Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

91–98 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#91

Is any of this really a surprise to any of you?

That's like walking up to an astronomer, and when he gives detailed remarks regarding the stars in the sky, you reply:

  You're really surprised that there are stars in the sky? 
I think you're missing the point.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#92
post #81
post #74

Earlier quoted context omitted.

Apple programmed a feature that cached all location data on a file on the iPhone. GCHQ's linked PowerPoint says "If it's on the phone, we can get it". Ergo, GCHQ and the NSA certainly had access to your cached location data if they wanted it. Maybe Apple intended this to be the case, maybe Apple did not, but the mere fact that the file existed is enough that it most certainly could have been scooped up by spooks.

No. "All the location data" was not cached. Only cell tower locations. "Maybe apple intended this to be the case" is baseless innuendo and has no place here. "If it's on the phone, we can get it" has separately been shown only to apply when the agencies have physical access to the device to extract data or implant malware. You seem to want to spread the idea that spies can access the real-time location of your iPhone…

Cell tower data is sufficient to determine phone location via triangulation. Additionally, spies can get real-time data from the carrier directly, as can law enforcement.

The parent comment said nothing about real-time access, but if someone has a remote exploit that gives filesystem access (and if jailbreakers can do it, then the NSA can, too), that location data file would provide a detailed history of the phone's location.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#93
post #8

The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.

And never use it to call anyone else or connect to anything else. Don't forget that when you're designing your NSA-proof phone.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#95
post #68
post #61

Earlier quoted context omitted.

I agree with you in general, but this is not the smoking gun you are suggesting. Once someone is a target , investigating them in general is legitimate, assuming that there is justification for regarding them as such.

What definition of "target" are you using here? Is the NSA/FBI/CIA/GCHQ/etc. using the same definition?

Considering the government has "targeted" political dissidents and protesters, I would say the definition is basically everyone.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#96
I will quote United nations declaration of human rights: Article 12

"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."

Privacy or correspondence... "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence"

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#97

Earlier quoted context omitted.

Old enough to know a non-answer when I see one. Again I ask: Any specific examples from companies or organizations that implement HTTP(S) in their products stating device power as reason for non-implementation?

I imagine it to be a horrible miscarriage of trust to not use HTTPS. We made the decision early on that handling any personal data not over HTTPS was massively irresponsible - and this is pre-Snowden. That said, if they have kernel-level hacks or can intercept and decode HTTPS (or sit and listen on say, any AWS server they want), what does HTTPS really matter against the NSA? Still, totally irresponsible - battery li…

The problem is that HTTPS is very difficult to audit, we just have to trust that it is being done correctly.

How do you know that the apparently random stream of bits is actually properly encrypted and does not leak private data? It would be better to let the OS add the SSL layer and only let apps talk HTTP. This would give the user much more control.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#98
post #81

Earlier quoted context omitted.

No. "All the location data" was not cached. Only cell tower locations. "Maybe apple intended this to be the case" is baseless innuendo and has no place here. "If it's on the phone, we can get it" has separately been shown only to apply when the agencies have physical access to the device to extract data or implant malware. You seem to want to spread the idea that spies can access the real-time location of your iPhone…

Cell tower data is sufficient to determine phone location via triangulation. Additionally, spies can get real-time data from the carrier directly, as can law enforcement. The parent comment said nothing about real-time access, but if someone has a remote exploit that gives filesystem access (and if jailbreakers can do it, then the NSA can, too), that location data file would provide a detailed history of the phone's…

No. Triangulation requires near-simultaneous signal strength readings from multiple towers at the time the position is to be computed.

The cell tower cache you refer to does not contain that kind of data, so the data file des not provide a detailed history of the phones location. This has been shown by the people who investigated the file.

An extremely coarse location, to the resolution of cell towers can be obtained from the file, but as we know, that is available to the phone network anyway.

The parent comment talks about geolocation data at regular X minute intervals. This file does not provide that. Nor does it provide any information that the NSA can't get via the cell network about any phone. Indeed the network likely can provide triangulation.

The link you referenced is nothing but innuendo intended to implicate 'Apple' somehow.

Post reply on HN