The “Location Off” switch on your phone is a lie
gabrielsieben.tech
gabrielsieben.tech
I've never heard anybody think setting "location services" to "off" prevented your cell service from detecting your location and presence, which can then of course be shared with law enforcement.
The toggle is for not sharing your location with installed applications.
I think everybody knows that if it's important not to be tracked by law enforcement (e.g. attending an illegal protest), you don't take your phone in the first place. (And certainly everyone on HN already knows.)
So no, the location switch is not a lie.
I wrote the article to notify an audience a little bit broader than Hacker News. There are many people who seem to think that it's only Google or Apple or Facebook they need to worry about; or that if they get GrapheneOS they are now really-secure and really-private (which they are, from Google, but not really overall). The very idea that their cellphone carrier may have their location, even without their phone cooperating, is often a foreign idea they never thought of.
This is, of course, a very long rabbit trail that never ends. Your license plate could get scanned. You could get picked up on cameras and run through facial recognition. But it's still important to call out areas that people may not have considered. Imagine a journalist - if nobody calls this out because "everyone knows," she might have installed GrapheneOS, signed up for ProtonMail, paid with cash for a SIM card, and gone off to cover some story without realizing this blind spot.
> I think everybody knows that if it's important not to be tracked by law enforcement (e.g. attending an illegal protest), you don't take your phone in the first place.
My home state would not have almost every police department armed to the teeth with IMSI Catchers if everybody just knew they weren't supposed to do that.
Otherwise known as a protest that isn't a 5k with signs and legally classified as a parade.
As far as I'm aware no jurisdiction in U.S. has a blanket ban everywhere, only in certain downtown areas, roadways, etc...
Think about when you open a private window in Chrome. There's a clear warning that your ISP or school or employer may know what websites you visit anyway. But there's no such warning for smartphones. It just says "Location: Off" and people don't know.
Linked from Location Setting.
But it doesn't mention carrier tracking your location. That is fundamental to how cell phones work, though, unless you enable Airplane Mode.
Despite all this, if it came to overthrow a surprise dictatorship tomorrow qI'd still expect almost everybody, myself included as well as a majority of hn readers almost as big as that amongst the general population, to naively show up at the street riots with their devices happily logged into the network. But not a single one of them would do so because they believed that toggling the GPS feature to off somehow protected them.
I agree this would be common but lower percentages after the George Floyd protests got a LOT of widely-circulated warnings on social media, and then a bit later a ton of right-wingers were getting rounded up for January 6th. I think those were eye opening for a lot of the people for whom this is likely to be relevant.
Meanwhile the intersection of “hasn’t heard this” and “is intentionally turning off location services on phones” is, I imagine, an extremely small cohort of the phone using population. But this would be a good sort of public poll to do!
yeah. most people don't know they're supposed to care about the amount of just how little to no privacy they really don't have anymore. general awareness to the function of a tap-on tap-off feature like this, something that's, with a staunch juxtaposition, not currently infringing nor bearing any matter to whatever social-media-esque consumption they're filling their eyes-on-screen time with as they go about living a naive inspired blissful existence, their attention no doubt occupied by and kept busy with literally any and every other thing.
:/
But they know from every police procedural TV show under the sun that you can have your location tracked by your cell service.
Same way TV used to always show a landline call taking 30 seconds to be "traced" and the criminal would always hang up right before...
lol, of course they know about it. they know about read receipts too.
Their friends tell them. then they get creeped out and figure out how to turn things off.
Generally you will need to be rooted to change the MAC address.
The second para starts: "Well, that would be the case if we lived in an ideal world, but that switch is more of a polite “please don’t” than an actual deterrent."
FFS this isn't /. 8)
I do understand that a site might have a house style or whatever but what exactly did I do wrong?
Why can I not call out a comment for being misinformed at best because the commenter clearly didn't read the article that they are commenting on?
2) because that sort of thing tends to lower the level of the conversation. Sniping at each other is easier than substantive conversation and tends to crowd it
I think dang also has an explanation of moderating style and intent floating somewhere that is persuasive and interesting. If you are interested I can try to find it for you, although you might be able to find stuff using the search or reviewing his comment history
Notice the article authors' age.
Unlike most of us, they likely never used a pre-internet-capable cellphone.
It is only private on your side, it changes nothing for the sites you visit or their partners, they can still track you, and your IP address is still visible. It is not a blocker like uBlock, though in the case of Firefox, turning on private mode also enables a builtin blocker.
It is explained clearly when you open Incognito mode in Chrome, and people complained that it doesn't do what it says it doesn't.
even with wifi/bluetooth/location services turned off, apple constantly connects to *.ls.apple.com. sigh.
Outside of the HN bubble, many. Besides, the point stands: the UI is misleading.
A phone should clearly show to the user what data is sent, where and why, without any exception.
You'd be quite surprised at what people do believe.
Back then turning the switch off made a smartphone as difficult to locate as a dumbphone. The phone had to exert a lot of energy to know where it was even within a city block.
I'm not convinced this has changed much. Obviously if the Eye of Sauron chooses to focus on your location there's no way to avoid it but I would bet that mundane cell phone location logs are sharply limited by tower storage, CPU limits, and probably by software licensing.
I'd be interested to hear from a cell tower software engineer.
That still makes its existence a misleading coercive lie giving you the illusion of control; for those that don't already know better. These dark patterns should be illegal (and in fact are if you take a strict constructional meaning from deceptive and unfair business practices already codified in law).
Its just effective enforcement of antitrust, and FTC violations simply isn't occurring at these monoliths.
These days it won't help, thanks to our friends from the AI department. Anyone's identity is easily found from the cameras filming the illegal protest.
Your carrier has in my mind, always been able to determine your location. We had movies doing triangulation based on phone calls to catch criminals.
The guy who wrote the article was 21, so it's not a stretch to think they only grew up in the smartphone world and didn't have that base understanding.
This is because they know that the "location off" switch is a lie.
NextDNS filter.
[1] https://www.vice.com/en/article/43z3dn/hundreds-bounty-hunte... [2] https://money.cnn.com/2018/05/18/technology/cell-phone-locat...
I looked into it a little bit, a good option depending on your threat model is to simply leave it in a faraday container (read: aluminum foil envelope - or the more sophisticated stuff) when you don't want it to be visible. But then, you kind of have to let go of having that phone usable at home at all, and end up having a "dirty" and a "clean" phone. Then again, just useful depending on your threat model.
I'm not trying to be snarky or anything, I'm genuinely curious here what the benefit is to you.
I think OP might be in a jurisdiction where you don't need to provide your address (yet) when
> using prepaid cash purchased SIMs
If you want to be untraceable you don't use cellphones, simple as that. Of course modern life is ridiculously difficult that way so it's pretty impossible.
Guess what a SIM card does when it's put into a new phone? Includes the last IMSI it was installed into when it joins the carrier's network.
They're not very well educated on digital privacy and engaging in a lot of cargo-cult privacy stuff that is almost certainly making them stand out like a giant red thumb. Very few people do things like switch SIM cards on a regular basis, at least ones who aren't engaged in criminal enterprises.
Their behavior reminds me of a former partner's ex, who was [paranoid-delusional | obsessed with] cell phone tracking.
I really have no idea why they're so concerned about their cell phone carrier "knowing" their home address.
Do you disable cell service manually when you're going home?
While I don't think an ordinary user would possess the knowledge that their cellular function relies on their respective telco knowing their approximate location at all times, I also don't think an ordinary user would be misled by this toggle, especially as further information is readily available, particularly so on iOS, with the first line of the click through directly underneath it reading:
"Location Services allows Apple and third-party apps and websites to gather and use information based on the current location of your iPhone..." Before delving into further lengthly, but transparent, detail.
Anyone who was concerned about their location being revealed this way would certainly be more careful than to just flick a singular toggle and call it a day.
In the past, at least in crime shows, the police could track your location for even "dumbphones" using the method in this article; therefore the common wisdom has been "use a burner/take the battery out/dont take your phone". But now that phones have GPS + location switch, the "legacy" method is no longer front of mind.
https://web.archive.org/web/20150101020635/https://www.zeit....
1. The fact is that some applications require any access to the physical location(lat long) to function is a lie. For example many app just needs to know if you are at "home/work/fav place" without knowing the lat long of it e.g. function for Assistant based Reminders to be triggered. yet google or ios just make access to location a creepy sounding binary permission with a less creepy variation on preciseness of location access. In reality these should be two permissions.
2. The fact that some apps need background location access to function is a lie. Locations can remain on the phone only for many apps and this can be enforced as a permission or the OS. For example Navigation can be done by rendering the blue dot on a screen and that is technically doable at a privileged OS level service without exposing the lat long info to apps. The apps just need to provide tiles and relevant styles to render. Garmin like navigators have been doing it for years with hardware older than smartphones. Google lies to you when it says it needs your lat long to function. In reality its just needed to target you with ads. "Nearby" functionality could be enforced by sharing location in an encrypted fashion through P2P networks, though apple in fairness is doing better at privacy of location sharing; Google has none of this AFAIK and at worst they both retain the data(or atleast we have no confidence if they do or not). In reality background location access could be almost exclusively be made more private by being on device only for many apps.
3. The fact that Google/Apple are doing public good by providing location permission is a lie. Try turning off precise location in a Google supported Android, the experience is horrible.
4. Non PlayStore installations on AOSP by other providers could be somehow better for Location Privacy is a lie. I will never buy a samsung phone because they are very likely to install various Location, Wifi, BLE Service Providers for serving up data for Location or Location Inference which is lucrative to closed ecosystems of Apps by Big Tech(FAANG et. al). These services are more of black and back room deals that don't show up conspicuously in public discussions and undermine privacy.
Better and more nuanced permissioning can really help a lot of location based apps to thrive. But Google and Apple have made anyone but their own apps have to choose between being creepy or not.
The example in the second link shows the details that the cellular network provider may have, and this includes the Cell tower ID, the enodeBID (4G), tracking area (TA) ID, geolocation, information about whether the device is moving (its velocity), the mobile country code (MCC), mobile network code (MNC), and a whole lot more.
This data is already with your cellular network provider, so it makes no difference if you have "switched off" location services on your phone.
[1] The Open5G Lab APIs https://swagger.open5glab.net/
[2] An example location tracking request https://swagger.open5glab.net/#/MonitoringEvent%20API%20Subs...
But seriously, it could be useful for people to share with family or friends who aren't technical. You never know.
I'm so sick of it. Fuck everything about participating in the surveillance state.
Does the LS button turn off the GPS/GNSS radios only? What about WiFi location services? Are those disabled by the button too? Bluetooth, is that a thing?
I couldn't find an analogous article by Google, but Apple does a pretty good job of explaining this: https://www.apple.com/legal/privacy/data/en/location-service...
Disabling location services should also disable the GPS/GLONASS/etc. chip because it's not useful. In theory the Android system could activate the chip of course, but in any clean ROM it won't. If you're trying to protect your location from the apps on your phone, you'll most likely be fine just disabling location services. Pay attention: some phones have a location toggle that actually only disables GPS, you may need to long press the toggle to get it to turn off all location services.
IP geolocation is also easy to implement, so consider using a VPN to make it hard to track you through your internet connection.
If you try to protect yourself from external factors, you're in for a challenge. Overrides may exist, for example when you call the emergency services; location services and GPS will turn on and send a GPS fix to the emergency services. Furthermore, if your phone has even a semblance of a cellular connection, triangulation from the ISP side becomes an option. With LTE, and especially mmWave, tracking from a cell tower becomes painfully accurate.
If you're on some large WiFi network, for example a building with tens or hundreds of WiFi access points, an active WiFi connection can be tracked very easily as well (down to the centimeter with the right firmware on the APs).
If you want to protect yourself from passive scanners that respond to your phone's WiFi scanning signal, be sure to keep MAC address randomisation enabled. Also consider making your phone use random MAC addresses when connecting to WiFi access points in case someone fakes an access point to get your phone to reveal its real MAC address. This isn't foolproof, there are ways to determine your phone's brand, model, and even the firmware version through WiFi probes if your adversary has enough information on it, simply based on the extra options set in the WiFi packet header and the order of them.
Using any Bluetooh devices also makes it easy to track you as you can't use random MAC addresses with Bluetooth peripherals.
If you want safety from external tracking, disable all communication systems unless absolutely necessary. If you just want to disable app tracking, retract location permissions or disable location services.
One final note: some apps have been caught going through photos in your gallery, extracting the time and date of the picture together with the GPS tag in them. This allows apps with media permissions to build up a location history if you've been taking pictures. Be wary of unnecessary full media permissions; apps generally don't need them as there are APIs that allow apps to select a single file or folder.
https://cs.android.com/android/platform/superproject/+/maste...
This function removes the coarse and fine permissions from all apps except those who are on the Emergency Bypass Allowlist or the ADAS Bypass Allowlist.
https://source.android.com/docs/devices/automotive/location_...
In the old days we had pagers to be still reachable and yet anonymous. But those networks have died out pretty much everywhere, sadly.
The phone's accelerometers will still run in aeroplane mode which can infer a surprising amount about your location.
I've heard of most of these but this one is new. How does this work? Are the accelerometers used to basically track direction and distance from a last known location?
I would think if the phones are doing this, there's no telling what else we don't know about them. I've decided now that it's pretty much "Game Over" when it comes to any privacy on a phone.
"Mr Defendant, records show that you carry your phone 99% of the time you leave home, except on the night in question"
If you care about battery life you should keep it off unless you need directions anyways
We have no privacy anymore, and no recourse to take it back.
Did people think that their networking didn’t reveal location? Or that joining Wi-Fi networks didn’t reveal.
All this setting means is that your phone won’t tell apps. It doesn’t mean that you’re impossible to find.
Find My iPhone still works when the iPhone is turned off. On new iPhones, it even says it on the screen that the iPhone is still findable when powered off.
What might be interesting, you turn location services off in the settings while the iPhone is turned on. Then power off iPhone and effectively turn location services back on via Find My iPhone.
for example, "Find My" can find your iphone even if it is turned off.
It's the sensible default option and it can be disabled in settings.
There have been cases where the phone _going offline_ during the "event" have been used as evidence.