Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

41–50 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#41
post #39
post #17

Earlier quoted context omitted.

Don't be alarmed citizen. They only 'know' about your movements if they actually look at them. Until then, they don't 'know' anything as long as it sits in their archives untouched.

It's a bit more Orwellian than that. The NSA claims it doesn't "collect" data until it looks at the data. Somehow the data magically appears in its databases, but it isn't collected.

If a tree falls in a forest etc.

These caches of information exist all over the place. While I'd prefer NDA/GCHQ to not slurp and store this stuff at least they have a duty to keep it secret. I am a lot more bothered by my ISP keeping that stuff. They're a lot less competant and have many fewer access controls.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#42
post #34

One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?" To me, this is quite telling. The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking…

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ. It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

Murdering people is technically feasible as well. If entities are given essentially no legal oversight then the correct response would be to act on the incentives they were given to murder freely.

The problem is with the legislature (and the judiciary), voters, and the media.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#43
I'm sure they are finding and identifying tons of "terrosim threats" by looking at angry birds data... /s

If anything they are just making it harder to find the needle (terrorist threat) in the haystack (their dragnet of data). At the end of the day maybe they don't care about finding the needle anymore.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#44
post #43

I'm sure they are finding and identifying tons of "terrosim threats" by looking at angry birds data... /s If anything they are just making it harder to find the needle (terrorist threat) in the haystack (their dragnet of data). At the end of the day maybe they don't care about finding the needle anymore.

All kinds of data are interesting. You've seen episodes of CSI. Position data scraped from some app, any app, can come in useful but only when you want to track somebody. Who to track is a different problem.

Its not all about finding criminals. But when you've found one, you want to know where he's at, who he's associating with etc.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#45

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

> It is time for a reboot, this time with much more focus on security.

Here's a helping hand for those that don't know where to start: http://prism-break.org/

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#46

Earlier quoted context omitted.

What about leaking bookmarks from Al-Quran app?

Still a ridiculous unneeded incursion onto an individual's right to be left alone when they aren't hurting anyone. As violent and primitive as the Islamic fundamentalists are, the vast, vast, vast majority of the world's 1.6 billion Muslims are not fundamentalists, nor are they terrorists, nor do they aid terrorists. The phrases that people bookmark in a religious app book are a very far cry from demonstrable intent…

While I would agree that the "vast, vast, vast" majority of Muslims do not present a threat to national security, it is going too far to say that the "vast, vast, vast" majority are not fundamentalists.

The majority are almost certainly not, but a frighteningly large minority are. For example, only 54% of Muslims in Turkey believe that suicide bombings are never justified, and 16% believe that they are sometimes or often justified: http://www.pewglobal.org/2013/09/10/muslim-publics-share-con...

This should not be particularly surprising. Fundamentalism also runs strong in Christianity. Nearly half of all Americans are creationists, believing that the earth is only a few thousand years old, and that people did not evolve (we're not talking Catholic-style "god used evolution" creationism here, we're talking straight up "literal talking snake" creationsim): http://www.gallup.com/poll/155003/hold-creationist-view-huma...

People take religion seriously, film at 11.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#47
post #36

Earlier quoted context omitted.

That was in 2008. Imagine what else they've been able to jimmy in 6 years! I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.

> I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes. Considering Apple did that on your behalf I would be surprised if this was not the case. http://bits.blogs.nytimes.com/2011/04/20/3g-apple-ios-device...

Apple didn't store users location data. Cell tower positrons were cached on iOS devices, and this was turned into a false controversy because sensationalism sells. Citing this piece as if it asserts that Apple collects user location data in the way the parent poster fears the NSA might do is dishonest.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#48
post #12

Earlier quoted context omitted.

Maps and other apps on the iPhone weren't using HTTPS in 08 (underpowered device, need to squeeze every last drop from battery). They do now however. It's not just a spy agency issue, anyone could have sniffed the unencrypted traffic.

(underpowered device, need to squeeze every last drop from battery) Really now? Is that the official reasoning for not using HTTPS?

Well, this is the most common argument before Snowdengate I heard against using HTTPS anywhere, not only on mobile devices.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#49
post #34

One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?" To me, this is quite telling. The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking…

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ. It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

Why should our government agencies not commit crimes just because no one is looking?

I'm just going to assume you were being sarcastic and move on.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#50
post #8

The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.

If people don't read and understand the code, ideally before running it since part of the code might be to make some low level change to its environment and then erase itself, then it doesn't matter whether it's there or not. And reviewing significant code bases is not something one person can do on their own, even in the unlikely event they've all the specialities to understand it all. It would require non-trivial organisations to be directed towards auditing the applications/system to ensure security.

Which isn't to say that I don't think open source is a necessary condition for security. But I don't see that sort of audit getting done for everything that your average user is going to run on their phone.

Post reply on HN