Live data from Hacker News

Mobile customer location data is ending up in the hands of bounty hunters

motherboard.vice.com

91–100 of 253 posts

Re: Mobile customer location data is ending up in the hands of bounty hunters

#91
post #72
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

No need to invent new jurisprudence - if the location data can be used to identify an individual, it is personal data under the GDPR and enjoys all the rights and protections enabled by the regulation.

I don't think it's enough or sufficient to make "bad" actions against the law. It's better and more comprehensive to make it difficult to take "bad" actions and "easy" to take good ones.

People break the law all the time, and if you're high enough up the food chain Eric Holder will leave you be.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#92
post #56

I think we need to reassess how we treat data generated by users via phones, devices and our digital activities. We had the concept of private and public property long before intellectual property became codified by law. I believe that we are entering a new phase which may require the development of a new type of jurisprudence around things like location data. I'm definitely not a lawyer, but I'm starting to believe…

Maybe we should think about location data in a similar way to photographs. Both are generated by smartphone hardware and software, but the person who presses the shutter button legally owns the copyright to the photo, not the device manufacturer or carrier. Why don't I own the copyrights to my location data, and why doesn't the carrier need to license it from me in order to sell on to these bounty hunters?

Regarding the actual copyright question: copyright requires 'creativity'.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#94
post #92

Earlier quoted context omitted.

Maybe we should think about location data in a similar way to photographs. Both are generated by smartphone hardware and software, but the person who presses the shutter button legally owns the copyright to the photo, not the device manufacturer or carrier. Why don't I own the copyrights to my location data, and why doesn't the carrier need to license it from me in order to sell on to these bounty hunters?

Regarding the actual copyright question: copyright requires 'creativity'.

The creative act here is my movement. If I go to an open space and walked the outline of an airplane I have created something, even if it can only be viewed in the data that the phone has collected, the creative act was mine.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#95
post #92

Earlier quoted context omitted.

Maybe we should think about location data in a similar way to photographs. Both are generated by smartphone hardware and software, but the person who presses the shutter button legally owns the copyright to the photo, not the device manufacturer or carrier. Why don't I own the copyrights to my location data, and why doesn't the carrier need to license it from me in order to sell on to these bounty hunters?

Regarding the actual copyright question: copyright requires 'creativity'.

[deleted]

Re: Mobile customer location data is ending up in the hands of bounty hunters

#96
post #18

Earlier quoted context omitted.

You guys need (something like) GDPR in the US. I believe it's a necessity.

Probably, though eliminating cash bail would address this particular problem and is a good idea anyway.

It seems to me that eliminating bondsmen is better. This should coincide with actual affordable cash bail.

Unless you meant eliminating all forms of bail involving money. I actually have no idea how that works here in the Netherlands.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#97
post #94
post #92

Earlier quoted context omitted.

Regarding the actual copyright question: copyright requires 'creativity'.

The creative act here is my movement. If I go to an open space and walked the outline of an airplane I have created something, even if it can only be viewed in the data that the phone has collected, the creative act was mine.

Exactly. There are a lot of people out there doing Strava art, which to me is undoubtedly a creative work, and more creative than a typical selfie or vacation shot. I believe copyright covers all photographs, regardless of their artistic merit. Why not also location data?

For those unfamiliar with Strava art: https://www.cyclingweekly.com/news/latest-news/five-best-str...

Re: Mobile customer location data is ending up in the hands of bounty hunters

#98
post #18

Earlier quoted context omitted.

You guys need (something like) GDPR in the US. I believe it's a necessity.

There are lots of things needed in the US.

Meaning, GDRP will be a result of other (political) changes? I'd concur.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#99

Earlier quoted context omitted.

That's fine for you Europeans under GDPR. (Sure, there's careouts for weird exceptions.) That doesn't do diddly for us US citizens living in the US. Our data policy is "we will sell your data, too bad so sad".

It is kind of our own fault, though. Judging by the sentiment on HN when GDPR was coming into effect, if something like it came up for a vote in the US, a lot of HN users and other tech people would vote against it. There was no shortage of angry geeks posting articles about their service turning away EU users rather than complying with GDPR.

If you work in tech or marketing your salary comes from eroding privacy. There is a lot of money at stake here and people don't vote against their interests.

Europeans aren't inherently better: if Facebook and Google were companies founded in Germany or France who knows if GDPR would exist.

Re: Mobile customer location data is ending up in the hands of bounty hunters

#100
post #14

For EU folks: anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store? I'm thinking any of the following are within the realm of possibilities: - Call history, including metadata and potentially also contents; - Text messages, same as with calls: metadata and potentially the contents; - Location history; - Data connection activity, again: metadata and potentially…

> anyone tried a GDPR request to their phone provider to figure out what do they collect and what do they store?

Yes. The Netherlands, carrier is called Youfone.

They have very, very little data on me: they claim not to be able to see which cell tower I'm even connected to (which would be tracking info), which makes me wonder how they even provide their service. They say it's all outsourced to third parties, one of which is the network operator, KPN, and they cannot list those parties for commercial reasons. I doubt that's legal (I'd assume you can't just stuff everything into subsidiaries and go "sorry can't tell, business secrets": either you have to get it from the subsidiaries, or you tell me who they are and whom to talk to), but the Authoriteit Persoonsgegevens (local authority) seems to have their hands full, as do I, so I did not bother pursuing it.

The info I did get was: everything I provided (name, DOB, bank account), everything you would commonly expect (call logs (though that is not as common in Germany, it is everywhere else afaik), the invoices based on those call logs, data usage per month, etc.), and I think one or two uninteresting pieces of information (probably SIM card number and such). They also provided storage time limits for the data.

I feel like they did not have the process in place yet before my request, as a dude quite high up in the orga replied to my support ticket and they exceeded their response deadline. After two months they gave me a professional-looking PDF with the data, so I think they quickly set that up because GDPR was fairly new (few months after May 2018). They're also cheap, I'm sure the mails back and forth (not to mention the investment in that "data to pdf" system) cost them much more than my 8,50/month subscription would warrant. I kind of want to cut them some slack for working on it rather than bother those who try. Maybe I'll pursue it again later. Or maybe someone else can ask better questions based on my experience.

Post reply on HN