- sanchay 6y agoLooks like we're moving to a Watch Dogs 2 era faster each day
- afpx 6y agoAt this point, most people seem to know that their mobile data is being used. And, interestingly enough, they don’t seem to care.
- harwoodleon 6y agoA broad statement. I’d like to see the evidence that they don’t care, especially when faced with the level of detail collected. I’d say they don’t care to know, not that they don’t care. Ignorance is not a defence, even if it is temporarily a business case.
- kovac 6y agoAlmost everyone, I've spoken to about these (including software engineers), know they are being tracked and they don't care. Actually, you know what, not almost everyone, everyone I've spoken to about this. I've got the reply "if you don't like it, stay off the internet". Well.
- Jon_Lowtek 6y agoI do care. More must be done to protect consumers. I have spoken.
- kovac 6y agoI agree. I find it utterly disrespectful for all the engineers who are working their asses off to save the free internet when someone tells me to stay off the internet if I don't want to use a Google service. It's that bad.
- afpx 6y agoI can't point you toward public data, unfortunately. But, I work in this space.
- m463 6y agoThey have no power to change it and no credible alternatives. Apple and Google create systems that make it possible to harvest data with no user control possible. Neither provide the ability to see or stop data leaving your mobile device. They do this so they can attract developers to their platform. They do provide "controls" to prevent some sort of data access to prevent mindful users from leaving the platform. It's just that the control have the same sort of ambiguity as a privacy policy. Many people still don't understand that "location services" really means two-way, or that bluetooth can be a proxy for very fine-grained location tracking. I hope that we finally get alternative phones (say pinephone or purism) because I firmly believe there's a HUGE market opportunity for this sort of thing.
- rrix2 6y agoA vast unaccountable ecosystem of data brokers simply cannot be the way society is forced to feed app developers.
- mirimir 6y agoThis isn't likely news, for most here. But it can't be reported enough, for the general public.
- carapace 6y agoYeah, I think this is one of those things where, when the normals catch on, there's gonna be pitchforks and torches.
- mirimir 6y agoIndeed, but what would it take? I gather that NRK is the BBC equivalent for Norway, so it's not surprising that Tamoco sold so much data to it. But I wonder how selective Tamoco and its competitors are. In particular, I can imagine that there's a substantial market for data that facilitates tracking people. Bounty hunters. Repo agents. Private investigators. But also people who want to stalk others for whatever reasons. If someone could document that application, perhaps there'd be "pitchforks and torches".
- carapace 6y agoI don't know what it would take, if anything. I was talking to some twenty-something folks in Berkeley about a decade ago and asked them what they thought of Snowden. They didn't know who he was. When I explained, they dismissed the whole thing. It turned out that they assumed the government was spying on everybody anyway. I don't know what to make of that, I'm just passing along the anecdote. Anyway, from what I've heard these marketing companies are not very selective at all. More precisely, they are selective but don't dig too deeply. But this is just my impression, not fact.
- mirimir 6y ago> It turned out that they assumed the government was spying on everybody anyway. I've assumed that since the 60s :) Anyone remember "The President's Analyst"?
- deleted 6y ago
- cornishpixels 6y agoIn Soviet Russia, your cell provider sells this data. Wait, no, that's America. I was thinking of America.
- labster 6y agoWhy would they sell data in Soviet Russia, when that data belongs to the people and the people’s secret police?
- jalk 6y agoGramma nazi on: you mean Russia or the Russian federation if you want to be precise. The Soviet Union collapsed almost 30 years ago.
- DreamScatter 6y agoIn soviet russia, cell phone data sells you
- cosmojg 6y agoCan I legally purchase the anonymized location data of a few thousand Americans, run that through a script which associates coordinates with addresses, and publish the deanonymized results as an art piece like this? If so, this could be a lot of fun. It would be interesting to see the political backlash, especially if the published dataset includes politicians. Perhaps, in the name of ethics, it should include only politicians, and only those who have voted against privacy legislation. Maybe we'd finally end up with something like the GDPR here in the States.
- Nextgrid 6y agoYou'd presumably get in trouble because legality is only part of the equation, the other part is how big/powerful you are and whether you have connections in the right places. Big companies can get away with crimes while the same thing would result in successful prosecution if a little guy does it, so you might very well get in trouble even though you're doing exactly the same thing as an existing company that manages to stay out of trouble. I however support your idea regardless of its legality (and especially if the data happens to contain details on politicians, the majority of which are responsible for the situation being as-is) and suggest you publish it anonymously (through Tor).
- surround 6y agoThe article assumes that the location data must have been collected because he gave an app permission to access his location. I bet they couldn’t figure out which app it was because it wasn’t an app. Cell service providers can and do track your cellphone location. All they have to do is measure the signal strength of your cellphone at different towers, and they can triangulate its position. https://www.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hunter-300-dollars-located-phone-microbilt-zumigo-tmobile https://www.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hu... I’m not familiar with other locations, but in the US, you only have the choice between three cell service providers. All of them admit to selling their own customer’s location data to third parties in their Privacy Policies. AT&T https://about.att.com/csr/home/privacy/full_privacy_policy.html https://about.att.com/csr/home/privacy/full_privacy_policy.h... Verizon https://www.verizon.com/about/privacy/full-privacy-policy https://www.verizon.com/about/privacy/full-privacy-policy T-Mobile/Sprint https://www.t-mobile.com/privacy-center/our-practices/privacy-policy https://www.t-mobile.com/privacy-center/our-practices/privac... Remember, you’re paying for these services. But they still sell you out. I seriously recommend you read the privacy policy for your provider. It seems they collect as much data as possible (not just location, also browsing history and a whole host of other metrics) and share it with as many different parties as possible. If you are using a cellphone, your location is being tracked. Period. You can’t avoid it. Even TOR isn’t gonna help you.
- etrabroline 6y agoFrom Verizon: >We may de-identify or aggregate information so that Verizon or others may use it for business and marketing purposes. For example, the data we aggregate might be used to analyze, personalize and improve our services, to provide business and marketing insights to others and to help make advertising more relevant to you. You have choices about some of these uses From AT&T: >Equipment Information includes information that identifies or relates to equipment on our networks, such as type, identifier, status, settings, configuration, software or use. Location Information includes your street address, your ZIP code and where your device is located. Location information is generated when the devices, Products or Services you use interact with cell towers, Wi-Fi routers, Bluetooth services, access points, other devices, beacons and/or with other technologies, including GPS satellites. [...] We may share information with AT&T affiliates and with non-AT&T companies to deliver or assess effectiveness of advertising and marketing campaigns
- rb808 6y agoThe real question is if you gave people a choice of paying an extra $100 a year or having apps send tracking data, most people would pay the latter.
- vaylian 6y agoLink in the original language: https://www.nrk.no/norge/xl/avslort-av-mobilen-1.14911685 https://www.nrk.no/norge/xl/avslort-av-mobilen-1.14911685
- erikbye 6y agoYou have to be a special case of naive for the collection and sale of data to be a surprise. Talk about living under a rock. As for mobile apps, specifically, you think these shitty apps make money off ads? No, the business model is data. GPS data alone is a multi-billion dollar industry that is growing very fast.