Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

111–120 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#111
post #72

Earlier quoted context omitted.

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. Because of this, black market re-sellers can operate with relative impunity. Most data brokers have a TOS that prohibits the re-selling of their data, but there isn't any copyright protection. For example, if a company has location data, the only way for them to be held liable is for a particular co…

>In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection.

It doesn't need (and shouldn't be) "copyrighted".

It's enough that the law classifies it as private info, and protects it from any third party without an immediate consent.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#112

Earlier quoted context omitted.

It is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.

If you work in tech or marketing your salary comes from eroding privacy. There is a lot of money at stake here and people don't vote against their interests. Europeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist.

I work in tech, but my and my companies work definitely doesn't involve eroding anyone's privacy.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#113
post #85

Earlier quoted context omitted.

Do we think skipping out on a bond is OK? If you are really wanting to do that, don't carry a phone around with you.

I think that’s a scummy business known for not following the letter of the law.

It's a scummy business but without it bail bonds wouldn't exist, or at least be as widely available as they are today. Maybe there are better systems for ensuring compliance with orders to appesr in court than that of Bail but as long as the concept of Bail exists, private Bail Bonds will have to be a necessary part of the system lest lower/no-income individuals find themselves with no recourse.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#114
post #113

Earlier quoted context omitted.

I think that’s a scummy business known for not following the letter of the law.

It's a scummy business but without it bail bonds wouldn't exist, or at least be as widely available as they are today. Maybe there are better systems for ensuring compliance with orders to appesr in court than that of Bail but as long as the concept of Bail exists, private Bail Bonds will have to be a necessary part of the system lest lower/no-income individuals find themselves with no recourse.

> It's a scummy business but without it bail bonds wouldn't exist, or at least be as widely available as they are today.

And...is that bad? The availability of bonds factors in to the level at which bail in a money bail system is set to give reasonable assurance of compliance, so the main effect of available bail bonds is to make purchasing a bond instead of paying cash necessary by driving up money bail prices.

> Maybe there are better systems for ensuring compliance with orders to appesr in court than that of Bail

Certainly there are better ideas than money bail structured to support a commercial bond industry.

> but as long as the concept of Bail exists, private Bail Bonds will have to be a necessary part of the system

No, because bail systems outside of the US and the Phillipines (as well as D.C. and California in the US) are not money bail systems.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#115

It should be illegal to sell people's data without a wet ink signature. That's really the end of the story.

Adding: You should still be able to use services, without consenting to them selling your data, like you can under the GDPR.

Would your tune change if by not agreeing to sell your own data, the service charges you money?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#116

Earlier quoted context omitted.

I fear the reason is that the pools of VoIP numbers have already been exhausted as a resource for setting up’accounts. Ie: some firm is renting VoIP numbers for a month for $1, creating accounts on 100 services and then moving to the next VoIP number. Perhaps the VoIP firms support this whenever they get a block of « virgin » numbers before putting them in their regular pool of numbers for rent.

This just means that phone numbers make for terrible identifiers because there's a fixed number of them and they're transient.

The transience bit is going to become a huge problem over the next decade. I've personally had 3 phone numbers since college (an out-of-state # doesn't mesh well with my career and I've moved several times) and at least one of the individuals who picked up one of my old numbers is the kind of person who has potential for serious run-ins with the law. My mother called my old # once and I guess it was auctioned to company that has a big market in prepaid "burner" phones. In the era of "Big Data" I can't even begin to imagine the sort of hilarious comedy (sarcasm) that can result from the two of us being linked together by what has become a primary source of personal identification.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#117
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

How about we start with not allowing people to legally kidnap individuals? I never understood the whole concept of “bounty hunters” in the US it’s not the Wild West anymore. The problem here is that “fugitive recovery” doesn’t need to meet any of the standards normal law enforcement does and unless they kill someone or injure bystanders there likely won’t be an investigation into their conduct and even if there is on…

The US can still issue letters of marque and reprisal:

https://en.wikipedia.org/wiki/Letter_of_marque

Re: Mobile customer location data is ending up in the hands of bounty hunters

#118
post #16

Earlier quoted context omitted.

google monetizes your data (targeting), but doesn't sell it to others.

#1 Reason: no one can monetize that data better than Google #2 They'd be helping their rivals with such data #3 Sharing might kill the golden goose (bad press etc) ...

Reason #1 sort of invalidates Reason #2. If Google is reasonably confident that they have an unmatchable (in the short term) advantage in interpreting and monetizing your data and can also generate additional revenue by selling it to firms that can't extract the same value from it, what incentive is stopping them? If competitors start to catch up in the areas jn which they have the clear advantage, they can simply shut off the faucet and the revenue generated by selling information jn the here and now helps fund initiatives to keep them ahead in the first place.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#119
post #100
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

> anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? Yes. The Netherlands, carrier is called Youfone. They have very, very little data on me: they claim not to be able to see which cell tower I'm even connected to (which would be tracking info), which makes me wonder how they even provide their service. They say it's all outsourced to third parties, one of w…

Thanks, I'll look out for that. @tapland and @jgibson also mention that mobile networks often outsource running the infra.

In any case - I agree with you that this seems like a shitty legal pseudo-loophole. At the very least the company you sign mobile contract with needs to share your phone number with those infra subsidies. But then according to GDPR: "15. 1. The data subject shall have the right to (...) access to the personal data and the following information: (...) (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed". Following this rule one should be able to reach the bottom of the data processing chain.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#120

Earlier quoted context omitted.

In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. Because of this, black market re-sellers can operate with relative impunity. Most data brokers have a TOS that prohibits the re-selling of their data, but there isn't any copyright protection. For example, if a company has location data, the only way for them to be held liable is for a particular co…

> In the US it is actually a big deal because data is not a "creative work" so it is not covered by copyright protection. It doesn't need (and shouldn't be) "copyrighted". It's enough that the law classifies it as private info, and protects it from any third party without an immediate consent.

As someone who has worked with a couple data aggregation startups, I find it surprising I am unaware of the laws that classify it as private info(or even the legal definition of what "private info" is).

With that said, I am certainly not a lawyer and was never directly involved. Which particular laws are you referring to?

Edit: I should mention I am aware of laws preventing the collection of certain types of data. But unaware of laws about possession of that data.

Post reply on HN