Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

51–60 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#51
post #33

Earlier quoted context omitted.

Can you post your request and who is sent it to - with yours as a starting point I reckon a few of us can iterate to a good solution

Nothing fancy, and I sent it to the contact point they have in their privacy policy. You can find it on their websites (or at least I found it; in my case it was just an email but it will possibly escalate to snail mail). As far as contents goes - here it is, translated into English: I am a/an [OPERATOR] subscriber, identification data: (...) I would like to get a complete list of personal data that [OPERATOR] stores…

I don't think it's your responsibility to play whack-a-mole and guess what types of data you think they might have. It's their responsibility to tell you.

The right to access your data is Article 15 of GDPR. Section 1 lays out what they have to provide you. Part (b) of that is "the categories of personal data concerned." I'm no lawyer, but I take that to mean that they have to provide you with the complete list of processing they do.

If I were making this request, I would scrap the entire bullet-point list you wrote and say that I'm invoking my Article 15 rights to be informed of the categories of personal data that [OPERATOR] processes about me.

Relevant law text: https://gdpr-info.eu/art-15-gdpr/

Re: Mobile customer location data is ending up in the hands of bounty hunters

#52
post #51
post #33

Earlier quoted context omitted.

Nothing fancy, and I sent it to the contact point they have in their privacy policy. You can find it on their websites (or at least I found it; in my case it was just an email but it will possibly escalate to snail mail). As far as contents goes - here it is, translated into English: I am a/an [OPERATOR] subscriber, identification data: (...) I would like to get a complete list of personal data that [OPERATOR] stores…

I don't think it's your responsibility to play whack-a-mole and guess what types of data you think they might have. It's their responsibility to tell you. The right to access your data is Article 15 of GDPR. Section 1 lays out what they have to provide you. Part (b) of that is "the categories of personal data concerned." I'm no lawyer, but I take that to mean that they have to provide you with the complete list of pr…

See, one of the reasons why I'd prefer someone who speaks legalese to do this :)

Thanks, makes sense. I wanted to make it clear I'm not happy with a response "Yeah sir, you live here and here, and your device model is X. That's your personal information.". But I'll keep pressing them, as I seriously do not entertain the idea that someone may store all the data that can be inferred from my activity in a mobile network.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#54
post #15

Earlier quoted context omitted.

The title doesn’t assert that this necessarily exists worldwide. edit: I mention this downstream, but it's worth correcting myself. The article prominently features a company named Zumigo, which provides mobile device location data in India as well as North America. So adding "in the U.S." to the (already altered) post title is not needed, especially since it could obfuscate the fact that these location companies do…

Yet mobile customers exist worldwide and I opened the article to see how they circumvent GDPR because I though it applies to Europeans too.

The article asserts that the authors have verified that this practice currently exists when tested in the U.S. They do not make claims whether or not the companies may be lying about whether this framework may exist in other countries. It's interesting enough that this framework exists at all in the U.S., and it's relevant worldwide because these mobile companies and their customers exist worldwide.

And not just the mobile companies, but the middlemen who provide this location data. Zumigo [0], one of the companies mentioned, has an office based in India and counts Indian banks among its clients for its "first-of-its-kind global location and identity platform".

[0] https://zumigo.com/zumigo-introduces-breakthrough-mobile-loc...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#55
post #22

Earlier quoted context omitted.

any reason to think google doesn't sell your data

Googlers seem to have leaky lips, so I figure if they do something shady one of them is going to go to the press.

I think the logical outcome is rather than Google avoiding ethically dubious, but highly profitable behavior, they will simply run a tighter ship of classification, isolation, and control. Companies and governments have become pretty decent at fingering over-eager leakers. And that's before you even get into who we're talking about. Google may rival even the NSA at this point in terms of the reach and breadth of their digital surveillance and data collection/categorization capacities, at least in the Western world. They're going to learn from and work against their leaks, not give up their 'ambitions'.

Consider the NSA for an example of what's possible. They were doing what Snowden outed for years. And not a peep. Actually that's not true. There were plenty of 'peeps' but they were brutally silenced. See, for instance, Thomas Drake [1]. He tried to obey the law relying on whistleblower laws and an assumption of good will from other government organizations. He got destroyed and lost everything he had, and was unable to effectively get his message out on top of it all. That's another topic though...

[1] - https://en.wikipedia.org/wiki/Thomas_A._Drake

Re: Mobile customer location data is ending up in the hands of bounty hunters

#56
I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data.

I'm definitely not a lawyer, but I'm starting to believe there is an argument that despite the fact that mobile phones and devices facilitate the generation of location data, that does not necessarily mean that the device manufacture 'owns' that data and can transact with it as they please.

This may all be moot because most of us agree to Privacy Policy contacts, but maybe a mind shift in treating data you generate as a type of property that is covered by property law is required to change behavior.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#57
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

For a sneak peak of the kind of data you can expect take a look here [1] (German newspaper, but in English).

Background story: Malte Spitz, a Green Party member, sued to get all data collected and retained (according to a law which has been overturned since) by his carrier. Die ZEIT/OpenDataCity cross-referenced the data with publicly available information from his Twitter and party website and compiled it all into one visualization.

Unfortunately, they seem to have stopped paying for the Google Maps integration, but you should still be able to follow along just fine.

[1]: https://www.zeit.de/datenschutz/malte-spitz-data-retention

Re: Mobile customer location data is ending up in the hands of bounty hunters

#58

> “The allegation here would violate our contract and Privacy Policy,” an AT&T spokesperson told Motherboard in an email. That pretty much sums up how much carriers care about this. But it is nice to see Senator Ron Wyden is still doing good work, almost restores my faith in politics.

This is why utilities need to be heavily regulated.

Selling real time location data to wholesalers in the bail bonds industry? Who would think there would be abuse?

Only license actions and criminal penalties will stop this kind of abuse.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#59
post #48

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

Google Voice doesn't actually provide cell service, though. Whatever telco you use with Google Voice will still have realtime access to your location.

But if you ask a telco to give you data on a number that Google Voice administers, would the telco be able to fulfill that request? I mean, obviously they could with a little digging, but would their middlemen be able to?

e.g. if my "real" email account is through Yahoo, but I tell the public about my GMail address which autoforwards to Yahoo, it wouldn't be straightforward (though it would be obviously possible) for Yahoo to deal with a request stated as "Please give me info about the email account, danspublicemailaddress@gmail.com".

Re: Mobile customer location data is ending up in the hands of bounty hunters

#60

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

any reason to think google doesn't sell your data

There’s a big difference in risk between Google selling your forwarding numbers and any random person finding a corrupt bail bondsman.
Post reply on HN