Live data from Hacker News

Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

oig.justice.gov

41–50 of 99 posts

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#41
post #32

Earlier quoted context omitted.

See also LOVEINT. Every once in a while, some NSA spy gets caught spying on their loved ones. Not even incompetence, just plain malice and abuse. Looks like they don't even face any criminal charges either. Governments are essentially adversaries, enemies we have to defend against. It must be mathematically impossible for them to abuse their power. Anything short of that is not enough.

> Anything short of that is not enough. I like that in spirit, but not as a practical standard. A major function of government is to prevent abuses of power. So I'm more inclined to shoot for overall minimization of abuse.

Well, in this case a random law enforcement deputy could get sensitive location information about random people with no meaningful cross-check of any sort - and this has only come to light after the fact, as part of a criminal investigation. So there's reason to be highly skeptical that the status quo is the best we can do when it comes to preventing abuse across the board.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#42

Earlier quoted context omitted.

I’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is…

Your cell phone company knows your name, address, and can infer where you've been based on the cell towers your phone checks in with. So that one's a given. Here's a sampling of others: Mastercard sells information on your purchases.[^1] (Based on the info Oracle had on me, I suspect they might be one of the sources for Oracle Advertising.[^2]) Equifax, who gets information from your bank, your car insurance company,…

And for completeness, here’s an article about the telecoms themselves: https://www.washingtonpost.com/news/the-switch/wp/2018/06/19...

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#43

Earlier quoted context omitted.

I don’t understand your question. Your telecom provider has your PII.

I’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is…

Just to clarify my point I’m not condoning this at all, but the telcos themselves have been selling live location data of their subscribers to aggregator services for years.

It’s really infuriating to me that people say Google or Facebook are “selling their data” (they’re not, they hoard data and sell targeted ads) when Verizon, T-Mobile, and AT&T literally sell your live, personally identifiable, non-aggregated, location data to third parties, hiding behind their subscriber agreement legalese.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#44

Earlier quoted context omitted.

I’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is…

Just to clarify my point I’m not condoning this at all, but the telcos themselves have been selling live location data of their subscribers to aggregator services for years. It’s really infuriating to me that people say Google or Facebook are “selling their data” (they’re not, they hoard data and sell targeted ads) when Verizon, T-Mobile, and AT&T literally sell your live, personally identifiable, non-aggregated, loc…

One of many sources: https://www.fiercewireless.com/regulatory/t-mobile-to-fight-...

Just google it, more examples are easy to find.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#45
post #33
post #23

Earlier quoted context omitted.

The cellphone companies have been selling the realtime location of all subscribers since at least 2018. It doesn't depend on whether you have location enabled either, since it figures out your location from the towers! On top of that, one of them had an unauthenticated API, meaning anyone in the world could track the realtime location of any US phone #[0]. If all of this bothers you, contact your state legislators. M…

> It doesn't depend on whether you have location enabled It's even better: the location can be enabled through a network initiated request. This is because A-GPS works "both ways". See https://en.wikipedia.org/wiki/Assisted_GNSS#SUPL : SUPL Position Calculation Function (SPCF) lets the client or the server ask for the client’s location. As part of the FCC’s updated 911 requirements, where cell phones (with no set loc…

This is very interesting - thank you for sharing your knowledge. Any other related rererences - the tech that enables this sort of tracking?

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#46

Earlier quoted context omitted.

I don’t understand your question. Your telecom provider has your PII.

I’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is…

> “It came from teleco companies” is not due diligence enough for

I never claimed this. I replied to the question about how a telecom provider would have PII. My mobile provider knows my legal name and other details. They obviously know which tower is closest to my phone at all times or my phone would not work. That it is terrible of them to sell this data was not in question.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#47

It's disturbing how much this information is sold and resold: * Securus purchased the location data from 3Cinteractive Corporation, which was located in Boca Raton, Florida. * 3Cinteractive Corporation, in turn, purchased such data from Technocom Corporation (doing business as LocationSmart), which was located in Carlsbad, California. * Technocom Corporation (doing business as LocationSmart) purchased this data direc…

there were rumors of gray market identity traders in the 2000 times, within the USA. What changes is accuracy, timeliness, noise levels and verifiability, off the top of my head... Apparently completely legal identity document sales have gone on since the 1950s at least, around driving registration, home address, employment and related things. Since that is in the USA, with newer laws and an alleged emphasis on citizen rights, I can only imagine that other large political powers have had this for centuries.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#48

Earlier quoted context omitted.

That's just impossible. Even if everyone had perfect e2e encryption, the government could just ban it and throw people who use it in jail. You can't solve social problems with technology. What is necessary is a governmental system which tends away from the abuse of power. This requires better voting, more transparency, and the literacy and engagement of its citizens. The problem is, just like in Conway's game of life…

That's why you use a constitution strong enough to prevent the government from having authority to ban a tool like that. The solution's been known and described for 250+ years now.

The problem is, if you rely on tools - and a constitution is nothing else than a tool - you will end up developing a reliance on that tool. And all of a sudden, that tool breaks, and you're fucked.

Democracy must be fought for every single day, and for that matter so does all progress. Democracy isn't something a society automatically converges to and which everyone loves, it must actively be maintained or someone will come, sow mistrust and preach "easy" solutions - and then you wake up and your country isn't a democracy any more.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#49

Earlier quoted context omitted.

That's just impossible. Even if everyone had perfect e2e encryption, the government could just ban it and throw people who use it in jail. You can't solve social problems with technology. What is necessary is a governmental system which tends away from the abuse of power. This requires better voting, more transparency, and the literacy and engagement of its citizens. The problem is, just like in Conway's game of life…

That's why you use a constitution strong enough to prevent the government from having authority to ban a tool like that. The solution's been known and described for 250+ years now.

The US Constitution certainly isn't modern or flexible enough to definitively protect (users of) E2EE. There are arguments for their protection, but none is ironclad (like "this is speech that is protected" ironclad). I'm not saying the Bill of Rights was wrong in its time period, but it would be more appropriate to lay out fundamental principles that must be upheld, and protection for E2EE (users) could then be derived. There's some of that already, but not in a clear and comprehensive manner.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#50

Earlier quoted context omitted.

That's just impossible. Even if everyone had perfect e2e encryption, the government could just ban it and throw people who use it in jail. You can't solve social problems with technology. What is necessary is a governmental system which tends away from the abuse of power. This requires better voting, more transparency, and the literacy and engagement of its citizens. The problem is, just like in Conway's game of life…

That's why you use a constitution strong enough to prevent the government from having authority to ban a tool like that. The solution's been known and described for 250+ years now.

That's silly. A constitution is just a piece of paper. It has no inherent power. It's the institutions put in place to enforce the constitution that give it power. If those institutions rot, the constitution will not protect you. As we've seen time and again.
Post reply on HN