Feds ordered Google location dragnet to solve Wisconsin bank robbery
theverge.com
theverge.com
Your accomplice would have to take possession of the phone at a comfortable distance from the target bank. (Again, in a place that no one, and no camera can observe the arrival of either party.) And the co-conspirator actually robbing the bank would have to make his/her way to said bank without being observed leaving the phone drop site. (And without being observed traveling in a direction inconsistent with his/her phone's location data.)
All of that is not as easy as it sounds. One traffic camera on a stoplight and they got you, in your car, heading towards the bank, in the opposite direction of your phone. Now your co-conspirator is in trouble too. (Aiding and Abetting at minimum.)
We're creeping towards an age of ubiquitous gaze, and only people who are way smarter than I really know if there's any averting it at this point. I think the only real defense against ubiquitous, 24/7 surveillance right now is to live life in a remarkably unremarkable fashion.
It's not yet illegal to walk around without phone.
"Show me your papers citizen"
You've got it all back to front. They won't check the CCTV outside the robbery area against non-suspects outside the robbery area.
You're basically saying they'll check the whole of the world that they weren't in Wisconsin.
While humans are doing the piecing together this tactic will probably be pretty decent, but it wouldn't be super hard to marry those datasets after you've seen it happen a time or two.
I’m not even disagreeing with you. It makes me sad, however, that this sort of automated surveillance is mostly accepted by wider society. We will force everyone into a Brave New World styled life, where being entirely unremarkable is the only way to avoid suspicion, no matter how innocuous the behaviour.
EDIT: Yes, that creates a data point that police could also search for — "give me all the phones in the vicinity that were turned off and then back on surrounding the incident." Okay, how far away? That would be a massively larger search, geographically, wouldn't it? How far before and after is your window for turning off and back on events?
That's still an additional search. It's also probably got a far worse signal:noise ratio than proximity to the incident — assuming the robbers were dumb enough to have their phones on them (and on) in the first place.
Leaving it at home, without turning it off, leaves no such trace; it's consistent with "this phone's user simply stayed at home today".
"We got 'em!"
But most people don't unless it runs out of battery and rarely when they are at home (people just plug it in when they are home).
Not that this is useful in court but it could point detectives in your direction.
Spies would look for this to see if they are being tailed. If they can see a pattern of people who are co-travelers on their same path, then that’s a pretty bright signal.
It would be more work for the police to look for these kinds of signals in the location data, but not companies like Google.
Essentially, they cross referenced list of hotel guests at three different hotels on three different dates and she was the only one at all three.
https://www.businessinsider.com/how-fbi-caught-paula-broadwe...
(Edit: That and Google wouldn't agree with T-Mobile on your location. Oh well.)
Does it have to be your car?
https://www.nycedc.com/blog-entry/new-yorkers-and-their-cars
https://www.dataprotection.ie/en/guidance-landing/guidance-d...
"Employee used crisp packet as 'Faraday cage' to hide his whereabouts during work"
https://www.telegraph.co.uk/news/2017/11/27/australian-sacke...
https://www.youtube.com/watch?v=MeKKHxcJfh0&feature=youtu.be...
Assumably it’s the judge’s opinion on this that matters, right? In the case of a national security letter this fight wouldn’t even be public. Assume the worst.
You, as a defendant, can also challenge the warrant as part of your trial if you are caught, potentially getting the results of the search thrown out.
> It was an aggressive technique, scooping up every Android phone in the area and trusting police to find the right suspects in the mess of resulting data. But the court found it entirely legal, and it was returned as executed shortly after.
I switzerland was a murder an rape case close to one of most busy highway. The police asked the phone providers for phones in this area (highway included). The first bill from the providers was 860'000CHF, they reduced it later to 200'000CHF.
https://www.google.com/amp/s/www.nzz.ch/amp/schweiz/teure-ue...
2030 - 2040 This kind of investigation becomes so common that the independent news outlets just stop finding instances of it. People are kind of relaxing about it.
2040 - 2050 It turns out that, like DNA evidence, there's now an entire innocence project started dedicated to getting people out of incarceration for any crime where the totality of evidence was GPS data and some made up stories.
2050 -> Oh sorry that new energy source blew up, earth is gone.
>It turns out that, like DNA evidence, there's now an entire innocence project started dedicated to getting people out of incarceration for any crime where the totality of evidence was GPS data and some made up stories.
Is also already the case. Denmark had such a problem recently.
https://www.nytimes.com/2019/08/20/world/europe/denmark-cell... https://www.theverge.com/2019/8/23/20829490/denmark-cellphon...
Given the history of every other technique the cops have ever used to solve crime I'm betting it's gonna wind up somewhere between forensic bite mark analysis and eyewitness testimony (i.e. not worth shit unless you've got a lot of other stuff to corroborate it). Of course a generation of prosecutors will get to make their careers on this kind of crap before it gets debunked.
One of my SDR projects was to boot a GSM base station if my burglar alarm went off and store copies of every IMEI it can see in the cloud. Seems like it would be a better lead to hand investigators than a fuzzy security camera shot.
It would also need permission from the licensed spectrum holder, that could be harder to get.
But yes, completely legit with the right paperwork.
[1] The FCC has been pretty engaged in understanding the impacts of SDRs because of their potential for abuse (as one attendee called it, "The Drones of spectrum." As an amateur (AI6ZR) and someone in industry I've been helping as an SME to explain some of this stuff to their less technical staff.
"Criminals deserve just as much privacy and safety as anyone else. If the government violates the criminal's rights to solve, prevent, or preempt crimes, even more crimes have occurred (privacy violations, killing of the criminal, etc.)
There should be explicit modes for phones and browsers available to criminals that allow them to safely commit crimes without risk of their rights being infringed upon."
Maybe "for the next hour, don't do the normal location-tracking/biometrics monitoring/reporting". I get that Google has no incentive to make that feature but maybe Apple does?
Trying to make a black and white distinction between criminals and everyone else is futile.
This. Drive 5mph over the limit? That's a crime. Buy some stuff off craigslist? I hope you paid sales tax on that, buddy.
I suppose we can sorta thank the FEC for their crazy broadcast device requirements when it comes to suspecting whether airplane mode actually stops a device from dialing home.
I could pretty easily verify my suspicions but I think others already have.
> you should just not carry the tracking device in the first place
So I guess a Faraday cage would be the only sure way...
Also, cables coming outside of your box must be shielded too.
The Faraday cage would still leave the accelerometer fully functional. Now you might say "but because of drift it will rapidly diverge". Yes and no. It turns out that it's possible to detect based on "gestures" where you might be. Works better for winding irregular streets than in a gridlike street network.
If we go full Sherlock Holmes, the microphone might also overhear trains and music from stores giving away the location.
Heh, are you a fed? ;)
>Google is tracking you. Even when you're in Airplane Mode without SIM card
Still, it would be nice if the default for phones was to not be connected to the mobile network. Instead, they could listen out for a signal broadcast on an FM frequency (for example), and only connect to the mobile network when a specific unique ID was sent, indicating that you have an incoming call. (The unique ID would be agreed with the radio transmitter in secret before hand, and changed after each call).
When your phone is on a Wi-Fi network, it could instead have all incoming calls directed to it that way, like a softphone, meaning you would only rarely have to reveal your location to the mobile network.
The economics of this could work in some places (based on my rough guesses), but not if users had to root their phone to grant apps this permission to turn airplane mode on and off. I also don't know how much battery life would be required to be constantly processing an incoming FM signal in software (at least whenever the phone was off a Wi-Fi network). I'm also assuming that phones have FM receivers that apps can interact with, or that this could be an external device, connected via BlueTooth, perhaps.
As an example of the sort of society I am hoping to avoid, let me offer this article:
https://www.theregister.co.uk/2018/05/11/top_judge_mulls_com...
In all seriousness though, I'm pretty sure your system fails in the deliverability department.
Mobile phones are meant to be...well... mobile, and that functionality basically requires that when a call intended for you is started from somewhere else, there has to be a way for the signal to get correctly switched to where you are.
If you treat cell towers as switches, that then means that each tower maintains a routing table of handsets within it's area which allows the signal to eventually find it's way to you. This is the fundamental operating principle behind packet switching and the Internet in general.
Let's say there's 4 cells. A, B, C, and D.
I call you from A. You're in D's coverage area. A can connect to B and C, and C can connect to A, B, and D, B cannot see D.
My handset tells the switch behind cell tower A I'm looking for you. It checks it's routing table to see if it's serving you, and finds it can't, so it pings the next switch that has announced a possible route (C). C checks it's routing table, to find you and doesn't, but it sees D knows of you, so forwards to D. D knows you're there, so it finally connects the call. The circuit is made. This works because information about what handsets are in range, and which cell knows routes to what is constantly updated and propagated through the network. So if you took a trip out of D to B while on a call, the call would not have to terminate since the towers hand you off from tower to tower as your handset's location changes.
The system you propose though, breaks that paradigm. Since the cell tower has no way of tracking the handsets in its service area, every possible tower has to chirp to see if your phone will respond. Once your session is established, some of the normal routing protocols can still be reused, however, the initial connection stage is where it gets problematic.
Routing tables clean themselves up over time, so if you don't use your phone for long enough, you essentially cause the system to attempt a network-wide chirp just for you.
Now multiply that by everyone, times the timeout to voicemail, on every tower on the network. Not ideal. You have no way of telling whether the call connected with the handset until the handset actually answers, or every switch gives up and returns cannot connect as dialed. You're a walking DoS attack because someone wants to call you, and you won't pick up your damn phone.
Furthermore, your scheme degenerates to the current arrangement if an always available mobile data connection is assumed, as your phone will just establish a session every time it sends data.
Basically, it's not the telephone part that makes you traceable. It's the "I can guarantee synchronous delivery part". And hell, even if you throw out the mobile bit, phone records still the you to a location; it just takes a bit more footwork and a cooperative witness/wiretap to prove it's you.
It's a pretty in depth problem, with a lot of nuances to be squirreled out. It takes a long time to explain, and even if someone could get most of the way there, that's only the start of the issue. I've got friends who have tried making ISP's before, and the amount of friction created by monolithic telco's is absolutely insane even when you aren't doing anything exotic.
You have to remember as well, telephony isn't magic. You're eating up bandwidth all the time. Stuff is incredibly fast nowadays, but everyone is using it too. Also, all successful networking suffers from tracibility problems. Things just get mitigated slightly by jurisdictional boundaries and the impracticalities of being able to trace through sufficient levels of proxy links. So it's not surprising you got a few "you really don't get it" downvotes.
Anyway... Hope that explains things, and I'm sure there's a bunch of detail I'm missing.
EDIT: Additional thinking: there's other reasons why a telco/mobile provider would want all handsets connected at all times even when not doing calls. It gives them an idea of where they need to install or upgrade infrastructure based on metrics w.r.t how many handsets are in the cell.
Basically, from a business standpoint, there is little reason to not go the direction that we have. The privacy concern does change things a bit. Not sure whether it would be enough to drive a push to abandon/change things so drastically. It's an interesting thought experiment though that I will happily cogitate on for weeks in my idle time. I like devising new protocols.
Criminals will adapt, they always do.
Because this was a bank robbery, it's a Federal warrant which is harder for Google to fight or procrastinate on (if for some reason they chose to).
Phones have a much more accurate location history since they can localize using AGPS. And with google location history turned on it stores that location to googles cloud.
Cops are only doing what makes sense. You can't really blame them. There needs to be a law that prevents them from doing it. Absent that, people need to stop being so liberal with their information.
This was a bank robbery, but the principle certainly applies to other activities as well. I mean really, do you really need your phone on you if you're going to see your mistress? I don't think you do.
“One man jumped onto the teller counter and pulled out a handgun, throwing down a garbage bag for the tellers to fill with money”
Outside cameras could have tracked them into a car, if it was reasonably close.
A security firm can monitor for false positive.
This would probably work for your average convenience store robbery too. In the US, we have a large market for security.
As with any real world problem, there are lots of obstacles. Sure, your AI will need to figure out if the gun is being pointed at someone, etc.
And whatever cameras the bank had, they were already recording.
Look at the grainy pictures.
https://fox6now.com/2018/10/16/recognize-them-hartland-polic...
"Our system zooms in on people who carry firearms. In addition, our network of cameras coordinate and will take several pictures from different angles and zoom levels. Furthermore, our AI looks for identifying features (e.g. moles) on the suspect's face, arms, etc"
How many bank robberies and convenience store robberies are there every year in the US? Why stop there? There's lots of gun violence in the US that lends itself to AI based security.
A better use of AI based law enforcement might be targeted against corporate+government institutions which actually harm people at scale.
Build whatever business you want. Thousands of companies are started every year.
Who are your customers?
A smart AI surveillance system might have 4k cameras, but not save the video in 4k format.
Instead, everytime a new face appears, it can use the maximum resolution to take a profile photo of the face for archival purposes and to calculate facial recognition.
If integrated into the banks software, it could match the faces to associated accounts by noting what account was looked up while the new face was at a tellers window.
If a robbery is detected through behavioral analysis or gun recognition, then the recording system would switch from 720p @ 15 fps (for example) to 4k @ 60 fps. It could also not just alert the police automatically, but could quickly pull up the associated account information, clips of previous visits discovered through the facial recognition, and send that to the police or have it ready for their viewing.
Granted the fusion center already have access to this information - alot of times they have to make it official to be admissible in court. So there might be something foul in play here(besides the blatant 4th amendment violation).
They did not find anything. But God help you if you have a prior record and happen to be black or match the description of the assailants... and just happened to be around the bank at the time.
Seems reasonable that you would be approached by investigators if you were present at the scene and matched a witness description.
The issue is that prosecutors don't act in good faith... and because of that legitimate exercises maybe used against people in illegitimate ways.
https://www.innocenceproject.org/
https://www.innocenceproject.org/eyewitness-identification-r...
https://www.innocenceproject.org/overturning-wrongful-convic...
The National Registry of Exonerations:
CURRENTLY 2,481 EXONERATIONS
MORE THAN 21,890 YEARS LOST
https://www.law.umich.edu/special/exoneration/Pages/browse.a...
I fit the description: I was between 5'3" and 5'11" and my skin color can be described as "coffee with a touch of milk."
Video evidence that showed, fifteen minutes before it happened, that I was 13km away at a wedding having dinner wasn't enough since I could have left immediately after the footage was taken and driven down.
I still have video evidence of the senior detective basically instructing the witness to select me out of a lineup. They also whispered to each other throughout which I only managed to hear thanks to some expensive headphones I had.
I made fake Facebook accounts and befriended all of the "witnesses" and victims. Beat the case on a technicality thanks to a post I found on Facebook by a eye witness.
I'd still be in jail right now 9.5 years later.
I'd say it happens extremely frequently, it's just that the people it happens to aren't as lucky as I am.
It's not something I'm particularly proud of or something I talk about - outside of my immediate family no one really knows all of the details, and only a handful of people outside of my immediate family know about it. It's the most traumatic experience of my life and had significant consequences on my mental health that still affect me daily.
My blind optimism helped me through it, but it had really hurt my family too.
Good luck and I'm glad the optimism paid off!
The general rule is not to talk to the police at all. Ask for an attorney if you're being detained; leave if not.
The line-up I mentioned was a photo line-up, where they place one of my mugshots among a group of other photoshopped mugshots.
They arrested me in the first instance, then released me, then arrested me again and charged me after they had performed the photo line-up.