8 ms·
I agree with the points raised by the article, but shouldn't there also be a push to stop cellular service providers from selling your location data? It's worth
by CAPSLOCKSSTUCK 3y ago
I agree with the points raised by the article, but shouldn't there also be a push to stop cellular service providers from selling your location data? It's worthwhile to call out smartphone app developers, but ISPs can get your location even if you don't have a smartphone, and in fact are required to be able to report on this by law (https://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act https://en.wikipedia.org/wiki/Communications_Assistance_for_... etc.). Does the EFF just think that it's moot to try to legislate against the latter?
- deleted 3y ago[deleted]
- daoboy 3y agoNot at all. The EFF does a lot of good work along those lines also. https://www.eff.org/issues/cell-tracking https://www.eff.org/issues/cell-tracking
- worik 3y ago> ...shouldn't there also be a push to stop cellular service providers from selling your location data? Yes There should be rules stopping the collection of that data There should be rules against locking down devices people "own" that prevent countermeasures Private use of this data is as worrying as government use. More so. States are often democratically accountable
- chaps 3y agoWe also have public records laws where we can hold gov agencies accountable to their abuse of, eg information. Doesn't really exist in private orgs, and it's one of the reasons gov agencies love third party vendors.
- j45 3y agoInteresting. Could the laws be changed without the population
- chaps 3y agoNot 100% sure what you mean, but yes we need something similar to GDPR which allows requests for our own information. It's a mostly a matter of legislative interest, which can stem from demands from the public.
- hedora 3y agoIn the US, with stuff like qualified immunity, having public access to records of crimes doesn’t allow anyone to be held accountable. Also, based on repeated leaks, our public records laws are completely inadequate. At least when an ad tech company gets caught breaking the law, they get fined a couple seconds of revenue, and there is a theoretical chance someone might get sent out for a few days of community service or probation.
- chaps 3y agoPreaching to the choir there! While public records laws stink, a lot of the work by orgs involved in transparency, and others have made it better. By no means is it going to be "good" anytime soon, but progress is certainly being made. Whether the work is being done fast enough is a different story, though I'll say that any amount of help makes a larger difference than it might seem. Just gotta be persistent. One of my proudest moments is (through reporting) getting the Chicago police department to admit they made an enormous mistake in their analysis, which a colleague says was the first time he's seen them admit to such a mistake in the years he's done this work. So there are signs that it's not all lost. Happy to chat about ways to contribute towards this work if you're interested. One thing I'll say about leaks is that they occasionally have the effect of revitalizing interest in these issues. But again, it takes persistence.
- j45 3y agoThe question may be too simple: Can the politicians already elected enact any laws they wish by their majority?
- hulitu 3y ago> States are often democratically accountable Maybe in a parallel universe. /s
- SoftTalker 3y agoAlso we need better education about the risks of carrying around an always-on GPS receiver that continually transmits your location to third parties. Victim-blaming? Maybe. But you can choose to turn your phone off.
- walterbell 3y agoHow many iPhone owners know their phones cannot be turned off, i.e. a faraday bag is required to stop radio transmission?
- SoftTalker 3y agoWhat transmission is still active when the phone is off?
- colinsane 3y agocan't say exactly, but the "find my" feature explicitly remains active even while "powered off" so it's evidently enough transmission that Apple can track location.
- SoftTalker 3y agoApparently this uses the phone NFC capability and other nearby active phones to determine location. So yes, either leave the phone at home if you don't want to be tracked, or use a faraday bag.
- LopovJack 3y agoThat is option that you need to turned on.
- Rebelgecko 3y agoBoth the UWB tracker and the NFC radio can be on even when the device is "off" (although there's settings to change that behavior). IIRC the baseband can potentially do all kinds of crazy stuff too (no evidence that iphones actually do anything unusual, but perhaps that could change if the government sent a very compelling court order)
- colinsane 3y ago> In the years since CALEA was passed it has been greatly expanded to include all VoIP and broadband Internet traffic. the article makes it sound like LE is freely able to tap any VoIP call. how would that work? i thought the usual setup for a VoIP call is SIP to ring the other party (which is partially secured), followed by ICE/STUN/TURN for the parties to find the most direct route between them, followed by the actual audio stream. do clients just not encrypt the audio stream? do carriers MITM everything downstream of that first SIP hop? (that would be inconsistent with the read-only probing suggested: “hardware taps or switch/router mirror-ports are employed to deliver copies of all of a network's data to dedicated IP probes.”).
- Nextgrid 3y ago> ICE/STUN/TURN for the parties to find the most direct route between them From my experience, using SIP to interact with the PSTN usually means your first point of entry into the PSTN also proxies the media. > do clients just not encrypt the audio stream? SIP encryption is very uncommon, and unless you use ZRTP (which is end-to-end), I believe any SIP server within the path mediates the key exchange and can thus capture the key or downgrade/disable the encryption. Given the above points, a packet capture on a switch port would give you both signalling and media traffic and is most likely how SIP lawful intercept is implemented.
- deleted 3y ago[deleted]
- jbmsf 3y agoI built one of the first location aggregation systems. Maybe the first, hard to be sure. My company had close relationships with all of the US cellular companies and built white label apps for them, mostly under the auspices of family safety (though many users were more concerned about the location of their partners than of their kids). Around the same time OAuth 1a came out and it seemed like a great ideal to offer a platform that leveraged these relationships to sell location to app developers, subject to consent and with a bunch of features to protect privacy. In the end, we had one app developer who was even remotely successful and the less privacy-focused aggregators partnered with the next generation of app developers and the product had no future. Nostalgia is fun.