Live data from Hacker News

Carrier sales of phone-location data is illegal, FCC plans punishment

arstechnica.com

141–150 of 166 posts

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#141

Earlier quoted context omitted.

The saddest thing about this is that my bank no longer requires notification for international travel, but still does for travel within the US. I've had my card shut off for fraud a few times while traveling in the US. Once when I had almost no gas and was outside of cell service, thanks for that. This is presumably due to all transactions outside of the US requiring chip, but those in the US only requiring swipe.

Wait, the US is still on magstripe? Isn't that literally just a bar code? No challenge-response, or encryption? Fraud detection seems like the wrong thing to be focusing on if that's the case...

Yeah, it's even worse than that. I was recently in the bay area and I went to pay for a burger with my Canadian chip&pin card and when I the card in the transaction was automatically approved with no need to enter the pin.

This was quite alarming.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#142
post #141

Earlier quoted context omitted.

Wait, the US is still on magstripe? Isn't that literally just a bar code? No challenge-response, or encryption? Fraud detection seems like the wrong thing to be focusing on if that's the case...

Yeah, it's even worse than that. I was recently in the bay area and I went to pay for a burger with my Canadian chip&pin card and when I the card in the transaction was automatically approved with no need to enter the pin. This was quite alarming.

Yeah, we do chip, and maybe signature if we feel like it

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#143
post #70

Biggest industry affected is the banks. They’ll ping your phone location if you make out of area purchases as a part of fraud detection. If your bank doesn’t require travel notices, they are probably pulling mobile location. Some don’t, I know chase uses mobile app to determine location.

The saddest thing about this is that my bank no longer requires notification for international travel, but still does for travel within the US. I've had my card shut off for fraud a few times while traveling in the US. Once when I had almost no gas and was outside of cell service, thanks for that. This is presumably due to all transactions outside of the US requiring chip, but those in the US only requiring swipe.

Make a point of carrying a spare card from a different bank and maybe a different payment network. In my experience, you’re always going to hit random declines from time to time.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#144
The problem is that many private companies now have the historic data. Even if they don’t receive any more in the future, most people only ever go 3-5 places. Collect data for a few years and you have the majority of the population’s locations predicted most of the time for a decade or two.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#145
post #93

Earlier quoted context omitted.

Fair, though Tom Wheeler (previous chairman) was also a lobbyist and he turned out really well.

What does a lobbyist even do? I can't even imagine the scene, they go in a politician's office and just start with "ok hear me out" or am I being naive and it just means finding ways to pay them money?

They organize ways for their clients to bundle significant financial contributions to politician's campaigns so that when they "talk", they can point to significant past contributions or promise future contributions. Or threaten contributions to challengers.

Although individual contributions are limited in theory, bundling allows vast contributions in practice. For example, a CEO can persuade senior execs to donate the maximum to a candidate. Or someone can host a fundraiser at their home (or wine cave) and "encourage" many acquaintances to attend. They get credit with the politician for the total raised.

Finally, Political Action Committees can take unlimited contributions from anyone so long as they don't "coordinate" with a politician's campaign. In practice they can of course be very helpful to a candidate's campaign, and lobbyists will use that to influence.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#146
post #141

Earlier quoted context omitted.

Yeah, it's even worse than that. I was recently in the bay area and I went to pay for a burger with my Canadian chip&pin card and when I the card in the transaction was automatically approved with no need to enter the pin. This was quite alarming.

Yeah, we do chip, and maybe signature if we feel like it

"feel like it" is practically never. I haven't had anyone ask to see my physical card to compare signatures in over five years.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#147
post #110
post #70

Biggest industry affected is the banks. They’ll ping your phone location if you make out of area purchases as a part of fraud detection. If your bank doesn’t require travel notices, they are probably pulling mobile location. Some don’t, I know chase uses mobile app to determine location.

I think they can just tell the zip code where you use the card.

Right, they know where the transaction is taking place. The point is that they can have much higher confidence that the card hasn't been stolen (or cloned, in the case of mag stripes) if your phone is also in the same zip code.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#148

Earlier quoted context omitted.

The saddest thing about this is that my bank no longer requires notification for international travel, but still does for travel within the US. I've had my card shut off for fraud a few times while traveling in the US. Once when I had almost no gas and was outside of cell service, thanks for that. This is presumably due to all transactions outside of the US requiring chip, but those in the US only requiring swipe.

Switch banks? I have never once had American Express decline a charge domestic or international. Highly recommend!

Opposite position here - American Express was the one card I could not use anywhere in my first European trips 20 years ago (don't know it that's changed) - ditched it forever then. MC and Visa works for me. Never looked back.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#149

But Facebook, Google, Microsoft, et al are still free to sell phone location data acquired through apps (or Android itself in the case of Google), right? I wonder if there is any hope of laws to limit the ability of companies to sell this data...

It's time to differentiate selling "Bob is in Location X" from "Show this ad to all people at location X". The first case is a far far bigger privacy concern to me, and seems to be what mobile networks were doing. Facebook, Google, and Microsoft are doing the latter.

No, it isn't. Both are essentially workable to do the same bloody thing, and just mean the same outcome can be achieved with the minor inconvenience of an additional layer of indirection.

Geolocation information shouldn't be considered a desirable dataasset to hold onto as a monetizable asset at all at the level of granularity that enables individual resolution.

Re: Carrier sales of phone-location data is illegal, FCC plans punishment

#150
post #70

Biggest industry affected is the banks. They’ll ping your phone location if you make out of area purchases as a part of fraud detection. If your bank doesn’t require travel notices, they are probably pulling mobile location. Some don’t, I know chase uses mobile app to determine location.

They can just ping their banking app on your phone and estimate your geolocation via ip address. No network provider level snooping needed.
Post reply on HN