Simply put: don't want to be tracked? Put your phone in a lead sealed box or leave it at home. Tracking only tracks the phone , not your person.
That doesn't do anything to protect your data from being accessed by the State, which is actually the bigger problem.
The problem with the current setup is that we don't know who's gaining access, when they're gaining it, what they're doing with it, etc. Once the cell carriers have it, there's no easy way of knowing who they are selling the data to, and who that entity sells it to in turn, and so on.
Sadly, I don't see a good way to resolve this at the moment. If you use a cell-phone the carrier can always get your (at last approximate) location through triangulation. And regulation only makes sense if you trust the State, and I would like to think we've all learned better than to do that by now. So what do we do?
Why thwart one great harm yet happily tolerate the other?
If Starbucks knows my location, they can send me a coupon if I enter a Dunkin' Donuts store. If the State knows my location they can falsely accuse me of a murder that I just happened to be near the location of and - if I'm unlucky or have a bad lawyer - execute me for it.
That's not, of course, to say that there aren't some cases where a private business having access to my location could have a deleterious effect. But here's the rub: if you rely on regulation to prevent those cases, you're right back to needing to trust the State, which is - IMO - a foolish proposition.
The division is so trivially violated it's pretty much irrelevant.
But those largely cosmetic boundaries certainly play a large role in public perception and acceptance of living in a surveillance state.
[1] https://motherboard.vice.com/en_us/article/gykgv9/securus-ph...
Wide availability of tracking data facilitates domestic violence and stalking, for starters.
Say that someone gets killed by their ex who found them through tracking data leaked by some irresponsible and/or profiteering company. How do we hold that company accountable? How can we prove that it was them who leaked the data, when it's everywhere?
We can't hold the credit authorities like Equifax accountable today for the identity theft they facilitate. This is the same problem. The aggregation of our individual data by companies causes massive negative externalities, borne by individuals.
Again, this cost is not borne by the data aggregator -- it's a negative externality borne by individual citizens. Good luck suing them.
Who does your cell phone's location belong to?
Who does the tower's connection data belong to?
Who does the multitude of tower signal strengths belong to?
Who does the user's cell phone data belong to if allowing multiple apps to use it?
Answer: User's location data belongs: to the user, 3rd party apps they have allowed, and terrestrial cell companies that run towers with the appropriate frequencies for your phone.
The technology isn't the right area to change it. In the end, you're doing stupid stuff with encryption and still emitting point-source radiation that can and will be triangulated.
I think this is probably correct.
The problem with the ban you suggest is that it will degrade service in many instances. Some level of location tracking is necessary for all cellular phones to make a smooth handoff between towers or for example to load balance connectivity between different towers.
In the end the more personalized the service you want to have, the more "invasive." Opt in is probably the best total solution, however it quickly becomes an education game if you want it to be effective, and most people don't have the time or technical understanding to put up with a dozen different opt ins.
They do not need to sell location data to other parties in any way, shape, or form.
Don't like the rules of the road, don't drive.
Don't like that your data goes over a third-party's network to get to its destination, don't put your data on a third-party's network.
Bans "by law" only work until the people making the law become people interested in your location and they change the law.
1. Allow the location data to be utilized by the cellular carrier only for legitimate engineering purposes relevant to the delivery of the cellular services. (The network needs to know your location in real time in order to route calls to you.) Also, allow the use of real time location data for emergency services in response to an emergency call. Potentially also allow the use of emergency services initiated real time locations, with a non-suppressible UI required to be presented to the user if this is performed.
2. Require that the cellular service providers purge / NOT retain this location data for any longer than is literally required to provide proper service.
The data retention policy #2 item here is essential in preventing temptation to come up with end-runs for the first rule. It's important that historic data that has no legitimate use under rule #1 not be preserved so that there isn't a mound of accumulating data of theoretically increasing value if only we could change / get rid of rule #1. That sort of thing will create ever mounting incentive to repeal / replace rule #1.
At least for GSM, that isn't as true as you say it. It only needs to know in wich group of cells you are, as as re-registering with each cell change was deemed too heavy on the battery, and they rather page for your phone in the entire location area.
Likewise, triangulation requires the phone to send something, which means that you can notice that, and also that continuous triangulation will drain your battery.
(Which brings up the question of how often and how smartly google sends updates for the traffic density map.)
I'm not sure how possible it is to anonymize that kind of data in a way that prevents it from being deanonymized, or how useful the anonymized data would be to the buyers, but this seems like a better solution than a blanket ban to me.
https://www.telegraph.co.uk/news/2017/11/27/australian-sacke...
Your next car will support telemetrics. Your insurer will know how fast and how often you drive. Your wife will know where you've been going after work. The cloud will gather and retain everything else of non-obvious value, up to the point where it all magically disappears when your self-piloting car drives itself through a schoolyard at recess and the company claims they don't have enough data to determine their responsibility, and insinuates that perhaps it was your fault.
All your future appliances will be factory-bugged so Amazon can listen to you arguing with your wife and sell you marital counseling books. Or they sell you imported counterfeit electronic shit, leaving bored interns with unchecked privilege (or strangers poking around on SHODAN) to activate those products' extraneous cameras to spy on your daughter undressing.
The ubiquity of cellphones in the hands of the masses mindlessly recording every droll moment of their lives in public for a chance at YouTube fame, combined with better and better facial|licenseplate|whatever-recognition algorithms means you're always on a camera somewhere, your movements being tracked and your identity easily annotated. Your wife's divorce lawyer will have a field day with this.
Don't want to be tracked? Hoard cash and modify the serial numbers. Throw away everything with a network interface or bidirectional antennas of any kind. Don't leave the house. Slap tinfoil on your windows. Make yourself a nifty pirate hat with the remainder. Your friends and neighbors will think it's endearing for a while, then they'll stop coming around for some reason.
Just don't take a selfie of yourself in your fortress of solitude without scrubbing the geolocation data from the EXIF tags!
There are still areas in which you can make choices. You can still buy appliances with no internet connections at all, or buy open hardware and run open source software. This is what I currently do.
Surely inexpensive and/or used cars will dispense with GPS and other high tech features; in addition, I wouldn't be surprised if (should this become a regular problem) a modding community develops around car ownership (ownership in the sense of right-to-modify).
This doesn't change the fact that it is incredibly concerning that always on tracking run for-profit is becoming the default, but I think it's too early to say we can't opt out. That's why I think cell phones are qualitatively more worrying. They're quickly becoming necessary devices for anyone in a salaried job, and they represent an always-on tracking device that's effectively glued to my hip. It is absolutely crucial that something be done abut these privacy violations, if not through legal means, then through hacking. If that turns out to be impossible I'm going to have to find a way to stop carrying a phone.
It would be nice to see Purism respond to this report given their work on the librem 5.
For a little bit. As you say, bad money pushes out good money. Most people will buy devices with tracking. Since more of them will be made, their prices will be lower than devices without tracking. Especially since the tracking will be profitable for the companies making the devices. Eventually you'll find all devices have tracking hardware and on some it will just be disabled. Either unplugged physically, or turned off via software.
If anything the parent's predictions are probably conservative.
> You can still buy appliances with no internet connections at all, or buy open hardware and run open source software.
Maybe, if you know what to look for. Most consumers don't. They'll buy a Dell and not realize Computrace exists. I work in the field and I don't even know a fraction of what I don't know. I'm just one asshole defending against legions of better-paid actors with an infinite capacity for insidiousness.
Just wait until some well-meaning, progressive state like California decides to legislate that all houses must be smart-conforming. All aspects of your house will have a network interface whether you like it or not. How many homeowners are capable of setting up VLANs for their lightbulbs? How many homeowners are going to deconstruct every (networked by default!) smart-item they purchase and check for motion sensors, cameras and microphones? The NSA backdoored smart TVs already. Huawei backdoored routers, and Blu sends god-knows-what to China in the background. It's happening.
In this day and age, you may as well assume every product that comes out of Silicon Valley is a glorified exfiltration agent. If you give anything a network interface, by god it's going to use it to report something, and you don't know that it's happening or what's being communicated. You-have-no-control.
Given the recent interest in mesh networking I expect that to become a new vector-- install enough Huawei appliances in an area (give them away for free, or undercut competing vendors), each serving as a wireless mesh node, and you only need one internet-facing node (like a Huawei cellphone or router) in that mesh to be able to command and control any of the devices or peripherals around it. If anybody questions why a digital pictureframe is emitting wireless signals, it's for the discovery service, of course. It has to get updated weather information from somewhere, right? Consumers will accept that. And thus you invite a decentralized botnet into your home.
> Surely inexpensive and/or used cars will dispense with GPS and other high tech features; in addition, I wouldn't be surprised if (should this become a regular problem) a modding community develops around car ownership (ownership in the sense of right-to-modify).
Used cars will, until that pool dries up, yes. How many cars can you find that still use carburetors in favor of ECU-controlled fuel injectors?
We lost the right-to-modify battle the day ECUs became standard in all cars, inexpensive or not. Without proprietary knowledge, you can dink around with the oil and tires, but you can't fundamentally change how the car works. You can't even change the brake fluid on some cars without a proprietary command telling the pump to expel it. The war for right-to-modify will be lost when we're all driving Teslas (or John Deeres).
You can hack it, sure, about as competently as you can hack a PS4 or iPhone. The day will inevitably come where you want to use a particular app or service you paid a premium for (like warranty repairs, autopilot, PS Online or iTunes) and they'll tell you to pound sand unless you install their factory-certified firmware that opts-in to tracking. Or new games/features will simply refuse to work on your hacked firmware. You will be left in the dust.
That also assumes your insurer doesn't find out you tampered with an otherwise autonomous car, potentially impacting its safety features by refusing OTA updates and putting you in a higher risk pool. They may decline to insure you altogether.
There are consequences for not complying with progress; you yourself mention one of them. I'm disappointed you think it's hyperbole-- this attitude is why things have degraded to the current state of affairs.
What car brand does this? The only thing that came up on a Google search was a comment on Quora that said that mechanics can command the ABS to go into a self bleed cycle to purge air (no brand was mentioned). Is this what you're referencing?
Not without messing up your ability to make and receive calls. Cell towers use precise timing and power-level measurements in order to do things like decide which cell-site is best, and to hand-over your call from one tower to the next without breaking your call or glitching.
Edit: Even if you were to play around with timing of responses of the radio signal, you have no control over how it radiates in free space. The time-delta between reception of the same signal by 3 towers at known locations is enough to triangulate your position. Maybe a unidirectional antenna pointing to just one tower might work, if there are no other towers within the beam behind it and no sideway leakages.
And it'd be useless unless you had many of these custom transmitters faking your signal spread out over large physical distances.
TLDR: GSM+LTE open-source SDR/hacked dumbphone baseband exists, suitable hardware is COTS for sub $2k.
Expanding this, you could have N directional antennas pointed to N cell towers, and some individual delays on each of those antennas, it might be possible to fool the network triangulation. Such a setup would look highly suspicious if you were carrying it around, and it definitely wouldn't fit in your pocket.
In the U.S., aren't dumb phones (or 'feature phones') locatable for E911 service?
It's not as accurate as GPS, but it gives a solid estimate of your location that neither you nor your phone can prevent unless you totally disconnect.
they absolutely had spies on the ground who were likely civilians, eg the doctor who got bin laden's family's dna under the cover of a vaccine program. the narrative that they were only using cell tower triangulation may have a seed of truth but it sounds a lot like counterintel meant to throw off the trail to me.
I'm sure they also had spies on the ground, but I believe the explanation that innocent bystanders being killed was something they'd prefer to avoid.
For iOS, assume every app using your location is selling the data. That means every app using a map or location smoothing SDK (GPS jumps around, there are services to smooth it out), since the map SDK providers (and there's not many) are selling your data even if the app itself isn't.
Google, Apple, Microsoft etc are pretty careful for good reason. Anyone below that is probably selling it.
In fact I don’t think that is even a gated permission on iOS.