My Phone Was Spying on Me, So I Tracked Down the Surveillants
twitter.com
twitter.com
> One of them was 31-year-old Karl Bjarne Bernhardsen from Stavanger. The information made it easy for us to identify him in the data that – according to the data provider – had been anonymised.
Here’s that article:
https://translate.googleusercontent.com/translate_c?tl=en&u=...
And the HN thread:
https://www.sygic.com/company/eula-gps-navigation-google-pla...
So, essentially, I'm now locked into this agreement with Sygic for the duration of my "lifetime" license.
This is one of those situations where I'd wish I had some "fuck you" money to throw at an expensive law firm.
Your privacy is not something they care about except as something to sell to others.
I rarely carry my dumphone around, if someone needs me they can leave a message. That takes care of tracking by cell station.
There are times I'd like to have a dumphone on me, eg. when meeting people, so at some point I'll get dumphone #2 not linked to me.
If possible, pay cash rather than a credit card. I have done this before but in the uk this was getting more difficult and may not be possible, I don't know. There are always ways around that with grey areas.
At higher levels pressure your government or use the local regulations to push back when a company seems to be behaving unethically.
I'm sure there's more.
But convenience triumphs and all you can see is "I need smartphone". You won't do any of this. People who ask how will never do, or they wouldn't be asking the question to which the answer(s) are obvious.
You seem absolutely determined to be both resentful of society and completely powerless against it, and not willing to actually do anything to change anything?
Well, I was talking about smartphones so you seem to have moved the goalposts with your questions so that my answers don't apply -- deliberately, to emphasise helplessness?
But okay, let's try
> GPS chip in car
I don't know anything about this so, don't buy such a car. If you do, is the chip enabled without drivers control? I'd be surprised at that.
> License plate readers?
To some extent I guess these are necessary, but they are a usable so you have to deal with this at the level of government rather than directly.
> Face recognition cameras
This has to be tackled at the legal level, and yes, it does concern me. Fortunately in a democracy you have some say. Unfortunately I don't think you will make the effort.
> Chip in the credit card...
Oh for heaven's sake, it's not broadcasting your location it's RFID, and if you want to disable it you can find instructions online. You basically make a small cut into the side of the card which breaks the antenna loop (or whatever it's called). I literally have done that and it took me a few minutes.
> Friends with my phone that have your number
Is this a serious objection? They can't track you via somebody else's phone -- did you even think about this before writing it?
> ID cards that swept into places
This really is scraping the bottom of the barrel. I've had worked cards like this, they simply let you in and out little more than an old-fashioned metal key, with a record being made. You can't be tracked by them other than when swiped.
You seem to have embraced failure while resenting it but it's clearly what you want.
The problem isn't DID or anything like that but a strange attitude that they want nice things but will put in zero effort to achieve that even if shown basic steps, and have a mindset that they're totally fucked, everything's against them, they can't win. It's a kind of learned helplessness.
I hate this whole premise. We have to agree to an incomprehensible text wall of vague legal nonsense, that very often violate our own laws (as in this case), in order to install an app.
These illegal contracts are completely void of any meaning, and it should not matter that you "agreed" to be screwed over like that. Being screwed over like this is illegal, so those who do this, should not stay safe just because you clicked "I agree".
More precisely, these agreements generally aren't legally binding in Europe, but generally are legally binding in the US.
Personally, this is what I detest the most. There's always a bit in the boilerplate that's akin to "you agree to everything here, even the unenforceable bits. If we're ever challenged on the unenforceable parts after the fact, you still agree to be bound by everything else here."
IA[very_much]NAL, but to me this always sounds like "We can and will stick whatever nonsense we want in this contract, whether the terms are illegal or not, and you will be bound by them for as long as we can get away with it. If you do ever discover the illegal bits, that doesn't void anything else (including any other illegal bits you haven't found yet!) and you can't sue us- you've given up that right and can only use a mediator from our approved list. May the odds be ever in your favor."
This is separable from the abusive nature of ToS of course.
That sounds like a good thing? Why should abusive illegal contracts be allowed to continue after the law has found them to be unacceptable?
It's one thing if the legislation is specifically targeting those contracts, quite another if the unintended consequence is much broader than you intend. It's easy enough to imagine legislators unintentionally invalidating basically all of a states employment contracts this way, for example.
> Signer agrees to become contract murderer unless pre-empted by local laws and regulations.
I'm over-exaggerating, and I get the value when it's prohibitively expensive to write a TOS when it's essentially impossible to pre-emptively vet the legality of all possible clauses internationally as laws constantly change. But if the clause I wrote is technically valid, then what's the point? Just write a short phrase saying "We're going to do whatever we like, unless it's prohibited by law. Accept? Y/N"
Literally who cares? Let them deal with it. It doesn't matter how much money they lose. They should have considered the consequences of abusing people's trust and violating their privacy under questionable consent.
Corporations are vastly more powerful compared to individuals. Courts obviously need to favor the latter in the vast majority of cases. To do otherwise is injustice.
"doesn't matter how much money they lose" -- of course it does, these companies employ people and generate lots of government revenue (even if they skirt corporate taxes).
There are political and economic concerns, not judicial. The fact the company is important does nothing to remedy the fact that it exfiltrated private information to foreign intelligence agencies.
I'm afraid you are correct, but hasn't the whole system collapsed if:
- Is this good for our businesses?
is is part of your consideration when you are trying to find out if something is illegal or not?
Example; how one individual singlehandedy forced the hands of Spotify to reverse an API decision they made blocking the export of your playlists. Note how Spotify thinks their TOS supersedes the GDPR. It does not. Otherwise, we would have corporations directly creating laws.
For example the UK's enforcement arm, the ICO, recently found that the adtech industry was in violation of the GDPR, then did nothing:
https://www.openrightsgroup.org/blog/the-ico-must-fix-the-ad...
As far as I know, I can't personally sue these companies for this, and if the ICO does nothing then what's the law is meaningless.
The follow up from the Open Rights Group is here:
https://www.openrightsgroup.org/blog/parliament-must-hold-th...
If you care about privacy in the UK, please donate to ORG, I started a direct debit years ago and have always been impressed with their work and focus:
Couldn't you sue ICO then?
https://action.openrightsgroup.org/help-us-protect-your-data...
Reality is generally less fussy about categorical boundaries. It likes spectrum. Linnaean classification is an approximation. Biology isn't strict about species, or even organism barriers. It's the same with a lot of cultural stuff.
On one end of the spectrum, we can have a business agreement negotiated diligently and in good faith between equal partners. On the other end, we have take-it-or-leave it agreements: The T&Cs stack a bank hands you when you take a loan. The wall of incomprehensible legalese we consent to when we use an app or website. An employment contract is somewhere on that spectrum. Employees may be able to submit "red line corrections" depending on their seniority and confidence, but generally its written by employers and treated as under their control.
In philosophy, contracts (including rhetorical ones like "moral contracts) are a popular mechanism for problem solving. They certainly are in law. In normal human life, norms are much more common.
Partly it's because consumers cannot tell a good from a bad contract.
And partly I think it's that a lot of people say the right signals ('I care deeply about privacy!') As it's the cause de celebre, but don't actually care.
Sometimes they just want to watch Hulu without going on a stallman esque campaign.
Most people of course, akin to how paying with card makes you overspend because you don't see the money, agree to anything because it's just a button on the screen not a potentially predatory human person.
In the case of overly vague terms of service, people agree to them because there are essentially no options or alternatives.
Sure, it does not help that people agree to them without thinking about it. Which is somewhat similar to people spending money without thinking about how much they have.
The whole culture around closed smart phone apps is completely rotten.
When you install an iphone it's even worse
They have a screen describing privacy.
You can click and see the privacy policy.
And then the privacy policy is actually pages and pages and pages of pointers to individual sub-privacy policies.
and there is no "I agree", they just show you all this.
You can opt out of some things later, but already they're a token gesture.
It can always get worse...
> .. pages of pointers to individual sub-privacy policies.
At this point expecting someone to have read them is just nuts. The "lawsuit culture" in the US, where you have to guard yourself from possible lawsuits all the time, have made these legal contracts comically bad. They have always been strange, since you typically get to read them after you unpack the phone/computer etc.
Seems as reasonable a way to negotiate the contact as the way it was presented to me in the first place.
After all, is Democracy not the best mechanism possible for executing the aggregate will of the people? And would the will of the people not be to not be tracked in this manner?
I predict this undesirable situation will be eliminated in less than one year - or, in case it is more complicated than it seems (and therefore takes more time to resolve), will at least have significant attention from both the government and the media until it is resolved to the satisfaction of voters.
I will keep my eyes open for an upcoming entry for this matter on the "Top 10,000 Concerns of the General Public" KPI tracker where we monitor matters of public concern like this, and I will use 10 of my monthly allocated voting units to express my level of concern.
Well sure, relevant being the operative word here. For the US CBP the only relevance is US law, since the USA has no concept of data subject ownership -- in the US, all data is owned by whoever holds it, not who it is about.
FTA:
In a statement, Senator Ron Wyden said “Venntel has stonewalled Congress for months and refused to identify the sources of the data it is selling to Customs and Border Protection and other government agencies. The U.S. needs far stronger laws to protect Americans’ privacy, and ensure transparency about where our data is going."
Another thing that I've started using recently is NextDNS[1], and it's amazing the amount of tracker garbage that's leaking out, and being blocked on a DNS level, out of almost any mobile application.
[1]: https://nextdns.io/
I didn't readily find a list last time I looked, so I'm not sure how single person dev shops are getting hooked up with these privacy bypassing hydras.
From DNS logs in Nov 2019, I had found some of the more common on iOS a year ago included:
iOS “User Linking” Trackers
[business].app.link
[business].onelink.me
[hash].ulink.adjust.com
[business].bttn.io
bnc.lt
branch.io
Some of these you can see who uses them, thanks to subdomains:
https://securitytrails.com/list/apex_domain/app.link (2962)
https://securitytrails.com/list/apex_domain/onelink.me (998)
https://securitytrails.com/list/apex_domain/bttn.io (60)
These are different from iOS Measurement Trackers such as:
events.appsflyer.com
reports.crashlytics.com
api.mixpanel.com
app-measurement.com
But it's gotten enough worse I almost want Apple to implement Little Snitch style blocking at the network layer, and offer a measurement anonymizing API that devs can use and is whitelisted by default. Ensure legit usage/debugging info is anonymously available, while use of other trackers would then suggest other motivations at play.
This is exactly how it works on Android as well (since version 10, IIRC).
Is there any way to mitigate the amount of data collected?
If I turn GPS off can they still track my steps?
One thing that I notice frequently is discussing some topic with my wife and then finding an AD related to the topic on Instagram, LinkedIn, and whatnot. Could be a coincidence but I not sure any more.
In the background, the phone uses its gyro sensors so it can tell what you are doing: walking, running, getting into a car/sitting down, getting out/up, ...
The unsettling part is that location logging continues to work with the phone off (saw an admittedtly obscure YouTube video on that which I can't seem to dig up again).
Like the Kindle, airplane mode also doesn't stop data from being transmitted to the overlords. It merely delays it from somewhat real-time to whenever you go online again.
There are specific bits of malware that make the phone appear to be off when it is in fact powered on. Such malware typically requires root access or an exploit, and is the realm of shady governments not advertiser's. But if you don't have that malware, you can't be tracked when the phone is off.
It would be fun to see if you could get a modern phone to shut up for even five seconds when powered on.
I’m very skeptical about this. I’d be interested to know how a phone could track location info while powered off.
If at any point this actually became a reality the OS would start treating mag access as needing location permissions.
Location services doesn't disable bluetooth. If you're in a dense area, your local stores may have bluetooth beacons which will report location hits against your bluetooth ID, which may be tied to you through applications you install.
https://www.nytimes.com/interactive/2019/06/14/opinion/bluet...
https://www.zdnet.com/article/us-cell-carriers-selling-acces...
It wouldn’t surprise me at all if baseband processors eventually start logging and asynchronously sending gps data to the cell carriers behind the operating system’s back, so you should also keep it in a mylar sack.
Similarly the accelerometer can gather all sorts of information (passwords, text typed on the keyboard, are you driving, flying, walking, etc), so you’ll probably eventually need to keep the phone in a drawer to avoid leaking that information. Similarly for the microphone (some surveillance libraries already snoop sounds in various primitive ways).
To recap: keep it off the network in a stationary, electromagnetically shielded, sound proof box. That’s simple enough, and from there you can use it as normal.
If it were true I feel confident that information would have leaked by now.
Yeah, there's no way for Facebook to be actively listening to conversations on millions of phones connected to private home networks without someone noticing. And that's not even addressing that someone currently or formerly working at Facebook would just blow the whistle at some point.
The problem with this conspiracy theory is that people just don't care about numbers and facts. They usually have an anecdote ("I was talking about cheese and hour later I got an ad for cheese") and that removes any need for hard evidence. Hard evidence that shouldn't be that hard to collect considering you own both the device and the network on which this supposed listening is happening on.
Spoiler: it actually does not happen. As the other person commented, snooping like this in scale would leak.
Edit: since you're asking, proof could be multiple testimonials from ex-engineers working on the project or a peer-reviewed article in a serious journal. Until that this is in the same bin with healing crystals and chemtrails.
Whistleblowers never prosper, at least in the US. Too many examples, take Stingray for a less controversial one. What was the result? Crickets. Exactly what would be the incentive for those engineers?
Myself, I'm a Bayesian and I grew up in a communist country, which means I start from "of course everyone is spying on me, all the time" and require strong evidence to change my mind.
You're expecting 100% of the engineers at Facebook (or previously at Facebook) that know about this to comply with the NDA. And history shows that 100% of Facebook employees will not keep quiet about Facebook doing bad/illegal things.
Where?
Besides that just don't install any apps you don't need. Stick to open source software, install a custom ROM on your phone, don't use Google location services, etc.
The iOS counterpart blocks location requests quietly when the app is in the background and allows them when the app is in the foreground.
One particular day I remember specifically because had a long call with friend who lives in some other city. We talked about meeting sometime in future, dating, job situation and travelling to Canada/Europe.
With in hours I received promotional email about "travelling to the city my friend lives in". Dating site AD. Looking for Job and article about how to travel move to Canada/Europe.
Fun day.
People only think about Facebook, but there are other AdTech companies as well which do not get scrutinised as much.
I have not named apps / companies I that were not relevant to this feature. I found other things, but I had to focus on a clear story.
[1] https://www.macobserver.com/news/background-app-refresh-data...
After I disabled background app refresh I installed a firewall (https://www.lifewire.com/why-you-need-a-firewall-app-for-you...) - in my case the open source, security audited, on-device-only firewall "Lockdown" see https://lockdownprivacy.com/
What I've immediately observed after switching to the new phone that I'm receiving more precisely targeted ads. Before, on smartphone no adds were relevant, after the smartphone new adds were all relevant.
My guess was the phone / the cellular service company is listening me all the time, not just when talking on the phone.
To test it we've started playing games. Sitting with friends, we've used a predefined brand name very often in a conversation. Next day I've got the ads on the social media, on my laptop, I have no other internet device.
What I'm doing now? Not using the phone at all. Which means 1-2 daily quick conversation to set up places to meet. For long conversations I use email or messengers.
How do I feel? It doesn't bother me at all. I'm not paranoid. I know we are all sold since the blogging era begun. Right now what I can do is to make the lives who exploit data harder in this particular case.
Edit: My phone is Nokia 8110 4G, with KaiOs.
Tracking is how cell phones and cell basestations work. You cannot have one without the other. The better the clocks in the base stations the better the multilateration accuracy. It's already well under <100m. That you turn off GPS positioning does not matter in the slightest.
As for listening to you to provide context for what ads to show, I find that supremely unlikely. Probably other aspects of your digital life are also monitored to inform this kind of thing.
Just in case somebody wants to reproduce the experiment.
Say the name of 20 places on a call (but never you nor any facebook contacts go there) [and have 20 controls you never mention]. Then count ads over the next month.
You can conclude something to a certain confidence level if the results show you were right.
Anyway, I don't want to convince anybody here, I might be pretty wrong. Just helping others who might have the job to verify all these findings.
This is more likely plain simple confirmation bias. The ads were there before, you just never noticed them.
https://www.digitalcitizen.life/how-block-internet-access-sp...
Transparency is just a first step, but it is a powerful tool.
(From the "Method" part at the end of the full article : https://nrkbeta.no/2020/12/03/my-phone-was-spying-on-me-so-i... )
Contact tracing addresses that shortcoming of the current surveillance tech. Today, finding out that 2 cell phones have been in proximity requires computationally expensive analytics on the server side. With the apparently mandated requirement for contact tracing, edge devices ("your" phone) will simply detect proximate "ids" and send that to the servers and that trivializes the task of determining your "romantic affair, secret meetings, or embarrassing health issues".
No, you just have to use the right data structures. Quadtree is the obvious one if you have lat/long, or if you have cell history you can observe that e.g. the UK only has ~25,000 base stations, so you can just use them as buckets. It's probably too expensive to run on every ad load, but for targeted surveillance it's easy.
Contact tracing will go away middle of next year with the end of the pandemic. Although I wouldn't rule out its reactivation next time there's a SARS or bird flu breakout.
Ideally users would have the option of having some sort of digital bank associated with their web browsing. Micro transactions could pay to support the websites instead of advertisements.
Users "rooting" their Android phones also usually doesn't involve any sort of real exploit either. Android devices don't come with the ability for apps to run as root by default, and can have their firmware flashed to add a means of doing so. Doing this requires that the user unlock their bootloader, which wipes the device and often requires manufacturer authorization. Rooted devices have weakened security by being rooted, but this doesn't affect ordinary non-rooted devices.
Also Android is marginally more useful than an iOS device. I know that it is fancy as a music player and social media apps, but it isn't really what it could be.
Would it? In iOS you can selectively forbid applications from using locations services.
That is the metric I use to determine that the app store security model is bad.
The same is true on Android. I have location services denied on the browser I'm typing this from.
Because getting your exact location extracted and send to marketing firms and government contractors is worse than quite a few trojans you could get on your local computer by executing random and even malicious code.
It is time that security experts get honest about this and that "experts" lower their voice a bit.
In my experience, security expert generally are honest about this and should, if anything, raise their voices more.
There is a technically correct argument that a locked down environment hinders the execution of malicious code, but for overall security, especially privacy and illegal data access, the current "security" solutions for smartphones perform very badly.
Does anyone actually believe these companies are segregating their data based on what they are legally allowed to do with it? And that those permissions somehow get propagated along with the data to third parties, who then also diligently segregate their data based on legal permissions?
It's difficult to hold these companies accountable and even if you could prove they were misusing the data as an individual, it's difficult to take legal action against them. And even if you do manage to beat them in court, the compensation will almost certainly be a pittance - especially if you're not covered under the GDPR.
Of course they're not doing managing users' personal data responsibly! Even with the GDPR, it's still more lucrative to just not bother.
I think this is an extremely clever technique for generating mainstream interest in a topic that would probably otherwise be considered boring for the typical person: associate it with something that people have very strong emotional feelings about. 10/10