Throwaway account. I work in location / mapping / geo. Some of us have been waiting for this to blow (which it hasn't yet). The public has zero idea how much personal location data is available. It's not just your cell carrier. Your cell phone chip manufacturer, GPS chip manufacturer, phone manufacturer and then pretty much anyone on the installed OS (android crapware) is getting a copy of your location data. Usually…
I'm in the space as well. I've tried telling my congressmen but they ignore me. I'm waiting for the backlash, especially will all the recent privacy issues. It hasn't happened yet and the problem is so large that I honestly doubt whether the public will ever truly grasp what the scope. The advice I always give when this topic comes up us to be very careful with what you install on your phone. The least expensive mobi…
US cell carriers are selling access to real-time phone location data
311–320 of 648 posts
Re: US cell carriers are selling access to real-time phone location data
#312I am starting to wonder what all have I consented to? Every week I learn I have consented to this and that because of a news article as I never read those contracts or TOS. I wonder if there will be a way to phrase long contracts into bullet list of ideas for someone simple minded like me in the near future.
TOSBack, the gitified version (https://tosback.org)
A new version of ToS;DR is also in development: https://github.com/tosdr/phoenix
Re: US cell carriers are selling access to real-time phone location data
#313Earlier quoted context omitted.
I can confirm this is happening, I designed some of the analysis systems used. Contrary to what many people assume, this is not just a US thing. It is done throughout the industrialized world to varying degrees, including countries where most people believe privacy protections disallow such activity. Governments tacitly support it because they've found these capabilities immensely useful for their own purposes.
> for their own purposes Such as? If this also happens in the EU and is as blatant as you say it is and with GDPR and all, surely this is just waiting to blow up?
Re: US cell carriers are selling access to real-time phone location data
#314Earlier quoted context omitted.
If you really wanted to do this, a more secure approach is onion routing. It's essentially the same problem -- attempting to preserve anonymity in the face of adversarial network hardware, while being limited by a requirement to enter / exit through certain nodes. So you'd want a mesh network, formed adhoc out of currently in range cellular device neighbors, with packets re-encapsulated and encrypted at each hop, eve…
Oh yeah, that's an interesting solution. I'm not sure simultaneous authorization and anonymization is impossible. Couldn't you use something like Chaum's e-cash to obtain tokens that guarantee the holder the right to use the network for some amount of data, but these tokens are tradeable and therefore the spender doesn't have to be the same as the buyer. Then you could spend this token in the network to get access an…
And it wouldn't play well with billing accounts being deactivated / reactivated.
And... now that I think about it, given the tower:location mapping, you'd also have to include bouncing traffic back out to a non-tower-sharing peer and then back into their tower w/ randomized timing, else outer layers of encapsulation would still identify tower association.
Which means latency would be utter crap.
Re: US cell carriers are selling access to real-time phone location data
#315Earlier quoted context omitted.
This is a problem with the GSM/UMTS standards themselves. Carriers always know where you are, but one could create a standard where they wouldn't have to know unless you make a call. With enough encryption and effort, I'm pretty sure one could even create a standard where carriers would never know where you are, even while you are using services.
They have to know your location if you want to receive a call.
Page messages are in-the clear, but that's fixable by (gasp) OTP.
Re: US cell carriers are selling access to real-time phone location data
#316One of these days, most of you will finally understand just how right RMS was and is... It's just a shame so many can't see it, and worse, give those of us who do shit.
Re: US cell carriers are selling access to real-time phone location data
#317Earlier quoted context omitted.
Any source for this claim?
The general public and repeatedly-reported-upon understanding of how data collection can be leveraged to find unexpected insights not obvious from the data, coupled with the Snowden leaks, coupled with the ever-increasing user count for cellphones, Facebook, Twitter, and the Internet in general. If people were deeply individually concerned about the risks vs. rewards of these technologies, they'd stop using them. Tha…
Re: US cell carriers are selling access to real-time phone location data
#318Earlier quoted context omitted.
What about a decentralized networks over 802.11? It wouldn’t be a total solution, because access points get hacked, etc. but it would make the data a lot fuzzier.
The reason that cell phone networks actually work (they're effectively decentralized networks) is that they pay the big bucks to rent space on high towers, building roofs, etc. The only thing that matters for radio communications is line of sight. The only thing that gives you line of sight is relative height. The only thing that gives you consistent height is money.
Or long rope, a balloon, and a heat source ;)
Re: US cell carriers are selling access to real-time phone location data
#319Earlier quoted context omitted.
Banning things works relatively well for people because they fear having trouble with law and justice. Doesn't work that well for corporations whose law department is just like any other department. In this case you must assume that if it's technically possible then it's done.
This argument can be used against any law, like antitrust law. Having a law department doesn't give you a free pass to break laws.
It then becomes a cost/benefit analysis weighing the likelihood of getting caught * cost of potential fine vs business value of ignoring the law. Ignoring the law is frequently the correct decision.
Re: US cell carriers are selling access to real-time phone location data
#320Earlier quoted context omitted.
Do you get that data before you place the bid? Can you can just bid the minimum amount so you never actually buy an ad, but get the tracking data anyway?
You get all the data (geo, user's year-of-birth, user interests, device type, etc) before you place the bid. All the json data fields are defined in the standard. I can see iOS and Windows-phone in the feed, it's not limited to Android phones. https://www.iab.com/wp-content/uploads/2015/05/OpenRTB_API_S... You don't actually have to bid. (HN is rate-limiting me) edit: Data is pushed to you as fast as you can process…
Also, most of the data on it is pretty shitty with lots of fraud since the publishers want to get more money. The geo data is often fraudulent (https://en.wikipedia.org/wiki/Geographic_center_of_the_conti...), and that's why companies that bid hire data scientists to sift through the fraud.
There's also rarely, in my experience, year-of-birth or any personally identifiable data.