4 ms·
It's disturbing how much this information is sold and resold: * Securus purchased the location data from 3Cinteractive Corporation, which was located in Boca R
by runlevel1 3y ago
It's disturbing how much this information is sold and resold:
* Securus purchased the location data from 3Cinteractive Corporation, which was located in Boca Raton, Florida.
* 3Cinteractive Corporation, in turn, purchased such data from Technocom Corporation (doing business as LocationSmart), which was located in Carlsbad, California.
* Technocom Corporation (doing business as LocationSmart) purchased this data directly from telecommunications services providers.
* This capability enabled Securus’s registered users to obtain the location data entered in the LBS platform, or, in other words, to ascertain the approximate physical location of a particular cellular telephone on demand.
Source: https://www.justice.gov/d9/press-releases/attachments/2022/07/14/pena_indictment_0.pdf https://www.justice.gov/d9/press-releases/attachments/2022/0...
- ransackdev 3y agoI’ve been asking where the hell these companies are getting our data to begin with for awhile because it has to be through shady means, even if technically legal. Tracking a user and selling that data should not be able to be slapped deep down in some TOS that grants intrusion into your life at that level. I wish laws would be changed to require explicit tracking requests for this type of data, that has to be conspicuous and separately authorized in addiction to any TOS. I wonder if these are all shell companies to hide the “origin server” for this CDN of unauthorized surveillance data. I’m also curious how many of these are just middle men that do nothing but markup and resell, vs how many of these companies do anything to enrich the data before flipping it. Wouldn’t it be funny if someone were to use these systems to get the location information for the executives at all of these companies, and it ended up online everywhere? I wonder if they would change their opinions on technical loopholes allowing the tracking of people without consent
- ianlevesque 3y agoThe answer is in the comment you replied to, "directly from telecommunications services providers".
- ransackdev 3y agoStill doesn’t answer my question of where my PII was acquired.
- mcculley 3y agoI don’t understand your question. Your telecom provider has your PII.
- ransackdev 3y agoI’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is how the companies continue to violate our right to privacy and flourish.
- runlevel1 3y agoYour cell phone company knows your name, address, and can infer where you've been based on the cell towers your phone checks in with. So that one's a given. Here's a sampling of others: Mastercard sells information on your purchases.[^1] (Based on the info Oracle had on me, I suspect they might be one of the sources for Oracle Advertising.[^2]) Equifax, who gets information from your bank, your car insurance company, your cable company, and loads of other places, makes a nice profit off selling your info.[^3][^4] ISPs know who you are, can infer a lot about you from unencrypted DNS queries and HTTPS SNI snooping, and they're happy to sell information about you.[^5] Then there are several tiers of companies that buy information from various other companies, aggregate it, and then sell that off. A veritable snowball rolling down a hill of privacy violation. [1]: https://www.wired.com/2012/10/mastercard-data-mining-holidays/ https://www.wired.com/2012/10/mastercard-data-mining-holiday... [2]: https://datacloudoptout.oracle.com/request-your-data/verify-identity https://datacloudoptout.oracle.com/request-your-data/verify-... [3]: https://www.inc.com/associated-press/equifax-data-money.html https://www.inc.com/associated-press/equifax-data-money.html [4]: https://www.equifax.com/about-equifax/why-equifax/differentiated-data/ https://www.equifax.com/about-equifax/why-equifax/differenti... [5]: https://www.vice.com/en/article/93b9nv/internet-service-providers-collect-sell-horrifying-amount-of-sensitive-data-government-study-concludes https://www.vice.com/en/article/93b9nv/internet-service-prov...
- wildrhythms 3y agoOur gerontocracy is unprepared to deal with issues related to technology and privacy. I don't think these data brokers need to hide at all. We already see how legislators (failed to) comprehend issues related to technology in the many of unproductive congressional hearings over the past few years (Google, Tiktok, Twitter, Facebook... all brought before congress with nothing to show for it now). I think issues of technology and privacy are moving too fast for our gerontocracy to possibly keep up. And I think our legislators show their ass in the case of the Tiktok hearing; effectively stating oh it's fine if the data is being bought and sold by a US company (Oracle).
- ransackdev 3y agoIf our legal system isn’t prepared to properly handle such things then it should default to being illegal to collect and sell data until the legislation is created to properly protect the rights of those who put them in office and pay their salaries. The default of “you will be violated until we get to it, if we are able to comprehend it” is a dystopia I hadn’t imagined, yet here we are.
- jhelps 3y agoThe cellphone companies have been selling the realtime location of all subscribers since at least 2018. It doesn't depend on whether you have location enabled either, since it figures out your location from the towers! On top of that, one of them had an unauthenticated API, meaning anyone in the world could track the realtime location of any US phone #[0]. If all of this bothers you, contact your state legislators. Most state privacy laws don't protect against ISPs selling your location & browsing info, even though that would be the common expectation. Maine's law is simple and does a good job[1][2]. 0: https://www.wired.com/story/locationsmart-securus-location-data-privacy/ https://www.wired.com/story/locationsmart-securus-location-d... 1: https://www.natlawreview.com/article/maine-s-new-internet-privacy-law-what-you-need-to-know https://www.natlawreview.com/article/maine-s-new-internet-pr... 2: Maine's law survived a federal challenge, and ISPs have dropped their appeals: https://www.mediapost.com/publications/article/377285/broadband-carriers-withdraw-challenge-to-maine-opt.html https://www.mediapost.com/publications/article/377285/broadb...
- csdvrx 3y ago> It doesn't depend on whether you have location enabled It's even better: the location can be enabled through a network initiated request. This is because A-GPS works "both ways". See https://en.wikipedia.org/wiki/Assisted_GNSS#SUPL https://en.wikipedia.org/wiki/Assisted_GNSS#SUPL : SUPL Position Calculation Function (SPCF) lets the client or the server ask for the client’s location. As part of the FCC’s updated 911 requirements, where cell phones (with no set location) are required to be routed to the correct 911 center, aGPS was developed to not only help GPS get a faster TTFF (time to first fix), but to transmit location data to the carrier (and to anyone else who can intercept the data) > If all of this bothers you, contact your state legislators If you don't like that and want a quick fix, on android devices check /data/vendor/agps_supl/agps_profiles_conf2.xml for ni_request="true": this is the Network-Induced Location Request functionality, where the network asks for the GPS position. Change that to false. Personally, I believe 911 AGPS is of limited use: if I'm unconscious and can't dial, the phone 911 AGPS working won't do me any good. If I'm conscious and I can dial, I can also open a map app. Still, if you want to keep the 911 stuff, just change reject_non911_nilr_enable="false" to true (because yes, by default, everything goes - 911 or not) There's also lpp_enable="true" (LTE Positioning Protocol, yet another method by which cellular providers can pinpoint your location via aGP S), imsi_enable="true" (which transmit a unique identifier along with the AGPS request!) Check also /data/vendor/agps_supl/agps_profiles_conf2_prv.xml Or even better: don't use a phone. I have a 5G/LTE module in my laptop when I need internet connectivity: it's turned off the rest of the time (rfkill block wwan). You can also disable the power to this M2 port (saving battery if you care about that)
- ClumsyPilot 3y agothis reads like a supply chain of a drug cartel
- mistrial9 3y agothere were rumors of gray market identity traders in the 2000 times, within the USA. What changes is accuracy, timeliness, noise levels and verifiability, off the top of my head... Apparently completely legal identity document sales have gone on since the 1950s at least, around driving registration, home address, employment and related things. Since that is in the USA, with newer laws and an alleged emphasis on citizen rights, I can only imagine that other large political powers have had this for centuries.