Live data from Hacker News

Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

oig.justice.gov

31–40 of 99 posts

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#31

Earlier quoted context omitted.

Yea I sometimes get a feeling that a large portion of the population just doesn’t understand conditionals. If you tell them “you have the authority to do X if Y”, they just ignore the Y part.

People who are drunk on power subscribe to the "ask for forgiveness, not permission" philosophy. They think everything they do is right and just. They cannot understand or even believe people would not trust them and see the conditional as a pointless hindrance, bureaucratic red tape meant to stifle upstanding people like them.

People love to wield power over those they oppose and don't care if the system they implement is abused until they're the targets of the abuse.

For example: most people love the police when they coercing wealth from strangers to fund their projects but hate when the same police step on their chest until they stop breathing during a traffic stop.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#32

It sounds like this was a piece of software where you uploaded a PDF of “proof” that you had the authority to track anyone in America, and then it let you. And someone finally bothered to look at the proof and it was a blank page. This is why I’m against giving the government the power to intercept communications or middle-man encryption. They always pitch it like “This power will be protected by courts and warrants…

See also LOVEINT. Every once in a while, some NSA spy gets caught spying on their loved ones. Not even incompetence, just plain malice and abuse. Looks like they don't even face any criminal charges either. Governments are essentially adversaries, enemies we have to defend against. It must be mathematically impossible for them to abuse their power. Anything short of that is not enough.

> Anything short of that is not enough.

I like that in spirit, but not as a practical standard. A major function of government is to prevent abuses of power. So I'm more inclined to shoot for overall minimization of abuse.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#33
post #23

It's disturbing how much this information is sold and resold: * Securus purchased the location data from 3Cinteractive Corporation, which was located in Boca Raton, Florida. * 3Cinteractive Corporation, in turn, purchased such data from Technocom Corporation (doing business as LocationSmart), which was located in Carlsbad, California. * Technocom Corporation (doing business as LocationSmart) purchased this data direc…

The cellphone companies have been selling the realtime location of all subscribers since at least 2018. It doesn't depend on whether you have location enabled either, since it figures out your location from the towers! On top of that, one of them had an unauthenticated API, meaning anyone in the world could track the realtime location of any US phone #[0]. If all of this bothers you, contact your state legislators. M…

> It doesn't depend on whether you have location enabled

It's even better: the location can be enabled through a network initiated request. This is because A-GPS works "both ways". See https://en.wikipedia.org/wiki/Assisted_GNSS#SUPL : SUPL Position Calculation Function (SPCF) lets the client or the server ask for the client’s location.

As part of the FCC’s updated 911 requirements, where cell phones (with no set location) are required to be routed to the correct 911 center, aGPS was developed to not only help GPS get a faster TTFF (time to first fix), but to transmit location data to the carrier (and to anyone else who can intercept the data)

> If all of this bothers you, contact your state legislators

If you don't like that and want a quick fix, on android devices check /data/vendor/agps_supl/agps_profiles_conf2.xml for ni_request="true": this is the Network-Induced Location Request functionality, where the network asks for the GPS position. Change that to false.

Personally, I believe 911 AGPS is of limited use: if I'm unconscious and can't dial, the phone 911 AGPS working won't do me any good. If I'm conscious and I can dial, I can also open a map app.

Still, if you want to keep the 911 stuff, just change reject_non911_nilr_enable="false" to true (because yes, by default, everything goes - 911 or not)

There's also lpp_enable="true" (LTE Positioning Protocol, yet another method by which cellular providers can pinpoint your location via aGP S), imsi_enable="true" (which transmit a unique identifier along with the AGPS request!)

Check also /data/vendor/agps_supl/agps_profiles_conf2_prv.xml

Or even better: don't use a phone. I have a 5G/LTE module in my laptop when I need internet connectivity: it's turned off the rest of the time (rfkill block wwan). You can also disable the power to this M2 port (saving battery if you care about that)

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#34

It's disturbing how much this information is sold and resold: * Securus purchased the location data from 3Cinteractive Corporation, which was located in Boca Raton, Florida. * 3Cinteractive Corporation, in turn, purchased such data from Technocom Corporation (doing business as LocationSmart), which was located in Carlsbad, California. * Technocom Corporation (doing business as LocationSmart) purchased this data direc…

this reads like a supply chain of a drug cartel

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#35

It sounds like this was a piece of software where you uploaded a PDF of “proof” that you had the authority to track anyone in America, and then it let you. And someone finally bothered to look at the proof and it was a blank page. This is why I’m against giving the government the power to intercept communications or middle-man encryption. They always pitch it like “This power will be protected by courts and warrants…

See also LOVEINT. Every once in a while, some NSA spy gets caught spying on their loved ones. Not even incompetence, just plain malice and abuse. Looks like they don't even face any criminal charges either. Governments are essentially adversaries, enemies we have to defend against. It must be mathematically impossible for them to abuse their power. Anything short of that is not enough.

That's just impossible. Even if everyone had perfect e2e encryption, the government could just ban it and throw people who use it in jail.

You can't solve social problems with technology.

What is necessary is a governmental system which tends away from the abuse of power. This requires better voting, more transparency, and the literacy and engagement of its citizens.

The problem is, just like in Conway's game of life, the current system's state informs what states it'll progress to. If a system tends toward corruption or abuse and isn't actively changed, well eventually it no longer will be possible to change.

https://xkcd.com/538

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#36
post #14

Earlier quoted context omitted.

Yea I sometimes get a feeling that a large portion of the population just doesn’t understand conditionals. If you tell them “you have the authority to do X if Y”, they just ignore the Y part.

It's not about understanding, it's about seeing these sort of rules bent dozens of times first and then finally doing it yourself. Rules are only as strong as their enforcement and in many cases it turns out that no-one has neither the incentive nor the ability to enforce them very hard.

After some bantering with Swedish police officers on Twitter I’ve come to believe that many of them simply do not make a distinction between what they have the authority to do, and what they can get away with in practice.

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#38

Earlier quoted context omitted.

I don’t understand your question. Your telecom provider has your PII.

I’d like a definitive list which contains the source for each piece of data, the means that source acquired it, when they acquired it, and proof of my consent for it to be collected, stored, and sold to other parties who then sell it off to the highest bidder. “It came from teleco companies” is not due diligence enough for me, and it shouldn’t be for you. That answer isn’t an answer and the lack of accountability is…

Your cell phone company knows your name, address, and can infer where you've been based on the cell towers your phone checks in with. So that one's a given.

Here's a sampling of others:

Mastercard sells information on your purchases.[^1] (Based on the info Oracle had on me, I suspect they might be one of the sources for Oracle Advertising.[^2])

Equifax, who gets information from your bank, your car insurance company, your cable company, and loads of other places, makes a nice profit off selling your info.[^3][^4]

ISPs know who you are, can infer a lot about you from unencrypted DNS queries and HTTPS SNI snooping, and they're happy to sell information about you.[^5]

Then there are several tiers of companies that buy information from various other companies, aggregate it, and then sell that off. A veritable snowball rolling down a hill of privacy violation.

[1]: https://www.wired.com/2012/10/mastercard-data-mining-holiday...

[2]: https://datacloudoptout.oracle.com/request-your-data/verify-...

[3]: https://www.inc.com/associated-press/equifax-data-money.html

[4]: https://www.equifax.com/about-equifax/why-equifax/differenti...

[5]: https://www.vice.com/en/article/93b9nv/internet-service-prov...

Re: Deputy US Marshal pleads guilty to obtaining cell phone location unlawfully [pdf]

#40

Earlier quoted context omitted.

See also LOVEINT. Every once in a while, some NSA spy gets caught spying on their loved ones. Not even incompetence, just plain malice and abuse. Looks like they don't even face any criminal charges either. Governments are essentially adversaries, enemies we have to defend against. It must be mathematically impossible for them to abuse their power. Anything short of that is not enough.

That's just impossible. Even if everyone had perfect e2e encryption, the government could just ban it and throw people who use it in jail. You can't solve social problems with technology. What is necessary is a governmental system which tends away from the abuse of power. This requires better voting, more transparency, and the literacy and engagement of its citizens. The problem is, just like in Conway's game of life…

That's why you use a constitution strong enough to prevent the government from having authority to ban a tool like that. The solution's been known and described for 250+ years now.
Post reply on HN