FBI: If you knew what your phone company tells us, you'd probably sue
aclu.org
aclu.org
Which is my roundabout way of saying that violating the constitutional freedoms of an entire people is probably not worth it just to catch a few bad guys.
I do not approve of FBI methods, but in the pedantic case I do recognize that a fundamental part of a republican (little r) government is doing what's best for the people, not what they like.
Except that it wasn't GPS data - just a list of cell tower and wifi hotspot pings.
This data is indeed used by Apple to build a database of Wifi hotspots and cell towers, along with their locations, doing this to improve their location services when GPS data is not available (the first iPhone could show you your location by doing triangulation on the cell towers nearby).
The fact of the matter is that if you can get your hands on such an iPhone (without a security fix, which I'm sure it's available by now) - you can find out where that iPhone has been.
You know, a simple search on Google could have told you the answer to this -- now you've just added noise.
From what I've read, the database was a cache of nearby cell tower and wifi hotspot locations from Apple's servers, not the GPS-calculated (or even tower-triangulated) location of the user.
Seriously, though, I wonder if the FBI can eavesdrop on a Skype call. It seems like it would be damn near impossible because it is peer to peer and encrypted.
My understanding was that some global intelligence organisations can request decryption and that China is doing this actively [see above link].
I also recall reading some time ago that organisations that work exclusively with skype to provide some add-ons can be given access to decrypt.
Further, there was also that techcrunch article - http://techcrunch.com/2010/07/08/skypes-innermost-security-l... - which spoke about this
Now take that pain, and multiply it by a million or more.
I do agree with you, and am using gpg.
I'm not a browser hacker so I'm not sure if it would be easy or hard to get this integrated, but ideally the browser would have built-in support for crypto on designated input fields, i.e., "encrypt this text box" option on right-click. I'm sure it would be hard, but I bet if Mozilla and Google got together and worked out a common interface that allowed Gmail et al to pass information to the browser (like whose keys should be used), this would eventually get implemented and be awesome.
As usual, Microsoft is the biggest roadblock with Outlook. Hopefully if your company is using Outlook it can afford a license for PGP, which afaik is the only complete crypto extension for Outlook.
We let companies get away with destroying the economy through sloppy and greedy irresponsible behavior and then we cover their asses by bailing them out. Because the committees that determine their bailing out are filled with former/current executives of the same companies they're bailing out (Goldman Sachs, for example).
We let companies stick dangerous and unproven chemicals in our food, soda, animals with little evidence that it's safe beforehand and little oversight afterhand, because the various government agencies (FDA, for example) are staffed primarily with executives of the companies that are trying to ram these things through (aspartame, roundup-ready seeds, rbgh in milk, etc).
We have food that is mass produced in conditions that are horrifying to anyone who, even if they love meat like I do, don't like to see living creatures abused and tortured in the process and that are filthy and commonly spread disease (that we see reports of all the time on the news when there are outbreaks and recalls), because the FDA and other agencies are - again - staffed with current/former executives of the biggest food manufacturers and processors in the world.
Hell, we even have government officials shutting down public run juvenile rehabilitation centers so that private ones can take their places and then those private companies paying judges directly to incentive's them to send juveniles to jail. I forget where this was (the northeast is what I remember), but a couple years ago it was huge news and it actually happened. The judge in question (and there may have been more than one) received millions of dollars in payola from the private prison industry system that built the juvenile detention centers. As a result, the judge just kept sending kids there. First time offenders. Kids who did very little to deserve it (get in a fight at school, use foul language, skip school) would get about two minutes of face time with the judge before he sentenced them to the facility. And once at the facility, they would keep kids indefinitely, until they said it was time to go. So a two week sentence could turn into a year. (Oh, found the story: http://www.reuters.com/article/2009/02/13/us-crime-usa-judge... -- "Two judges pleaded guilty on Thursday to accepting more than $2.6 million from a private youth detention center in Pennsylvania in return for giving hundreds of youths and teenagers long sentences.")
So if we know all of these things and we don't care (I'm sipping on a diet coke and eating a processed microwave burrito right now, for example), why should I expect that people are going to give much more concern to their privacy or the liberties of anyone else around them? Unless they think you're taking jesus away from them, cheap gasoline away from them, or their $5 latte away from them, or their favorite television show away from them . . . they don't fucking care.
Not only don't they care, but a big percentage will always play the role of apologist. For anything. FBI pouring through your personal information, using your geolocation data. Whatever it is, the complaining voices are always few and the people taking action even fewer.
If so, you can hardly complain about the FBI breaking down your door.
If not, then gaining additional evidence doesn't make it more likely that they're going to break down your door.
No, but neither was this guy: http://www.foxnews.com/scitech/2011/04/26/mistaken-fbi-porn-...
Unless they tap your lines without a warrant to gain one. I thought we were passed the "if you're not a terrorist you have nothing to hide" mentality.
Remember that guide that was leaked a few weeks ago, detailing the procedure required for law enforcement agencies to get user info? Presumably that is not some sort of elaborate conspiracy to convince Facebook users that the government is not monitoring each and every one of their check-ins.
http://arstechnica.com/tech-policy/news/2011/05/domestic-sur...
Time and time again, no one cares or at least cares enough to do anything.
It seems to me that this data is not being used to keep anyone safe, but for other purposes.
(edit) Thanks for all the info. I hadn't heard as much about this stuff.
I have only heard bits and pieces since then and have not followed up.
Telecom companies don't exactly have a history of protecting our privacy and standing up to its abuse by law enforcement agencies.
And then I would guess it is probably one of those things that is possible in theory but probably not happening necessarily, just because there are other ways, and it is just more of a hassle to modify, upload and patch the firmware on a wide variety of cell phones. Maybe if it is a very high profile case ...
> It would also be relatively easy to discover (vs snooping of traffic that is out of your control).
Well it depends. If it is a GSM phone, it could betray the fact that it is transmitting when it is supposed to be 'off' if you suddenly hear those characteristic clicks when that phone is near a set of computer speakers for example. Otherwise you could, I guess, notice that battery life has suddenly decreased considerably. Besides those things, what other methods could an average consumer use to determine if this is happening?
This here is the key thing. I know that when the phone sitting in front of me is off, it is off because when I turn it back on it has no idea what time it is and I don't have cell reception here. If it's not even running a clock, it (trivially) can't be running GPS, and other stuff is fairly unlikely.
[1] http://en.m.wikipedia.org/wiki/Covert_listening_device
[2] http://news.cnet.com/2100-1029-6140191.html
[3] http://www.schneier.com/blog/archives/2006/12/remotely_eaves...
Some handsets can't be fully powered down without removing the battery; for instance, some Nokia models will wake up when turned off if an alarm is set.
I'm not so sure that this is still a common practice for modern phones.
Does the iPhone/Android phones do this?
If my Android phone is off, it's off. It doesn't turn itself on, period. If it's just idle, screen off, with lots of stuff asleep, sure it will "wake up" in that the screen turns on, and sound an alarm. But that's it.
This is done commonly by builtin services.
May be useful in business surroundings, but this makes the iPhone an awfully bad travel alarm.
Be sure to use real tin foil, not the inferior aluminum kind.