Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

231–240 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#231
post #209
post #202

Earlier quoted context omitted.

For the same reason a photo take of you in a public place isn't yours, it belongs to the photographer. The Internet is a public space; you don't own the public space and you don't have any right or authority to tell anyone collecting public data that you own it just because you're in it. It's not your data, it's my data, I collected it. You don't want it collected, don't go spewing it out in public spaces.

You have a point, but the problem is that there's no way to not spew data out in public spaces. I'd have to cut off all of the following: - my mobile phone - my landline phone - all credit cards and bank accounts - all hosted email solutions - all other hosted ways of communication (social media, messaging apps) - all ways of transport unless I own the devices (and even some cars you could own have telemetry these da…

Hey, that's the price of using all of those things, if you don't want to pay that price; don't. You don't own a photo I take of you nor do you own data I collect about you from the public sphere.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#232

Earlier quoted context omitted.

I am saying I believe the creditcard-sized card that contains a fresh prepaid SIM card, probably contains an RFID loop antenna. This is trivial to verify or falsify, just buy some acetone in the hardware store: https://learn.adafruit.com/rfid-iphone/dissolve-the-card I already bought the acetone, but I did not yet dissolve the SIM card, I want to do this in front of my sister, so she understands why I attach importan…

http://www.dslreports.com/forum/r28362704-RFID-sim-cards-goo... https://patents.google.com/patent/US7784693B2 Neat read, and Godspeed. Not sure whether your theories on there actually being an infrastructure for doing these sorts of things is correct, but even a 5 minute google search seems to suggest it is well within technical capabilities to do so. Might do some more searching for ISO's and other Engineering stand…

>Not sure whether your theories on there actually being an infrastructure for doing these sorts of things is correct, but even a 5 minute google search seems to suggest it is well within technical capabilities to do so.

The infrastructure would just be an (perhaps surveillance grade) RFID reader and a small office or locker where the suspect letters end up at each post sorting facility, so a security officer or perhaps just the branch manager can store these until the surveillance state replies what to do with the letter.

I also believe it is probable the standards are visible somewhere, just like I remember the bulk of the surveillance state in Europe was/is visible pre-snowden in very high detail through the ETSI (european technology and standards institute) standards.

> I doubt that the RFID is in the plastic containg the card, it's probably in the card itself.

I may have used the incorrect word with "contain", so first the SIM card and the PIN and PUK card are one and the same card, before breaking out the SIM card. I mereley suspect the larger PIN/PUK card to contain the RFID coil, because the perforated C-shape around the SIM has the open part of the C directed at the closest edge. Of course it is possible that the RFID coil is in the smaller piece of SIM card itself, but I don't think so because: the contact pads would provide shielding to the coil, and to have the same total area as a 4 turns in a Credit Card size, the coil would need many more loops. As a designer I would prefer putting the RFID loop in the larger card.

So I did not mean to say that the coil is in the plastic wrap or anything, in case that was how you understood me.

It may seem weird that (if I am right) the surveillance state designed the SIM cards so the connection with the RFID coil breaks, why not design it monolithically such that you can also track used SIM cards in the mail? I simply predict that there is demand for clean SIM cards on the market, and unopened prepaid packages are considered clean, but then the coil is not broken yet... so used SIM card's may turn out safer (if the previous usage was clean)...

I agree the holding times would be roughly reproducible, but I don't want to cram my file full of red flags...

Yeah, spying involves lots of deceit, and as everyone (hopefully) rememmbers from kindergarten, the web of lies only grows (and the observable inconsistencies grow with them)

If it hadn't been stalled, I would probably have ended up calling some friends from university time, probably only spent 2/3's of the call credit before it expires, then simply went on with my life. It's their reckless tradecraft that betrayed them. I have no problem talking openly about what I suspect, I am pretty sure plenty of actual criminals have noticed this before me, but they probably don't talk about it in public fora...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#233
post #221

Earlier quoted context omitted.

Bail is a common mechanism outside of US too.

Depositing money as part of bail is only really a practice in the U.S. and Philippines. https://www.politifact.com/california/statements/2018/oct/09... > "Only Duterte’s Philippines and Trump’s United States of America have money bail."

Canada has bail too. In recent news

https://www.cbc.ca/news/canada/british-columbia/huawei-meng-...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#234
post #19
post #9

It would appear that sometimes even paying for the service doesn’t mean you won’t end up as the product anyway. How can one avoid this kind of aggregated location tracking?

As long as you want to receive calls, the cell service provider will know your approximate location. If you have wifi available, you can mitigate this by only using a voip/messaging service like jmp.chat. You'll still be unavailable while on the road, though. If you have tons of money, satphone is always an option.

There's nothing wrong with a cell phone provider collecting aggregate information on where their subscribers are on their network. Its reasonable for them to do so, as it helps them analyze how to properly prioritize network upgrades (where to build towers, add capacity, etc.) It is not reasonable for them to sell individualized data to anyone and everyone who feels like tossing them a few hundred bucks.

Its reasonable that a hospital would know a good deal about me. They'll know current diagnoses, previous diagnoses, medications, probably some generalized family medical history, extensive identification numbers, etc. Its important for them to be able to have this data for them to do their job of healing me. However, its unreasonable for them to then just sell this data on the open market. That's why we passed HIPAA/HITECH.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#235

Earlier quoted context omitted.

Depositing money as part of bail is only really a practice in the U.S. and Philippines. https://www.politifact.com/california/statements/2018/oct/09... > "Only Duterte’s Philippines and Trump’s United States of America have money bail."

Canada has bail too. In recent news https://www.cbc.ca/news/canada/british-columbia/huawei-meng-...

It’s not about the amount of bail but rather the price of a bond.

If the bond costs 10% then you can’t pay bail if it’s set to 10 million or even a million or even lower for most people, if it’s capped at say $100 something that even some US states do then it’s not as much of a problem.

If you look at the US bondsman industry it’s focused on the states not with the highest average bail set but those with the highest prices on bail bonds.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#236

Earlier quoted context omitted.

http://www.dslreports.com/forum/r28362704-RFID-sim-cards-goo... https://patents.google.com/patent/US7784693B2 Neat read, and Godspeed. Not sure whether your theories on there actually being an infrastructure for doing these sorts of things is correct, but even a 5 minute google search seems to suggest it is well within technical capabilities to do so. Might do some more searching for ISO's and other Engineering stand…

>Not sure whether your theories on there actually being an infrastructure for doing these sorts of things is correct, but even a 5 minute google search seems to suggest it is well within technical capabilities to do so. The infrastructure would just be an (perhaps surveillance grade) RFID reader and a small office or locker where the suspect letters end up at each post sorting facility, so a security officer or perha…

Oh,no worries. I just think that SIM and handset manufacturer's are going the route of integrating NFC into handsets to support SIM stored payment credentials. I know for a fact it's a hot item in the FinTech industry.

Odds are, you could get a generic reader to get a chirp out of an RFID even without the PIN/PUK card that wouldn't be present in any other package.

IF I were an evil surveillance state taking an interest in mail borne SIM cards in ANY state (I mean think about this, if you could automate it, figuring out the networks of people who often send SIM's to each other in and of itself is a useful data point) I'd exploit using a small machine that can be innocuously placed on the sorting line to get that chirp.

Biggest problem I imagine would be possible tipping off through damage caused to EMF/RF sensitive packages, but I've not really looked up the math or engineering involved enough to make an educated guess.

Like I said. Interesting problem, and I seriously hope you're not right. That's levels of cyberpunk dystopia that just shouldn't be possible in anything remotely resembling a healthy society.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#237
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

Even if the subject had legal ownership and control over their cellular location data, they would certainly have to sign it over to the bondsman. Just like you sign over the right to hunt you down and physically capture you (which could otherwise be grounds for a lawsuit against the bounty hunter).

Re: Mobile customer location data is ending up in the hands of bounty hunters

#238
post #72
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

The subject’s location is necessary for the performance of the bond. As long as it’s clearly disclosed, there should be no problem signing over those rights as part of the contract. If there is, the bondsman can just make you wear a tracking anklet.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#239
post #119
post #100

Earlier quoted context omitted.

> anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? Yes. The Netherlands, carrier is called Youfone. They have very, very little data on me: they claim not to be able to see which cell tower I'm even connected to (which would be tracking info), which makes me wonder how they even provide their service. They say it's all outsourced to third parties, one of w…

Thanks, I'll look out for that. @tapland and @jgibson also mention that mobile networks often outsource running the infra. In any case - I agree with you that this seems like a shitty legal pseudo-loophole. At the very least the company you sign mobile contract with needs to share your phone number with those infra subsidies. But then according to GDPR: "15. 1. The data subject shall have the right to (...) access to…

Yeah, I read the same clause. The crux is this:

> or categories of recipient to whom the personal data have been or will be disclosed

They provided that by saying it's for network operators.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#240
post #227
post #191

Earlier quoted context omitted.

The GDPR doesn't apply to "roaming European users."

What's your reasoning for this assertion? If the user is a European citizen, I was under the impression that GDPR was applicable. The location at which the user is at does not matter one iota. US companies need to understand this, or risk losing trading abilities with citizens and organisations in EU member states.

No, Youre wrong, citizenship doesn't matter, the application dependeds on physical location. If youre an American in Europe the GDPR applies to you, if youre a European in America the GDPR does not

https://www.compliancejunction.com/does-gdpr-apply-to-eu-cit...

https://ec.europa.eu/info/law/law-topic/data-protection/refo...

Post reply on HN