Live data from Hacker News

New documents reveal scale of US Government’s cell phone location data tracking

aclu.org

311–320 of 327 posts

Re: New documents reveal scale of US Government’s cell phone location data tracking

#311

Earlier quoted context omitted.

There are no "backdoors into Google and Apple." The government has to request specific accounts' data with a court order. The NSA isn't "vacuuming up all the metadata and a good fraction of the content from the main nodes." It does full take in some countries with national security interest and collects data to or from some endpoints outside the US known to belong to foreigners with a court order. We know all of this…

That "court order" is from the FISA court, which may as well be a monkey with a rubber stamp. We learned that from the Snowden documents too.

No, we learned that they were approved at roughly the same rate as other search court orders. Investigators aren't going to spend the time making an application for a court order unless it has a very high chance of being granted.

https://www.quora.com/What-percent-of-law-enforcement-search...

Re: New documents reveal scale of US Government’s cell phone location data tracking

#312

Earlier quoted context omitted.

You can do that right now with Android without root, including Little Snitch functionality.

How?

Using the VpnService API. There are several apps to choose from, including https://f-droid.org/en/packages/eu.faircode.netguard/

Re: New documents reveal scale of US Government’s cell phone location data tracking

#313
post #161

Earlier quoted context omitted.

Buying? The NSA has backdoors in nearly everything through PRISM and they directly monitor internet traffic. Zero chance congress would/could put a stop to that.

Just because the NSA can see it doesn't mean we should allow the local PD, DA or even state legislature to see it.

Very true

Re: New documents reveal scale of US Government’s cell phone location data tracking

#314
post #241

Earlier quoted context omitted.

The developers may not be aware of the full consequences of what they've been asked to do. I was recently discussing the Uber revelations in an ethical tech group that I run. The most shocking part for me was that at one time the app was designed to behave differently depending on whether the user was categorised as law enforcement based on their usage history. This surely required complicity at all levels, from mana…

I can believe that some employees of these companies are genuinely shocked and surprised that this is being done, but few will refuse to do it, and fewer still will quit. The sad fact is that our surveillance society was built with the willing cooperation of countless developers for whom money was far more important than the privacy of their users.

Framing this as "money vs privacy" is disingenuous. There are many other factors at play. It takes a lot of courage and social/emotional skill to be able to say "no" to a work request in a way that is assertive, respectful, and doesn't lead to becoming a pariah. Consistently doing this in the face of deadlines and incoming requests is a big investment of energy. Switching jobs whenever you find yourself in that position is also a big investment of energy. Not everyone has that energy to spare, for example if they have a young family, are going through bereavement, divorce or moving house, or have a health condition etc... .

Re: New documents reveal scale of US Government’s cell phone location data tracking

#315

Earlier quoted context omitted.

C'mon, it's just someone with some opinions you don't like, not the bogie man. It's not a rabbit hole to hear out someone you disagree with. Unless you're either afraid 1) they might be right, or 2) the listener doesn't have critical thinking skills. I get that #2 is scary, and it's a legit issue in society, but they shouldn't be listening to you either. Also, there are good tear-downs Peterson's message online, the…

Just a quick link to alert people who may not realize who/what he promotes. I read all sorts of terrible stuff, and it probably influences me more then I'd like, but it's easy to jump in the middle of something that "seems" reasonable on the Internet.

[flagged]

Re: New documents reveal scale of US Government’s cell phone location data tracking

#316

Earlier quoted context omitted.

Just a quick link to alert people who may not realize who/what he promotes. I read all sorts of terrible stuff, and it probably influences me more then I'd like, but it's easy to jump in the middle of something that "seems" reasonable on the Internet.

[flagged]

[flagged]

Re: New documents reveal scale of US Government’s cell phone location data tracking

#317

When Google and apple came out during the pandemic and showed the anonymous data on every city… it was pretty obvious they were prepared for that way too quickly. It’s safe to assume, you’re tracked 24/7 and everything’s recorded imo.

> you’re tracked 24/7 and everything’s recorded imo If you have Android, open Google maps, open menu, select "Your Timeline", and scroll through days.

I did this and was greeted with a prompt explaining said functionality and asking if I wanted to "Turn it on". There was another button beneath it with the option to "Skip". I clicked Skip to see what happens and all location info for every day I checked was empty ("No visits for this day").

So looks like this functionality is disabled by default. I don't recall ever using google maps on my phone before, let alone tweaking specific settings.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#318
post #81

Earlier quoted context omitted.

The Federal Government purges data that was non-encrypted after a number of years. The Federal Government retains a copy of all https-encrypted communications indefinitely on the understanding that the encryption may be broken at some point. The push to HTTPS was gleefully supported by the US federal government. HTTPS is not a panacea, and is generally useless for most non-sales applications.

You're neglecting to consider the most important aspect of HTTPS, even if you don't care about privacy or believe the encryption will eventually be broken: integrity. HTTPS significantly raises the bar on MITM attacks, such as ISPs adding or replacing ads with their own. It also prevents folks sitting in the same coffeeshop as you from snooping. Calling "generally useless" is incredibly uncharitable.

Considering that HTTPS completely and utterly fails to solve its stated purpose of cryptographic verification of content, it's basically security theater, the last vestiges of which have been completely broken by LetsEncrypt.

But I'm a luddite who also thinks we shouldn't have gone beyond HTML 4.01 as a spec, and that JS in the browser is a pox upon the web.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#319
post #308
post #267

How does Apple’s removal of IDFA affect this? The ad companies no longer have a cross-app identifier that would be of any use in correlating data from a specific phone/person?

The phone company is still tracking your IMSI/IMEI, and they sell data too. The former is directly linked to your identity; the latter also trivially so for most people.

I understand there is a separate level of privacy issues caused by phone companies selling data, but all of the reports refer to data collected from apps which can't be IMSI/IMEI since that's not available from apps?

Re: New documents reveal scale of US Government’s cell phone location data tracking

#320
post #309

Earlier quoted context omitted.

There are DOZENS of us! ---- As a fellow non-mobile phone user, my life has drastically improved. There are many (MANY!) acquaintances whom this frustrates immensely (for they cannot instantaneously speak with me), but my inner circle all know how to reach me by pager a/o physically visiting. As for my outer circle... good riddance (FWIW I am retired)!

Ha, I don't even have a pager. Just another thing being triangulated by cell towers that sell the location. I have VoIP landlines... and SMS can go to my email, but that is the closest thing to telephony that I have. I check email and chat from my desktop when I am in my home office when I want to be reachable. I am mid 30s, so almost everyone in my social circle has their face buried in their phones at all times whi…

>Ha, I don't even have a pager ... [trackable]

I use a one-way pager with a receiver-only module.

The downside to this is there is no error correction/receipt.confirmation.

>I simply schedule time with them when they want it, and set a 24 hour response expectation.

This is how it has to be done. I also require minimum billing hours if they don't meet this expectation (or don't show up within 15 minutes of scheduled start time).

Post reply on HN