Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

161–170 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#161
post #152

Earlier quoted context omitted.

And do you think the bondsmen don’t have an incentive to keep the status quo? It’s a multi billion dollar industry which effectively taxes the poor. Make bounties illegal and it fill fall, once it falls the entire bail system in the US will have to be rethought as there isn’t a way to lock so many people up, more judges will release them until trial without setting a bail which they can already legally do and do so f…

You're putting the cart before the horse; until you change the government and thus the bail system, we need bondsman. Making bounties illegal won't stop judges from setting bails people can't afford and is thus not a valid solution.

Very dumb argument. There is no cart and there is no horse. Eliminate the bail system and something has to fill the void.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#162

Earlier quoted context omitted.

relevant clip: https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s on a more serious note, even if such data is not resold commercially, and even if more detailled surveillance by a real human analyst only occurs when automated red flags are raised, and the system was designed to only allow the analyst access to the detailed data if enough or the right combination of red flags are raised there is a remaining problem…

I have no idea what your story is trying to say.

I am saying I believe the creditcard-sized card that contains a fresh prepaid SIM card, probably contains an RFID loop antenna.

This is trivial to verify or falsify, just buy some acetone in the hardware store:

https://learn.adafruit.com/rfid-iphone/dissolve-the-card

I already bought the acetone, but I did not yet dissolve the SIM card, I want to do this in front of my sister, so she understands why I attach importance to finding out the origin of the unused expired SIM card she sent.

The card is supposedly expired anyway (well to be honest the validity date is printed on a sticker on the outside of the plastic foil package, so in theory it may be a still valid card with a fake early expiration date to encourage my sister to hurry with giving it away...).

I did not yet dissolve the card, but I feel pretty certain there is an RFID coil inside, and that is how they detected and stalled the letter without opening it. Stalled to determine if it is OK or not to allow the card to be sent on or not. "insufficient postage" to increase the possibility of the recipient deciding not to want the letter.

If you can't wait a couple of weeks to hear back from me if there is an RFID tag inside, you can try buying a prepaid SIM card and dissolving in acetone yourself. If you or someone tries this before february, I would like to know the result.

The whole story got me thinking that the human analysts that process and interpret red flags can easily build a repertoire of tricks to arrange for a red flag concerning a person to go off.

If my sister provides me with a name (perhaps even an address) of whoever gave her the card, I could consider tagging the person back (by sending the SIM card to him).

However I think it is unwise:

1) the person who gave it to her would not necessarily be the analyst, it may be an informant (perhaps a criminal turned informant, in which case I am effectively tagging myself into association with a criminal!)

2) if the person who gave it to her was the analyst, and I addressed the letter to Mr [name] "The Tagging Spook" [surname], and possibly arrange for the letter to have insufficient postage, while hilarious that my case file would then contain a red flag associating me with the analyst called out as a spook, it's unclear how he would react. Any future analyst could notice the burnt name of a colleague. He might need to self-report his bypassing of the automated system raising supposedly spontaneous red flags... Also, I estimate it would not be wise of me to go and poke the hornets nest. So I think I will stay with just observing and learning...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#163
post #127
post #72

Earlier quoted context omitted.

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

The GDPR doesn't apply to most of the world, it's awful legislation anyway. It's not your data, it's my data about you, I own it, it's in my databases, and if you don't want me to have it, you shouldn't have given it to me freely to begin with.

I'm afraid you accidentally posted your canned response about the GDPR next to an article that directly refutes it.

The opening paragraph of the article:

> Nervously, I gave a bounty hunter a phone number. He had offered to geolocate a phone for me, using a shady, overlooked service intended not for the cops, but for private individuals and businesses. Armed with just the number and a few hundred dollars, he said he could find the current location of most phones in the United States.

Do you own a phone?

Re: Mobile customer location data is ending up in the hands of bounty hunters

#164
post #72

Earlier quoted context omitted.

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

relevant clip: https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s on a more serious note, even if such data is not resold commercially, and even if more detailled surveillance by a real human analyst only occurs when automated red flags are raised, and the system was designed to only allow the analyst access to the detailed data if enough or the right combination of red flags are raised there is a remaining problem…

This is:

a) the longest comment I’ve ever read all the way through on HN

b) an interesting anecdote

but c) most likely a coincidence.

I agree that the likelihood of such a thing happening is miniscule. However, I’ve had all sorts of strange postage-system-related issues in my time (granted, I’m in the US, which has likely a much worse system) and it doesn’t seem that far out to me that such a letter would have been mishandled by what is likely an automated system.

Maybe if you buy a SIM card and send it to someone else, you can get more conclusive evidence about whether prepaid SIMs are genuinely slowed in transit or if you were just very unlucky. One occurrence does not a trial make.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#165
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

Maybe we should think about location data in a similar way to photographs. Both are generated by smartphone hardware and software, but the person who presses the shutter button legally owns the copyright to the photo, not the device manufacturer or carrier. Why don't I own the copyrights to my location data, and why doesn't the carrier need to license it from me in order to sell on to these bounty hunters?

The data is created by the phone towers that you connect to. Its a similar situation to when you visit a website and the server logs your request.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#166

Earlier quoted context omitted.

It is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.

If you work in tech or marketing your salary comes from eroding privacy. There is a lot of money at stake here and people don't vote against their interests. Europeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist.

Hi I work for a printing company as a full-stack developer. My work involves things like writing API wrappers to ingest order flow so our customers can print brochures, or building web UI tools to create and order print resources. The last algorithm I wrote was to generate 5000 unique BINGO cards. Please explain to me how my salary comes from eroding privacy.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#168
post #164

Earlier quoted context omitted.

relevant clip: https://www.youtube.com/watch?v=GOkFHTGgao8&t=68m36s on a more serious note, even if such data is not resold commercially, and even if more detailled surveillance by a real human analyst only occurs when automated red flags are raised, and the system was designed to only allow the analyst access to the detailed data if enough or the right combination of red flags are raised there is a remaining problem…

This is: a) the longest comment I’ve ever read all the way through on HN b) an interesting anecdote but c) most likely a coincidence. I agree that the likelihood of such a thing happening is miniscule. However, I’ve had all sorts of strange postage-system-related issues in my time (granted, I’m in the US, which has likely a much worse system) and it doesn’t seem that far out to me that such a letter would have been m…

a) I didn't realize how long my post had gotten in the tiny entry box, until after I had posted it... but I will gladly accept the dubious Cup of "Longest readable HN comment in the Guinnes Book of Records"

b) Yes I also think it's very interesting. Initially before coming to these suspicions, I was pissed off about having to dissapoint my sister next time I see her, and the money that was lost buying the SIM card etc, ... but the longer I thought about it and noticed all the inconsistencies in what had happened, it's actually a nice puzzle/gift to receive! Turns out the journey really is the reward after all

c) I have also thought about possible mistakes, but really there is little that can go wrong with a strain gauge! And even if the strain gauge somehow broke, there would have been a long run of letters suddenly appearing for redirection, surely this would be noticed and the letters reweighted... And even if it is incorrectly marked with "insufficient postage" both the sorting which is supposed to redirect it to the return address, as the eventual post man who did not ring failed to see the return address! And with D+1, a delay of ~20 days is totally unheard of (counting up till Nov 7th when the strike was anounced)...

in my response to a sibling of your comment I describe we can simply dissolve a fresh prepaid SIM card to detect the presence of a possible RFID loop antenna

Re: Mobile customer location data is ending up in the hands of bounty hunters

#169
post #142

Earlier quoted context omitted.

Most other countries don't have our intractable political system; bondsman solve a problem, they let people get out of jail when the government is being absurd.

And do you think the bondsmen don’t have an incentive to keep the status quo? It’s a multi billion dollar industry which effectively taxes the poor. Make bounties illegal and it fill fall, once it falls the entire bail system in the US will have to be rethought as there isn’t a way to lock so many people up, more judges will release them until trial without setting a bail which they can already legally do and do so f…

Bounty hunters are not universal. For example, here in Oregon they are illegal.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#170
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

How about we start with not allowing people to legally kidnap individuals? I never understood the whole concept of “bounty hunters” in the US it’s not the Wild West anymore. The problem here is that “fugitive recovery” doesn’t need to meet any of the standards normal law enforcement does and unless they kill someone or injure bystanders there likely won’t be an investigation into their conduct and even if there is on…

> it’s not the Wild West anymore

They didn't get that memo. The mentality and folklore is that it still is. Laws, politics, government, privacy, policing, social mores, business and especially foreign policy all seem to retain the idea they are a frontier society blessed with Manifest Destiny. Their way, however flawed, is the only way etc etc.

Post reply on HN