top | item 17163013

Why Is Location Data No Longer Private?

378 points| lainon | 7 years ago |krebsonsecurity.com

143 comments

order
[+] exabrial|7 years ago|reply
Because Facebook and Google have been guided by the principal: if it's not illegal, it's ethical. Just take a look at the language in UIs lately, it's gotten passive aggressive; instead of a polite "No thanks", our choices are now: "Maybe later". I thought 'no means no'? Silicon valley had a serious ethics problem; as much as they try to ride the white horse on 'I don't want Google partnering with the DOD", watch their eyes light up when you give them access to a middle class single mom's phone with a click through EULA.
[+] codedokode|7 years ago|reply
On Android 5, every time you enable GPS, a popup comes up asking you to share location with Google. There is a checkbox "don't ask me again", but if you tick it, the button "Decline" becomes inactive [1]. So it is going to pop up every time you want to know your location unless you agree. This attitude is openly hostile to the user (and yes, that's why we need more regulation).

[1] https://android.stackexchange.com/questions/115944/in-lollip...

[+] unclebucknasty|7 years ago|reply
It's all down to the hyper-toxic idea that every company must now extract as much data from you as possible. Google and Facebook were two of the early pioneers of "here is a 'free' product in exchange for your data" that succeeded at serious scale.

Now, it's no longer even enough to simply pay for a product from just about any company. We must also consent to essentially being further exploited for the company's gain ever-after.

There is a lot of discussion about dark UI patterns here and it's true that they are pervasive these days. Much of it is spawned by this customer-hostile "dark business model".

Replace the word "nothing" with "something" in this "300" clip and it pretty much sums up many company attitudes these days: https://m.youtube.com/watch?v=uHxIssSROjk

[+] makecheck|7 years ago|reply
Such a pet peeve of mine, weasel-worded buttons. I remember the first time something gave me the option to “Archive” a thing but not “Delete” it...I stopped using the service after that. Also, usually their least favorite options do not even look like options (random non-button-like text off to the side or whatever).

Another atrocity is an alert with a “don’t ask again” check box, especially in something that is unnecessarily-modal (read: developer was lazy). Pro tip: if you think the user won’t want to see your message ever again then you need to redesign your system to keep the message from appearing even the first time.

[+] mhuffman|7 years ago|reply
The ones that make me rage is where they say something along the lines of "Opt out of ad tracking" then have a disclaimer that says something like "you're still going to get a bunch of ads, they will just suck worse".

How about just offering me an option to pay you to get rid of tracking and advertising?

[+] dragonwriter|7 years ago|reply
> Just take a look at the language in UIs lately, it's gotten passive aggressive; instead of a polite "No thanks", our choices are now: "Maybe later".

Since that's how the “No, thanks” option was usually treated in the past, it's just truth-in-UI.

[+] sbhn|7 years ago|reply
Try cancelling your wordpress subscription if you want to see dark patterns in ui
[+] emilsedgh|7 years ago|reply
When did this ethical issue happen? Up until a few years ago, my feeling was that hackers had the high horse regarding ethics, considering free software movement, crypto movements, etc.

Did hackers lose their ethics when money was poured in?

[+] mLuby|7 years ago|reply
I want to see where lawmakers are spending their time (especially in their off hours). There's probably plenty of fun stuff to discover in the data.
[+] hedora|7 years ago|reply
Honestly, a publically available real time map of the location of all lawmakers that haven’t pledged to fix this is probably the only way to fix it.

If that’s not enough, some simple data mining to list all their known associates, mistresses (etc), would probably get it fixed.

Sadly, they’d probably just make it illegal to publish data about the ruling class and not the rest of us.

[+] hutzlibu|7 years ago|reply
Yes. Thats still my main problem with this whole post privacy thing - the big players know allmost everything about us, but we only know redegated informations about them.

I just heard (so no sure if true, but likely) Mark Zuckerberg bought all of the surrounding houses of his home to protect his privacy...

[+] rasz|7 years ago|reply
Talk to your friendly local Repo men, they can track every bit of asset, and all they need is owners name. That includes tracking personal and car embedded cellphones, digging thru social media for close friends and family, scanning ANPR databases etc.
[+] the_seraphim|7 years ago|reply
Yep, mostly FBI agents waiting to arrest you for felony wiretapping charges
[+] voodootrucker|7 years ago|reply
Googling for "phone location ss7" returns some interesting results that may or may not work given some protocol upgrades:

http://s3.documentcloud.org/documents/1275167/skylock-produc...

https://berlin.ccc.de/~tobias/25c3-locating-mobile-phones.pd...

https://blog.c22.cc/2009/12/28/26c3-sccp-hacking-attacking-s...

A commercial provider for these services: https://www.pccwglobal.com/en/service-provider/products/mobi...

Wireshark screenshot of GSM packet with cell site info: https://resources.infosecinstitute.com/wp-content/uploads/05...

[+] dannyw|7 years ago|reply
LocartionSmart isn’t SS7. They get the feeds and triangulation directly from the carrier (they purchase it).
[+] conradev|7 years ago|reply
The thing that scares me the most about the LocationSmart stuff is that I can't think of any workaround besides "don't use cellular data".
[+] voodootrucker|7 years ago|reply
It works as long as your phone is turned on and within range of at least one cell tower.

Whether you have data turned on is irrelevant, along with phone type, OS, smart or dumb - This affects all cell users.

[+] pacala|7 years ago|reply
Airplane mode + WiFi + Signal? Covers 95% of my daily routine. Home-Work-Home-Work-Home-Work-Home-Work-Home-Work-Weekend-Weekend.
[+] psergeant|7 years ago|reply
The solution is political, not technical.
[+] uptown|7 years ago|reply
Faraday bags work when you want devices offline - but it doesn’t make for a very useful device.
[+] mcrady|7 years ago|reply
Do you have a source for that? Even without cellular data turned on, carriers know your rough location based on cell tower locations.
[+] dexter0|7 years ago|reply
Use a "proxy" phone number that forwards to your cell phone number and keep your real cell phone number private.
[+] WillPostForFood|7 years ago|reply
Love Krebs, and there is an important point here about location privacy, and the scandalous selling of it, but it really gets lost in trying to tie it to net neutrality, which really is largely a separate issue.
[+] rectang|7 years ago|reply
It's not tied because of Krebs. It's tied because Ajit Pai's FCC performed selective "deregulation" in the name of repealing "net neutrality" and further entrenched the telecom oligopoly by allowing them to abuse their market dominance in other verticals.
[+] simion314|7 years ago|reply
Net neutrality has in common with the selling of user data the same theme big company "rights" versus the customers/citizens rights, I don't thing "rights" is the best word there but I can't find other right now.
[+] codedokode|7 years ago|reply
I might be wrong, but LocationSmart wouldn't be able to work under GDPR. So the correct title should be "Location data is no longer private in non-GDPR countries".
[+] himom|7 years ago|reply
People must demand privacy protections similar to HIPAA for their digital lives. And to have ownership over location and contact details. If not, the corporate stalking and creepy targeting will continue.
[+] mcovey|7 years ago|reply
I spent a while not carrying a phone with me at all. It was kind of a pain. I went back to carrying the dumbphone, turned off. I turn it on during my breaks to check if I missed anything.
[+] ikeboy|7 years ago|reply
Trying to imply that this has anything to do with the NN law is incredibly dishonest. The post doesn't explicitly claim it would have prevented this but shifts back and forth between several topics to create a clear implication.
[+] djsumdog|7 years ago|reply
The article talks about Ajit Pai and how he was promoted by Trump. This is a bit misleading as Pai was appointed originally by Obama and served in high level roles in the FCC, although Trump did place him in his current position.
[+] flatfilefan|7 years ago|reply

[deleted]

[+] mcrady|7 years ago|reply
Mobile carriers are selling your real time location to anyone willing to pay. The number of nefarious uses for real time location is immense

And meanwhile, the press is worked up about cambridge analytica accessing your facebook friend network.

It seems like someone ought to put a site with real time locations of our senators and congressmen. My guess is that will solve the problem quickly.

[+] the_seraphim|7 years ago|reply
All the mobile carriers in the US are shit at keeping your data secure, real time data has been leaked on one hand, comcast leaked home addresses and wifi router login details on the other, article is calling out Ajit Pai for trying to repeal 2015 privacy rules amongst said bullshit.

and im her in europe basking under the protective blanket of the GDPR (which sounds too similar to the DDR (Deutsche Demokratische Republik for my tastes))

[+] ryanlol|7 years ago|reply
When Was Location Data Private?
[+] pmiller2|7 years ago|reply
For all practical purposes, about 35 years ago, unless you were under targeted surveillance.
[+] Maarten88|7 years ago|reply
When you were outside the US.
[+] just_observing|7 years ago|reply
Please use a responsive theme.

It matters.

[+] hedora|7 years ago|reply
On iPhone, long press reader view, and click on the option to automatically use it for all sites.

Problem solved.

[+] sametmax|7 years ago|reply
On firefox, click on the paper like icon in the url bar to turn on readability mode
[+] afpx|7 years ago|reply
Isn’t the problem more about users of technology blindly agreeing to contracts that very few actually read? In some cases, there are actual breeches that expose private data to misuse, but most location data is obtained from users who quickly scroll through a long EULA without understanding what they’re agreeing to.
[+] tropdrop|7 years ago|reply
I would like to hear more from individuals that actually take the time to read every single EULA that gets thrown at them - and what their next course of action is after they do.

For some EULAs, it is possible to abstain using the service once you find something egregious in that agreement. I can avoid downloading an app or taking an Uber.

But when it comes to internet service providers - what are your options? Okay, you read through Comcast's EULA and found something alarming. So your next option is to... read AT&T's EULA and also be alarmed? Is the solution to forgo any cell/internet service?

[+] wu-ikkyu|7 years ago|reply
>Isn’t the problem more about users of technology blindly agreeing to contracts that very few actually read?

Isn't this problem more about purposefuly obfuscated legalese documents that are impossible for users to understand and that are constantly updated and constricted like "bait and switch" schemes?