Mobile carriers can get your GPS location
an.dywa.ng
an.dywa.ng
We live in a reasonably dense suburb. Police showed up at our front door and asked to speak with him. They just wanted to make sure he was doing OK. He asked them "how did you find me?" and their response was just "we pinged your phone".
Watching my security camera, they did not stop at any of my neighbors houses first. It was very direct to my front door. This leads me to believe whatever sort of coordinates they had were pretty spot on. His car was parked well down the block and not in front of our house so that was no give away.
This was five years ago and always struck me as a "Huh"
Clearly they don't need that now because 5g cell towers have gotten precise enough? Also, if that's true then 5g being that precise might still not apply to urban dense areas, where more postprocessing is required to get better location accuracy...
5G infrastructure isn’t limited to tall easily visible radio towers like 4G and before; 5G transmitters are small and relatively inexpensive, making them very common. My employer has a private 5G infrastructure, and we are not related to telecommunications in any way.
For the most part they use the same or lower frequencies. N71 (600mhz) is lower than any of the 2G/3G bands and requires less cell density than 3G (UMTS/WCDMA) did.
> 5G infrastructure isn’t limited to tall easily visible radio towers like 4G and before;
Nor were earlier technologies. DAS systems get used in large buildings/cities and were done with 4G as well. Small cells and femtocells have been a thing since at least 3G era.
> 5G transmitters are small and relatively inexpensive, making them very common.
Transmitter cost wasn't the primary limitation before, the options for unlicensed/lightly-licensed spectrum were low before and the standards weren't really designed to use them as primary carrier until NR. Also you had to run way more components to run earlier technologies, the stack is just smaller for a NR deploy.
You can read more about 5G positioning here:
https://www.ericsson.com/en/blog/2020/12/5g-positioning--wha...
https://www.ericsson.com/en/blog/2024/11/5g-advanced-positio...
https://arxiv.org/abs/2102.03361
https://research.chalmers.se/publication/542739/file/542739_...
It is just VERY VERY hard to beat the predictability of orbits.
We aren't going to remove the security state. We should make all attempts to, but it won't happen. What needs to happen is accountability. I should be able to turn off sharing personal information and if someone tries I should be notified and have recourse. This should also be retroactive. If I have turned off sharing and someone finds a technical loophole and uses it, there should be consequences. The only way to stop the rampant abuse is to treat data like fire. If you have it and it gets out of control you get burned, badly.
They're raising the possibility of asking _why_ the data was collected if there was no emergency?
Of course if the telco doesn't store the rewuests/responses, there will be no records to show.
Way you could argue it doesn’t apply to government is that the government makes the law so they can make the law that makes data processing and having your name on some kind of registry required.
But still they have to show you the reason and you can escalate to EU bodies to fine your own country if they don’t follow the rules.
What security state? They aren't doing this for anyone's safety. This is the surveillance and parallel construction state.
> What needs to happen is accountability.
No agency can have this power and remain accountable. Warrants are not an effective tool for managing this. Courts cannot effectively perform oversight after the fact.
> The only way to stop the rampant abuse is to treat data like fire.
You've missed the obvious. You should really go the other direction. Our devices should generate _noise_. Huge crazy amounts of noise. Extraneous data to a level that pollutes the system beyond any utility. They accept all this data without filtering. They should suffer for that choice.
I like the idea on principle, but I'll like it far less when I'm getting charged with computer fraud or some other over-reaching bullshit law.
Strictly speaking, this is not completely true. When you call an emergency number, it’s very good that they can see exactly where you are. That was how this was sold 15+ years ago. But of course, that’s basically the only use case when this should be available.
Warrants are so easy to obtain and so abused it is required that we all do something differently.
The problem is that individuals no longer have confidence in their institutions, for both good reasons (official corruption, motivated prosecutors, the dissolution of norms of executive behaviour) and bad ones (propaganda on Fox News, and the long tail of disinformation online).
The question becomes: how can citizens have confidence their rights will be protected? What structure would protect the right to privacy?
This was well understood in the decades following WW2, and many countries implemented protections of this kind, only to roll them back again later when people had forgotten why they existed, and believed once more that everything will be fine as long as the “right” actors were in power.
Structurally, that means the law must require consequences for cooperating participants (telcos, state agencies, subcontractors, IT providers and Apple/Google), and ultimately it will be the end of the Presidential individually exercised pardon power.
As it stands, a cop has to get a warrant to enter and search your home, for example. If we remove that hurdle because we also don't trust the courts then we just have more searches.
I get the reaction to turn on the whole system, I have very little faith in it myself. But I don't think many people are really aware of or ready for what would come without it.
If you have 10 friends and you ask them what they want to eat for dinner and 6 say let’s go to a Mexican restaurant and 4 say let’s kill Bob and eat him, you still need to worry about your friend group.
Right this second ICE agents are killing people with impunity and police for the longest have had qualified immunity to kill people unjustly.
The country voted for this knowing exactly what they were going to get. Don’t believe the Michelle Obama “this is not who we are” this is who this country has always been
I live in a very red part of the country, and in a very red, rural area that voted ~90% for Trump. I don't know anyone that is okay with everything he has done. Some take issue with Venezuela, some with the handling of the Epstein files or the federal budget. Some don't like sabre rattling over Greenland.
Most people I know that do vote Republican are one issue voters. At least here people voted because they always vote republican, support the second amendment, think the republicans actually want a balanced budget, or just hated Clinton/Biden. It isn't about supporting whatever Trump does, though I'm sure some small percentage does.
People regardless of party or region don't think critically often enough and can't set aside their own personal beliefs. We've made our country bipolar and we're seeing the repercussions. It isn't a problem with any one party or person, and the answer isn't to tear down the fundamentals of our system. We need to actually get back to the fundamentals because of late both parties have been going the way of socialism and authoritarianism.
https://www.economist.com/interactive/trump-approval-tracker
Someone saying to a pollster that they approve of Trump is very different from them saying they approve of everything he is doing.
https://www.foxnews.com/politics/fox-news-poll-59-voters-say...
All of that being said: that is how polling works. You are inferring too far beyond the actual question posed. For instance, somebody could think they are acting too aggressively, but completely agree with the final outcome/objective. Or somebody could disagree with the objective, but think that they’re not acting too aggressively because perhaps they’re sympathetic to LEO’s having to make snap judgments in the field (an excuse I do not agree with but many do).
I think the general sentiment that the question tells you something about how people support or don’t support ICE is valid, but the exact number and statement you’re throwing out cannot be assumed and is likely wrong, even if it’s maybe close. And that’s not even getting into how different people will have different ideas of what “too aggressive” even means.
59% think they’re being too aggressive, assuming the polling is decent quality, means you can credibly say 41% do not think ICE is being too aggressive.
I think “multiple people ending up dead” is a “too aggressive”
This is exactly who 40% of the US is.
Carpenter v. United States (2018)
This country has never been what you're saying. We have some over policing happening. That seems to come and go in every country and doesn't say anything by itself about what a county is about, especially where it's trending over a 25 year timeline in the opposite direction from what you're describing.
Let it go to court, at least, before you flip your lid and turn on your countrymen.
Please.
Today on HN on the front page there was an article about someone being forced to use their biometric security to unlock their phone.
And then to say this country has never been what I’m saying is to ignore Jim Crow, sundown towns that were prevalent into the mid 80s, etc.
The Republicans won that war. We live in that country that won. Not the one you're describing. Jim Crow was a Southern state thing. The North never allowed it. We live in the North. The South is gone and it was never part of this country because it violated the laws that would have made it so. They rebelled against anti slavery laws from the beginning and they finally got what they deserved, to be conquered by the United States that we live in today. And then they still argued to keep slavery and the Supreme Court kept slapping it down. Over and over and over.
If you believe that the United States was ever about slavery, then you carry the rhetoric of the very party that created Jim Crow and that supported slavery, and you make them the good guy in the story. You support their version, where it was always legal and they got screwed by the lying North.
The irony... Don't ignore the writings of Washington, Franklin, Hancock, etc. All wrote to say that slavery has no place in this country. And it never did! Their letters are preserved for you to read. They are available online or in one of the museums in DC. Probably the National Archive? Someone can correct me if they know.
Anyway, that some people refuse to follow the law, isn't a reflection of the country as a whole. Similarly, when someone is killed in Norway, I don't jump to conclude that Norwegians are murderers. That wouldn't make any sense.
Did you go to high school in the South somewhere? The revisionist's history of the US seems to stem from that part of the country. I'm just curious if it tracks.
The 3/5 vote was part of how the North protected from the South using greater numbers (voting in place of their slaves) to remove the expiration date that the North placed on slavery as a concession.
The North wanted to ensure that slaves would in fact be released as soon as possible, without losing the South as an ally against the impending invasion from England.
Had they not reduced the voting ability of the South, the South would have simply removed that expiration date and kept their slaves. (They kept them anyway, that's why the civil war happened.)
There was no “expiration date” in the constitution.
“Plessy vs Ferguson” was decided by the US Supreme Court after the Civil War which enshrined Jim Crow and “Separate but Equal”.
It wasn’t until 1967 that the Supreme Court outlawed bans on interracial marriage.
In 1985 there were still sundown towns (https://www.reddit.com/r/Georgia/comments/1f4hzlt/oprah_visi...).
This country was built on racism and it was enshrined into law up to 6 years before I was born
In all fairness, my family had a house built here in 2016 and the only reason we sold in 2024 was to move to Florida. While my (stepson) was one of only 5 Black students in his high school, he never had any issues.
Article I, Section 9, Clause 1 of the U.S. Constitution (often called the Slave Trade Clause) prevented Congress from prohibiting the importation of slaves prior to January 1, 1808. This effectively allowed the international slave trade to continue until that date, after which Congress could (and did) ban it.
Seems I need to reword my take, as this demands a bit more specificity, but the overall take remains unchanged. Had the 3/5 provision not been made, the South would have further prevented the North from enforcing a ban on slavery and inequality, which was already in place in the North, and in place federally with the "created equal" component in the Declaration, as was argued by founders in court cases.
We can't just ignore court documents and the Constitution itself, along with the Declaration. Not to mention the first draft of the Constitution which had a lot more provisions against slavery before the English forced then to take allies with the South or die. They had no choice but to agree to the South's terms and allow for the South's slaves, temporarily. A stark difference from the previous Constitution of the first Congress.
You can try to frame it however you like, but you can't hide the fact that the founders wrote that slavery is bad, and they don't want it in this country even before it was a country. And they subsequently fought to eliminate it as soon as the wars were over. Those documents remain, right in the face of your argument.
Sundown towns existing doesn't change that. There was no sundown country, just as this isn't a sex cult country, despite there being some law breaking Nexium participants setting up shop and torturing people. It happens, that doesn't mean we as a country yearn to have more racists walking around. In fact, I think if you read why Republicans voted Trump, it's because they perceive immigrants to be racist and they want to reduce the inflow of racist ideology and rape culture into the country. That's exactly the scare tactic that their advertising relies on. They believe they are the ones who aren't racist, just like Democrats.
(I hate both political parties equally by the way. I'm not sure if that's clear from my commentary. But I reject the South's view of history because I can read the damn court cases and see that it's a total fabrication. And I know that Democrats like to spread that version as justification for why black people need help, and I think they know full well that it's bullshit, but it convinces juries on rare occasion so they continue to use it.)
Lincoln also didn’t really care about the slaves early on
https://www.reuters.com/article/fact-check/abraham-lincoln-q...
Again, this country has always been built on racism and inequality and was enshrined into the law in some shape or form until the 60s.
This is in no shape form or fashion a “I couldn’t get ahead because of my race” conversation.
I’ve had every door opened to me - private school, academic college scholarship, worked at startups, lifestyle companies, boring enterprise companies and BigTech less than 3 years ago and turned down another one because I refuse to ever go into an office or work for BigTech again.
I never opposed that fact, but I apologize if I gave that impression.
I think that overall, when you look at the trend over time and the majority of cases, overwhelmingly the legislature and the courts have sided with anti slavery, equality (not equity), and presented an image of freedom and justice.
Maybe you disagree, but to say that it was always the opposite, I just don't see that. There are just a handful of cases supporting that argument against a mountain of wins in the other direction.
All that is true so long as you don't zero in and focus only on the South which, as I said, isn't this country. It's a rightfully defeated one. I'm thankful for that, and I'd rather avoid acknowledging the false rhetoric of that evil empire that fell. I certainly don't identify with it, and I'm offended at the notion that this country is required to. Why should we be? We won.
(Not "we," really. I'm an immigrant.)
https://en.wikipedia.org/wiki/List_of_Jim_Crow_law_examples_...
And saying that the “Supreme Court didn’t always rule the way you like” is minimizing an entire race of people - including my still living parents having to grow up in schools that were underfunded but supposedly “separate but equal”, people getting hung if you looked at a White woman the wrong way and didn’t “know your place” or even marrying outside of your race was illegal until 1969. Not to mention colleges that ny parents weren’t allowed to go to, having to drink from “colored water fountains” - again the US Supreme Court said this was legal
So if you ignore half of the country that had segregation and the US Supreme Court that condoned it, everything is fine?
Not minimizing. Just acknowledging that this alone doesn't characterize the general take of the complete history of the country. It describes a nation divided on moral lines at best. Not all states participated in segregation and those states that didn't ultimately are those who won in the end. So to take that win away degrades the victory that your parents (probably) helped to win.
The federal army - ie run by the US was officially segregated until 1948 but it really was through the late 50s.
https://www.archives.gov/milestone-documents/executive-order...
The GI bill run by the federal government was discriminatory
https://heller.brandeis.edu/news/items/releases/2023/impact-...
If you want to go by just one SCOTUS ruling to make your argument then why shouldn't we go with just one to make mine? And for that matter the number of rulings that make my argument are many many more than those that make yours.
Now what?
Let me ask you this: what party did Strom Thurman swap to and why?
Republicans say they absolutely did, just as they always have.
Democrats say they absolutely didn't, just as they always have.
I would argue that realignment occurred geographically, not on the basis of morality. Under slavery, the southern states were rich and mostly Democrats, now the northern states are more largely rich and leaning Democrat. That's to be expected, I think, where the wealthy wouldn't enjoy the new found poverty of the southern states as they rebuilt after the war, and would take their ideals with them. But that's just my guess, I don't have any research to substantiate that. Maybe it's an interesting topic for research.
Similarly, the stance on issues of whether people are naturally born inferior and deserving of special treatment, good or bad, remains a largely Democrat ideology, just as it always has.
Republicans on the other hand argue that all man is created equal not equitable, and they used that rhetoric to free slaves, stop Jim Crow era horrors, etc. And they continue to use it to argue against race based government aid.
So on these specific topics, I don't see any realignment as objectively observed.
All of this was and is documented in many SCOTUS cases, old and new.
I’m still curious what your response is to my Strom Thurman question. It illustrates the entire point and marks one of the most recent major party realignments in the US.
Theory is just an explanation for what we observe and I think this theory explains some things better than others. The two items I listed are are clear contrast to the theory.
Let's say it's not a unified theory of American politics, at the least.
I'll edit here for Thurman, I have to go read... Back soon to update.
Edit: I wasn't and still am not familiar with Storm Thurman. From a brief skim of the Wikipedia page, I gather he was a political "spy" of sorts, working from the inside to further the opposing party's goals.
You may need to elaborate a bit for me to see the tie in.
Do we include you in support of that ideology? I worry that you might be missing the irony of your argument.
Strom Thurmond was a Democrat who changed parties - swapped to a Republican - when democrats supported and pushed integration. It is surprising to see you repeating a fringe conspiracy explaining his racism having never heard of him only minutes prior. This is the man who yelled, “segregation now, segregation forever” on the senate floor during a 24hr+ filibuster attempting to thwart reintegration. There’s no secret here, he wasn’t a spy. He swapped to the party that cultivated “the southern strategy” on the heels of ending Jim Crow: the Republican Party. Any claim to “the party of Lincoln” was forfeited by that time.
You’ll never hear me call the Democrats “saints” but they were on the right side of history with that one and I hope we both can agree on that.
If it did then this example would be all I need to make my point. Is it?
House of Representatives vote on civil rights act: Approximately 63% of Democrats (153 yes out of 244 total Democrat votes cast) and 80% of Republicans (136 yes out of 171 total Republican votes cast).
Senate: Approximately 69% of Democrats (46 yes out of 67 total Democrat votes cast) and 82% of Republicans (27 yes out of 33 total Republican votes cast).
Here again it appears that Republicans as a larger majority remained true to the traditional Republican push for equality (not equity).
The Republican President just said that Hatians are eating pets and starting a civil war in MN to get rid of brown people.
Not to mention how he is inviting White people only from South Africa to come over.
Lyndon Johnson - a Republican - said after the Civil Rights Act that “the Republicans have lost the South for two generations”.
But Southern Democrats were literally “Democrats in name only” with Zell Miller the current governor of GA at the time a Democrat speaking at and supporting the Republican President’s nominating convention
On the topics of race based inferiority as a biological construct, and on whether slavery was ever legal, the party alignment has never changed.
Democrats still argue that black people are inferior. What's changed is that now they want to help them because they are inferior whereas before they wanted to exclude them because they are inferior.
Republicans continue to argue that black people don't deserve any reparations or special treatment because they are not inferior.
The above take is based solely on what these people argue in court.
Do you disagree with that?
https://www.pbs.org/newshour/politics/jd-vance-dismisses-bip...
And Trumps defense of known anti-Semite
https://www.pbs.org/newshour/politics/trumps-comments-about-...
And let’s not forget about the racist podcaster that it seems like “everything was taken out of context” that was deified beloved by all Republicans
https://www.theguardian.com/us-news/2025/sep/11/charlie-kirk...
As far as reparations…
https://www.politico.com/news/2025/03/25/trump-floats-possib...
I expect that everyone would agree Alabama is a very conservative state. It was voted solid Democrat until the late 80s, at which point the state went republican along with any elected politicians that stayed in office.
If I'm not mistaken, Richard Shelby was elected as a democrat in the early or mid 80s before being the last elected official to switch to the republican party. He stayed in office for decades and had state university buildings named after him.
The voting opinions largely didn't change over that time, only the party name they were voting for.
1. Whether or not race objectively determines inferiority.
2. Whether or not this country always supported slavery.
On these two items, opinions remain true to the original parties' opinions regardless of whether or not they swapped.
I'm not going to debate whether or not they swapped overall because that's entirely subjective regarding what constitutes a swap officially. That would be a waste of time. I'm a scientist, not a cheerleader. I frankly don't care outside of the two items relevant to the discussion. And in these two items they didn't swap.
This is particularly offensive considering that everyone was forced to replace his phone in the early 2000s to comply with "E-911." Verizon refused to let me activate a StarTAC I bought to replace my original, months before this mandate actually took effect.
Looking back on it, it was a perfect scam: Congress got paid off to throw a huge bone to everyone except the consumers. We were all forced to buy new phones, and for millions of people that meant renewing service contracts. Telcos win. Phone manufacturers win. Consumers lose.
Its simply made for 911 calls.
In the 2G era there was no compute space to just put in extra evil shit for fun
https://en.wikipedia.org/wiki/Radio_resource_location_servic...
...you could just listen to calls in the clear. Pager traffic was completely unencrypted as well.
In the same way that a Yale lock on your door means it's locked and secure, until someone comes along with two thin flattish bits of springy metal.
Qualified immunity is the only legal doctrine I can think of where piling on extra crimes reduces your liability.
Under 42 USC § 1983, a plaintiff can sue for damages when state officials violate their constitutional rights or other federal rights.
https://en.wikipedia.org/wiki/Qualified_immunity
Qualified Immunity only sets the bar or threshold that you have to meet in order to sue.
The cops involved in the most recent Minneapolis shooting will almost certainly face no repercussions because of this. The state can bring a case but the feds are clearly uninterested, they would simply take the case into federal court and spike it.
The law is such that a prosecutor that wants to prosecute them has to ask the parliament. Then there is a vote and the parliament decides if the immunity is taken off.
In a healthy democracy, where there are more than same two parties switching the rule to one or the other it is very likely the current opposition will be the majority next time and they will vote to strip immunity from those that try to use it as a shield for criminals.
I think the price we pay for this (delay in getting justice) is well worth paying so the justice system can't be used as a weapon against political opponents easily.
Imagine you get Neuralink and your best friend files for the right to be forgotten. Then poof. All your memories together gone.
If I send it to the company A, company B doesn't execute it unless they're a subsidiary of A (or A is their data controller) and my request was carefully crafted.
In the scenario you painted, that would mean that my _former_ friend has issued their request to me.
In that case? Fair. Poof if that's their wish.
Otherwise? How do you imagine it work?
We definitely won't get rid of it if we accept failure. I get that it seems extremely unlikely, but there's no use in trying to just mitigate the risk short term. One way or another that power will be abused eventually (if it isn't already).
The reality is somewhat more murky. On a long enough time horizon your point makes sense, we might be able to get rid of the security state by slowly chipping away at ig over hundreds or thousands of years.
Most of us are going to be dead in about 40 years tho. Security state isn't going anywhere in that timeframe.
“Just give up, it’s a hard problem.”
I would have guessed it was more likely this is where you'd find the people who built the security state, not want to destroy it.
People love idealism. It never works, but it sounds amazing.
Reddit, HN, and every democracy has the same problem... at least for a few years.
I think after this bout of Trumpism, the republicans will not be able to elect another populist demagogue for a generation. I think democrats need to do a round as well.
Trump repeatedly said there won't be elections.
How would you know? Think about the collapse of the Soviet Union, or communism in other countries. 2-3 years before it was unthinkable.
By canceling my cell phone subscription.
I know I know, I must be amish, I have heard it all. But I run two tech companies, travel, have a family, and do most of the things most around here probably do other than doom scrolling.
So much more time in my own head to think.
That’s the reason most other people are (fundamentally) going to struggle.
All the ways of living an active life engaged in the modern world that worked before the 2009 smartphone explosion still work just fine today. Just without tiktok and instagram. I think I am okay without those.
Certainly possible, I guess, if everyone in your circle does the same, and has a ton of patience, and you spend a ton of extra time doing all the prep in advance. And don’t need to deal with things like traffic jams right now, or the like.
For people who don't know their way, you can use in-car navigation systems rather than smartphone map apps.
While I agree, that isn’t something 99.9% of the population is going to do successfully.
I personally respect other peoples time and I expect the same for me. That is, I have cut out people from my life in the past that repeatedly would text "hey I'm 20mins late" 2mins before the agreed time. That is still disrespectful with my time, because now I know you are late, but still lost those 20mins. Some people don't consider that rude and for some reason do not see that this would not work if everybody does it. Needless to say, my friends know that I value reliability, and most of them do. People that don't respect that don't need to be in my social group, or at least I don't make plans with them.
At the international relations level, this idea falls under Constructivism.
Maybe these are a bit obvious, but knowing the word that describes this may help further research.
Let us use Constructivism. Countries do not drop nukes on each other. However, if one starts, everyone will follow. Or you may have an arms race situation, one country gets colonies and unless you want to be dominated by other countries, they also get colonies.
No phone number? Spend more time getting services. Unable to get services from some companies. Miscommunication/frustration. Less connections/acquaintances.
Maybe this ends up working for you, but it lowers your 'power', the ability to get what you want. I do have concerns that it works in the short term, not long term.
Sounds like you'd like Stoicism/Asceticism if you want further reading on your status quo idealism.
All sorts of places to make friends at any age once one is willing to put a phone down long enough to say hi to someone new!
For complex routes. Otherwise I just jot down a couple exits and an intersection and call it good.
> No ‘where are you?’ texts or the like?
No one expects this from me day to day because I am rarely away from home for more than a few hours at a time without a friend or family member, but when air traveling I have my tiny pocket laptop and check in at travel hubs from wifi. Everyone in your life will get used to it, especially if they see the results in it allowing you to be a more present person.
> No looking up nearby anything you’re curious about but didn’t know about before hand?
I tend to discover a lot of authentic hidden gems the travel guides don't mention, by just walking around a new area. Generally if I am traveling somewhere new, I go early to get a lay of the land.
This won't be possible soon, last couple of venues I went to were digital tickets only. Will call is basically dead now, and that used to be my preferred way of getting into events.
Maybe you live somewhere this is possible but it's definitely not in the developed world
But also, one doesn't always need a phone - phones can die, signal is not gauranteed. What are your "must have" things that require one to have a smart phone to participate? Assume the poster has a home phone, laptop, and credit card.
It's rather dramatic, but the phone call/conversation I could never forgive myself for missing, is the last words of a loved one before they die, whether due to car crash or some other calamity (9/11). Or missing the opportunity to take the very next flight out to see them before they pass. You are free to treat your family, biological or chosen, as you see fit, I just know there are some phone calls I'd rather be woken up in the middle of the night for than miss. Reaching me via cellphone is more direct than trying to find whatever hotel I'm at since I'm on the road as CEO and talking to customers and vendors in person on the road as CEO, so calling my house phone doesn't help.
I spent most of my career as an infrastructure engineer so high redundancy, self healing you can trust, infrastructure-as-code, and follow-the-sun shifts, are healthier for everyone than expecting people to be available to work 24/7.
You pay a price (we miss many party invitations, only one friend consistently emails us and FB everyone else), but it's worth it.
Recently spoke to a colleague in Italy that told me he hates WhatsApp, but is forced to use it because the school of his kids in Rome use it as sole means to communicate, despite this being a legal violation (public organizations in Europe must use GDRR-compliant tools).
I lost so many connections to people and it seemed to set me back multiple years on my goals. I thought it would make me more productive, instead my userbase got cut in half.
I'm never doing that again. Huge mistake.
These are shitty shallow people, not real friends. Real friends will support, or at least tolerate, your honest ethics based lifestyle choices. Smart people often -prefer- being around people that think differently from them, and being different can even be an asset in making more smart friends.
Many of the most talented people in the world only exist on free open source platforms. Social media is not the enemy. Proprietary centralized stock price driven social media is the enemy.
Come hang out on #!:matrix.org or other great tech communities on Matrix, and/or get invested in networks like Mastodon.
Many have done this and won around the world. People just need to stop being cowards.
That said I’d be lost in five minutes if I tried to drive somewhere without gps
I used to be that way, but MRI brain scan studies have proven that regular use of GPS actually atrophies the parts of your brain responsible for navigation. You likely need a GPS because you make too much use of a GPS.
I weaned myself off by regularly printing directions or writing them down before I leave. Eventually I finally learned to navigate the san francisco bay area on my own but I always keep a map in the car just in case, though I almost never use it.
Since the whole world is covered by satellites, living in the undeveloped doesn't guarantee privacy.
A burner phone left at home just for the ability to receive SMS would be helpful for account registrations though
I'm not sure about this. With everyone moving to the cloud and web applications, this seems to not have been the case for a while to me. There surely are what are now called "local-first" alternatives to the main services (in the past those would just be called desktop applications), but if someone is using Office 365, does it have an offline mode? (Sincerely asking since I never tried this, plus, you should still get to load the web application before losing connection, right?)
Depends on how you define a phone. Cell phones are not required but SMS capable phone numbers kind of are.
I ported my cell phone number to a voip provider and get SMS and can even take calls from my desktop, or laptop, or simple voip capable DECT phones around my home as needed.
Mandatory SMS 2FA is always a red flag on a product anyway as SMS is wildly insecure. FIDO2 or GTFO.
You can also set up a phone number to accept texts from a laptop.
I can do whatever on my bank by just calling. It would be a bit weird to never be able to pitch in on meals with a $ transfer app, but I suppose when you run 2 tech companies you're probably paying most of the time, or you just take a note and transfer it later.
I have several business and personal bank accounts with two major banks. No Android or iOS needed.
Sure they push you hard to use them, but just say it is against your unspecified religion. They cannot make you use Android or iOS.
I spent December last year looking for a new bank to move to. One of my criteria (not the most important but it was on the list) was better-than-SMS 2FA.
No one offers it. There may be some niche, loosely-based finance org that does but none of the banks or Building Societies do.
So, unfortunately, you need it in the UK.
What you could do is put them in a faraday cage if you wanted.
It’s less clear what is the “art of the possible” vs. practical for people who aren’t actively under surveillance.
There are also conspiracy theories that claim the last 10% of battery is reserved for tracking, so that when your phone says its out of battery and wont turn on, it still has plenty of power left to ping tracking data say once per hour or something. I dont push those theories, but judging by what Snowden released all those years ago I wouldnt be surprised.
I started out doing this for a couple years before abandoning mine.
Set it as a local proxy to channel all network access through it and you can selectively block any app from accessing any network, or isolate it.
But IF its possible for law enforcement to ping your phone when its on standby, dont you think its possible that it can be pinged whilst on airplane mode too?
If you are using it on wifi its game over anyway, hard internet connections are easy to track by law enforcement via ip and ISP. Even if you use a VPN your device is still connected to the wifi and can be pinged.
Not sure why people here are thinking they are more clever than than the smartphone makers.
We do not need to wonder, because this is a physics problem and we have science. Radio waves are easy to measure. There have been plenty of experiments with putting phones in faraday chambers with SDRs proving a phone in airplane mode does not emit any cellular frequencies.
You could prove this yourself with cheap home equipment if you wished.
But also, implementing airplane mode that did not actually disable the baseband modem would be an outright violation of FCC law that would be noticed by curious members of the public if this was widespread.
That said a specific targeted device with backdoored software can just make the airplane mode button do nothing, to your point, so physical switches for the baseband are always best, though few devices support them.
If someone has the motivation to backdoor devices they can do the same with physical switches (that will still talk to software regardless). If anything adding a switch that does nothing is easier.
Your question is silly
Before mobile phones, there were public phone booths. Along motorways there were often call boxes. There’s little to none of that anymore.
Also before mobile phones, if you had an accident in a remote area you were at the mercy of someone passing by and noticing you. Today, modern cars can call 911 on your behalf along with your location without you even being conscious. Or if you don’t have a car that does this, then your cell can be used. Let’s not also forget iPhones calling for help when they detect you had a fall at home.
Yes emergencies existed before mobile phones. I contend that the use of mobile phones has led to better outcomes when an emergency happens. I also admit mobile phones will have caused some of those emergencies (distracted driver etc).
I never noticed them until I got rid of my phone but they are everywhere.
In NYC all the payphones were replaced with wifi stations that also allow you to make free phone calls for emergencies etc.
Also all cell phones can call 911 without a sim or subscription so someone really worried about having instant access to call 911 in an emergency could have one of those keychain sized dumb phones they leave charged and powered off until they need it.
You are highly conditioned by marketing and social pressure to think you need to have a cell phone tracking you and distracting you at all times to live a safe and productive life in the modern world, but this is just not true.
Lived without one for 5 years, and have experienced accidents and emergencies in that time like anyone else.
A rather elegant solution to the problem how not every person likes smartphones, no?
Turns out if you leave your home and hang out with people a lot, you build better social skills, and potential partners can get to know you as a friend first, and are more inclined to give you a chance at something more than they are when you are just another awkward photo in a dating app.
We should make it impossible for the data to be obtained without express user agreement.
If anyone wants to look at the future of 5G (well ORAN) here it is: https://gitlab.eurecom.fr/oai/openairinterface5g
When talking about the 5G system, cell towers can request a users estimated velocity which when combined with the towers own location combined with the physical radio (that is communicating with the phone (UE)) you can get a pretty good position estimation.
What is new is that network providers are trying to sell this tower/5G data to other companies.
I could be wrong but from my understanding 5G has always required precise tracking of every device connected.
Not disputing that location data is used for beam optimisation just that I dont believe it is required.
If I recall correctly, the tower will report channel information to the higher up controller system which will then decide which next tower should be notified of a phone that’s entering its range.
So while explicit positioning isn’t required when dealing with one tower, the system overall does need to determine a users position and velocity to handle tower to tower transfers.
In other words my opinion is that the difference between a towers channel information and a users position is almost one and the same. It’s a handful of math equations away.
It's a peer to peer network based on Lora. It really only allows text messaging but with up to 20km hops between peers coverage is surprisingly huge. Incredibly useful if you go hiking with friends (if you get split up you can still stay in touch).
See https://eastmesh.au/ and scroll down to the map for the Victoria and now more widely Australia network that's sprung up.
:)
Both projects are hitting their limits because of this. Every new feature and every bug fix causes endless amount of pain and breakage.
I was involved in both - and gave up because of this.
IMHO both projects need some kind of thin-client which delegates most of the functionality into the client. Only keep some basic LoRa/Message Buffer/Routing/Battery Saving functionality in the hardware itself.
Based on the very “bursty” nature of LoRA, how much does an adversary need to spend to radiolocate it? What’s the threat model there?
Note: did things in .mil
I’ve deployed lots of nodes, and the technology reminds me of ipfs: people who don’t use it much vastly oversell its capabilities.
Handheld radios, meshtatic (not meshcore), and in 5 minutes you're set up and good to depart. Or ideally inreach indeed.
The fundamental problem of distributed networks is that you can either have centralized control of the endpoints, or your network becomes vulnerable to denial-of-service attacks. So meshcore/meshtastic are great because they are used only by well-meaning people. If they become more popular, we'll start getting tons of spam :(
I just tested the other day. I'm in the midwest US so it's winter, no leaves. I managed to get about a quarter mile before my two portable nodes couldn't talk to each other. T-Echo with muziworks whip antenna.
Without a bunch of solidly placed, high elevation, high gain antenna nodes, this just isn't really that usable.
Plus, all the other issues others have highlighted.
I couldn't get ANYTHING on my first/test ESP32 (Heltec v2).
Anything. I didn't see any packets. Then I finally heard one station later when I held it high on the upper floor.
The I hanged it at the top of my roof and I currently have almost 130 repeaters and room servers.
In your scenario a couple of 5W handhelds woukd work better.
But I agree the usabity is very limited. This is why I think of hanging a couple of guerilla solar repeaters in my neighborhood :)
Exactly, in nearly every “off-grid”/no cell service scenario where I’ve needed comms, the GMRS radios > Lora.
Its an interesting idea but I can’t go site prep 100s of miles of snowmobile trail before I go just to be able to send a text to someone a mile away.
For one, meshcore doesn't do a fantastic job of protecting metadata. Advertisements include your public key, and if I'm reading this[0] right, your GPS coordinates.
Second, the default public channel uses effectively no encryption at all.
Moreover, the network doesn't exhaustively prevent someone who intercepts a packet from identifying who sent it. It's no Signal.
[0] https://deepwiki.com/meshcore-dev/MeshCore/7.1-packet-struct...
The PKI is basic because these networks are tiny and merging. And running on tiny computers ($5 boards with no display)
Public channel is public and it uses the default encryption key because it's a default channel, so by definition everyone is invited to participate. Not sure what your critique is.
And no, it's not trying to be signal. It's also currently less reliable.
But it's still safer than Sms, by a country mile.
1. Telling someone to use one of these devices because their phone carrier might look up their location is silly in the first place, because meshcore doesn't even eliminate the possibility of being tracked geographically.
2. It protects your messages better than SMS but if you care about the privacy of your messages, it's infinitely worse advice than suggesting someone use Signal or another app that actually replaces SMS securely.
Not by users. The new thing is that Apple allows users to disable this feature. Hopefully they still detect emergency calls on the phone and enable it unconditionally for those.
This is a system you can disable as a user, but it's not the on-modem feature discussed in the article.
It doesn't need to ask the OS, it can just get the coordinates and send them off.
The 911 feature can be activated fully remotely, the 112 feature is supposed to only activate when dialing an emergency number.
Source? Even if the phone isn't actively doing a 911 call?
>The dispatcher's computer receives information from the telephone company about the physical address (for landlines) or geographic coordinates (for wireless) of the caller.
Unfortunately, definitive capabilities and constraints of this kind of cellular technology is hard to come by.
The format is not secret either, it's just binary encoded.
The spec says:
> The AML SMS should not be seen by the caller and therefore should not appear in the SMS "sentbox" of the smartphone. This is to avoid any customer confusion and to avoid making the format of the message widely known. In addition, there is also a potential privacy concern in storing the location of an emergency call from the handset, which could be seen by others.
The AML SMS gets triggered by software on your smartphone when you dial an emergency number. You cannot use it to obtain someone else's location.
> Next is a text to your phone number, which is intercepted by firmware and sends gps coords back.
I don't think it indicates their article reading either way and wouldn't personally wager a guess. They are just adding their own personal experience to the conversation.
A supported carrier: Germany: Telekom United Kingdom: EE, BT United States: Boost Mobile Thailand: AIS, True
Turn limit precise location on or off
Open Settings, then tap Cellular.
Tap Cellular Data Options.
If you have more than one phone number under SIMs, tap one of your lines.
Scroll down to Limit Precise Location.
Turn the setting on or off. You might be prompted to restart your device.
Why does it list specific carriers, then?
Only Boost Mobile in the U.S. Weird. About 7.5M subscribers. Maybe it requires 5G? Wonder if it works when roaming?
https://en.wikipedia.org/wiki/Boost_Mobile
https://en.wikipedia.org/wiki/List_of_mobile_network_operato...
Unfortunately Boost/Dish struggled significantly with finances and customer attraction post COVID, largely due to two problems (seamless roaming between their own network and partners’, and more importantly, getting manufacturers like Apple to build compatible phones). When the current president came into the picture, the FCC essentially forced the sale of Dish’s primary spectrum licenses to administration-friendly SpaceX, for future Starlink use.
As of now, they are in the process of moving their customers to AT&T (and possibly a secondary agreement with T-Mobile), but they seem to be maintaining their own network core - that’s likely why they’re able to implement support for this, while AT&T does not.
Basically, if you have any cell phone the government can track you. Buying a burner phone with cash (via strawman proxy) seems like the only way to temporarily obscure your location.
I imagine with the ubiquity of cameras in the commons and facial recognition and gait analysis they can knit that up even more.
I can imagine a scenario where emergency servies are authorized to send the ping to get your precise location and if you disable this, you may regret it. And a major feature of some phones/watches is the ability to automatically call 911 under certain fall/crash movement detection, where you might not have the ability to re-enable your GPS location.
It is tiring. I am doing something about it by making technical contributions. If you are able to do the same, please do.
The only way to actually do this was develop a way to ask the phone because the tower isn't accurate enough. In the US it could have been more privacy preserving by being push but I imagine carriers don't want to maintain and update a list of current emergency numbers. "Sorry person in a car crash, we can't find you because cellular modem firmware is out of date and your emergency number isn't on list" is a PR disaster waiting to happen. Easier to coordinate with police and fire and let them do the asking.
Sometimes it seems dumb, but as long as its an honest report I've never heard of anything more than an annoyed patrol officer. Felt stupid calling in an interstate sized sign hanging by a literal bolt-thread but the patrol shut down that lane.
Far better than getting the call "This sign has come down and chopped a bus in half, and then four cars have run into the back of the wreckage".
Build the fence at the top of the cliff, not the hospital at the bottom.
What, you want me to call 999? To get a ring that's too tight off? I mean it's hurting my finger but is it really an emergency?
Yes, dumbass, it's an emergency. Get the ring off your finger right now before the blood supply gets compromised and you end up with a big slug of stale dead blood washing round you when you finally do get it off. You could lose your hand if you piss about with it too long.
I know it seems like overkill to have a 18-tonne Scania rock up with five guys in it just to cut through that little ring, but they have the right tools to do it quickly and easily, and no-one wants to have to cut your hand off.
Ring 999 while you still have two working hands.
Smoke alarm going off? No apparent reason? At least ring them up for advice. There might be something you haven't seen. Just phone them.
It's far easier dealing with you not being on fire in the first place, than dealing with you being on fire later. Not being on fire is good.
In fact the apple feature the article talks about says [1]
> The limit precise location setting doesn't impact the precision of the location data that is shared with emergency responders during an emergency call.
So it actually now implements what it should have been all along. (except that it should be the default)
But we want to support privatization at all cost, even when privatization these days has significant influence on our daily lives, akin to the concerns we had when we placed restrictions on government. Seems like we need to start regulating private actions a bit more, especially when private entities accumulate enough wealth they can act like multi state governments in levels of influence. That’s my opinion, at least.
It really isn't, given that the government literally has a monopoly on violence, and therefore it makes sense to have more guardrails for it. That's not to say private entities should have free reign to do whatever it wants, but the argument of "private entities can do [thing] that governments can't, so we should ban private entities too!" is at best incomplete.
>Furthermore, the issue is exacerbated by then allowing governments to bypass these issues by then just paying private entities to do the things it can’t do as a proxy for the same functional outcomes.
Again, this is at best an incomplete argument. The government can't extract a confession out of you (5th amendment). It can however, interview your drinking buddies that you blabbed your latest criminal escapades to. Is that the government "bypassing" the 5th amendment? Arguably. Is that something bad and we should ban? Hardly.
You're right, it should be even more scandalous for the government to get information out of my drinking buddy, because the information I told him was in confidence, and he promised he wouldn't tell anyone. My cell phone provider, on the other hand, clearly says in their ToS who they'll share data with and in what circumstances.
Anyone who offers them money?
They value it alright. At several dollars per person.
> 'Does Drinking Buddy exist?' 'Of course he exists. The Party exists. Drinking Buddy is the embodiment of the Party.' 'Does he exist like you or me?' 'You do not exist', said O'Brien.
> Oceanic society rests ultimately on the belief that Drinking Buddy is omnipotent and that the Party is infallible. But since in reality Drinking Buddy is not omnipotent and the party is not infallible, there is need for an unwearying, moment-to-moment flexibility in the treatment of facts.
Thats basically the foundational idealogy of the united states. Thats not the issue.
The real issue is your next sentence. The government can just loophole around their intentional limitations by paying private companies to work on their behalf.
It's so much worse than even those of us who are moderately interested in mass surveillance know.
https://ballotpedia.org/States_with_initiative_or_referendum
This is why they get their laws passed.
Somehow this reminds me about Blackwater / Xe Technologies? :-/
(Im betting 100 USD that soon we will find out that ICE also deployed "private financed forces" to "support state actions"?)
>Somehow this reminds me about Blackwater / Xe Technologies? :-/
Is there some context I'm missing? Skimming https://en.wikipedia.org/wiki/Blackwater_(company) it shows they might have perpetrated some war crimes, but that alone doesn't really make them worse than the US military. For instance, consider https://en.wikipedia.org/wiki/July_12,_2007,_Baghdad_airstri....
This is all automatic and completely pervasive. Worrying about GPS and userspace computers in the smartphone is important but even if you protect that you've already lost. The baseband computer is announcing your position by the minute. Cell phones couldn't really work without the basestations deciding where you are and which will handle you.
I'm sorry. It is not a law. I am wrong. Thank you for the correction and preventing me from continuing to repeat this embarrassing falsehood.
That said, they do still collect and use this data and turning off GPS doesn't do anything.
Regulations say the baseband MUST control: all wireless signals (including wifi and GPS), all microphones and speakers, and it must be able to disable the camera electrically. It must have a tamper-resistant identifier (IMEI number ... kind of).
Oh, it must allow calling the emergency services. If in this mode, during a call to the emergency services it MUST be able to send the exact GPS position (not just once, continuously) to the emergency services at the request of the emergency services (ie. NOT the user, and carriers must facilitate this)
By the way, it's worse: as you might guess from the purpose, it doesn't matter if your phone is on the "spying" carrier or not, other carriers can send commands to other carriers' phones' basebands (because "get off this frequency" is required: spectrum is shared, even within countries. Since phones may go from one tower to another and be required to vacate frequencies, you need this command). It doesn't even matter if you have a SIM in your phone or not (ever tought that if eSIM works, it must of course be possible for any provider to contact and send instructions to the phone, so it opens up an end-to-end encrypted connection to the javacard that the actual phone cpu cannot intercept). In some phones it doesn't even matter if the phone is on or not (though of course eventually it dies). So "meshtastic" or anything else cannot make a phone safe.
And in practice it's even worse. A lot of phone manufacturers "save on memory" and use the same memory chips for the baseband processor and the central cpu. Which means that it's a little bit cheaper ... and the baseband has access to all the phone memory and all peripherals connected through the memory bus (which is all of them in any recent phone). It may even be the case that these chips are integrated in the cpu (which I believe is the case for recent Apple chips). Oh and the regulations say: if there's a conflict over control over (most) peripherals, including the microphone and speaker, the baseband processor MUST be guaranteed to win that fight.
Oh and because governments demand this, but of course neither fund nor test these devices, they are old, bug-ridden and very insecure. This also means that despite the government requiring that these features be built into phones, governments, carriers and police forces generally do not have the equipment required to actually use these features (though I'm sure the CIA has implement them all). Not even carriers' cell phone towers: they have to pay extra to allow even just frequency sharing ...
Here is an article about baseband and baseband processors.
https://www.extremetech.com/computing/170874-the-secret-seco...
This is simply not true.
Source: I own a phone where this is not the case. Many Linux phones internally attach their wireless devices via USB, so there is good separation.
Also many upscale phones have decoupled the baseband from things that were once connected to it, as an attempt to improve security. (On iOS for instance the main CPU controls wifi.)
Cellular, Wi-Fi, Bluetooth, GNSS NFC, UWB, etc. do get implemented on secondary processors running their own OS but on mainstream smartphones those are typically well isolated and don't have privileged access to other components. The cellular radio in an iPhone or Pixel is on a separate chip but that's a separate thing from it being isolated. Snapdragon devices with cellular implemented by the main SoC still have an isolated radio. Snapdragon implements multiple radios via isolated processes in a microkernel-based RTOS where the overall baseband is also isolated from the rest of the device. There are a lot of lower quality implementations than iPhones, Pixels and Snapdragon devices but the intention is still generally to have the radios isolated even if they don't do it as well as those.
Edit: I’ll add that I think smartphone “security” is almost impossible to achieve, given the complexity of everything and the opacity of modem vendor stacks, which is why I just assume endpoint compromise. I use my phone rarely and with toggle switches normally “off”, and I don’t consider it a secure device or use it very often. If you believe that a secure phone is possible, however, then Graphene is definitely a better fit than a Linux phone.
(Founder/lead dev/ex lead dev, can't recall exactly)
Really? Does the radio somehow become the USB Host in this equation and magically start driving the conversation? How?
I'm going to need a specific citation for this, given that it seems trivially falsifiable by the existence of bluetooth headphones (which the baseband obviously can't control), not to mention other sorts of call forwarding features like the one iPhones have.
What is the tamper resistant number that is kind of the IMEI?
This can be mitigated e.g. via an IOMMU: https://grapheneos.org/faq#baseband-isolation
> It may even be the case that these chips are integrated in the cpu (which I believe is the case for recent Apple chips).
I don't know whether it's true or not that they use the same RAM chips. But either way it doesn't change the fact that they can still be properly segregated via the IOMMU.
https://en.wikipedia.org/wiki/Covert_listening_device#Remote...
And the linked sources are:
- Kröger, Jacob Leon; Raschke, Philip (2019). "Is My Phone Listening in? On the Feasibility and Detectability of Mobile Eavesdropping". Data and Applications Security and Privacy XXXIII. Lecture Notes in Computer Science. Vol. 11559. pp. 102–120. doi:10.1007/978-3-030-22479-0_6. ISBN 978-3-030-22478-3. ISSN 0302-9743.
- Schneier, Bruce (5 December 2006). "Remotely Eavesdropping on Cell Phone Microphones". Schneier On Security. Archived from the original on 12 January 2014. Retrieved 13 December 2009.
- McCullagh, Declan; Anne Broache (1 December 2006). "FBI taps cell phone mic as eavesdropping tool". CNet News. Archived from the original on 10 November 2013. Retrieved 14 March 2009.
- Odell, Mark (1 August 2005). "Use of mobile helped police keep tabs on suspect". Financial Times. Retrieved 14 March 2009.
- "Telephones". Western Regional Security Office (NOAA official site). 2001. Archived from the original on 6 November 2013. Retrieved 22 March 2009.
- "Can You Hear Me Now?". ABC News: The Blotter. Archived from the original on 25 August 2011. Retrieved 13 December 2009.
- Lewis Page (26 June 2007). "Cell hack geek stalks pretty blonde shocker". The Register. Archived from the original on 3 November 2013. Retrieved 1 May 2010.
I am entirely, 100% certain that my telco can't just enable the microphone on my iPhone and record me, short of some 0-day exploit. I simply cannot make that bet on many other devices.
That assertion is a bit overblown. And people can easily find out it's overblown with a bit of research.
But at the same time, my whole philosophy is never let it touch any network connected device at all if it is critical. I don't care if it's an Apple device.
Here's reality, mobile carriers have been able to get your location from nearly the inception of mass market mobile phone use. I'm not sure anyone really believed their location was somehow secret and not discoverable. If you're using the phone or internet networks, you're not anonymous. Full stop.
Forget whatever anyone told you about your VPN, or whatever other anonymization/privacy machine that Mr McBean is selling Sneetches these days. Assume everyone is tracked, and some are even watched. Therefore everything you do or say with your devices should be considered content that is posted publicly with an uncertain release date.
Where? Apple's whitepapers aren't audited by anyone other than themselves.
> Assume everyone is tracked, and some are even watched.
Fatalist non-sequitur.
"You're holding it wrong" might be the laziest thing anyone has ever said about a tech product.
The article touches on this by saying Apple is making the baseband/modem hardware now. Something they should have done since day one, and I’m not sure what took them so long. However, it was was clear they didn’t have the expertise in this area and it was easier to just uses someone else’s.
Apple found out the hard way with the iPhone 4. Their secrecy didn't help. People doing real world testing had a case that made it look like an iPhone 3s and that also happened to mitigate the death grip problem. We know this because one was stolen and given to gizmodo.
And that was even only antenna design, they still used a standard RF stack then.
https://grapheneos.org/faq#future-devices
The radios on the supported devices can't access the microphone, GNSS, etc.
GrapheneOS has never supported a device without an isolated cellular radio since that isolation was in place even with the initial Nexus 5 and Galaxy S4. However, some of the devices prior to Pixels did have Broadcom Wi-Fi/Bluetooth without proper isolation similar to laptops/desktops. Nexus 5X was the initial device with proper isolation for Wi-Fi/Bluetooth due to having SoC provided Wi-Fi from Qualcomm. Pixels have avoided this issue for integrating Broadcom Wi-Fi/Bluetooth. Nexus devices left this up to companies like LG, Huawei, etc. and anything not done for them by Qualcomm tended to have security neglected. Qualcomm has taken security a lot more seriously than other SoC vendors and typical Android OEMs for a long time and provides good isolation for most of the SoC components.
Don't believe everything you read about smartphone security and especially cellular radios. There are many products with far less secure cellular radios which are far less isolated but rather connected via extremely high attack surface approaches including USB which are claiming those are better. A lot of the misconceptions about cellular come from how companies market supposedly more secure products which are in reality far worse than an iPhone.
Could you perhaps elaborate on what the more-secure alternative to USB ACM would be?
Does that mean a Pixel with GrapheneOS won't be susceptible to the "attack" (GNSS location request via RRLP/LPP) mentioned by the OP?
This isn’t a new capability and shouldn’t be surprising.
This is a specific service inside the phone that looks for messages from the carrier requesting a GPS position, it could just refuse, or lie. It's not the same as cell tower triangulation.
I think it would be sufficient to just have a log of this information being queried, and cases where the information has been pinged without a legitimate use case would the be investigated.
Last time I called 911 (well, it's 112 in my country) my android phone asked if I want to provide gps coordinates. I did, but they still asked for address, so probably this is not integrated/used everywhere.
https://rapidsos.com/public-safety/unite/
When the call comes in they can click a button and query RapidSOS for current 911 calls for that number and pull the information inwards.
https://www.baycominc.com/hubfs/2025%20Website%20Update/Prod...
Tons of "free" and crapware apps are also recording location, and sending it to data brokers.
https://www.wired.com/story/jeffrey-epstein-island-visitors-...
https://5g-tools.com/5g-nr-timing-advance-ta-distance-calcul... shows an example of the parameters necessary. I don't think you can get your smartphone to dump those stats for you, but the granularity of the individual distance measurement is in the tens of centimeters.
Of course this strongly depends on cell infrastructure being placed precisely, continuously updating correction factors, and a bunch of antennae being around the target to get measurements for, but in most cities that isn't much of a challenge if the operator is working together with whoever wants to spy on citizens.
The last time I checked, that included Google Play Services, and some of their iOS apps.
When you dial 999 it forwards your phone's GPS location if it has a lock to the provider, who then forwards it on to one of the 999 call handling centres in the UK, who then in turn forward that on to the appropriate emergency service control room. All the various services use various different products for telephony and dispatch but they will show the incoming location, and often will prepopulate an incident with the location.
The system that does this is called "EISEC" - Enhanced Information Service for Emergency Calls - and has a lot of cool stuff defined in the spec (which is publically available! You can just go and read it! BT offer a "Supplier's Information Note" with the protocol and details of how the information is encoded) that also handles calls from landlines. These are easy - your telephone provider knows where you live. OMG! The phone company know where I live? Yes, dumbass, they pulled a wire right into your house, of course they know where it is. For VoIP the situation is a little different but you can notify your VoIP provider of the location that the number is being used at, and it'll inject that into the EISEC request.
You can do other cool stuff like if you've got fixed mobile telephone in a vehicle, you can assign the make, model, registration number, colour, and so on in the EISEC database, so given a call from a phone number they know what car they're looking for. No-one uses this.
The very great majority of calls coming in to 999 are from mobiles. It's extremely rare to get one from a landline.
None of the providers use triangulation for determining where a phone is, it's all GPS.
That's true, but you can always be triangulated down a couple hundred meters by figuring out which towers you're connected to.
Between buying a phone and reading the OS EULA to providing an E911 address to my carrier, I can count at least three disclosures of this feature.
Nothing is secret or magic here.
That’s the majority of uses for the system in the UK. People love to run away and waste police time.
It’s a cost vs benefit analysis and the cost is pretty damn high.
I’m not arguing all locations should be collected, just that “during a 911 call” is a really reasonable time to do it by default.
If it could be adequately controlled so that it couldn’t, I would agree
We definitely got the cellphone tower triangulation data. I never once saw GNSS data provided by a carrier. We used FindMeSAR https://findmesar.com/, the subject would usually text back the coordinates from the phone.
Just one data point.
The revolution that's occurred since my SAR volunteer days is the wide availability of satellite messenging on consumer phones. I'm guessing that's really changed the situation quite a bit.
The article seems to describe another system which can be involved externally.
As for this location stuff, I'm curious though into how this works and how Apple (and BOOST/DISH) somehow prevent it happening when the big 3 in the US don't. We all know Apple would have complete control over the modem they designed, that's not a surprise. T-Mobile at least it's possible to stay NR-SA connected, it's apparently not a feature limited to SA like resistance to IMSI catchers are. Is this an OpenRAN feature, which Boost uses?
At least in the past, towers had a piece of equipment called a LMU that is sometimes installed separately from the radio equipment and it's used for measuring the timing advance to triangulate where a device may be for 911. Here's a reddit thread I started years ago for a KML of all the T-Mobile LMU installs in the NYC market: https://www.reddit.com/r/cellmapper/comments/hq2h7u/kml_of_a... (I just found it leaked, it's not online anymore probably). An FCC doc on LMU's: https://transition.fcc.gov/pshs/services/911-services/enhanc... (this is all old tech now, we're doing LTE/NR now in 99.9% of circumstances in the US)
Trilaterate :)
2017 Broadband Consumer Privacy Proposal
https://www.congress.gov/bill/115th-congress/senate-joint-re...
Here's a summary. In late 2016 the FCC passed a rule that:
(1) applies the customer privacy requirements of the Communications Act of 1934 to broadband Internet access service and other telecommunications services,
(2) requires telecommunications carriers to inform customers about rights to opt in or opt out of the use or the sharing of their confidential information,
(3) adopts data security and breach notification requirements,
(4) prohibits broadband service offerings that are contingent on surrendering privacy rights, and
(5) requires disclosures and affirmative consent when a broadband provider offers customers financial incentives in exchange for the provider's right to use a customer's confidential information.
The bill, introduced early in 2017, nullifies that rule.
It passed the Senate 50-48, then the House of Representatives 215-205, and was signed by Trump.
The 52 Republicans in the Senate voted 50 yes, 0 no, 2 not voting. The 47 Democrats, along with the 1 independent, voted no.
In the House the 236 Republicans voted 215 yes, 15 no, 6 not voting. The 190 Democrats all voted no.
1) Leave the phone at home
2) Use a phone with a hardware toggle switch that physically kills power to the cell modem, or turn off the phone and put it in a tested Faraday bag
3) Conspire with other citizens to make such location tracking illegal and to enforce that law
I’m tired of privacy doomerism. You have options, use them.
> False. You can: 1) Leave the phone at home
Then you dont have a phone, do you? Come on you are being pedantic for no reason.
It was the selling point of mobile phones before smartphones became a thing. It obviously hasn't been the main selling point of mobile phones since then.
I have a phone so I have options if I need to be reachable or reach someone immediately while out (rare), or for travel. And because some services, mostly banks, refuse to accept VOIP numbers but require a verified phone number.
> False. You can: > 1) Leave the phone at home
If you're going to be pedantic, at least be pedantically correct. The tower (and carrier) would still know the location of your phone in that case. (It just wouldn't be with you.)
One day, I was waiting to pick up someone at the bus station and a crazy driver came roaring through the parking lot, jumped the curb and took out a stop sign, then backed up to free it from his car and careened off.
I got on the phone with 911.
I got put on hold, and while waiting on speaker I took a picture of the stop sign from the crash. later the call ended.
The next day I noticed that the photo I took had an embedded location.
location services was globally enabled on the phone during the call.
I wouldn't be surprised if all apps on your phone during 911 get your precise location.
Of course, this doesn't require having GPS location, just cell tower info is enough.
Literally every website and app you use with any kind of shared analytics/ads gets your general location just from your IP address alone, and can update your profile on that analytics/ads provider.
It is far more likely this, than your cell phone provider.
And I don't know about you, but I've put my phone number into a lot of apps and sites. Sometimes it's required, sometimes it's for 2FA, etc.
It doesn't matter if you don't give your phone number to many companies, it only takes one.
It's also not clear why I would have an uptick in spam calls when I'm traveling. I get 2x/week at home and 2x/day when traveling.
But if they're trying to get me to answer the phone, calling from a local number actually makes me less likely to answer. Nobody would be calling my cell phone from the city I'm visiting. I'm more likely to pick up a call if the area code is from back home.
Does it still happen?
Almost every carrier can triangulate a handset in an area with multiple towers without help of the handset using relative signal strength to each seen towers and data processing. This is how most police in most jurisdictions are able to find an active handset within ~100m given only a phone number. Don't think carriers in some countries aren't constantly logging that approximate and precise queried location metadata and selling it to data brokers.
The only method to prevent continuously location tracking is to disconnect a handset from the cellular network by attenuating the signal with a blocking bag, antenna disconnection, or real power off. The lack cellular network connectivity may be extremely inconvenient by defeating the purpose of a phone. There are situations where someone doesn't want to power down their phone but does want to be RF clean where a Faraday bag would be a good idea(tm).
TL;DR, this is nothing new.
Carriers have offered location of your device for 911 calls for years now, through a set of metadata called Automatic Location Identification (ALI).
This is only provided to 911 (police & fire) by carriers alongside your 911 call.
Mobile Device Manufacturers can also provide "precise location" to 911 for the same calls, but that's a separate form of data and closely secured.
Bottom line - Carrier data has always been less precise, but more readily available. Device data (i.e. Apple and Google) is more precise, but harder to access.
https://www.rfwireless-world.com/terminology/cellular-tower-...
FTA:
> But this is not the whole truth, because cellular standards have built-in protocols that make your device silently send GNSS (i.e. GPS, GLONASS, Galileo, BeiDou) location to the carrier.
NB: same applies for NB-IOT. NBB: this has actually SAVED lives source: I use to work as a core network archictect for tier1 carriers
So I don't think a single foil sticker would make much difference.
You'd need to run an open source baseband modem with settings and logs in all the right places. I don't think those exist.
Someone might be able to exploit the Linux kernel running on Qualcomm modems and build a tool for rooted Android phones after reverse engineering the baseband, but I imagine a lot of copyright lawyers and probably law enforcement people will send you very scary letters if you document remote location tracking features like these.
Also, if you have any 4G or 5G modem, your carrier already has a pretty good idea where you are. They probably log your location too. The advanced precision and timing information necessary for high speed cellular broadband is enough to get a decent location log. That also includes other connected devices such as cars, of course.
https://www.t-mobile.com/support/plans-features/t-mobile-fam...
It doesn't require any type of download or application on the target phone or device and doesn't give notice while giving an almost precise location with history of where the device has been.
It has been available for many years under different names. The ability to track any phone or device under the account.
I bet that even the most well versed security researchers don't know it all.
The trivial examples like where users assume safety because they use HDD encryption and TLS but they run firmware they don't know about (like a whole parallel OS being ran by some CPUs) are just what is very visible.
In practice, we should assume that everything that is connected and everything we do online is unsafe.
It was purely based on triangulation based on which tower the cellphone was connected to, so not precise at all (narrow down to a few city blocks).
So at least back in 2018, precise location was not possible.
That said the baseband modem in the phone could certainly be updated to collect and automatically send GPS based location data (notwithstanding security on the device).
It is interesting that we let this happen. Modern phones are very useful devices, but they're not really mandatory for the vast majority of people to actually carry around everywhere they go, in many cases they merely add some convenience or entertainment, and act to consolidate various other kinds of personal devices into just one. If you wanted, you could more often than not avoid needing one. Yet, we pretty much all carry one around anyways, intentionally, and this fact is somewhat abused because it's convenient.
Having watched a fair bit of police interrogations videos recently (don't knock it, it can be addicting) I realized that police have come to rely on cell phone signals pretty heavily to place people near the scene of a crime. This is doubly interesting. For one, because criminals should really know better: phones have been doing this for a long time, and privacy issues with mobile phones are pretty well trodden by this point. But for another, it's just interesting because it works. It's very effective at screwing up the alibi of a criminal.
I've realized that serious privacy violations which actually do work to prevent crime are probably the most dangerous of all, because it's easy to say that because these features can help put criminals behind bars, we should disregard the insane surveillance state we've already built. It's easy to justify the risks this poses to a free society. It's easy to downplay the importance of personal freedoms and privacy.
Once these things become sufficiently normal, it will become very hard to go back, even after the system starts to be abused, and that's what I think about any time I see measures like chat control. We're building our own future hell to help catch a few more scumbags. Whoever thinks it's still worth it... I'd love to check back in in another decade.
With that being said, my 10th floor apartment has a 5g radio installed by one of the major carriers and I am still placed one block wrong when looking on Google Maps.
4G (LTE) networks had more cell sites so could give better precision multilateration, but by then smartphones were taking over the market and they usually had GPS receivers.
https://en.wikipedia.org/wiki/Radio_resource_location_servic...
This data is vital for a mobile carrier to make sure to have a good signal coverage under all the possible conditions.
It's just a guess since I've seen similar data being analyzed in a previous telco I worked at, but I don't know their exact source. The goal there was to improve the network quality. I guess you can do the same w/o GPS, but triangulation with cell towers is very coarse.
Most of those features are not user visible and are compatibility hacks - ie. "use lower profile in video calls if country = FR".
Until then, we must assume that using anything connected implies risks.
> Germany: Telekom > United Kingdom: EE, BT > United States: Boost Mobile > Thailand: AIS, True
So turning this "off" on other carriers results in GPS data still shipped off?
It’s also illegal to sell new cars without a cell modem in them.
The phones are the least of our worries.
Even the article mentions this.
> I have served on a jury where the prosecution obtained location data from cell towers. Since cell towers are sparse (especially before 5G), the accuracy is in the range of tens to hundreds of metres.
I've also personally witnessed murder cases locally where GPS location put a suspect to "100 meters away". The rest of the evidence still pushed the case forward to a guilty verdict, and the phone evidence was still pretty damning.
For example, if you drop a pin a hundred metres off from the incident, then when you're maybe several hundred metres off the column of smoke is probably a better indicator of locus than the wee dot on your screen.
Certain devices (especially tablets) don't have GPS or various sensors integrated and still can tell you your approximate location, if WiFi is enabled.
If you want to play around a bit, you can try my tool that queries Apple's location services for your nearby networks. The precision is remarkable.
Is it a coincidence most smartphone manufacturers were suddenly all on board with removing the 3.5mm jack and forced Bluetooth? A mesh network of sorts like Amazon is doing with Ring. I even sometimes forget to save my battery and turn Bluetooth off when I'm not using my earbuds. It's probably a false sense of security having it disabled because I'm sure it's doing something in the background anyways. I can't say for sure though. Kind of like years ago with Google getting caught with the whole location data thing. I'm sure the average Joe doesn't care if Bluetooth is enabled 24/7.
I try and not be on the tin foil bandwagon, but every once and a while I come across things that make you go hmmm...
Wi-Fi is better for positioning since BSSIDs are (mostly) static and APs don't move around.
On top of that, BLE usually uses random addresses - so it won't be of much help knowing that you were around CC:B9:AF:E8:AE at 10:05 AM - since that address is likely random.
This kind of trilateration relies on beacons that don't move around (much). (And phones move. That's kind of their whole point.)
Fortunately for location data, there's a ton of Bluetooth beacons that are in reasonably fixed locations: Google used to give them away for businesses to use, but things like smart TVs, speakers, and game consoles are all pretty chatty about broadcasting their presence over Bluetooth to anyone in earshot. (And it's easy enough to observe with any app that displays nearby Bluetooth beacons. I see over a dozen right now where I sit in my suburban home.)
Back when my OG iPod Touch was minty and new (2008, IIRC), it was in many ways a stripped-down iPhone.
One of the features that was stripped out was GPS: It didn't have that at all. It also lacked Bluetooth.
But it did have a Maps app, and it also had location services. This used visible wifi access points and a database back home on the mothership to determine location.
It was pretty neat at that time to take this responsive, color-screened pocket computer with me on a walk, connect it to a then-ubiquitous open SSID, and have it figure out my location and provide a map (with aerial photos!) of where I was. It wasn't ever dead-nuts, but it was consistently spooky-good.
It's pretty old tech at this point, and devices still use it today.
(Related tech: Those plastic table tents that you take with you at McDonald's after ordering at the kiosk? They're BLE beacons. Sensors in the ceiling track them so that the person bringing the tray with food on it knows about where you're sitting before they even walk out of the kitchen. And modern pocket supercomputers use the locations of these and other beacons, as well, to help trilaterate their position. Urban environments are replete with very chatty things that don't move around very much.)
It was 5 meters back in 2006 in urban areas.
This has been the case since the e911 project in the 1990's and is mandatory. Prior to this I would reset the message waiting indicator on their phone continuously to see what cells and cell sectors they were moving through but that would basically just show what road or roads they may be on and what direction they are going very roughly. Assisting the FBI with tracking kidnappers or at least that is what they told me.
There are loads of other tags that can be set on someones phone. My favorites were priority override and caller-id blocking override. This was before SS7 spoofing was so prevalent.
How anyone could think this isn't a 4th Amendment violation is a mystery to me.
Edit: I’m not on 26.3. I hadn’t clocked this was a new release thing
You want EMS looking for a needle in a haystack while you are suffering a heart attack?
How might people suggest that this would work, do you suppose?
"We've narrowed the victim's location down to one city block, boys! Assemble a posse and start knocking on doors: If they don't answer, kick it in!" ?
(And before anyone says "Well, it can work however it used to work!" please remember: Previously, we had landline phones in our homes. When we called 0118 999 881 999 119 725 3 for emergency services, there was a database that linked the landline to a street address and [if applicable] unit.
That doesn't work anymore because, broadly-speaking, we now have pocket supercomputers instead of landlines.)
Everyone was effectively doxxed yet it was never a security issue.
And if the phone rang, it was answered. It was almost certainly a real person calling; spam calls were infrequent to the point of almost never happening.
It was a different time, and it is lost to us now.
(We do still have public name-to-address databases, though. For instance: In my state of Ohio, that part of a person's voter registration is public information that anybody can access. Everyone is still effectively doxxed and it's still not a security issue.)
> The limit precise location setting doesn't impact the precision of the location data that is shared with emergency responders during an emergency call.
The fact that something has some good side effects does not make it good or even reasonable.
Mobile carriers have so much information about you. They know exactly where you are, what you are doing (location combined with mapping tools) combined with who you are talking to.
They know when you are at home depot, when you are the grocery store, when you are at home, when you are awake, when you are asleep, etc.
In the U.S. there are very few laws stopping them from using all your data. In the E.U. you should definitely read up, as you aren't as protected as you think you are.
Forget Nation/State nonsense. You have an active relationship with a company who, by it's very existence and your business relationship, knows what you do all day long.
Don't even get me started about the rabbit hole surrounding 'incognito'/anonymous browsing.
EDIT: You've probably heard of Man-in-the-Middle attacks, right? They are the man in the middle. They will exploit this as best they legally can (and in certain cases, without regard to legality)
The best way to protect yourself is not to play the game at all. The same goes for your ISP, FWIW.
Why wouldn't carriers be able to ask your phone about what it thinks its location is?
> Apple made a good step in iOS 26.3 to limit at least one vector of mass surveillance, enabled by having full control of the modem silicon and firmware. They must now allow users to disable GNSS location responses to mobile carriers, and notify the user when such attempts are made to their device.
They never said "triangulate" but read phone for information. Your inner monologue swapped what was written with an already understood technical method.
And just because access to GPS has never been confirmed publicly before does not mean they previously only relied on tower triangulation.
Worked for Sprints network team before they bought Nextel. We had access to eeeeverything.
The crux of the argument seems to come from this
> It’s worth noting that GNSS location is never meant to leave your device. GNSS coordinates are calculated entirely passively.
OK so? The fact that GPS is calculated passively means nothing about the phone being asked what its position is after the fact.
The article admits this capability is no secret
> These capabilities are not secrets but somehow they have mostly slid under the radar of the public consciousness.
If the article just wants to say phones should block that ability, fine. But don't pretend this is some shady BS.
It is shady BS, and it’s why this phrase appeared in the article. Just because industry insiders are aware doesn’t mean it’s not shady.
The same applies to modern cars reporting their information back to manufacturers.
The cell network does not need to know where you are down to the meter and phones have no business giving this information up.
Generally I'd not expect them actively triangulate my exact location, but I'd realise that's at least possible - but GPS data, wake my phone up, switch on the GPS radio, drain it's battery, send that data back... no. That wouldn't be legal where I live either, let alone expected.
Where does the article claim this turns on the GPS if off?
While this is an important question, I don't see the sources mentioning it, what the standards mandate, and how the phones behave.
For example the wiki article https://en.wikipedia.org/wiki/Radio_resource_location_servic... describes the protocol as using the GPS and not as getting the location info from Android.
https://www.theindustrycouncil.org/post/911-location-accurac...