Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

61–70 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#62
post #39
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Possibly on the network facing side of the business in the form of logs that get purged when old, but I have yet to see any IMEIs, possibility to log texts, call histories etc, but if they are sent there will be a trail in the network. Could probably send the GDPR-request to Huawei and Ericsson as well. Just keeping track of phones permissions in the network 100 times/second is an insane amount of data, but there cou…

I'm not familiar with how GSM networks operate. Why would I send a request to Huawei or Ericsson? Don't they just provide networking equipment? Or do they also provide services, part of which may be relevant for end user privacy?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#63

Earlier quoted context omitted.

I’ve set up a DID that leads directly to a voicemail box that emails me the recording. It’s worth the $1/month expense to have a number to hand out to people I don’t want to be available to. And, in a way, it keeps me available when I’m overseas and don’t have my usual SIM card installed. I use VoIP.ms

What gets me are all of the places (like Venmo, et al) who pitch a fit if a user dares give them a not-a-real-mobile-number. Even if the number is SMS-capable, they complain. I wonder if the fact that services like this won't work on VoIP numbers is a reason why. Regardless of the motivation, it's annoying because I don't give out my real mobile number to hardly anyone for this--and spam call/text avoidance--reason.

Not-a-real-phone-number accounts have a much higher than average probability of being a bot or a scammer. (That's because scammers can automate signing up for voip numbers; getting a thousand real Verizon numbers is much harder.) And Venmo had a strong financial incentive to ban signups that look like bots and scammers.

If Venmo were a brick and mortar business, they could just ask you to come by a local office so they can verify your ID in person. But they don't have a local office; so the reasonable and profitable solution is to preemptively ban you.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#64

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

I’ve set up a DID that leads directly to a voicemail box that emails me the recording. It’s worth the $1/month expense to have a number to hand out to people I don’t want to be available to. And, in a way, it keeps me available when I’m overseas and don’t have my usual SIM card installed. I use VoIP.ms

Can you discuss how you set this up? I looked at voip.ms and it looks like it supports Asterisk and other VOIP software, how did you configure yours?

Thanks

Re: Mobile customer location data is ending up in the hands of bounty hunters

#65
Are we gonna talk about the Silicon Valley VC's investing in these shady companies?

> Zumigo is a pioneer of mobile services providing _deeper insights_ into consumer behavior to help secure transactions, devices and identities.

https://www.crunchbase.com/organization/zumigo

> Intel Capital

> Aligned Partners

Re: Mobile customer location data is ending up in the hands of bounty hunters

#66
post #62
post #39

Earlier quoted context omitted.

Possibly on the network facing side of the business in the form of logs that get purged when old, but I have yet to see any IMEIs, possibility to log texts, call histories etc, but if they are sent there will be a trail in the network. Could probably send the GDPR-request to Huawei and Ericsson as well. Just keeping track of phones permissions in the network 100 times/second is an insane amount of data, but there cou…

I'm not familiar with how GSM networks operate. Why would I send a request to Huawei or Ericsson? Don't they just provide networking equipment? Or do they also provide services, part of which may be relevant for end user privacy?

My info may be a little dated, but yes, most of these companies (Huawei, Ericsson, Alcatel-Lucent, etc) also provide network services and ops to run the network.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#67

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

well, except for one of the largest advertising and data collecting companies on the planet, that really really wants to know where you are right now.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#68
post #42

Earlier quoted context omitted.

Yet mobile customers exist worldwide and I opened the article to see how they circumvent GDPR because I though it applies to Europeans too.

As a European, having "bounty hunters" in the title implied that already. I was unaware of bounty hunters being aserious profession in any particular EU country. Then again, i don't know any EU country where an accused can bail themselves out of jail till the court case.

> Then again, i don't know any EU country where an accused can bail themselves out of jail till the court case.

Germany (1), UK (See Assange) I’d assume that most European Countries have a similar system. However, it’s comparatively rare that bail is set in Germany. If I follow the US bail reform debait correctly I get the impression that jail before trial (Untersuchungshaft) is comparatively rare in Germany and requires specific reasons (2) while it’s comparatively normal in the US.

Both might be contributing reasons why the bail system is not commercialized as in the US. Generally, the European Systems frown upon private law enforcement much more, that might be another reason for the nonexistence of bounty hunters.

(1) §116 StPO https://www.gesetze-im-internet.de/stpo/__116.html

(2) mostly Fluchtgefahr (Danger the accused may flee and leave the country, Verdunklungsgefahr (The accused might hide evidence, the danger of repeating the offense on violent offenses) §112 StPO https://www.gesetze-im-internet.de/stpo/__112.html

Re: Mobile customer location data is ending up in the hands of bounty hunters

#69
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

For a sneak peak of the kind of data you can expect take a look here [1] (German newspaper, but in English). Background story: Malte Spitz, a Green Party member, sued to get all data collected and retained (according to a law which has been overturned since) by his carrier. Die ZEIT/OpenDataCity cross-referenced the data with publicly available information from his Twitter and party website and compiled it all into o…

This is interesting, if that's indeed the case then I'll publish my findings and encourage people to 1) fill similar requests, 2) fill requests for data deletion and ceasing of further collection. Hopefully eventually we'll get an option to opt-out via the web, like on http://myactivity.google.com/

Also, EU readers: why not ask your own provider today?

Apart from location I'm still concerned about actual data transferred via those networks (calls, text and data).

Re: Mobile customer location data is ending up in the hands of bounty hunters

#70
post #66
post #62

Earlier quoted context omitted.

I'm not familiar with how GSM networks operate. Why would I send a request to Huawei or Ericsson? Don't they just provide networking equipment? Or do they also provide services, part of which may be relevant for end user privacy?

My info may be a little dated, but yes, most of these companies (Huawei, Ericsson, Alcatel-Lucent, etc) also provide network services and ops to run the network.

Good to know, thank you! It should be enough to harass one's provider, but perhaps a more broad approach will work.
Post reply on HN