Live data from Hacker News

US cell carriers are selling access to real-time phone location data

zdnet.com

511–520 of 648 posts

Re: US cell carriers are selling access to real-time phone location data

#511
post #208

Earlier quoted context omitted.

> for their own purposes Such as? If this also happens in the EU and is as blatant as you say it is and with GDPR and all, surely this is just waiting to blow up?

Parralel construction. You pull the phone location records of everyone near a protest without a warrant (and no intention of using the location data in court) then you dig into them to find something unrelated to the protest you can nail them on. That way you take out key players without it looking like a political crackdown.

That's absolutely a chilling effect. Just thinking about this I'm thinking back on events I've been to what what the government can infer from that. And they can probably nail us for anything now whenever they want to and it will be hard to trace it back to this kind of monitoring and analysis. The only way to avoid that would be to leave your phone at home and hope nobody records you or takes photos.

Re: US cell carriers are selling access to real-time phone location data

#512
post #216

Earlier quoted context omitted.

That's always been common knowledge, the shocker is that it's being transmitted to "everyone and their dog" or even being sold. Afaik that was never the case with dumb phones.

A dumb phone can be localized by cell triangulation. The US military disclosed that it was using such a technique in Afghanistan to locate Al-Qaeda targets (they disclosed this because Al-Qaeda had gotten so paranoid about he accuracy of US military operations that they had assumed they had human spies on the ground feeding the US information and began killing civilians on suspicion of spying).

...or maybe they had a lot of human spies to protect by telling tech stories.

Re: US cell carriers are selling access to real-time phone location data

#513

Earlier quoted context omitted.

How does one determine which tower to route an incoming call through, in your model? How could roaming work? Spoiler: I don’t think doing what you are describing is feasible.

Calls could be done over IP, and as long as you could anonymously authenticate to the tower then you could be granted a new IP address at each tower via something like DHCP. I imagine roaming and handovers would have to be done on the end-device though; the end-device would need to proactively associate to new towers and both ends of the voice call would need to agree to switch to the new IP address. But if the tower…

Proving to the tower that you are a paying user should be easy, but routing the data securely will not be as easy. You'd probably need some kind of onion routing or similar on the back haul, unless you want to forego incoming calls. I would not like to have to forego those. Also, why even bother with DHCP, just say that the tower assigns you an IP, without knowing your MAC, right after you were able to prove that you are a paying customer. Handling data quota is going to be non-trivial there, as you'd either need to route everything to the provider anyway, or have a DoS-proof way of decreasing your remaining quota, e.g. by signing a new value with some key of yours, ensuring that the tower can't use that as your ID (maybe don't tell him or so), and then have to prove to the tower that your quota really got diminished, preferably without revealing how much is remaining, and just telling the tower that you still got something to spare. The main issue seems to be that you'd have to hold a session with each tower where you got quote allocated, as you can't re-run that quote proof for each packet. The finest granularity that seems remotely reasonable would be like 16kiB of traffic, which you would deduct form your account, let it get claimed by the tower, and then be required to repeat for each successive block (obviously you could assign larger blocks, but a block, once assigned, can't be put back without serious unnecessary cryptographic hurdles.

I am not well-versed enough in these cryptographic details to tell you how one could do this exactly, but I doubt it's impossible/infeasible to create a cellular protocol technically as powerful as LTE, but without tracking ability by the tower or the provider (byzantine fault tolerance, stochastic).

Re: US cell carriers are selling access to real-time phone location data

#514
post #306

Earlier quoted context omitted.

Anonymous attestation protocols is a thing

"without a side channel" Do you have any links where this is done without a third party?

Blockchain? No, seriously, just a block-oriented write-ahead-log replicated to the towers, allowing them to cheaply-ish verify a proof-of-traffic quota.

Re: US cell carriers are selling access to real-time phone location data

#515
post #441

Earlier quoted context omitted.

The general public and repeatedly-reported-upon understanding of how data collection can be leveraged to find unexpected insights not obvious from the data, coupled with the Snowden leaks, coupled with the ever-increasing user count for cellphones, Facebook, Twitter, and the Internet in general. If people were deeply individually concerned about the risks vs. rewards of these technologies, they'd stop using them. Tha…

Tu quoque . See also: "Ayn Rand collected Social Security benefits." (And I abhor her oeuvre and "movement".)

Tu quoque requires someone to have made a claim in the first place.

I'm saying people make the claim on the average person's behalf that they want privacy and information such as their location (as triangulated by cellphone towers) kept generally secret from governments and corporations who can offer them benefits, and that claim is not actually supported by much evidence. I think the digital intelligentsia cares deeply; the average cell user, not so much.

Re: US cell carriers are selling access to real-time phone location data

#517

Earlier quoted context omitted.

Even simpler: don't want to be tracked? Don't have a mobile phone.

It doesn't help. Your next car will support telemetrics. Your insurer will know how fast and how often you drive. Your wife will know where you've been going after work. The cloud will gather and retain everything else of non-obvious value, up to the point where it all magically disappears when your self-piloting car drives itself through a schoolyard at recess and the company claims they don't have enough data to de…

Parts of your analysis are hyperbole, clearly, and I think that undercuts what are several very important points.

There are still areas in which you can make choices. You can still buy appliances with no internet connections at all, or buy open hardware and run open source software. This is what I currently do.

Surely inexpensive and/or used cars will dispense with GPS and other high tech features; in addition, I wouldn't be surprised if (should this become a regular problem) a modding community develops around car ownership (ownership in the sense of right-to-modify).

This doesn't change the fact that it is incredibly concerning that always on tracking run for-profit is becoming the default, but I think it's too early to say we can't opt out. That's why I think cell phones are qualitatively more worrying. They're quickly becoming necessary devices for anyone in a salaried job, and they represent an always-on tracking device that's effectively glued to my hip. It is absolutely crucial that something be done abut these privacy violations, if not through legal means, then through hacking. If that turns out to be impossible I'm going to have to find a way to stop carrying a phone.

It would be nice to see Purism respond to this report given their work on the librem 5.

Re: US cell carriers are selling access to real-time phone location data

#518
post #441

Earlier quoted context omitted.

Tu quoque . See also: "Ayn Rand collected Social Security benefits." (And I abhor her oeuvre and "movement".)

Tu quoque requires someone to have made a claim in the first place. I'm saying people make the claim on the average person's behalf that they want privacy and information such as their location (as triangulated by cellphone towers) kept generally secret from governments and corporations who can offer them benefits, and that claim is not actually supported by much evidence. I think the digital intelligentsia cares dee…

And I'm saying that lack of care is a product of ignorance — ignorance in no small way imposed upon them by the shady behavior of the people who are doing this. As such, it can't be reason to blame them for that "choice". It's a passive choice. It's opt-out, without being told there's a option. And there isn't actually an option.

That is, if Verizon was unambiguous with Joe Customer, "We may sell your real-time location information to companies known to re-sell that kind of information to the government, and you can't do anything about it" how many of them would be pissed? Isn't the state being restrained from un-warranted — literally — snooping into people's lives a core American value?

Your position is that most people would "meh". I think you're wrong. You're probably right that there's scant evidence either way, though.

Re: US cell carriers are selling access to real-time phone location data

#519

Earlier quoted context omitted.

A dumb phone can be localized by cell triangulation. The US military disclosed that it was using such a technique in Afghanistan to locate Al-Qaeda targets (they disclosed this because Al-Qaeda had gotten so paranoid about he accuracy of US military operations that they had assumed they had human spies on the ground feeding the US information and began killing civilians on suspicion of spying).

> A dumb phone can be localized by cell triangulation. The US military disclosed ... In the U.S., aren't dumb phones (or 'feature phones') locatable for E911 service?

if it doesn't have GPS, it doesn't have GPS

Re: US cell carriers are selling access to real-time phone location data

#520

Earlier quoted context omitted.

Cricket's Privacy Policy looks much better than T-Mobile's or Google Fi's: "We will not sell your personal information to anyone, for any purpose. Period." https://www.cricketwireless.com/privacy But they also say that they may share personal information (which may include location??) to 3rd parties with user "consent": "Do you share my Personal Information with other companies for them to market to me? We may share…

I'm on Cricket Wireless and I tried at your link, but I'm not getting the SMS message.

That either means LocationSmart doesn’t have access to location data from Cricket, or it’s not working for some other reason.

LocationSmart’s website says they can get location of 95% of cell phones in the US. I’m tempted to try and call their sales department and see if they would tell me which carriers they don’t support...

Post reply on HN