GSMA considers giving away mobile device locations through API
gsma.com
gsma.com
GSMA are actively attempting to lockdown them existing methods, as they’re built on trust in a very untrustworthy environment between carriers, and in some cases state actors.
Sure on the face of it this isn’t brilliant to the average HN reader, but with context it’s a significant improvement vs where we are today.
Such as?
Difficulty: nothing that requires an end-user to understand PKI; and also would not impede a lawful (and for the purposes of this conversation: ethically necessary) police wiretap.
None is needed, how hard it’s for a bank handing over physical tokens to the customers when they open an account or mailing them to existing ones?
- You can loose them? Sure, just like any smartphone or even government ID, but the process after to replace is what will make you careful next time.
- They can be stolen? Same as above
- They can be used in banks or even for online banking, just tap it with your NFC enabled phone (yubico is an example)
- They can be used by someone else? Sure, just like your phone.
- However, no sim-swap attacks or similar, so in theory it’s better given no negligence from the users which is always the biggest risk anyway, but overall it’s an improvement.
>and also would not impede a lawful (and for the purposes of this conversation: ethically necessary) police wiretap.
Why would the police wiretap a banking verification, they can wiretap the transaction at the banks if they are legally authorized.
(yes, i'm talking about every modern..ish credit and debit card)
The second factor is typically a mobile app that prompts your biometric authentication, and this obviously allows geofencing ATM withdrawals.
There are no better ways for the average human (who doesn't have a clue what 2FA means but can understand being sent an SMS and using the code in it to access an account).
And for the handful of people who just don’t have a phone… RSA/Duo tokens exist for a reason.
SMS allows a whole class of additional attacks, it’s a terrible system and should be removed.
Here are some articles:
* https://www.nytimes.com/interactive/2018/12/10/business/loca...
* https://readwrite.com/loc-aid-the-biggest-location-s/
* https://www.technologyreview.com/2011/12/09/189247/startup-t...
>Traffic management of drones: the Uncrewed Aircraft System Traffic Management or the drone operator can obtain drone location information from its GPS data, however this is vulnerable to jamming or spoofing. They can query the API to verify the drone location, e.g. for law enforcement purposes or to check compliance with approved flight plan.
That’s not the real use case since not a single drone (commercial or consumer) is using the builtin GNSS in the modem (if any as most don’t even have modems) as they are usually weak compared to professional ones, the real reason is
> or to check compliance with approved flight plan.
There! Quick background: consumer drones like DJI are easily trackable by DJI AeroScope [1] which is actively used by police to track these drones in specific events, and now FAA is also requiring the remote ID is an extension to that to cover other drones. However, that doesn’t cover all drones, you have a sub-category of drones that are un-trackable, not easily anyway, the ones that fly over cellular networks, which is a challenge to know since from network perspective it’s just another UE, so what’s the easiest way to know?! Exactly, the builtin gnss, a quick query and you can tell, although I’m still not sure how they will distinguish the normal UE from drone UE. So I wouldn’t be surprised that people are disabling the builtin gnss either by the AT commands or just disconnecting the antennas.
Ah! Meeting information are also included... you know, in case one is interested in attending.;-)
I'd say this can only "give away" the location if you already roughly know where someone is AND no rate limit exists.
Same goes for anyone with, say, subpoena powers in your jurisdiction and/or sufficient (social) engineering skills. And cell ID to geo mapping is also a solved problem...
If you live out in Nebraska or the middle of the Sahara this attack is easy to defend against, but humans tend to clump up.
[1] https://en.m.wikipedia.org/wiki/Stingray_use_in_United_State...
I wouldn’t be surprised..
Hopefully by the time this is rolled out, GDPR enforcement would’ve actually caught up and forced them to make it opt-in only.