But there's the mobile provider piece of this -- the tower knows where you are because currently it has to, and the network providers are part of this location data market, selling location data for everyone, whether they use leaky apps or not. This is worse with 5G due to smaller cells and thus finer-grained location data.
With a colleague I've founded a startup, Invisv, to provide location privacy -- and more. FWIW, Wired wrote up our work on this several weeks back: https://www.wired.com/story/pretty-good-phone-privacy-imsi-w...
Link to research paper: https://www.usenix.org/system/files/sec21-schmitt.pdf
These are the people who have been giving literally trillions of dollars to the wealthy in their spending bills.
What would they have to do to convince you they are not going to help you?
It's possible for the state and big business to both be your enemy. In a country like the USA where big business owns the government that's often the case.
The standards are all open right, for modern mobile networks. Every time I see this topic come up there seems to be something about patents and entrenched oligopolies (i.e with Qualcomm). Is there any legal or IP issues raised from making open source modems for LTE/4G/5G/whatever networks.
How does that help? If you do that the best you can do is obfuscate your location by a mile.
Being a service provider shouldn't mean an unlimited license to spy on your customers. Being a big corporation shouldn't mean you get to ignore the rules applied to individuals.
We need better laws, and we need to exclude megacorps and megamoney from the legislative process.
but doesn't that mean you can still pinpoint people at the cell level? With cells being smaller in 5g networks, the problem is going to get worse.
The entire planet's mobile telephone system would then stop working.
As far back as GSM, your approximate location is continually updated in the HLR/HSS database (and VLR) so the the system knows where to send the MAP SS7 paging message to tell your phone to ring when someone calls you (or where to deliver a SMS).
Its a mobile network - it needs to know where you are.
Please prove me right.
Location data is probably the single best demographic info to have to make money, and at least 3 companies in the world have basically everyone's phone bugged. Ads, maps, social... all totally dependent on location data from users.
Why would they care about me? Anti-terrorism, anti-competition, who knows. I tried not to think that much about it. I simply noticed the extreme regularity and improbability if it and thought in those terms and went about my limited life.
The vans are very menacing with their spinning sensors and black helmet, I’d hate to have been an actual criminal. Built charachter ignoring them.
I’ve been in a survival frame of mind before and it can feel like the whole world is against you. It’s hard to trust anyone. Living in a car in SF (or any city) would give me massive anxiety, there’s no “safe place” where you can fully let your guard down.
I know you don’t want to hear this, and have probably heard it before, but your paranoia may be a sign of untreated mental illness. Stress can trigger mental health issues, and treatment may help. I also understand that the medications have some pretty bad side effect profiles, and being labeled mentally ill means you get treated completely different than everyone else (in healthcare in particular) I also understand that your experience of feeling surveilled felt very real to you, the hard part of treating the disorders is that it’s hard to accept what you experience isn’t real, since it’s very real to you.
I encourage you to consider seeking help, but understand why you’d be hesitant. Take care.
I don't agree with the current directions of technology in terms of surveillance and data collection for private and powerful interests, but I find it far more likely that living in SF you'd be exposed to more mobile Waymo platforms that just happen to be collecting data regularly as part of engineering work, data collection, testing, and so on.
No offense but why would Waymo care about you in particular unless you were some significantly important/critical former disgruntled employee or risk/potential asset to their business?
They were just testing their equipment to track everyone better!
Absolutely surreal the mental gymnastics some are capable of convincing themselves to be comfortable with. Sometimes the problem is that the technology is being applied at all. The fact every techbro hides behind "Pfft, it ain't you we're interested in," doesn't quash the unspoken "it's everyone and you".
Yes, a couple of dollars per user is what is at the root of this privacy nightmare.
And guess who is ultimately paying this price anyway.
I'd trade my flat for all transactions involving everyone in the medical field (in UK) for the past 4 years(including relatives and friends). If only location data is available... I'll do with that.
Is it legal to publicly disclose this data, or is it only legal to collect and sell it?
The one potential obstacle is that the shady 3p data brokers might refuse to sell it if they smell the purpose.
The steps they list only cover gps data. In my final year at uni, during the capstone fair, I recall one group built a tracking system that relied on Bluetooth or wifi or something (maybe cellular signals?) to identify and track people indoors. I think they pitched it to be used in malls or airports, but really could work anywhere. It was surprisingly robust.
There are other projects that track you by license plate on highways, or by facial recognition. All this is location data too. I don’t think a highly motivated person could avoid location tracking any more without living in the woods
Our watches haven’t changed their their bluetooth addresses during that time.
(The detection is accomplished by having a raspberry pi periodically call `hcitool name <address>` and checking whether it gets a response)
You wouldn't let a Google rep come to your house and physically map out your home, or note down the MAC addresses of your Wifi access point. Yet people are totally OK with them doing it as long as someone physically doesn't show up to do it.
Can't you just turn that off? Am I missing something?
https://support.apple.com/en-ca/guide/security/secb9cb3140c/...
https://source.android.com/devices/tech/connect/wifi-mac-ran...
I guess US is not as motivated as the EU, so, they'll follow, as usual.
I have heard it is used by some marketing firms, I have heard that some corporates use it for data on their own properties/competitors (the former may not be obvious, but some malls may do this to check on tenants, malls also usually have their own tracking stuff on site too btw) but the main user are hedge funds.
Not all of this data is useful by itself but it is useful once you integrate it with everything else (lots of firms have tried to use this data on it's own, and then complained it "doesn't work" when they employ no-one who actually understands the restaurant business, for example).
Also, I will say too...99% of this data is coming from free apps whose only purpose is to harvest data from the unwitting. I don't understand fully how this is possible because, presumably, it should be quite obvious to App Stores that a flashlight app does not need to know your location...but it keeps happening. Some of the big data aggregators are actually pretty creepy, I have seen some companies retailing personalised data on every person in the US, I don't think anyone knows where it is all coming from apart from them (I also wouldn't discount hacking tbh, there is so much money in this that I think they have to be doing it).
Imo, all this shit should be blocked. Even within hedge funds, you are seeing funds that are using this data, no-one knows where it comes from, how it was collected, and they making piles of money from it but no-one else can access it...they just call up a firm, tell them they will pay $50m/year if you don't sell this to anyone else, it is all very opaque.
> Modeling consumer behavior and forecasting future financial performance based on foot traffic and POI data;
> Evaluating and managing real estate asset portfolios based on migration patterns;
> Conducting trade area analysis for new investment opportunities;
> Leveraging property-level insights to build more specific insurance risk assessments; and
> Assessing sector and competitor performance.
Note that this is the words of the data broker itself. This one in particular doesn't appear to sell individual data, but rather aggregates by age/county/census group/income etc. It appears as most of their source data is mobile/app based.
I'd not be surprised if fraud is common among data miners and brokers - it'd be easy to inflate numbers in order to make more $.
Feeding the data miners with fake data would probably be relatively easy to pull off - say you just bought a house in a remote area and you want some new shops to open and the price of your house to go up..
But they have other data: they have your bills, emails, app usage data...again, not sure how legal it is or whether some of this isn't hacked data (App Annie is a, presumably, legal source...but there are far more).
Does this exist, but require a boatload of money and contracts first?
* Apps
* Carrier geolocation
* Bluetooth tracking
Are there any others?If I disable location tracking then am I safe? I don't install crappy vendor apps on my smartphone to begin with.
Most people connect to wifi at home and at work. Every app on your phone reports your current IP address. Even if you don't open an app, the app server can send it a silent push notification which wakes up the app and lets it send back your current IP address. Therefore every app knows where you live and work and when you are at those places. If you connect to wifi at friends' places or coffee shops or a hotel, they get that data, too.
This is missing from the article. It is a major omission.
iOS & Android could help reduce IP-address tracking. They could treat Internet Access as a privacy setting: require apps to ask for permission and let the user control when the app communicates (never, when in use, always). One can disable app notifications to reduce app wake-ups, but the OS does not teach users about this. Notifications are not listed under "Privacy". Also, apps can use other ways to wake up frequently and report the current IP address.
Additionally, iOS & Android could support hermetic proxy services. Currently, one can install a VPN app on iOS, but device traffic goes through the VPN only when the app is running and connected. All apps get direct access to the network (and your IP address) whenever the VPN connection is not enabled, which occurs during device restarts, VPN service outages, VPN app updates, and when switching between mobile & wifi. iOS has the ability to disable network access when the VPN is down, but setting it up is a complicated procedure which requires using a macOS device and wiping the iOS device. And there's no emergency-disable option.
Both Apple and Google ignore many easy things they could do to improve user privacy.
I'm not sure what all counts as "getting data off" the phone, but some other methods of smartphone tracking:
- wifi (sometimes even if wifi is "off")
- EXIF on photos you take and share
- QR code usage
- public USB charging ports
Then there's cross-tracking by other means. It's likely someone has enough data to associate your phone with your credit or debit accounts, or a public transit card, or vehicle plate numbers & toll tags, or with your face and voice.Also stuff like iBeacon is pretty much impossible to avoid, it still works even when bluetooth is completely turned off. I got an iBeacon based alert when I walked into an apple store with bluetooth turned off for example, and there is no setting to turn off iBeacon tracking.
Google is worse in other ways, it's incredibly infuriating.
Check out: CalyxOS GrapheneOS LineageOS AOSP
As to the precision argument, US cell carriers can locate you to within 150ft easily in a city / populated area (and are required to be able to by the FCC[1]). They don’t just depend on multiple tower triangulation, but use much more advanced techniques (can provide sources if asked). Back in 2017 multiple carriers were demonstrating to my then employer how they could generally even determine what floor you were on in a building within a range of 4-5 floors. Apparently now the FCC mandates it to be within 10ft[1] vertical accuracy now in the top 25 markets.
The same PRS system that tracks a UEs precise location for E911 / law enforcement / government use / etc is also used on tracking the general usage of any customer of the carriers all the time.
[0] one story among many from back then: https://www.engadget.com/2018-06-19-verizon-stop-selling-cus...
[1] https://www.fcc.gov/public-safety-and-homeland-security/poli...
Emergency services and LE after properly executed warrants are the only parties that should have access to this information without your explicit consent to be used for advertising.
Just enabling 'Google maps' on your phone should not give Google, the advertising giant unfettered access to your location data just to give one example.
And for developers, you are forced to enter the spy-on-your-users rat race because everyone expects free shit.
I remember years back talking to friends and people I knew who all said things like 'think of the data we're collecting' - nobody thought about asking the end user if they wanted that data collected.
It's not about 'oh no, I have to spy on my users;' the users aren't considered at all. If they are, there are patterns built to prevent them noticing and limit liability. It's pretty vile.
Ethically, you should only try collect the data you reasonably believe your users would be ok with you collecting if they knew as much as you did about what a bad actor could do with it, and you should ask them first.
I would happily pay for a quality product that respected my privacy.
But I'm, what, a 0.1% minority of global internet users?
Meanwhile I try to find suitable games for my kids to play or video's to watch, and 9 out of 10 things I find have monetize through some quality-reducing, interruptive, annoying ad-driven modus operandi.
It's not just services or software: consuming content is equally degraded by the expectation of limitless quantities of free shit.
If you are a weirdo who is not available to communicate with like everyone else, people stop being your friend, you economic opportunities reduce and so on. If your more late because you got lost more often, because you don't use gps, people don't want to associate with you as much and so on.