17 ms·
Surveillance data challenges what we thought we knew about location tracking
- aucisson_masque 1y agoI didn't quite understand how they are capable of tracking people and breaking WhatsApp encryption. There is mention of fake antenna but I don't think they cover entire country with that, how do they do?
- jonplackett 1y agoYes - and they also claim not to track users themselves. Is that just a lie or is there someone else doing the tracking? This article answers none of my questions!
- kipchak 1y agoThere's more details in the technical explainer linked in the article. https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/ https://www.lighthousereports.com/methodology/surveillance-s...
- CGMthrowaway 1y agoThey use vulns in the outdated SS7 system to trick networks into revealing a numbers location (1), and intercept SMS including the verification codes sent by apps like WhatsApp - allowing them to hijack accounts and monitor messages and calls directly (2). This method works remotely and doesn’t require antennas The SMS are intercepted because thru SS7 by tricking the network into thinking the target phone is roaming (3). (1)https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/ https://www.lighthousereports.com/methodology/surveillance-s... (2)https://www.motherjones.com/politics/2025/10/firstwap-altamides-phone-tracking-surveillance-secrets-assad-erik-prince-jared-leto-anne-wojcicki/ https://www.motherjones.com/politics/2025/10/firstwap-altami... (3)https://www.fyno.io/blog/is-it-easy-to-intercept-sms-a-complete-guide-clzs7nipc00fb78t2fdebxdan https://www.fyno.io/blog/is-it-easy-to-intercept-sms-a-compl...
- arkadiyt 1y ago> intercept SMS including the verification codes sent by apps like WhatsApp For anyone worried, this approach: 1) Breaks the existing phone from receiving WhatsApp messages, so you can notice that behavior 2) Can be prevented by setting up a WhatsApp pin in your settings
- simultsop 1y agoProbably these were addressed way too late. Developers are the last to know their backdoors surprisingly.
- citizenpaul 1y agoNot just vulns. It is possible to simply purchase access or become a provider in the SS7 system (<$20-50k USD). SMS is basically a completely open system at this point. Cybersecurity companies do it all the time for pentesting. So do "Cybersecurity companies". Horrifying that nearly banks still require you to use sms as a 2fa and do not offer any other alternative. Did you really think the US Gov was OK with facebook running the biggest "encrypted" SMS system on earth. LOL of course they already had access to all the messages.
- varenc 1y agoHijacking WhatsApp SMS authentication codes can be prevented by just adding a PIN to your account. Doing this attack also doesn't grant you access to someone's old WhatsApp messages, and contacts with "security notices" enabled will see that your device has changed. It's quite different than big gov just having access to all your WhatsApp messages. (But there might be other ways they can do this, but just SMS sniffing doesn't get you there)
- bayindirh 1y ago> Horrifying that nearly banks still require you to use sms as a 2fa and do not offer any other alternative. In my country banking applications are tied to your phone via IMEI, SIM and other hardware dependent information available. Forget getting banking details and use another device without the user knowing, either. If someone clones your SIM or gets a replacement in behalf of you, your all banking access is blocked until you enable them one by one with your ID card or other means. One of the banks can use FaceID as a secondary factor, too. So, other methods are possible. It's an "implementation detail" at this point.
- simultsop 1y agoAnd then they call people paranoid to go off the grid.
- deleted 1y ago[deleted]
- dylan604 1y agoThat's what they do to the people that figure things out. They discredit them so other people will not listen to them. It's the ones that go full tilt with lining the walls of their houses to be Faraday cages that make it all fringy cringy the rationally paranoid folks get lumped in with.
- physarum_salad 1y agoWell its always funny to observe politicians/other VIPs use similar technologies to the most "loopy" prepper when they need to. Like actual faraday/signal jamming tents during negotiations or similar.
- deleted 1y ago[deleted]
- lawlessone 1y agotbf, when the UK introduced a text to notify people of missing children ,some people(including relatives) were complaining on facebook that it could be used by the UK government to track everyone. As if their government couldn't just track the smartphone or them via social media already.
- dylan604 1y agoThe cognitive dissonance of thinking that apps are needed to track someone with a phone vs just being able to track your phone directly is very telling. Even before smart phones with apps, the tracking was there as a required feature to make mobile work. Granted, the number of people that spend any cycles thinking about how mobile signals work probably rounds to 0. It takes someone really dialed in to the details to come up interesting bolt on things to an existing system like tracking people with a mobile device just by looking at the logs. Same thing with looking at "just the metadata". While it may be obvious to those dialed in, to those oblivious it sounds crazy.
- baxtr 1y agoFor anyone interested, they also have a technical explainer that describes their methodology in detail. https://www.lighthousereports.com/methodology/surveillance-secrets-explainer/ https://www.lighthousereports.com/methodology/surveillance-s...
- Sammi 1y ago"Signalling System 7, or SS7, is a decades-old set of protocols that allows phone networks to communicate with one another, routing messages and calls across borders. It was never designed with security in mind, and while operators have moved to more secure evolutions with 4G and 5G, they still need to maintain backwards compatibility with SS7. This is likely to remain the case for years if not decades to come. Phone networks need to know where users are in order to route text messages and phone calls. Operators exchange signalling messages to request, and respond with, user location information. The existence of these signalling messages is not in itself a vulnerability. The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose. These signalling messages are never seen on a user’s phone. They are sent and received by “Global Titles” (GTs), phone numbers that represent nodes in a network but are not assigned to subscribers. Surveillance companies have often leased GTs from phone operators and used them to send unauthorised signalling messages into other networks, benefitting from the fact that the signalling messages appear to be coming from the legitimate operator which owns the GT. First Wap primarily works via in-country installations of Altamides. In this setup, a government client uses Altamides via an SS7 link belonging to a local phone operator. The local phone operator provides the GTs and Altamides uses these GTs to conduct location tracking domestically and internationally." So basically the telecoms network itself has no security. Anyone operating network equipment on the telecoms network can see where any phone is at any time. I didn't know we lived in a world that is this stupid. Great. If you're a dissident you basically cannot have a phone or be around anyone who has a phone.
- janwillemb 1y agoIt is about a company, First Wap, that makes it possible to track individuals. Their USP is a piece of software that operates at phone network level and uses the fact that phone companies still support an old protocol, Signalling System 7: > Phone networks need to know where users are in order to route text messages and phone calls. Operators exchange signalling messages to request, and respond with, user location information. The existence of these signalling messages is not in itself a vulnerability. The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose. > These signalling messages are never seen on a user’s phone. They are sent and received by “Global Titles” (GTs), phone numbers that represent nodes in a network but are not assigned to subscribers.
- beached_whale 1y agoI assumed it was the telecoms just selling the data about their subscribers. https://www.telecomstechnews.com/news/fcc-fines-major-telcos-selling-users-location-data/ https://www.telecomstechnews.com/news/fcc-fines-major-telcos...
- pkulak 1y agoWhy not both?
- beached_whale 1y agoOne would hope the selling is illegal and did more than just fine the companies.
- overfeed 1y ago> The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose 'Fun' fact: "other networks" includes all foreign networks with a roaming partnership. It's possible to abuse SS7 to track people across borders, from half the world away.
- Tenemo 1y ago> We found Netflix producer Adam Ciralsky, Blackwater founder Erik Prince, Nobel Peace Prize nominee Benny Wenda, Austropop star Wolfgang Ambros, Tel Aviv district prosecutor Liat Ben Ari and Ali Nur Yasin, a senior editor at our Indonesian partner Tempo. Political figures being there I somewhat understand, but a Netflix producer? Why would anyone need to track a Netflix producer?
- kipchak 1y agoMaybe hoping to bump into them for a impromptu elevator pitch for a show?
- gnatman 1y agoLooking at his career and production credits, it’s probably more accurate to describe him as a journalist who’s covered some sensitive subjects.
- layer8 1y agoHe’s also a journalist and had a carrier at the CIA. Why don’t you look him up if you’re curious about that?
- deleted 1y ago[deleted]
- kjs3 1y agoThey're a critic?
- attila-lendvai 1y agolook up Operation Mockingbird. half of the media is government operatives... netflix is a crucial tool of narrative control... they are nowhere near "just producers"...
- trinsic2 1y agoThis is why I think Microsoft, Apple and Google are owned as well. And answers a lot of questions about gatekeeping and vendor lock-in
- nostrademons 1y agoIt's fascinating how these secrets are turning up in the press now. The article is (probably intentionally) vague about it's sources: they only say "Lighthouse found a vast archive of data on the deep web". But reading between the lines - does that imply that this surveillance company kept records on thousands of targets, and then left them in an open S3 bucket? Not the first time - the TM_Signal leak of upper-echelon U.S. government communications was also facilitated by an open S3 bucket that contained the message archives of everything that, say, the Secretary of Defense was messaging to the POTUS. But it is highly ironic that these companies specialize in surveillance, tracking, and security, and then have a tendency to leave the data that they steal from others open to the Internet in a very amateurish security lapse that in turn leads to everyone stealing from them.
- dylan604 1y agoIs it possible the phreakers are so specialized they have no experience with cloud admin and just went with some copypasta from SO answers to get the boring shit done so they could get back to phreaking? Not everyone is an expert in cloud management. It is easy to bork something when you have no idea what you're doing because you don't want to be doing it. They could have also hired low level people to do something for them and just didn't spend enough to have it done correctly. There's many reasons for a very specialized group of smart people to do something utterly dumb and easy to avoid by people with other specialized skills. These people would probably look at you as silly and amateur for using SMS.
- deleted 1y ago[deleted]
- dontNotDoDrugs 1y ago[dead]
- mdani 1y agoIf I can make a guess, I'd say that the reporters engaged with them as a potential customer and demanded a sample of the data so they can indeed verify the accuracy. That's how they obtained the sample records, not via a s3 leak.
- huflungdung 1y ago[dead]
- walterbell 1y ago"Why the US still won’t require SS7 fixes that could secure your phone" (2019) https://arstechnica.com/features/2019/04/fully-compromised-comms-how-industry-influence-at-the-fcc-risks-our-digital-security/ https://arstechnica.com/features/2019/04/fully-compromised-c... the group: - dragged its feet on resolving SS7 security vulnerabilities - repeatedly ignored input from DHS technical experts - [identified] best practices.. using different filtering systems - [but] pushed.. to rely on voluntary compliance
- daxfohl 1y agoDid I miss something? This was not surprising. I figured all this would have been possible (and commonplace) decades ago. I was expecting this to be about government eyes and ears in my toilet or something.
- Lapsa 1y agomind reading technology is here, an actual reality
- lschueller 1y agoAnother brilliant example, why we need good (cooperating, international) journalism
- DyslexicAtheist 1y ago[flagged]
- malwrar 1y agoI wish journalists would explore why the technical methods & information sharing that enable this surveillance are allowed to exist. Highlighting instances of abuse and the quasi-legal nature of the industry doesn’t really get at the interesting part, which is _what motivates our leaders to allow surveillance in the first place_. I recently completed Barack Obama’s A Promised Land (a partial account of his presidency), and he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety. I often think about this when I drive past Flock cameras or walk into grocery stores; our leaders seem more enticed by the power of this technology than they are afraid of vague abuses happening in _not here_. It seems like no one sees a cost to just not addressing the issue. By analogy, I feel that reporting on the dangers of fire isn’t really as effective as reporting on why we don’t have arson laws and fire alarms and social norms that make our society more robust to abuse of a useful capability. People who like cooked food aren’t going to engage with anti-fire positions if they just talk about people occasionally burning each other alive. We need to know more about what can be done to protect the average person from downsides of fire, as well as who is responsible for regulating fire and what their agenda for addressing it is. I’d love to see an article identifying who is responsible for installing these Flock cameras in my area, why they did so, and how we can achieve the positive outcomes desired from them (e.g. find car thieves) without the negatives (profiling, stalking, tracking non-criminals, etc).
- 01HNNWZ0MV43FF 1y agoIt might be like prison reform and prisoners' rights - Nobody gets elected on a "soft on crime" platform, and civic engagement at the state and local level is so bad that people typically put up with cameras instead of agitating to get them banned. I say agitate. Show up, keep showing up, keep talking, keep telling friends. We can fight this. Democracy will work if we get people onboard, one way or another
- 3eb7988a1663 1y agoYou are more optimistic than I am. Flock and friends seem something like ChatControl. Those in power who want it have unlimited patience. They will keep pushing for expanded capabilities for the day when public attention has failed. Once they win, near impossible to revoke.
- kklisura 1y ago> This investigation began with an archive of data. [...] It contains 1.5 million records, more than 14,000 unique phone numbers, and people surveilled in over 160 countries. Why not HIBP (Have I Been Pwned) style site to check against the database if your number is in?
- hughw 1y agoRight! I expected one.
- Flockster 1y agoI could not compare it completely, but it sounds very much like this talk that I saw many years ago at the CCC. SS7: Locate. Track. Manipulate. [2014] https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271715_-_ss7_locate_track_manipulate_-_tobias_engel https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271...
- effdee 1y agoTobias Engel's initial video about this was "Locating Mobile Phones using SS7" given at the 25C3 in 2008: https://media.ccc.de/v/25c3-2997-en-locating_mobile_phones_using_ss7 https://media.ccc.de/v/25c3-2997-en-locating_mobile_phones_u...
- alganet 1y agoI think the world is not ready for the level of surveillance that exists in the wild. For example, this post could have been a product of just probing a particular group of people to understand if they are interested in the subject and what they have to say about it. That can be done indirectly, by suggesting someone (offering a link or planting an idea) that is already known to be interested in surveillance and prone to share interesting discoveries (in other words, the poster might not even be aware he could be an asset). Think about the many ways someone could know your interests and how prone you are to react to something and how that could be used. If you are in tech, think about all the silly ways that kind of information can leak publicly. People often disregard the possibility that they could be an active part of a surveillance network (as an unkowingly asset), instead focusing on more fantastical ideas such as technological hacks or coding wizardry.
- EMM_386 1y agoMore on ALTAMIDES and system modules: https://www.giosec.uk/specialist-services---geo-location.html https://www.giosec.uk/specialist-services---geo-location.htm...
- dogman144 1y agoReads like they’re doing one of several way to get mobile device IDs, and then x-ref those against anon’d adtech datasets that anchor on the mobile ID. If your device privacy is a mess, mobile ID links you to all the good and bad things you do on a phone. Had no idea this was part of the tool options, but backbone cell network makes sense. Other TTPs I’d read about was variations on geo-fenced adserving to phish a mobile ID basically via user interaction or scroll past the ad. Small enough geofence and do it a few times, one could safely figure out the user being the ID. Googling “RTB surveillance” or “DSP surveillance” are ways into the topic. Scary stuff! Pair that with this tech has been working for years, and is international. Frames a bit differently every action by a public figure - also at risk via the same threat model. Also long have wondered what data analysis like this is done on technical forums… ran by a VC firm… with a lot of insider context (product market fit?) in the comments.
- deleted 1y ago[deleted]
- titzer 1y agoStallman was a firebrand and jerk, but he was right. When it comes to devices that have the potential to invade our privacy and make us easy targets for authoritarian governments, every last line of code and every transistor should be open.
- sciencejerk 1y agoSS7 telcom vulns still seem to be prevelant in 2025: Femtocells and Fake Base Stations Attackers deploy femtocells — small cellular base stations — or fake base stations, commonly known as IMSI catchers, to intercept SS7 traffic. A modified femtocell can act as a man-in-the-middle, capturing signaling messages between a phone and the network. Fake base stations mimic legitimate cell towers, tricking devices into connecting and relaying SS7 messages to the attacker’s system. IMSI catchers exploit a known security vulnerability in the GSM specification, which requires the handset to authenticate to the network but does not require the network to authenticate to the handset. They broadcast a stronger signal than legitimate cell towers to lure mobile phones into connecting. Once connected, an IMSI catcher can force the transmission of the International Mobile Subscriber Identity (IMSI) and compel the connected mobile station to use no encryption or easily breakable encryption. For 3G and LTE networks, sophisticated IMSI catcher attacks may involve downgrading the connection to less secure non-LTE network services to bypass enhanced security features. For example, a hacker might deploy a fake base station near a target to capture their IMSI and initiate SS7 queries. https://www.how2lab.com/tech/mobile-communication/ss7-vulnerabilities https://www.how2lab.com/tech/mobile-communication/ss7-vulner...
- Mars008 1y agoI must say translation in Firefox is great. Now I don't have to learn Turkish... As for article, imagine, at those times and for thousands years after in most places humans were still hunting-gathering..
- yupyupyups 1y agoIn Europe: - Almost everyone has a phone. - Almost everyone takes their phone wherever they go. - All SIM-cards have been forcefully (by law) linked to people's identities. - Almost all people are therefore being tracked.
- sellweek 1y agoOne small note - Czech Republic still allows for anonymous SIM cards. You can walk into any tobacco shop, pay around 4€ and get a pre-paid SIM which can be charged in cash.
- nebularHaven90 1y agoWhen even Obama couldn't resist the power of surveillance, maybe it's not the tech we should fear, it's how easily power changes good intentions.
- ocelotBridge 1y agoPrivacy isn't just about hiding, it's about having the freedom to grow and change without constant watching. We need more leaders who understand this simple truth.
- deleted 1y ago[deleted]
- rollulus 1y agoWhat I understand is that this SS7 is difficult to get rid of. If I understand it correctly, the purpose of the location queries is for routing calls/messages. Couldn’t (shouldn’t?) telecom providers run monitoring and alerting if location queries are fired without a subsequent call/message?
- Bengalilol 1y agoVisiting the site is a one of a kind "back in time" experience: it was probably developed in 2000[1]. Even the WAP part of the name makes me wonder[2]. I know I have some futile questions, but why does seem France so untouched? [3] [1] <https://www.1rstwap.com https://www.1rstwap.com> [2] <https://en.wikipedia.org/wiki/Wireless_Application_Protocol https://en.wikipedia.org/wiki/Wireless_Application_Protocol> [3] <https://i0.wp.com/www.lighthousereports.com/wp-content/uploads/2025/10/notus_map-2048x1102-jpg.webp https://i0.wp.com/www.lighthousereports.com/wp-content/uploa...>
- ThaSwissA 1y agoWhere can I find the list? I got some contacts that might be in there
- absolutevibe 1y agoTake a look at the agenda and tracks for the conference referenced in the article some of the talk summaries are wild https://www.issworldtraining.com/ISS_EUROPE/ https://www.issworldtraining.com/ISS_EUROPE/ "In this talk, we shall discuss various security mechanisms used in WiFi and Bluetooth networks and how to abuse them"
- tripzilch 1y ago> The story of Altamides dates back to the early 2000s, when former *Siemens* engineer Josef Fuchs recognised a critical vulnerability in the global telecom network. By exploiting (...) Reminder that around the same time a joint venture of Nokia+Siemens had been developing and deploying deep packet inspection and surveillance systems in Egypt and Iran. They got called out by human rights organisations and posted an "oops sorry\" press release.
- AdmiralKrunch 1y agoDemocracy was an experiment from the beginning. All the funding for that experiment dried up long ago. When democracies fail new ones do not replace them. Disposing of the US over some trivial BS is not wise. The replacement forthcoming will be much worse than what we have now. It is literally impossible to do better in this day and age. We are looking at the ultimate failure of not only capitalism and democracy, but western values and even common morality. The new reality is that the surveillance state is part of the ride. If you are not a rapist or pedophile then why would you be concerned about cameras in Public anyways? If nobody is trying to smuggle children then why do we keep losing them? These ideas would not get so much traction if they were not a legitimate response to a real world stimuli. Favouring any argument made by non citizens and/or “the naysayers” tends to be labeled as “Anti” which is a dangerous label I would assume anyone who has kids would support the idea of tracking programs because it implies a higher level of operational security and access denial. I am truly curious who's voices these are calling for transparency and open security, because they are trying to rape your daughter. Prove me wrong, prove me wrong. I repeat, only a rapist, thief, terrorist or spy would be alarmed about the development of this “Surveillance State” technological paradigm. So when the trolls try to argue Philosophy as some generic excuse to protest scrutiny, take another look. What does he have to hide. What business is it of theirs to speak for you about cyber security or domestic opsec? And in fact who are you to care about that stuff at all either?