Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

31–40 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#31

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

any reason to think google doesn't sell your data

They make much more money using it for their own products. Data is Google's core competitive advantage; you don't sell your core competitive advantage to competitors.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#32
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Great idea, not sure how they implement this though. They can just email it to you because GDPR does not specify the delivery means.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#33
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Can you post your request and who is sent it to - with yours as a starting point I reckon a few of us can iterate to a good solution

Nothing fancy, and I sent it to the contact point they have in their privacy policy. You can find it on their websites (or at least I found it; in my case it was just an email but it will possibly escalate to snail mail). As far as contents goes - here it is, translated into English:

I am a/an [OPERATOR] subscriber, identification data: (...)

I would like to get a complete list of personal data that [OPERATOR] stores about me:

  - The history of telephone calls, metadata (when and where [to which number] I called or when and who [what number] called me) as well as the data itself (the content of the calls themselves);
  - The history of text messages, as in the case of calls - metadata and the data itself;
  - History of data transfer (Internet), as above - metadata and the data exchanged itself;
  - Connection history - when my phone was connected to the [OPERATOR]'s network, when in [OPERATOR'S COUNTRY] or when via roaming;
  - Location history - where my phone was located, e.g. which base stations it was connected to or from which country it was connecting or any other information allowing to determine my location more accurately than "Planet Earth";
  - History of used devices - IMEI numbers as well as other data collected about my device / devices;
  - Any additional information collected about me.
If any of the above mentioned types of data is not stored by [OPERATOR] please let me know.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#34
>“The allegation here would violate our contract and Privacy Policy,” an AT&T spokesperson told Motherboard in an email.

Probably now AT&T execs are looking at increasing prices on such data. This is very valuable to be sold so cheap.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#35
post #16

Earlier quoted context omitted.

any reason to think google doesn't sell your data

google monetizes your data (targeting), but doesn't sell it to others.

Maybe not intentionally but problem is that often such data can be partially or fully de-anonymized using various statistical analysis techniques.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#36
post #15

Change title please and add "in the USA"

The title doesn’t assert that this necessarily exists worldwide. edit: I mention this downstream, but it's worth correcting myself. The article prominently features a company named Zumigo, which provides mobile device location data in India as well as North America. So adding "in the U.S." to the (already altered) post title is not needed, especially since it could obfuscate the fact that these location companies do…

Yet mobile customers exist worldwide and I opened the article to see how they circumvent GDPR because I though it applies to Europeans too.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#37
post #18
post #9

It would appear that sometimes even paying for the service doesn’t mean you won’t end up as the product anyway. How can one avoid this kind of aggregated location tracking?

You guys need (something like) GDPR in the US. I believe it's a necessity.

There are lots of things needed in the US.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#38
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Great idea, not sure how they implement this though. They can just email it to you because GDPR does not specify the delivery means.

That's what I'd do if I were in their shoes.

I planned to document it and share with wider audience in case I find something out of the ordinary. For example, if they kept my location history for longer than is necessary to just route my data through their network, or if they had the contents of my texts, or DNS requests history.

Not sure how to pressure into the Google-style solution, but I think knowing would be a fist step.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#39
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Possibly on the network facing side of the business in the form of logs that get purged when old, but I have yet to see any IMEIs, possibility to log texts, call histories etc, but if they are sent there will be a trail in the network.

Could probably send the GDPR-request to Huawei and Ericsson as well.

Just keeping track of phones permissions in the network 100 times/second is an insane amount of data, but there could be leaks/compromised systems somewhere in the User -> Apps -> Phone -> Network -> Provider chain.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#40

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

any reason to think google doesn't sell your data

If it's just a voicemail box it doesn't have your location data to leak, although a DID onto a voicemail box (and maybe a SIP trunk if you really want it) is better.
Post reply on HN