Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

131–140 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#131
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

Great idea, not sure how they implement this though. They can just email it to you because GDPR does not specify the delivery means.

Just because the user is the one asking for the data doesn't mean the rest of the GDPR stops applying. They're still required to have appropriate safeguards, which means they certainly can't email it to you (at least not in plaintext).

Also, more specifically about the Right to Access, Recital 63 says: "Where possible, the controller should be able to provide remote access to a secure system which would provide the data subject with direct access to his or her personal data". (emphasis mine)

Re: Mobile customer location data is ending up in the hands of bounty hunters

#132
post #122

Criminal investigations have to stand up to court scrutiny. Fugitive recoveries do not. I expect there’s a lot more misconduct where this came from.

The whole bounty hunter system sounds like something out of a bad movie.. I would be very surprised if it wasn't full of abuse stories.

Professional law enforcement agencies are a recent development historically, and for a long time were resisted as something out of an authoritarian dystopia. Policing was the job of amateurs and freelancers for much longer than it’s been a civil service bureaucracy. Even death investigation was, until recently, a side gig for the town doctor.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#133
post #73

Perhaps this is a good reason to use Google Voice and not give anyone the underlying real phone number with cell service.

Yep, I've been doing this for years. Only my wife and a few trusted friends have the real cell phone. Everyone else and their mother gets the GVoice number. I also change the underlying number occasionally just to mix it up even more (although truth be told that's to get better wireless deals, but it has a nice bonus of added security).

How do you avoid giving your mobile number to service providers on sign up (banks, paypal, uber etc)?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#134

Earlier quoted context omitted.

I’ve set up a DID that leads directly to a voicemail box that emails me the recording. It’s worth the $1/month expense to have a number to hand out to people I don’t want to be available to. And, in a way, it keeps me available when I’m overseas and don’t have my usual SIM card installed. I use VoIP.ms

Can you discuss how you set this up? I looked at voip.ms and it looks like it supports Asterisk and other VOIP software, how did you configure yours? Thanks

They have a configurable out-of-the-box voicemail setup option.

No software or server running on my end. It’s all on theirs.

I originally set it up when my phone provider wanted to charge me several dollars per month for a less useful voicemail system, so I set up such a thing by telling my provider to forward unanswered calls to that other DID.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#135
post #126

Earlier quoted context omitted.

How about we start with not allowing people to legally kidnap individuals? I never understood the whole concept of “bounty hunters” in the US it’s not the Wild West anymore. The problem here is that “fugitive recovery” doesn’t need to meet any of the standards normal law enforcement does and unless they kill someone or injure bystanders there likely won’t be an investigation into their conduct and even if there is on…

> How about we start with not allowing people to legally kidnap individuals? Then you'd have to give up being able to afford bail; without bounty hunters, bondsman would have no recourse when you didn't show up to court and thus not much incentive to loan you bail money. You're not being legally kidnapped, you agreed to those terms when you borrowed the bond money for bail.

The bail money isn't an essential part of the system either. Most other countries have radically different systems; in the U.K. it's unconditional and free for minor offenses with escalating conditions (and violence may result in no bail at all).

https://www.cps.gov.uk/legal-guidance/bail

Re: Mobile customer location data is ending up in the hands of bounty hunters

#136
post #115

Earlier quoted context omitted.

Would your tune change if by not agreeing to sell your own data, the service charges you money?

If we're talking about the GDPR, the service can ask you to sell your data, and it can charge you, but it can't force you to choose between the two. Data ain't currency.

And what is the answer if we're not talking about GDPR?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#137
post #122

Earlier quoted context omitted.

The whole bounty hunter system sounds like something out of a bad movie.. I would be very surprised if it wasn't full of abuse stories.

Professional law enforcement agencies are a recent development historically, and for a long time were resisted as something out of an authoritarian dystopia. Policing was the job of amateurs and freelancers for much longer than it’s been a civil service bureaucracy. Even death investigation was, until recently, a side gig for the town doctor.

Its almost like we outsourced our civic duties to hired guns

Re: Mobile customer location data is ending up in the hands of bounty hunters

#138
post #72
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

relevant clip:

https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s

on a more serious note, even if such data is not resold commercially, and even if more detailled surveillance by a real human analyst only occurs when automated red flags are raised, and the system was designed to only allow the analyst access to the detailed data if enough or the right combination of red flags are raised there is a remaining problem: if your job consists of interpreting all day long the details surrounding red flags concerning an individual case by case, and an individual piques your interest (legitimately or not) and if your access to detailed surveillance on this individual expires when the red flags expire (in order to keep the analyst workforce focussed on their job, not their pet theories), then it becomes trivial for the analyst to "tag" an individuall of choice (out of curiousity, fascination) or a previous target (to prolong detailed surveillance): just arrange for an automated red flag concerning this individual to go off! you don't need to guess what types of automated red flags exist since you are constantly handling cases of individuals, and the red flags that were triggered!

(Oct 15) A few months back, my sister visited me in the city I live, and at one point she asked if I could use a prepaid sim card that was soon to get expired (16 days later or valid till including Oct 31), I said I don't really need it, but if she couldn't think of anyone else I would probably use it to call some of my more remote friends (I usually text). She remarked it was stupid that she had forgotten to bring the card. I remember asking why she bought it if she didn't use it?? But she said something along the lines of "I'm not really sure", I had the impression she didn't buy it, but in turn somebody had given her the card... I also said it's OK if she gave it to someone else. At that point I assumed that was what would happen, and simply forgot about her mentioning the SIM card.

Here in Belgium, the mail is delivered "D+1", so pretty quickly..

(Oct 24) Nine days after my sister visited me, I am staring out my living room out on the street, and I see the postman going through the street and crossing to enter the apartment building I am in. After a while I notice him at the end of the street, so he already passed.

I go down to check the mail, and there's a notification card, telling me about a letter with insufficient postage, that I wasn't home, and that I can go to the post office if I wish to pay and receive it nonetheless...

Here the weight for a single post stamp is 50 grams. So thats quite a letter. I had forgotten about the SIM card and started fantasizing about a (long) loveletter from N (a girl from the past).

Obviouly I go to the post office, I say I want to pay for the postage, and I ask who the letter was from. The employee looks at me as if I don't understand the postage system and says: "If it had a return adress, it would have gone straight back to the sender. So the envellope did not state a sender, in which case the recipient can elect to pay for sufficient postage." I suddenly had a flashback to elementary school, and these once-deeply-studied facts long ignored immediately sprang alive. "Of course!" I said...

I ask when I will receive it, and he says it depends if I want to go pick it up today at the main post depot, or if I wish to receive it by mail, and in that case in just a few days. I tell him they can send it by mail.

From then on, the first thing I do upon awaking, is run down to get "N's loveletter". However no letter marked with "insufficient postage" stamp arrives.

(Nov 1) The SIM card expires.

I distinctly remember one day noticing it had already been exactly 2 weeks and I still didn't get the letter. That same day (Nov 7) I read in the papers that the national postage system starts a strike, and mail already underway will be on tine, but new mail may get delayed.

The strike is still ongoing about 2 days later, when I finally receive the letter marked with the "insufficient postage" stamp. Immediate dissapointment: it's not from N but from my sister, and it's the SIM card.

Immediately more inconsistencies pop up: 1) my sister did of course as always state her name and return address on the letter 2) the whole envellope, greeting card, unopend prepaid SIM card weigh less than 20 grams, let alone 50 grams!

So I fire up my abductive reasoning skills.

Of the hundreds of letters I receive:

What is the probability or how often do I receive a letter that is insufficiently stamped? it was my very first such letter!

Moreover what is the probability that a letter is incorrectly marked with "insufficient postage"?

Moreover what is the probability that a letter with return address is sent on to the recipient if it has "insufficient postage" ?

Those co-incident probabilities are very low indeed. And it is also the first letter I receive that contains a prepaid SIM card. Bingo! obviously authorities do not want people mailing unused prepaid SIM cards! That may re-anonymize any over-the-counter de-anonymization, like paying with card!

Probably criminals (perhaps also investigative journalists) create demand for clean SIM cards, where the cleanliness to the buyer is illustrated by the prepaid SIM card package still being unopened...

So the motive to detect and intercept SIM cards in mail exists.

Now I obviously get curious, how did they detect this in the benign case of my sister sending me her almost expiring SIM card?

The actual SIM card is to be broken out of the larger card, which states the PIN and PUK code...

This larger card has the same dimensions as credit/smart cards...

They both contain a chip under the contacts...

Some credit cards contain RFID for contactless payments...

So I postulate abductively that the larger card with PIN and PUK code contains an RFID coil, and when breaking out the SIM card, it's connection to the coil is broken!

Are these RFID tags visible with off the shelf commercial RFID readers? or are their also "secret" tags that the readers refuse to identify by design? If so, and someone finds a way to detect this secret class of RFID tags, then we may find more of these in unexpected places/locations...

I will see my sister back in a few weeks, and she will obviously ask if I made use of the SIM card. Now I hate lying, and I also hate dissappointing people when something is not really my fault, since the unjustified inssuficient postage delay caused the card to expire. Then I will ask if she actually bought the card herself, was given the card, or if she somehow found the card, for example mysteriously in her mail box...

Everybody has their own SIM card, nobody really needs an extra one, and my sister is not very sociable, she wouldn't know who to give a surplus card about to expire.

So if an analyst wanted to tag me (or her), it is entirely predictable she would ask her younger brother if he perhaps could use it! And that she would send it by mail (since we live in different cities).

Any future analyst will come to believe this red flag in the record is genuine, and not a placed one! It is entirely conceivable that there are some very unlucky people with a boatload of flags on their record, which convince the new analyst that this individual needs more tracking even if the last flag expires... so they place a new flag! and after this analyst's second term of observing the individual, he gives up, ... until next time a new analyst observes the person's record, is amazed with the richly filled flags in the past, and perhaps does the same....

Now apart from being overzealous and having pet theories, what other motivation could the analyst have to bypass the agency focus mechanism by placing tags? What about pure boredom? The first time you investigate a bunch of neo-nazi scum you are all excited, and the first time you investigate some angry muslim lowlife, you are similarily excited... but after a few weeks/months/years you realize there is nothing exciting, just the endless stream of boring as hell hitler greetings, and the boring as hell angry muslim's communicating things like "the infidel whore!" etc... It's like working at the zoo, when you are small it seems awesome, and the public part of the zoo is nice, but when you actually work there, the non-public part of the zoo is just grim walls, and shovelling different kinds of excrement. Of course the analyst / zoo employee tries to make quick work of the shoveling part, so he can spend some time checking out the lizards or whatever kind of people really fascinate him in an entertaining way!!

Re: Mobile customer location data is ending up in the hands of bounty hunters

#139
post #18
post #9

It would appear that sometimes even paying for the service doesn’t mean you won’t end up as the product anyway. How can one avoid this kind of aggregated location tracking?

You guys need (something like) GDPR in the US. I believe it's a necessity.

No we don't, it's a terrible law that unnecessarily burdens business and just makes it even harder to run a business. We don't need any more legal hoops to jump through; it's not the users data, it's our data about the user. The notion that data about you belongs to you is frankly absurd, just because the EU hopped on the crazy train doesn't mean the rest of the planet should follow them.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#140
post #135
post #126

Earlier quoted context omitted.

> How about we start with not allowing people to legally kidnap individuals? Then you'd have to give up being able to afford bail; without bounty hunters, bondsman would have no recourse when you didn't show up to court and thus not much incentive to loan you bail money. You're not being legally kidnapped, you agreed to those terms when you borrowed the bond money for bail.

The bail money isn't an essential part of the system either. Most other countries have radically different systems; in the U.K. it's unconditional and free for minor offenses with escalating conditions (and violence may result in no bail at all). https://www.cps.gov.uk/legal-guidance/bail

It's essential in a system where changes to how government operates largely aren't possible due to partisan divides; bondsman are a free market solution to absurd government policies on bail. When you can't fix the government, you go around them.

btw, that wasn't me that down voted you.

Post reply on HN