HNHacker News
TopNewBestAskShowJobs

dude123456

160 karma · joined May 16, 2018

submissionscomments
dude123456··on US cell carriers are selling access to real-time phone location data
In a typical bid entry there are between 500 and 5000 bits of information relating to an individual, per the definition of GDPR. And that's not including the dreaded "IFA", which uniquely identifies the individual.

I don't agree with your claim that "the geodata is often fraudulent".

Anyone can read the linked pdf specification (above), download sample data from the exchanges, and judge for themselves.

dude123456··on US cell carriers are selling access to real-time phone location data
True++ there are at least 4-5 OSes on Qualcomm with direct access to the Internet:

1. Linux Kernel / Android OS, running on main ARM CPU in "normal mode"

2. QSEE or Trustonic OS, running on main ARM CPU in "trusted execution environment" mode, in parallel with "normal mode"

3. OKL4 / REX Kernel + AMSS OS, running on the baseband CPU (modem)

4. SIM card processor, although it is very limited (typically 32k RAM) and acts only as a MITM for SMS's, not cellular data

5. The OS running on the Wi-Fi card

dude123456··on US cell carriers are selling access to real-time phone location data
You get all the data (geo, user's year-of-birth, user interests, device type, etc) before you place the bid. All the json data fields are defined in the standard. I can see iOS and Windows-phone in the feed, it's not limited to Android phones.

https://www.iab.com/wp-content/uploads/2015/05/OpenRTB_API_S...

You don't actually have to bid.

(HN is rate-limiting me) edit: Data is pushed to you as fast as you can process it. It's a firehose.

dude123456··on US cell carriers are selling access to real-time phone location data
You're looking in the wrong place.

TrustZone OS is started during SBL2 (secureboot level 2), running in hypervisor mode, while you're looking at the Android OS started during SBL3 (secureboot level 3). You cannot see hypervisor processes & apps from your vantage point (the android kernel).

The trustzone OS is usually located in TZ partition, and it uses some additional partitions for custom TZ apps and data persistence.

The hypervisor has independent access to the internet, the wifi card (for indoor location), and more.

Qualcom boot process, showing SBL1, SBL2 and SBL3 stages:

https://forum.xda-developers.com/showthread.php?t=1769411&pa...

It goes without saying that without TrustZone OS, the phone won't boot to Android OS (won't proceed to SBL3).

dude123456··on US cell carriers are selling access to real-time phone location data
Any company that sells you access to ad real-time bidding. You connect to a event fire-hose that gives you a nice standardized json for each ad target, with plenty of data about the user (including geolocation), and you choose whether to bid or not on each ad, in realtime.

It is an open standard:

https://www.iab.com/guidelines/real-time-bidding-rtb-project...

dude123456··on US cell carriers are selling access to real-time phone location data
You have a Qualcomm Snapdragon 820? Oh yes, IZat is definitively there, along with other interesting trustzone applets :)

It is running under QSEE (Qualcomm) and/or MobiCore (Trustonic) OS, which is separate from your Android OS. It is left untouched by custom ROMs.

dude123456··on US cell carriers are selling access to real-time phone location data
some of crapware can be avoided by using custom ROMs, but not all of it. For example: Qualcomm IZat location services and other location-based trustzone applets remain running even on custom ROMs.