Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

81–90 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#81
post #74
post #47

Earlier quoted context omitted.

Apple didn't store users location data. Cell tower positrons were cached on iOS devices , and this was turned into a false controversy because sensationalism sells. Citing this piece as if it asserts that Apple collects user location data in the way the parent poster fears the NSA might do is dishonest.

Apple programmed a feature that cached all location data on a file on the iPhone. GCHQ's linked PowerPoint says "If it's on the phone, we can get it". Ergo, GCHQ and the NSA certainly had access to your cached location data if they wanted it. Maybe Apple intended this to be the case, maybe Apple did not, but the mere fact that the file existed is enough that it most certainly could have been scooped up by spooks.

No. "All the location data" was not cached. Only cell tower locations.

"Maybe apple intended this to be the case" is baseless innuendo and has no place here.

"If it's on the phone, we can get it" has separately been shown only to apply when the agencies have physical access to the device to extract data or implant malware.

You seem to want to spread the idea that spies can access the real-time location of your iPhone remotely - which is what the parent post was fearing, but for which there is no evidence. What is your motive here?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#82
post #60

Earlier quoted context omitted.

(underpowered device, need to squeeze every last drop from battery) Really now? Is that the official reasoning for not using HTTPS?

Back then it was.

I just don't recall anything official regarding that line of thought. Direct PR or otherwise. Is there any examples off the top of your head?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#83
post #63
post #59

Earlier quoted context omitted.

If the government offered a legitimate and effective way for whistleblowers to expose wrongdoing and unconstitutional behavior, perhaps they could limit this type of damage from being done. As it stands, the release of this information could be considered collateral damage as result of their continued persecution of whistleblowers.

The people who are harmed by making this information public is not the U.S. government. Think it through. Who wins by knowing how the US government conducts targeted counterintelligence operations? That will be primarily terrorists, organized crime, and oppressive governments. So then who loses? That will naturally be victims of terrorism, organized crime, and oppressive governments. That is why I don't think it's re…

That will be primarily terrorists

Ooga-booga! TERRORISTS!!!11!!

Still waiting for a list of "terrorists" caught by this program.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#84
Between this and the recent credit card and identity leaks by Target and others, I really wish people would connect the dots. If companies are grabbing and storing incredible amounts of information about millions of people, that information will inevitably get the attention of spammers, scammers, stalkers, criminals, governments, and anyone else who could possibly put it to use. The solution is to limit what companies collect in the first place.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#85
post #60

Earlier quoted context omitted.

Back then it was.

I just don't recall anything official regarding that line of thought. Direct PR or otherwise. Is there any examples off the top of your head?

"HTTPS is expensive" has been a widespread (stupid) meme since the invention of HTTPS. How old are you?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#86
post #57

Exploiting phone information and location is a high-priority effort for the intelligence agencies, as terrorists and other intelligence targets make substantial use of phones in planning and carrying out their activities, for example by using phones as triggering devices in conflict zones. That's a good point and a good reason why it's irresponsible for these newspapers to post the details about this technology. This…

To be clear, you are saying that a cell phone used to receive a command to denotate a bomb is the same phone the bomber uses to share photos on Facebook?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#87
post #46

Earlier quoted context omitted.

Still a ridiculous unneeded incursion onto an individual's right to be left alone when they aren't hurting anyone. As violent and primitive as the Islamic fundamentalists are, the vast, vast, vast majority of the world's 1.6 billion Muslims are not fundamentalists, nor are they terrorists, nor do they aid terrorists. The phrases that people bookmark in a religious app book are a very far cry from demonstrable intent…

While I would agree that the "vast, vast, vast" majority of Muslims do not present a threat to national security, it is going too far to say that the "vast, vast, vast" majority are not fundamentalists. The majority are almost certainly not, but a frighteningly large minority are. For example, only 54% of Muslims in Turkey believe that suicide bombings are never justified, and 16% believe that they are sometimes or o…

"Fundamentalist" is code for militant here, and you knew that.

What percent of Americans believe drone attacks are justified?

What does "fundamentalism" have to do with any of this?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#88
post #85

Earlier quoted context omitted.

I just don't recall anything official regarding that line of thought. Direct PR or otherwise. Is there any examples off the top of your head?

"HTTPS is expensive" has been a widespread (stupid) meme since the invention of HTTPS. How old are you?

Old enough to know a non-answer when I see one.

Again I ask: Any specific examples from companies or organizations that implement HTTP(S) in their products stating device power as reason for non-implementation?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#89
post #85

Earlier quoted context omitted.

"HTTPS is expensive" has been a widespread (stupid) meme since the invention of HTTPS. How old are you?

Old enough to know a non-answer when I see one. Again I ask: Any specific examples from companies or organizations that implement HTTP(S) in their products stating device power as reason for non-implementation?

I imagine it to be a horrible miscarriage of trust to not use HTTPS. We made the decision early on that handling any personal data not over HTTPS was massively irresponsible - and this is pre-Snowden.

That said, if they have kernel-level hacks or can intercept and decode HTTPS (or sit and listen on say, any AWS server they want), what does HTTPS really matter against the NSA?

Still, totally irresponsible - battery life is a constant struggle, but not enough to even make us consider changing our API client code.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#90

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

The sad thing is that if I watched these sort of pronouncements in an episode of "Person of Interest" or some other show I would normally laugh them off like I do the infinite zoom/sharpen capability of security video.

Interestingly, things like the zooming and enhancement of video similar to the TV capabilities often portrayed are also now easily accessible. Read about 'super-resolution' [1,2] techniques for more details.

[1] https://en.wikipedia.org/wiki/Superresolution [2] http://research.microsoft.com/en-us/um/people/cmbishop/downl...

Post reply on HN