Live data from Hacker News

Your mobile data sold, without your knowledge

translate.googleusercontent.com

61–70 of 162 posts

Re: Your mobile data sold, without your knowledge

#61
post #38

This is one of the reasons why I'm generally not OK with "anonymized" data collection without an explanation of how it's being anonymized. It's almost always easy, often trivially easy, to correlate the data together and basically get a perfect recreation of whatever the original data was back.

Anonymization in the data reselling industry is often some form of md5(lower($email)). It's a joke. They even do that for extremely small search spaces like phone numbers. It's still provided at the individual user-level and even if the anonymization is done in a way that's irreversible, you only need to know a single event for a given person and you now have their entire history. For example, there's a popular email…

> coworker saying "Oh, I bought this awesome coffee maker on Amazon last night!"

This x1000.

I have seen people invite others to eat lunch at restaurants that only accepted credit cards in order to elicit such a data sample.

Re: Your mobile data sold, without your knowledge

#62
post #39

What I don’t get about this kind of thing is that it’s not just shady data resellers you’ve never heard of. It’s also overt, high profile, branded tech companies like Foursquare and Yelp, with huge amassed data sets of foot traffic, wifi scans, battery status, often paired with demographic info or data that can be joined by ad IDs or commercial device graphs. If these companies are able to keep on truckin’ with massi…

The fact that Apple Maps integrates Yelp is a big red flag for me, and I think a big hole in their privacy story. It's why I am more comfortable using Google Maps than Apple Maps.

The data doesn't come directly from Yelp AFAIK. It goes throught Apple's servers. Yelp isn't queried directly.

Again this is from my memory of MITM proxying iOS.

Re: Your mobile data sold, without your knowledge

#63
post #38

Earlier quoted context omitted.

Anonymization in the data reselling industry is often some form of md5(lower($email)). It's a joke. They even do that for extremely small search spaces like phone numbers. It's still provided at the individual user-level and even if the anonymization is done in a way that's irreversible, you only need to know a single event for a given person and you now have their entire history. For example, there's a popular email…

> coworker saying "Oh, I bought this awesome coffee maker on Amazon last night!" This x1000. I have seen people invite others to eat lunch at restaurants that only accepted credit cards in order to elicit such a data sample.

Yeah, it's not just emails of course. You can do it with web traffic data. You can do it with credit card data. You can do it with geolocation data. You can do it with TV viewing data.

Re: Your mobile data sold, without your knowledge

#64
post #55

Can I legally purchase the anonymized location data of a few thousand Americans, run that through a script which associates coordinates with addresses, and publish the deanonymized results as an art piece like this? If so, this could be a lot of fun. It would be interesting to see the political backlash, especially if the published dataset includes politicians. Perhaps, in the name of ethics, it should include only p…

You'd presumably get in trouble because legality is only part of the equation, the other part is how big/powerful you are and whether you have connections in the right places.

Big companies can get away with crimes while the same thing would result in successful prosecution if a little guy does it, so you might very well get in trouble even though you're doing exactly the same thing as an existing company that manages to stay out of trouble.

I however support your idea regardless of its legality (and especially if the data happens to contain details on politicians, the majority of which are responsible for the situation being as-is) and suggest you publish it anonymously (through Tor).

Re: Your mobile data sold, without your knowledge

#65
post #39

Earlier quoted context omitted.

The fact that Apple Maps integrates Yelp is a big red flag for me, and I think a big hole in their privacy story. It's why I am more comfortable using Google Maps than Apple Maps.

The data doesn't come directly from Yelp AFAIK. It goes throught Apple's servers. Yelp isn't queried directly. Again this is from my memory of MITM proxying iOS.

They are still promoting that garbage company though (for a lot of other reasons besides privacy).

Re: Your mobile data sold, without your knowledge

#66
post #19

A question for the Android experts: is it possible to block or spoof location data, through a custom build? Could I have an Android phone running a program that spoofs a long steady drive from Tampa to Butte?

Why bother spoofing when you can simply turn location permission off ?

Re: Your mobile data sold, without your knowledge

#67
post #37

At this point, most people seem to know that their mobile data is being used. And, interestingly enough, they don’t seem to care.

They have no power to change it and no credible alternatives.

Apple and Google create systems that make it possible to harvest data with no user control possible. Neither provide the ability to see or stop data leaving your mobile device.

They do this so they can attract developers to their platform.

They do provide "controls" to prevent some sort of data access to prevent mindful users from leaving the platform.

It's just that the control have the same sort of ambiguity as a privacy policy. Many people still don't understand that "location services" really means two-way, or that bluetooth can be a proxy for very fine-grained location tracking.

I hope that we finally get alternative phones (say pinephone or purism) because I firmly believe there's a HUGE market opportunity for this sort of thing.

Re: Your mobile data sold, without your knowledge

#68

Earlier quoted context omitted.

Being a user of free applications and services does not automatically give corporations the right to exploit people by collecting and selling their personal information without consent. Ironically, the data of paying customers is even more valuable. Spending money on these things is probably a great way to make them pay even more attention to you. For example, mobile game companies seem to know everything about their…

> without consent. that's the point, they "gave consent" via the terms and conditions checkbox, and this is upheld in court since the user knew they were getting the service for free. Few countries have kept up with their laws to protect consumers from this.

> Few countries have kept up with their laws to protect consumers from this.

Seems to be a US thing. Apparently people can give up their rights and consumer protections by agreeing to a contract. Naturally, these "you agree to not exercise your rights" clauses have become standard in privacy policies and terms of service. In many other countries, a judge would simply invalidate the abusive clause.

Very few people are going to take this to court though. Regulators need to establish rules and proactively enforce compliance in order to bring about change.

Re: Your mobile data sold, without your knowledge

#69

Earlier quoted context omitted.

> without consent. that's the point, they "gave consent" via the terms and conditions checkbox, and this is upheld in court since the user knew they were getting the service for free. Few countries have kept up with their laws to protect consumers from this.

> Few countries have kept up with their laws to protect consumers from this. Seems to be a US thing. Apparently people can give up their rights and consumer protections by agreeing to a contract. Naturally, these "you agree to not exercise your rights" clauses have become standard in privacy policies and terms of service. In many other countries, a judge would simply invalidate the abusive clause. Very few people are…

>> Few countries have kept up with their laws to protect consumers from this.

> Seems to be a US thing.

This article was written about data collected in Norway by a data broker based in the UK.

Re: Your mobile data sold, without your knowledge

#70
post #52

This isn't likely news, for most here. But it can't be reported enough, for the general public.

Yeah, I think this is one of those things where, when the normals catch on, there's gonna be pitchforks and torches.

Indeed, but what would it take?

I gather that NRK is the BBC equivalent for Norway, so it's not surprising that Tamoco sold so much data to it. But I wonder how selective Tamoco and its competitors are.

In particular, I can imagine that there's a substantial market for data that facilitates tracking people. Bounty hunters. Repo agents. Private investigators.

But also people who want to stalk others for whatever reasons. If someone could document that application, perhaps there'd be "pitchforks and torches".

Post reply on HN