Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

101–110 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#101
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

> More specifically, the screenshot showed a location in a particular neighborhood—just a couple of blocks from where the target was. What gets me is that the writing on wall appears to be that this data did not come from an app on the phone but from the phone company themselves, data collection that is required by the government. "A couple of blocks from where the target was" implies to me that it was locating the n…

The government is supposed to need a warrant post-Carpenter:

https://www.lawfareblog.com/summary-supreme-court-rules-carp...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#102
post #93

LocationSmart advertised themselves to bounty hunters[1]. This kind of unethical/illegal location sharing from other location brokers like Zumigo is unsurprising. 1. https://twitter.com/sephr/status/1082711937257893888

They're the same folks who accidentally left an API public that let literally anyone do it:

https://krebsonsecurity.com/2018/05/tracking-firm-locationsm...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#104
post #72
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection.

Because of this, black market re-sellers can operate with relative impunity. Most data brokers have a TOS that prohibits the re-selling of their data, but there isn't any copyright protection.

For example, if a company has location data, the only way for them to be held liable is for a particular company to prove they obtained that data directly from them. Once the data has reached a minimum of two parties, everyone now has plausible deniability. If this data was under copyright, the original copyright owner would always have a claim and it would be each parties responsibility to prove they had a right to hold and distribute it.

The lack of a copyright style concept of original owner allows data to flow freely even if that transfer is violating a specific TOS.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#105
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

> More specifically, the screenshot showed a location in a particular neighborhood—just a couple of blocks from where the target was. What gets me is that the writing on wall appears to be that this data did not come from an app on the phone but from the phone company themselves, data collection that is required by the government. "A couple of blocks from where the target was" implies to me that it was locating the n…

So an offence against the espionage act then - it would probably be one under the official secrets act in the UK (unless your a tabloid journalist)

Re: Mobile customer location data is ending up in the hands of bounty hunters

#106

Earlier quoted context omitted.

What gets me are all of the places (like Venmo, et al) who pitch a fit if a user dares give them a not-a-real-mobile-number. Even if the number is SMS-capable, they complain. I wonder if the fact that services like this won't work on VoIP numbers is a reason why. Regardless of the motivation, it's annoying because I don't give out my real mobile number to hardly anyone for this--and spam call/text avoidance--reason.

I fear the reason is that the pools of VoIP numbers have already been exhausted as a resource for setting up’accounts. Ie: some firm is renting VoIP numbers for a month for $1, creating accounts on 100 services and then moving to the next VoIP number. Perhaps the VoIP firms support this whenever they get a block of « virgin » numbers before putting them in their regular pool of numbers for rent.

This just means that phone numbers make for terrible identifiers because there's a fixed number of them and they're transient.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#107

Earlier quoted context omitted.

That's fine for you Europeans under GDPR. (Sure, there's careouts for weird exceptions.) That doesn't do diddly for us US citizens living in the US. Our data policy is "we will sell your data, too bad so sad".

It is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.

Were these people that actively work on projects that depend on this data for their business to remain viable?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#108

Earlier quoted context omitted.

It is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.

If you work in tech or marketing your salary comes from eroding privacy. There is a lot of money at stake here and people don't vote against their interests. Europeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist.

I don't know if I'd say that. "Tech" is a really big field, and most areas don't have anything to do with eroding privacy.

Unfortunately, many areas that would have been "safe" years ago, like games and standalone applications, are moving in the direction of violating privacy by phoning home and sending "telemetry" data, but there's still a lot of areas that are good.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#109
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

How about we start with not allowing people to legally kidnap individuals?

I never understood the whole concept of “bounty hunters” in the US it’s not the Wild West anymore.

The problem here is that “fugitive recovery” doesn’t need to meet any of the standards normal law enforcement does and unless they kill someone or injure bystanders there likely won’t be an investigation into their conduct and even if there is one the result is often that at worse that could happen is then loosing their license. Criminal investigations against fugitive recovery agents are pretty darn rare and there is no internal affairs or any body that really investigates their conduct on a regular basis.

I’m pretty sure that a large amount of these people violate much more than the privacy of their targets on a regular basis.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#110
post #72

Earlier quoted context omitted.

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. Because of this, black market re-sellers can operate with relative impunity. Most data brokers have a TOS that prohibits the re-selling of their data, but there isn't any copyright protection. For example, if a company has location data, the only way for them to be held liable is for a particular co…

You're trying to use the wrong kind of law for the problem at hand.
Post reply on HN