Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

11–20 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#11
post #8

The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.

Not just the OS, but the entire phone, chipset -> firmware -> os (including wireless sub-OSes) -> app.

Of course, if your open source apps request any data related to your activities (such as detailed map data about your current location, even without your exact location, or routing information for TCP packets), you're leaking data about yourself again.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#12

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

Maps and other apps on the iPhone weren't using HTTPS in 08 (underpowered device, need to squeeze every last drop from battery). They do now however. It's not just a spy agency issue, anyone could have sniffed the unencrypted traffic.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#14
post #4

There ought to be more emphasis that these documents are circa 07/08. HTTPS websites were an oddity back then.

Thus their obsession with undermining public key encryption and obtaining the private keys for popular services.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#15
post #8

The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.

That's not enough. Take the Google maps example, for instance. I bet the NSA could grab the same data from an open-source map app that used OpenStreetMap data. They can infer your location based upon the set of map tile URLs that your phone is loading over the network.

No need for any code weaknesses in the app. Open source is not your saviour here!

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#16
One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?"

To me, this is quite telling.

The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking for "what can we get", and worry later about how it might be useful (or legal!).

This is no way to run a successful organization in the 21st century.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#17
post #6

Ridiculous,seems like they are taking data and storing it and waiting to get subpoenas to look into and analyze the data later. Welcome to the new world order where your every movement is known.

Don't be alarmed citizen. They only 'know' about your movements if they actually look at them. Until then, they don't 'know' anything as long as it sits in their archives untouched.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#18

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

That was in 2008. Imagine what else they've been able to jimmy in 6 years!

I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#19
So they're spying on the children playing Angry Birds in the name of preventing terrorism. I bet the data they're gathering has saved a lot of lives.

This is just one more strike into the already well-beaten dead horse of an argument that the NSA is spying in the name of preventing terrorism.

I will spell it out: the goal of the NSA surveillance is omniscience in the name of preserving the power of the state. They have made great progress toward this ideal.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#20
post #17
post #6

Ridiculous,seems like they are taking data and storing it and waiting to get subpoenas to look into and analyze the data later. Welcome to the new world order where your every movement is known.

Don't be alarmed citizen. They only 'know' about your movements if they actually look at them. Until then, they don't 'know' anything as long as it sits in their archives untouched.

For now. Just wait until sophisticated AI is developed...
Post reply on HN