Live data from Hacker News

New documents reveal scale of US Government’s cell phone location data tracking

aclu.org

271–280 of 327 posts

Re: New documents reveal scale of US Government’s cell phone location data tracking

#271

I wish the apple privacy team would address this, otherwise what good are their privacy claims

Depends on your threat model. I don't include state actors in mine, they can employ $5 hammers just as easily as crypto breakers

This is a common false dichotomy. Border agents and random highway stops are done by state actors. Vanishingly small slice of them are james bond-esque high stakes games.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#272
post #163

Fellow humans, there are alternatives to being tracked via cell phone! Your neck need not be under anyone's boot! You don't even need to give up any functionality: Data service: The simplest thing is to buy a prepaid SIM and top it off with cash. The lovely people over at /r/nocontract maintain a big spreadsheet so you can filter by various properties of the available contracts. Another way to go is to pay for a post…

AT&T is able to tell when you activate your prepaid phone what other phones are nearby. Drug dealers have been unmasked using this. They thought they did everything right but someone had a normal phone plan near their phone as it was activated and then the pre-paid phones were around those with regular plan phones. Unmasking the whole group. The best way is buy the prepaid phone from a 7/11 type store. Wait 6 months,…

Do you have a cite or know the specific technology? If they do this using 4G it wouldn't be too accurate. Are they somehow turning on Bluetooth or something?

Re: New documents reveal scale of US Government’s cell phone location data tracking

#273
post #230

Every person, living and dead, has been uniquely identified and is tracked in near real time. Source: I read the news, don't suffer from amnesia or willful ignorance. We used Seisent (since bought by LexisNexus) in the mid-aughts. At the time, every person in North America was accounted for, with pretty good coverage of the Caribbean and Central America. The NSA bought a few clusters, then wove in their own datasets…

South Korea used to require that people log in with their government ID to websites. Through an ActiveX control, even. I believe they eventually gave up on this level of direct tracking. > We could, trivially, resolve all the policy food fights .. flash points into simple database queries. The flashpoint is that people don't want to be queryable. You can't wish that problem away.

The great irony is that actual privacy requires unique identifiers, like RealID or equiv.

GUIDs unlock the Translucent Databases achievement, actual per field encryption of PII data at rest. TLDR, clever applications of salting and hashing, just like with proper password storage. https://www.amazon.com/Translucent-Databases-Peter-Wayner/dp... http://wayner.org/node/46

I was utterly against RealID, until I figured this out. Much chagrin. Super embarrassing.

Source: Worked on both electronic medical records and protecting voter privacy. Did a translucent database POC for medical records, back in the day.

If there's another technical solution, I haven't found it.

But I think to your point, people generally don't want the sensitive data being collected in the first place. I don't have an answer for that.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#274

These are the engineers and PM types that have know this for years: - security engineering - privacy engineering - digital marketing - data science Maybe the first two did a vocal but bad job raising the flag due to how antagonistic some of that dialogue goes. But to this whole post acting surprised - look around at what you work on and who with, and what you’re paid for doing it. Be the change you want to see, but p…

I absolutely hate when people respond to these kind of articles with "Why are people surprised". The truth is that no one is surprised. People are more disappointed, and frustrated, that this is allowed to happen, not just from a legal sense, but in a technical sense also.

People are surprised in this thread. The truth is I run into engineers who are oblivious to this, perhaps deliberately so. Accountability for this starts with the teams building these products and choosing what to/to not include as data.

Or; what I absolutely hate is engineers outside of privacy/security acting frustrated, while collecting checks on the back of this data. Like that group of ex-Facebook Trust and Safety that founded that ludicrous and smug user protection group in Boston based on their experiences at Facebook.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#275
post #27

It's important everyone becomes educated about the fact that virtually every mobile app sells some part of your data that leads to some private company possessing the ability to draw a circle around your house on map and then detect all patterns of life without any PII. I don't think it's fair to pit this as a US gov't surveillance problem. It's true though - the Government missions involved, where this type of data…

These sorts of things are compartmentalized. The FBI, ICE and DEA absolutely do scaled collection. DEA/ICE was known (ie NY Times article) to be tracking cars via LPR/camera a decade ago up and down I95, for example. Individual cities and other jurisdictions share LPR and camera data. Things like fusion centers and drug task forces probably get access to various forms of intel. Civilian government is different - they…

> usually take data protection seriously

Do we need to list the number of government data breaches/leaks over the past 20 years? My own PII has been in several.

They may take it seriously, but their actual track record isn't really that great.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#276
post #246

Earlier quoted context omitted.

Lol if you believe them… Burr regardless, the point was government has it. It’s also safe to assume 3rd party apps track it and capture the same data. Which can then be purchased.

Well selling that data is completely against their business model! For example Google's entire revenue model is based on the idea you give them money and ads to show and they choose where best to show that. If they sold the raw data it would undermine that. Basically no amount of money would be enough for Google to give away their entire business.

I'm sure they would be happy to sell data provided the person purchasing the data would not be in the ad space.

For example, if the government says, "here's $10B dollars / year" give us that data and we wont use it in ads. Google doesn't have a business incentive not to provide it the data.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#277
post #27

It's important everyone becomes educated about the fact that virtually every mobile app sells some part of your data that leads to some private company possessing the ability to draw a circle around your house on map and then detect all patterns of life without any PII. I don't think it's fair to pit this as a US gov't surveillance problem. It's true though - the Government missions involved, where this type of data…

No post body was provided.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#278

Every person, living and dead, has been uniquely identified and is tracked in near real time. Source: I read the news, don't suffer from amnesia or willful ignorance. We used Seisent (since bought by LexisNexus) in the mid-aughts. At the time, every person in North America was accounted for, with pretty good coverage of the Caribbean and Central America. The NSA bought a few clusters, then wove in their own datasets…

All great points. >We could, trivially, outright stop all anonymous trolling and disinformation. Purveyors of social media don't authenticate their users because they don't want to. Their business models require that they remain willfully ignorant. Yes well what argument would you make, if you could or would, to change the current landscape?

Since you asked...

Social (popular) medias all eventually implode. Lifecycle maturity models and all that. Seems to me that Facebook and Twitter are well into the top of their S-curves. (I can't speak to TikTok.)

If I wanted to accelerate their demise, I'd attack their revenue. Like pop the digital advertising bubble. Congressional and criminal investigations into digital ad fraud would mosdef do the trick.

--

If we could go back in time, perhaps lessons for whatever comes next, I'd advocate three general categories of reforms.

1) All the "well duh" stuff that Sen Mark Warner et al advocate. Here's the PR for SAFE TECH Act and Warner's white paper.

https://www.warner.senate.gov/public/index.cfm/2021/2/warner...

https://www.warner.senate.gov/public/_cache/files/d/3/d32c2f...

And a layperson's summary:

https://diginomica.com/sen-mark-warners-15-common-sense-rule...

I particularly like clearly identifying bots. Some are authentic, legit activity. So not an outright ban of bots.

"Media literacy" is quixotic; I guess they want to say they tried.

I want to know more about "information fiduciaries"; see #3 below.

2) Nerf the algorithms, squelching instead of boosting viral content. Addressed by section 1.4 of this commission's recommendations. (Which also has a lot of "well duh" general purpose civil society stuff.)

https://www.bbc.com/news/technology-54901083

https://informationdemocracy.org/wp-content/uploads/2020/11/...

3) Most radically: Individual property rights over personal data. My data is me. If someone is using my data in some economic way, I want my cut. This nicely dovetails (necessitates) the misc proposals of treating aggregated data as a liability, instead of as an asset. Which would totally flip the current script for investors, regulators, insurers, etc.

I've tried to understand the opposition to "personal data sovereignty" -- just came up with that, clever!, because I don't know what else to call it. I dimly recall some "privacy experts" in California concern trolling that state's initiatives. I think their reasoning was something like "we can't put a price on personal data because that'd encourage more collection". Um. Okay. Felt very cassandra, unattached to our reality. So a philosophical rather than a practical opposition, I suppose.

FWIW, talking about this stuff is really hard. My "pay me for using my data" proposal doesn't make sense unless the audience already understands the current ecosystem.

As I've said elsewhere, I worked on electronic medical records information exchanges. Our startup was bought by a national laboratory (Quest Diagnostics). I sat in various meetings and calls, with PHBs, lawyers, and other goons, brainstorming ways to further monetize medical records.

Back in the mid-aughts, every single participant (doctors, hospitals, labs, scripts, insurers, pharma) absolutely considered patient data as "theirs". And our potential partners like Google Health and Microsoft HealthVault and Cerner and EPIC were all hellbound in trying to figure out how to monetize it.

It was absolutely disgusting.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#279

Earlier quoted context omitted.

> I don't know if any location data might leak in airplane mode, but I would not be surprised if some did, for example, through NFC or Bluetooth. Not sure about NFC, but at least BT gets disabled in airplane mode.

Bluetooth stays enabled on iOS in airplane mode. You have to disable Bluetooth separately.

Weird choice for a "stop all radios" toggle to not stop a certain radio.

Re: New documents reveal scale of US Government’s cell phone location data tracking

#280
post #261
post #196

Earlier quoted context omitted.

I’ve just given up on the federal government. It stopped working for common people in any meaningful way a long time ago. State and local, sure, but federal? Why bother.

It is what you put into it? I won't get into detail but it is hard and thankless. Writing off all the public sector in the US is writing off the private sector BC of bad actors like the data marketers. Should we write them off entirely?

Yes.
Post reply on HN