Live data from Hacker News

New documents reveal scale of US Government’s cell phone location data tracking

aclu.org

251–260 of 327 posts

Re: New documents reveal scale of US Government’s cell phone location data tracking

#251
post #189

Earlier quoted context omitted.

Sincere question: what new steps would you recommend they take? The iOS location request prompt uses very clear language while allowing for granular access, and the granted permissions are easily reviewed in Settings. The App Store requires data usage disclosures, which are presented about as succinctly as possible. They could mandate that apps share absolutely no location data with any third party, but that would br…

One feature they could provide (but never will) is fake location data for apps that refuse to work without it. I remember way back when CyanogenMod was a thing even they refused to implement this.

AFAIK iOs Apps have to work without additional permissions, otherwise they get rejected.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#253
post #27

It's important everyone becomes educated about the fact that virtually every mobile app sells some part of your data that leads to some private company possessing the ability to draw a circle around your house on map and then detect all patterns of life without any PII. I don't think it's fair to pit this as a US gov't surveillance problem. It's true though - the Government missions involved, where this type of data…

I always get annoyed how these programmers can have a good sleep at night given what they have done. Note that blaming it on the marketing VP is not fair. If even 50 % employees have a thought this tracking can be stopped.

Listen to Jordan Peterson - especially Maps of Meaning lectures and/or book.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#254

I wish the apple privacy team would address this, otherwise what good are their privacy claims

Sincere question: what new steps would you recommend they take? The iOS location request prompt uses very clear language while allowing for granular access, and the granted permissions are easily reviewed in Settings. The App Store requires data usage disclosures, which are presented about as succinctly as possible. They could mandate that apps share absolutely no location data with any third party, but that would br…

> Are there mitigations they could provide that I’m missing?

Apple could start by stopping their constant tracking and uploading of MAC addresses around Apple devices.

That's right, even if your device has no telemetry whatsoever but has active WiFi / Bluetooth network scanning, Apple is still tracking you if someone close to you has an Apple device.

https://www.scss.tcd.ie/doug.leith/apple_google.pdf

> We investigate what data iOS on an iPhone shares with Apple and what data Google Android on a Pixel phone shares with Google. We find that even when minimally configured and the handset is idle both iOS and Google Android share data with Apple/Google on average every 4.5 mins. The phone IMEI, hardware serial number, SIM serial number and IMSI, handset phone number etc are shared with Apple and Google. Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this. When a SIM is inserted both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple together with their GPS location. Users have no opt out from this and currently there are few, if any, realistic options for preventing this data sharing.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#255

Earlier quoted context omitted.

You can make emergency calls without a SIM card. The phone identifies itself to the network (with IMEI), even if there is no SIM. The telcos, obviously, map IMEIs to SIMs. (Perhaps needless to say, but for basic operational purposes they have to quite efficiently triangulate your position, to know which cell tower to instruct your phone to use.) Having no SIM does not help you conceal your phone's location at all, on…

> I don't know if any location data might leak in airplane mode, but I would not be surprised if some did, for example, through NFC or Bluetooth. Not sure about NFC, but at least BT gets disabled in airplane mode.

Bluetooth stays enabled on iOS in airplane mode. You have to disable Bluetooth separately.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#256
post #153
post #101

The Feds have been buying consumer data for decades, this is far from new. This goes back to “junk mail”, pre internet. As usual the US congress sat by and did nothing, and in all likelihood, will continue to do nothing.

Agreed that this has been going on for years and Congress has done nothing to date. But ... The Fourth Amendment Is Not For Sale Act, sponsored by Senators Wyden and Paul, has a hearing tomorrow morning -- and may actually have decent chance to pass Congress this session. If you're in the US, EFF's "Tell Congress: The Fourth Amendment Is Not For Sale" page has a web form to encourage your representatives to support t…

But I don't want private companies having this data either (on me, or others). Since we're barrelling full-speed towards corporate feudalism, I see this act as deflating the motivation to fix the root cause of the issue, and ultimately doing more harm than good.

In this case (and many others), "the perfect is the enemy of the good" is inverted. Such as algorithmic suppression instead of censorship. Outright censorship would alert us that there is something wrong, mere suppression fools us into thinking the problem is minor.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#257
post #248

Earlier quoted context omitted.

> I don't know if any location data might leak in airplane mode, but I would not be surprised if some did, for example, through NFC or Bluetooth. Which is why hardware kill switches are the future (see Librem 5 and Pinephone).

The future of never happen. The worlds worst privacy offenders make/sell phones. Google. Samsung. Apple. Google, no need to explain. Samsung? All their apps, their keyboard, collect, collect collect. Apple? Walled garden of share data with Apple. And beyond this, for example on Samsung builds, the GPS daemon calls home(Qualcomm? looked into it a year ago...) to update agps data, but also... provide tracking info. Non…

Which is why we should support the ones I listed.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#259
post #27

It's important everyone becomes educated about the fact that virtually every mobile app sells some part of your data that leads to some private company possessing the ability to draw a circle around your house on map and then detect all patterns of life without any PII. I don't think it's fair to pit this as a US gov't surveillance problem. It's true though - the Government missions involved, where this type of data…

I always get annoyed how these programmers can have a good sleep at night given what they have done. Note that blaming it on the marketing VP is not fair. If even 50 % employees have a thought this tracking can be stopped.

I don’t find it is generally one programmer enabling it. Decimation of privacy often occurs slowly at most orgs. One exception at a time. One “critical” temporary need on top of another. Often in different teams. The person who built the UI didn’t build the GPS modules. The person who built the GPS module didn’t build the data store. The person who built the data store didn’t deal with report exports. And that person didn’t deal with their privacy and compliance policies- or sales pipeline. Lots of people wanting to say yes and do a good job. Often leadership is caught up chasing a dollar

Re: New documents reveal scale of US Government’s cell phone location data tracking

#260
post #228

Earlier quoted context omitted.

the programmers sleep at night because doing this is the only thing that lets them feed there families. like it or not, there are always people who will see this as the lesser evil because of their personal circumstances don't give them other options.

I'd agree if we were talking about low-skill work where people are just scraping by. Programmers have the luxury of choosing from a wide range of places to work. We're all in a position where we can refuse work we find unethical, even if it means taking a pay cut.

Yes, but… I’ve seen that it is often just shades of bad. There are so few morally pure companies out there- they are all willing to do bad things for money. Or the vast majority of them. And it is hard to evaluate that upfront. Even the most virtuous will bend privacy for the right stakeholders

I should go work for Google? Because they clearly value privacy?…

Post reply on HN