Google Gives Feds 1,500 Phone Locations in Unprecedented ‘Geofence’ Search
forbes.com
forbes.com
https://www.nbcnews.com/news/us-news/police-used-google-loca...
via
While true, it's unclear how relevant this is. The equivalent police process of canvassing people determined to be likely bystanders also involves police interviewing and investigating people who turn out to be innocent.
Probably the relevant question is "Is there a fundamental difference between police identifying potential involved parties via eyewitness testimony and 'common sense' practices like looking for windows overseeing a crime scene and police fetching location identifiers from passive sensors?"
Naturally this hinges on whether or not your activity on google is yours or theirs. While their terms of service is clear, courts may have different opinions.
If it were, police would be prevented from executing warrants where evidence shows that stolen goods are being warehoused until they had an idea of who was doing the stealing, right?
The property typically has an owner. This is the individual to which I was referring, though this is obviously a metaphorical application like you need to do applying the constitution to modern day.
What's possible now was unimaginable when those laws were created.
However rationally I think there is a balance. Investigators need to do their jobs and chase every lead they can to catch criminals. I wonder if google could have complied with a query that simply grabbed the users in the areas during the 3 time periods combined.
Maybe we just need laws that limit how much data can be returned per warrant, to encourage more limited warrants.
Do they really though? This is the question.
Is there no other way to live peacefully and be good to one another without an overarching busy-bodied state apparatus causing perpetual fear even among the innocent?
I consider myself an anarchist in the sense that I believe that we should strive not to need government, taking responsibility for our own actions.
I do not currently believe we as a society have found a way to make that a reality :(
Just saying this is rational because investigators must do their jobs seems entirely ignorant of the obvious, implicit balance of powers issue here between free peoples and government authorities.
In short: There are, in fact, good reasons most civil liberty organizations fight against dragnet searches. It is not an emotional hunch.
- The laws that govern legal search and seizure have departed dramatically from the protections afforded by the bill of rights.
- There have been multiple incidents of companies not disclosing extralegal "cooperation" with state actors such as the US government (and others)
- Warrant canaries are legal, yet big tech refuses to use them. Why not? Because using legal methods to improve user privacy and security are not considered "cooperative" enough.
- We have no reason to believe that governments are following the laws, even in the US. The recently revealed CIA scandal illustrates just how out of control things are.
- There is now a revolving door between big tech and state intelligence agencies, and big tech is becoming increasingly sympathetic to authoritarian candidates and hostile to third party or far left candidates.
That, right there, is the problem. That should be illegal and should have been shot down every single time such a law was challenged in court. The fact that it wasn't says something about the status of the 4th amendment. And the lack of citizen revolt over this is disheartening.
"Fuck you I got mine" might just be the death of the enlightenment.
I'm honestly starting to contemplate how hard it would be to setup on Mars and breakaway from all current earth governments. Maybe the only hope is freedom of space travel.
Likewise, if live in SF and someone breaks in your car, the police won’t investigate it unless you’re A-Rod.
Why does SF have a sizable increase in property crimes over the past 10 years but a drop in violent crimes? I'd imagine if chaos did truly beget chaos, then rates of crime across the board would be going up.
It's often that crimes restore lost order and stability for some people. Not saying it's moral on one side or the other, but it certainly doesn't feel like a neat little package.
I respect the law, and the lawmakers should work for me. The ROI calculations are to be budgeted and accounted for, otherwise why am I being taxed?
In fact, most of the time, there's very little alignment, because there's no incentive to have those things be aligned. Sometimes even disincentive: there are laws on the books nobody wants enforced, and a culture in policing of enforcing the letter of the law, not the spirit—but one can always choose to not enforce a law one doesn't agree with by just making an informal agreement that certain crimes (of basically equal severity) take enforcement priority, such that those crimes nobody sees as crimes just get "de-prioritized" to the point that they're never enforced at all.
I understand the goal of this sentiment, but this is not how most societies work. Equality under the law is the proper ideal, but it's not at all how things work. There are a lot of reasons for that, from bias to lack of resources. But whatever the particular reason may be, most people only notice and complain about inequality when they are its losing side.
Make no mistake about it though, from the police at the bottom of the stack, all the way up to how the judges rule on cases at the top of the stack, the legal system has never been equitable.
>The ROI calculations are to be budgeted and accounted for Often this would require you to pay more in tax than the value you would get back from it. Are you ok paying $1000 to track down the person who smashed your window when you will likely never get any money from them or will you just pay the $100 it costs to get a new window which doesn't happen very often.
Generally, a tiny fraction of the population commits the vast majority of such crimes. People will do 500$ worth of damage to make 30$, work out what it takes to make useful amounts of money and these people end up destroying a lot of property. So, the ROI calculation needs to account for windows not smashed.
A good example is copper wire thieves. They pull up to a house and access the electrical panel in the garage which they turn off. Using a winch, they pull out all the copper wire in the house that's directly connected to the box (there's also many branch lines left behind). They then sell the wire as scrap for $20 or so and presumably use the money to buy drugs.
Fixing this damage can run $30,000 to $100,000. The whole house can have to be torn apart from the inside to reinstall all the electrical.
A massive miscalculation -- stolen wallets, cell phones etc are individually small-ticket items, but the criminals who make a living stealing them do hundreds per month and thousands per year. Taking the perpetrator of a thousand muggings or pickpocketings off the street is a job worth doing, possibly more so than chasing small time drug dealers or runaway teens.
You got a source for that claim? At least in the US, it’s significantly higher than any number I’ve ever read in a study / report.
"How much justice can you afford?"
Punishing an already poor and marginalized person is counterproductive to that goal, so we try to avoid it as much as possible. And that's probably who you're going to find on the other end of a car break in. So why bother looking?
So judging by off the napkin math on costs and optimistically assuming stronger enforcement would lead to 50% less car break ins, if strong enforcement costs more than $15 million is it worth it? When does the cost of enforcement become inconsequential to the results? A good question to debate on either side IMO.
That's not really the point, though. It's not just a simple monetary calculation. Even if the true value of repairs and stolen items was $30M, I would allocate several times that of taxpayer money just for the quality of life benefits, assuming it would do some good.
It's one of many reasons I moved away from there and do not entertain any job offers from that region, regardless of how much they are offering. At a certain point one needs to write off these cities. That or accept being a victim with no legal recourse knowing your car's going to be vandalized damaged and stolen on a regular basis and you are going to be hassled by guys with guns when walking down the street.
Spending more on the crimes with negative ROI, makes the total ROI higher because it acts as a deterrent for future would-be criminals.
Reddit was full of video of really trashy kids, driving their bicycles through malls and stores harrassing random people there, and "nobody could do anything" about them. If those kids were arrasted, sent to juvie, given community service (or maybe even just shown on tv crying in court, instead of acting all badass on their bikes), that would sure stop many others from repeating what they did.
Of course all of this feels gross, but as someone who was homeless in SF for a bit, going after people on the outs feels really backward.
I've had three home break in and robberies. In no case would the police even show up to take a report. In the case where my cameras identified the perps and I tracked down and documented them trying to fence my property, and worked with other neighbors to document an actual crime syndicate that was taking orders for specific things to steal, the police would do absolutely nothing. Police are about collecting fees from "in" drug dealers in return for looking the other way, while protecting their turf against incursion from rival drug gangs. They are also involved, along with judges in the USA, with child sex trafficking. The idea we need to give up freedom and be surveilled by these people is unrealistic.
"We can only give them a citation, and the thieves know that, so they don't care," said officer Pete McLaughlin (retired) to me.
Admittedly, this was in regards to stealing bikes and not into breaking cars, but I suspect the punishment is the same.
Surveillance still is one of the most uncreative and probably also one of the worst forms of crime prevention/reduction.
We don't need draconian surveillance measures enacted to solve this type of crime. We need police resources to actually follow up and prosecute petty theft for all victims, not just corporations and celebrities. A couple of years ago my father was involved in a hit and run when a man in a red late model corvette turned out of a small subdivision right in front of traffic. This was during morning rush hour on a weekday, there's only about a dozen houses on that road, and only one red late model corvette parked in the driveway of one of those houses. That single red corvette was also parked with a car cover on it afterwards. Even though there were numerous witnesses to the hit and run given that it was during morning rush hour traffic, and even though it is pretty obvious what happened and there are plenty of ways to get evidence to support it, the police couldn't be bothered to do anything about it. As far as I know, they didn't even so much as question him about the hit and run.
We're currently paying the privacy tax with existing surveillance yet people like you and me cannot benefit from that surveillance.
> Investigators need to do their jobs and chase every lead they can
That's circular reasoning. What they can and cannot do is defined by the rules we set.
Systems to associate 'burner' phones to individuals, with patterns of metadata, have been commonplace for decades
https://github.com/kimgr/asn1ate/blob/master/testdata/public...
What balance is there when one side operates without limits or consequence and can use gag orders and the ability to classify information to operate in secret?
The court system does a pretty good job, in fact that's why the police want to bypass it so often. It's much easier for the police to catch real criminals if they don't have to worry about due process (it's just that due process is what removes the false positives).
[0] Under many complex and often conflicting legal codes, this is admittedly a dubious statement. Add in budget issues and whoo-boy, might as well throw dice. But, in general, this is mostly true. Also, I am not a lawyer, consult your own lawyer.
[1] https://www.amazon.com/exec/obidos/ASIN/B00505UZ4G/ref=nosim...
[2] https://www.popehat.com/2018/12/18/alan-dershowitz-is-lying-... The book is HOTLY contested and Dershowitz may or may not be an insane person
This country was founded on the principles that all governments decay, and all legislation should take this into account. We can't give the government power which could be abused to public detriment with a simple change in leadership.
I upgrade infrequently. Recently I was alerted my 3G phone is not going to work after December 31 as 3G networks are being shut down in the US nationally and all bandwidth reallocated to 4G only.
So, I've bought and returned 4 phones since then because I very carefully read and analyzed the terms of service and privacy policy that I couldn't read until buying them. All were totally and completely unacceptable in every way to me. But obviously not to others.
As a result come the new year I'm going phone less. I literally could not find a single contract that was not morally reprehensible.
I know of not a single other person sharing my concerns. Some say I am a mad man or unreasonable or unrealistic, or a potential terrorist ne'er do well. But I'm none of those. I just read the contract. Something they, and no one else in the entire USA, has done.
There is a balance. I know this is Hacker News and we're all supposed to be progressive technical vanguards fighting against The Man, but genuine bad guys exist out there. And we need to protect ourselves from them.
This isn't a case of an innocent man going to prison just so we can jail a hundred criminals. This is giving up a modicum of privacy in order to make the world safer for everybody. I think that's entirely reasonable.
It is no surprise that people like you still romanticize the notion of state violence and greater authoritarian power. Fascism is always popular amongst certain types.
Is our government getting increasingly Authoritarian and Repressive? Yes. Are we anywhere near fascism? Fucking no
This isn't rational, this is purely emotional. This could be a statement from a police officer that did see some awful criminals, but that would be filed under being emotionally compromised.
If you look on large scale threats to the general population, this kind of surveillance poses a much bigger risk.
I doubt this is about protecting people or preventing crime. Justice comes after the fact and is all about retribution. Depending on the crime, the damage done by perpetrators can never be undone.
> This is giving up a modicum of privacy in order to make the world safer for everybody.
How far will you go? Would you give up all privacy for safety? What if society's idea of safety doesn't align with yours?
There is a crime, you get a warrant or subpoena and you act on it. As long as it’s transparent it works. This idea that percolates particularly from the very left of the software community is dangerous as you pointed out.
They are so anti law enforcement they’d prefer to never help law enforcement do their job but at the end of the day, an overwhelming majority of the crimes they investigate are in support of actual crimes and not some oppressive government overreach.
It’s ok to not trust law enforcement, the US is built on distrust of government.. But then don’t cry bloody murder when nothing gets done because now you’ve tied their hands so much that they can’t investigate properly .
There is an excellent podcast called intelligence matters where an FBI chief went on to talk about end to end encryption and said something along the lines of yes e2e encryption hinders their job but if the public wants and supports that. Then they’ll have to work around it as long as the public understands reaction to crimes will be slowed drastically or go uninvestigated due to lack of evidence.
could be a charging lock box with a little accountability like the ones at bars and clubs
Sorry couriers you never had a chance for additional income, already replaced within 45 minutes
1) Governments have law and warrants allowing them to get those data.
2) Companies with a lot of data are complying with those warrants.
The question is: can we fix #2 without fixing #1?
The only real way to address #2 is by finding a way for companies to get all the value that comes from having this data without having to store or even process it.
If you catch a child doing something they aren't supposed to... Say sneaking chocolate you hid in your closet, when you aren't looking, and you don't catch them doing it until a week later; are we seriously going to entertain that the right action on catching these misbehaving children is to let them keep/continue to reap the benefits of their ill-gotten gains? That's what allowing the continuation of this metadata collection sounds like it amounts to to me.
This pervasive invasion of privacy is not normal, never has been; nor should it ever be.
Not breaking the capability for companies to engage in surveillance capitalism represents an implicit acceptance of the nullity of Constitutional protections through indirections facilitated by Third Party Doctrine. That is not okay.
Again, the question becomes: can you fix the child's behavior without fixing the fact that they are legally required to follow the police's words with no recourse?
In many cases, they're using it to do things users like. Such as estimating commute times. Or do demand modeling and understand where they should upgrade cell networks.
You can offer services without these things - and please do! - but expect users to notice.
It's just so far proven to not be as large as one might hope. Consumers, when faced with services that don't offer them the features they want and higher prices, often think twice about preferring privacy.
There's a lot of money to be made by someone who finds a way to deliver the full-fat experience consumers want at the prices consumers are used to while also respecting privacy. Until then, I expect things like Purism and Protonmail to stay fairly niche concerns.
Does this have to do with Pixel phones? Or the Google Maps record of a person's device location (which goes across many device types and doesn't even require smartphone)?
From my understanding, in the case of Android (with Google services), if you have location history turned on, that location data is pushed up to Google at very regular intervals.
You don't need to be using a specific app.
It's high time for me to get off of this bus.
I haven't been able to find any real dumbphones that will work well in the US (non-LTE call service being phased out). Where are you and what do you plan to use?
https://ting.com/shop/alcatel-go-flip_Black-4GB-refurbished-...
I guess from the description that it does have some internet capabilities, but I would assume they can be disabled.
Another option if you're just trying to get away from Google/Apple would be an Android phone with Lineage OS and no Google services. You loose access to the usual Play store apps, but still have a lot more capabilities than a flip phone.
There is also microG, a free reimplementation of Google Play Services, which would allow you to even use apps that depend on that (for instance, for push notifications).
Of course what I actually recommend is doing neither of those and only using apps from F-Droid instead. But it is an option.
Obviously there's some inconvenience here, but it has the nice property that assuming you can use wifi at your main locations (home, work, coffee shop, library, etc), you'll only ever be on the cellular network in between places. And because the stick is naturally de-powered when not plugged in, there's no need to seek out a battery-removable phone.
Unless you're using the phone for a lot of calls and texting, it's probably not much worse to do it all from the "pocket computer" or laptop than to have two separate devices.
In any case, I traveled overseas ~12 years ago with no phone and just a white MacBook, so I'm aware of some of the compromises required, things like saving pages and making screenshots of maps, always on the lookout for places likely to have free or inexpensive wifi.
If you care about that stuff, you should abandon carrying a phone--switching away from a smartphone is probably useless if not counterproductive.
Alternatively what RMS does is he shuts off his phone and only turns it on when he needs to use it.
I mentioned radio, because wifi / cell tower triangulation can be used to infer location.
Or at least I know that in one court case there was a nice big 8x10 of the defendant purchasing a burner phone. Apparently a lot of Point of Sale systems, especially where they sell burner phones, are wired to take a nice portrait of you when you purchase. I didn't know that at the time, and apparently, neither did the defendant.
That, combined with the location of his phone matching the location of his license plate around town did him in.
So if you try the burner phone thing, someone else has to buy it, and you should never take it with you to places where there are likely to be security cameras. And you also might want to refrain from driving with it in your vehicle.
However, if state persecution isn't part of your threat model, a burner is one layer of indirection that might make tracking and identification difficult for surveillance companies.
He also only browses the internet by emailing himself text/HTML from a remote server.
Once I've completed the project, it's very likely that I'll write it up on one of my websites. I'll submit the link to HN at that time so everyone can see what I've done.
The short and sweet, it's an ARM-based micro, with WiFi, Bluetooth, a couple of USB ports and an HDMI output (to use with a HUD that I have). It will have an old-school color 4-inch LCD with resistive touch for its screen (not ideal, but the best I can do right now. I'll work on upgrading that to an OLED w/capactive touch in version 2). It will also have 8 physical buttons, because I like physical buttons. It will be in a 3D printed case. The total size will be roughly the same as an average thin smartphone, but will be a mm or two thicker.
It will link up with my watch, which will be the primary way I interact with it on a daily basis. My goal is that 90% of the time I won't need to actually handle the device itself.
Are you using an existing smartwatch or building something yourself there too?
Come to think of it, would an iphone with the cellular network disabled do?
There’s just something about running LineageOS on an old Galaxy Tab 2 (still Android, although apparently the hardware support is phenomenal) that has me trawling eBay for cheap tablets.
This is true. But I'm not a privacy absolutist. I'm willing to sacrifice privacy for some things, and having a phone is one of those things.
But that I'm willing to put up with that from one company in no way means that I'm willing to put up with that from other companies.
> switching away from a smartphone is probably useless if not counterproductive.
I don't see how -- can you explain? Reducing data leakage seems useful even if I'm not completely eliminating it, and I don't see how it's actively counterproductive at all.
There is a large amount of $$$ that goes into security of iOS and iPhone (sometimes orthogonal to privacy, sometimes not) that does not go into a dumbphone. The iPhone is also much more scrutinized and researched into than a random dumbphone, so it is plausible that you get much more exposure to exploits, etc., using a dumbphone that does not get updates etc.
It seems unlikely they put the same efforts into finding a zero day for a nokia. There might be a super easy to find zero-day though, like you're saying.
There were always obscure pieces of software that would pull your forgotten pin right off the device with the right secret code, in which case you have full access to the device.
I'd also expect them to be vulnerable to much simpler attacks like just reading flash chips directly
What's your threat-model? If your adversary is a nation-state on par with China, you're probably toast unless you have a well-resourced entity supporting you (think large corporate or another nation-state)
The dumb phone has no access to the pocket computer, after all.
edit: In a laboratory environment, it is probably easier to break into a dumbphone vs breaking into an iPhone, yes.
I can't tell you which results in better opsec today for say carrying out government-disapproved commerce. But I can tell you that the privacy benefits of having a bona fide computer that you control in your pocket will continue to grow, while the cell network is stuck being forever subservient to government/commercial surveillance.
Source: it was one of my less-unsuccessful projects :)
I'm always confused by statements like this. What makes you think Google and Apple are any different in willingness than Verizon and AT&T? Or what makes anybody think any of them even have a choice turning over data on their users?
What do people think other people do when some law enforcement agencies show up on their doorsteps with warrants?
Also, empirically, I trust Apple and Google to keep data more secure from hackers than AT&T.
(I was also careful to use “blanket” requests as opposed to warrant in my original post)
We can protest all we want and these entities would be ready with their PR script, about how they value their users, blah, blah, blah. Because, they know, at the end of the day, users are going to come back to them, use their platform to protest.
Unless there is a mass exodus towards p2p & decentralized network, these entities aren't going to budge, not an inch!
Case and point, if you've enabled location history for your Google account you can take a look at your own history and see for yourself just how easy it would be to identify someone given the power to subpoena surveillance footage, vehicle registration records, driver's licenses, etc. For my own data for the month of November right off the bat I walked to a nearby McDonald's and paid with a debit card. Even if they didn't have surveillance footage from all of the cameras in the restaurant they still have financial records of the small number of orders that were placed soon after I walked into the restaurant, that combined with the driver's license addresses and vehicle registration records in close proximity to my house would almost immediately identify me. Even just looking at where someone lives is enough to narrow it down to a tiny list of candidates and for >90% of citizens they are going to be on some record as having that address. In short, tax returns generally indicate where you live, as well as specifically state if any dependents that you claim also live with you. Then there's utilities which are just about impossible to avoid, then there's property records which don't need any subpoena as it's literally public records posted on a searchable website for most (all?) of the country. Voter registration data would also tie an individual to an address. USPS, UPS, and Fedex would be another easy way to come up with candidates, the list goes on and on but unless you're homeless you're going to be on a list somewhere. The next day after the McDonalds I drove to WalMart, where I again made purchases with a debit card and walked around in plain view of a plethora of surveillance cameras and again, just from the time of arrival and the time of departure you can narrow down the list of candidates to a relatively small list and I highly doubt any of my immediate neighbors also went to WalMart at the same time as me and left that WalMart at the same time as me. Also even if WalMart did not cooperate with any subpoena or if I paid in cash, it's not uncommon for private companies to drive around with a license plate reader through parking lots cataloging which license plates are present at a location for the purposes of selling that data to repossession companies looking for cars. I drove to that WalMart in a car registered in my name. After that there's a very obvious pattern indicating where I work and when. The company I work for files payroll taxes, none of my coworkers live anywhere near me, assuming it's just less precise positional estimates that a phone company would have for E911 purposes maybe they'd need to also look at the surrounding businesses as well but still, end of the day I think it's highly unlikely that my neighbors right by my house happen to also work right beside my employer. Right after that I travelled to one of our branch offices which would very strongly imply that I work at my specific employer and not the one in the adjacent unit. After that there's more visiting restaurants and gas stations and paying via a debit card as well as visiting my parents house. That's all in the span of a single week. Even with just a coarse history of the location of my phone it's absolutely trivial to identify me specifically. In fact, just off of the property records alone and some public records to determine employment history and family relationships I'd bet it'd be relatively easy enough to identify me by name even ignoring all of the different areas where police could simply subpoena payment records or surveillance footage.
Location data, even coarse location data, is definitely enough to identify almost everyone if you're in a position to correlate that with additional records. Unless you have your burner phone turned off almost all of the time, it really doesn't matter if the phone provider doesn't have your name, there's so many other sources.
You should also abandon:
- Dumbphones (AT&T will give LEO all the same information.)
- Landlines (AT&T will give LEO all the same information.)
- Automobiles (Automated license plate readers abound. I suppose if you never drive on a toll road, or an arterial, or within line of sight of a cop car, you may still be OK...)
- Public transit (Passes + pre-loaded cards are the only reasonable way to use them, nobody is going to be fishing for 2 dollars and 3 quarters every single bus trip - and your travel is recorded.)
- Private transit (Uber, Lyft, coach buses, airlines all keep records of passenger travel. I guess you could hand-hail a regular taxi, and pay in cash, if you live downtown, but as we all know, HN hates taxis.)
- Debit cards (Payment processors will give LEO all of your information, and sell the rest to other companies.)
- Credit cards (Payment processors will give LEO all of your information, and sell the rest to other companies.)
- Bank accounts and cheques (See above.)
Have fun commuting by bicycle, paying for every minor purchase with a mixture of one-dollar bills and exact change, and communicating with your acquaintances by carrier pigeon, snail mail, and semaphore.
Alternatively, you can accept that the 21st century is a world where every third party you transact with is constantly making records of those transactions, and where (in the US) the law of the land allows law enforcement to compel these third parties to turn over those records. [1]
You'll be in the company of people who are outraged that passports are required to travel, and that you have to do a background check, credit check, and criminal record check to get a job flipping burgers at Mickey D's.
[1] If you really want to make an impact, this is actually what you should push on. It's much easier to change, than to make every single firm you transact with not keep records.
If you can't get access to third party record rules overturned (Good luck, there's centuries of legal precedent for this sort of thing), it's not a hill worth dying on.
If you turn it into a battle, you will be fighting that battle with every single organization that you will ever do business with. You are not going to win any meaningful number of them. Since some of these organizations are monopolies, or duopolies, you can't meaningfully make a choice to opt out, short of becoming a cave hermit.
If you do want to fight, fight the problem at its root - whether or not third party data should be accessed by LEOs through a warrant[1], how it can be shared with other organizations, and what purposes it can be used for. The (much-reviled on HN) GDPR happens to go a long way to address the latter two points...
This requires legislature, not grand-standing about cherrypicked examples. But for various reasons, the hacker community is very much against using legislature to solve these global problems, so it sticks to grand-standing. [2]
[1] As I've mentioned before, centuries of western legal precedent believe the answer to this is 'Of course, how is this even a question?' I don't think that's going to change in my lifetime.
[2] Consider your own example - do you think it's more productive for you to boycott the clerk that wouldn't sell you cough medicine, or to try to change the rules for what requires, and what does not require ID?
https://oag.ca.gov/system/files/attachments/press_releases/C...
You're not telling me anything I don't already know, but I think you're overlooking the asymmetrical problems wherein it's far easier for corporations to collect data (even with these regulatory requirements) than for individuals to maintain even basic privacy.
This smacks of the same stupid arguments that you cant possibly not like huge amounts of corporate money in politics if you dare purchase anything from a corporation.
Attitudes like this ensure that nothing changes, ever.
The comparison I'm presenting is trivial. OP has issue with third party collection of their records, and is dumping smartphones. I point out that this will accomplish nothing meaningful in reducing the global third party collection of their records - especially if they switch to a dumbphone.
This is why I always lol at people putting duct tape over their laptop webcams when their phone cameras are completely exposed always and taken to much more private places than their laptops. (Phone microphone too.)
You basically have to accept that nation-states know everything about you and will always know everything about you. Therefore the only practical goal of personal opsec is protection against other civilians.
You need to think in terms of risk assessment and onion security. Use your most secure and cumbersome security apparatus for activities and data that afford it.
If you don't want ANY data to be collected about you, anywhere, you're going to have a very hard time. Not even fully analog people can easily manage that anymore.
In summary, ask yourself what you're protecting from. I've gone through a paranoid phase and learn all of this the hard way. It's not fun and brings little tangible benefits.
Trying to evade a governmental body who is interested in me specifically isn't really on my radar at all, in part because I'm not interesting to such bodies, and in part because if that becomes a point of concern for me, then I need to stop carrying any devices that transmit radio signals at all.
Threat: The Mossad doing Mossad things with your email account Solution: Magical amulets? Fake your own death, move into a submarine? YOU’RE STILL GONNA BE MOSSAD’ED UPON
http://scholar.harvard.edu/files/mickens/files/thisworldofou...
One day I will do this.
Technically I do have a 6 year old Android something-or-other my sister gave me that I use sometimes on wifi (no sim card in it).
I do think I might get a sim for it soon for the convenience, though my usage plan will be different than most people.
Leave the phone off 99% of the time, and just turn it on when I want to use it for something - make a call or send an email.
Install zero apps so I never get notifications or have to deal with things that intrude into my life.
Essentially I will have the phone so I can use it when I want, but not so that it can get my attention when I don't want. It will be an interesting experiment.
A far more reasonable - and less freightening - request would be: which customers were in 3 of 4 or 4 of 4 areas in the time windows. People of showing up once or twice are likely not suspects.
[1] > The requests, outlined in two search warrants obtained by Forbes, demanded to know which specific Google customers were located in areas covering 29,387 square meters (or 3 hectares) during a total of nine hours for the four separate incidents.
Well I do.
If they had narrowed what information they collected to the absolute minimum and deleted it as soon as it was no longer required, then they wouldn't have any information to give.
Information is a "toxic" liability. Google chose to hoard it. They are absolutely liable.
In fact on every new device I seem to have to enable it separately.
Google often doesn’t provide information right away, investigators said. The Google unit handling the requests has struggled to keep up, so it can take weeks or months for a response. In the Arizona investigation, police received data six months after sending the warrant. In a different Minnesota case this fall, it came in four weeks. https://www.nytimes.com/interactive/2019/04/13/us/google-loc...
Also: https://www.engadget.com/2019/04/14/surge-in-police-requests...
We should try to limit the gathering of, because once they have it, it's over.
a phone is a PUBLIC device ruled by the courts.
Putting the words “Privacy“ and “Google” in the same sentence is a permanent oxymoron in my view.
If not it is a setting not a feature.
I'm pretty sure it asked me if I wanted to enable Location History separately, but not 100%.
https://www.hackread.com/google-collects-android-location-da...
As far as Google is concerned - I'd have them not store the data in the first place, and at a minimum have the spying be opt-in, instead of out. But I can't fault them for what they did after getting the warrant. Ideally they would try to fight it and get a supreme court ruling, but that's squarely in the good bucket. As it stands, the best I can hope from them is to be neutral, or at least not too evil.
But equally, they have become a form of 1984 in which the citizens freely pay for and constantly upgrade. Orwell never saw that aspect comming.