Live data from Hacker News

US and UK spy agencies scoop up private data from 'leaky' phone apps

theguardian.com

31–40 of 98 posts

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#31
post #4

There ought to be more emphasis that these documents are circa 07/08. HTTPS websites were an oddity back then.

Indeed! 2008 is 5+ years ago. 5 years in tech is a couple of eternities.

On both sides. You should assume they have broader and deeper capabilities now.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#33

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

I find the two green slides (Capability - iPhone and Capability - Android) the scariest. Hot mic? Kernel stealth? And self protection? How many networks - knowingly or unknowingly - are delivering these things?

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#34

One slide from a May 2010 NSA presentation on getting data from smartphones – breathlessly titled "Golden Nugget!" – sets out the agency's "perfect scenario": "Target uploading photo to a social media site taken with a mobile device. What can we get?" To me, this is quite telling. The NSA is not considering what data they need to achieve their mission, and then trying to find that data. Instead, they're just looking…

Why not? It is technically feasible. There was essentially no legal oversight at NSA or GCHQ.

It seems like they responded correctly to the incentives they were given. The problem is with the legislature (and the judiciary), voters, and the media.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#35

Curious, how many app devs are doing security/permissions audits? On Android java side we have a tool called: sable/soot Which I am recently learning to use..

You mean this: https://github.com/Sable/soot ?

> Soot is a Java optimization framework

Seems to be a Java static analysis tool and not related to Android permissions (although maybe related to security).

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#36

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

That was in 2008. Imagine what else they've been able to jimmy in 6 years! I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.

> I'm still waiting on the reveal that they've stored geolocational data at regular timepoints of every X minutes.

Considering Apple did that on your behalf I would be surprised if this was not the case.

http://bits.blogs.nytimes.com/2011/04/20/3g-apple-ios-device...

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#37

So they're spying on the children playing Angry Birds in the name of preventing terrorism. I bet the data they're gathering has saved a lot of lives. This is just one more strike into the already well-beaten dead horse of an argument that the NSA is spying in the name of preventing terrorism. I will spell it out: the goal of the NSA surveillance is omniscience in the name of preserving the power of the state. They ha…

What about leaking bookmarks from Al-Quran app?

Still a ridiculous unneeded incursion onto an individual's right to be left alone when they aren't hurting anyone.

As violent and primitive as the Islamic fundamentalists are, the vast, vast, vast majority of the world's 1.6 billion Muslims are not fundamentalists, nor are they terrorists, nor do they aid terrorists.

The phrases that people bookmark in a religious app book are a very far cry from demonstrable intent to commit violence, anyway. If you spied on everyone's bookmarks in religious text apps, I'm fairly certain that if you pitched it properly you could depict my own gentle mother as a genocidal crusader.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#38
post #8

The only solution is to move to a phone OS that is 100%, completely, open. I.e. Not even apps developers are allowed to ship blobs - its All-Source-Code, All-The-Time. I know, its a highly unlikely scenario, but I can't help but feel in the midst of this human rights disaster, Open Source can come to the rescue.

The baseband is the problem. It leaves even a 100% open source OS quite vulnerable.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#39
post #17
post #6

Ridiculous,seems like they are taking data and storing it and waiting to get subpoenas to look into and analyze the data later. Welcome to the new world order where your every movement is known.

Don't be alarmed citizen. They only 'know' about your movements if they actually look at them. Until then, they don't 'know' anything as long as it sits in their archives untouched.

It's a bit more Orwellian than that. The NSA claims it doesn't "collect" data until it looks at the data. Somehow the data magically appears in its databases, but it isn't collected.

Re: US and UK spy agencies scoop up private data from 'leaky' phone apps

#40
post #12

Many interesting "nuggets" buried in this report. For example: ...A more sophisticated effort, though, relied on intercepting Google Maps queries made on smartphones, and using them to collect large volumes of location information. So successful was this effort that one 2008 document noted that "[i]t effectively means that anyone using Google Maps on a smartphone is working in support of a GCHQ system." At this point…

Maps and other apps on the iPhone weren't using HTTPS in 08 (underpowered device, need to squeeze every last drop from battery). They do now however. It's not just a spy agency issue, anyone could have sniffed the unencrypted traffic.

(underpowered device, need to squeeze every last drop from battery)

Really now? Is that the official reasoning for not using HTTPS?

Post reply on HN