Cell Phone Tracking Firm Exposed Millions of Americans' Real-time Locations (zdnet.com) 39
Earlier this week, ZDNet shed some light on a company called LocationSmart that is buying your real-time location data from four of the largest U.S. carriers in the United States. The story blew up because a former police sheriff snooped on phone location data without a warrant, according to The New York Times. ZDNet is now reporting that the company "had a bug in its website that allowed anyone to see where a person is located -- without obtaining their consent." An anonymous reader shares an excerpt: "Due to a very elementary bug in the website, you can just skip that consent part and go straight to the location," said Robert Xiao, a PhD. student at the Human-Computer Interaction Institute at Carnegie Mellon University, in a phone call. "The implication of this is that LocationSmart never required consent in the first place," he said. "There seems to be no security oversight here." The "try" website was pulled offline after Xiao privately disclosed the bug to the company, with help from CERT, a public vulnerability database, also at Carnegie Mellon. Xiao said the bug may have exposed nearly every cell phone customer in the U.S. and Canada, some 200 million customers.
The researcher said he started looking at LocationSmart's website following ZDNet's report this week, which followed from a story from The New York Times, which revealed how a former police sheriff snooped on phone location data without a warrant. The sheriff has pleaded not guilty to charges of unlawful surveillance. He said one of the APIs used in the "try" page that allows users to try the location feature out was not validating the consent response properly. Xiao said it was "trivially easy" to skip the part where the API sends the text message to the user to obtain their consent. "It's a surprisingly simple bug," he said.
The researcher said he started looking at LocationSmart's website following ZDNet's report this week, which followed from a story from The New York Times, which revealed how a former police sheriff snooped on phone location data without a warrant. The sheriff has pleaded not guilty to charges of unlawful surveillance. He said one of the APIs used in the "try" page that allows users to try the location feature out was not validating the consent response properly. Xiao said it was "trivially easy" to skip the part where the API sends the text message to the user to obtain their consent. "It's a surprisingly simple bug," he said.
Why?!? (Score:1)
Why are cellular companies even allowed to sell that data to just anyone?
Re:Why?!? (Score:4)
Because they all put it in the terms of service you agreed to and USA has no law that says they can't add that to the contract.
Re: (Score:2)
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
Re: (Score:1)
Because they all put it in the terms of service you agreed to and USA has no law that says they can't add that to the contract.
A question. Wasn't it a rule during Obama administration recently voted down by the current Congress and signed by Mr Trump?
On March 28, Congress voted along party lines to kill a set of rules adopted by the Federal Communications Commission in October that would've forced your internet service provider, or ISP, to ask you before it collected certain personal information.
The joint resolution that enacts those changes, S.J. Res. 34, was presented by Republican Sen. Jeff Flake of Arizona and cosponsored by 24 other Republicans. President Donald Trump signed the resolution on Monday night, turning it into law.
Re: (Score:2)
Their hardware and software has to work.
A cellphone thats too hard to decrypt and track all around the USA is a cell phone that should not be approved.
Re: (Score:2)
Police and FBI support. DEA and High Intensity Drug Trafficking Area policing. State task forces and city, state police.
Their hardware and software has to work.
A cellphone thats too hard to decrypt and track all around the USA is a cell phone that should not be approved.
Exactly.
The government loves them some "third-party doctrine". It means that not only does it make it trivial for government to implement mass surveillance/tracking, it also means all these corporations can cash in on your privacy as well, and so can bad actors.
Glad I don't own a cellphone. Not planning on getting one until this privacy/security stuff is fixed to at least a somewhat reasonable level, which likely means I'll never own a cellphone.
What needs to happen to force change is to use this to publish
We need a new law (Score:2)
We need a new law.
A privacy by default law. Lets call it Title III. Basically Title II lets these ISPs and data hoarders do whatever with this data. They need to be reigned in a bit. Just like Title I restricted the phone companies from basically spying on everyone. This is not the first time this has happened. It is happening right now.
Would it shock you to know that cell phones are not covered under Title I rules? But II rules. Because they are more flexible.
Re: (Score:3)
Let me guess, voip services sold as a replacement for traditional phone lines are also under Title II rules?
I've been waiting... (Score:3)
...popcorn in hand for some company to leak data like this. I always figured it would be something like FB messages which I am fully convinced was the the way the world in 'The Road' became that way.
If I recall correctly there was a poll that showed in roughly 30% percent of marriages one or both partners admitted to cheating. Imagine ~10 million married couples finding out about infidelity in the relationship near simultaneously.
Re:I've been waiting... (Score:4, Funny)
That means 10 million ladies willing to get payback by sleeping with slashdotters! Let the good times roll!
Re: (Score:2)
That means 10 million ladies willing to get payback by sleeping with slashdotters! Let the good times roll!
Five million ladies. The infidelity rate is basically the same for both men and women, hence if 10m marriages have infidelity then around half of them would be cheating wives.
Re: (Score:1)
Re: (Score:2)
There was that whole Ashley Madison thing... around 10 million accounts. A dozen or so people are known to have committed suicide following it... people got blackmailed for Bitcoin, but it was hardly the end of Western Civilization.
Four of the largest US Carriers... (Score:5, Insightful)
Considering that there are only 4 mobile carriers in the US (Verizon, ATT, Sprint, and T-Mobile) and pretty much everyone underneath is an MVNO leasing space from them, that covers pretty much 95% of the whole US.
Re:Four of the largest US Carriers... (Score:4, Insightful)
Correction, the big 4 mobile carriers are the only games in town. That means everyone with a cell phone has been spied on.
Re: (Score:2)
how about no double standards here... (Score:5, Insightful)
that sheriff should be strung up by the courts and given 30 years for 'hacking'.. as anyone else would get if they were a normal person who did the same thing.
Re: (Score:2)
He's being charged. What more do you want?
What's a "police sheriff"? (Score:1, Insightful)
Re: (Score:2)
There should be the additional charge of hacking a computer network. Once that access right demand comes up and you actively thwart it, you have hacked a computer network and then the other laws come into play. So the computer network crime should take priority. Else it is like claiming a locked door is not secure of there is a pane of glass that can be readily thwarted right next to it. So busted for the lessor crime, failing to adhere to the requirement for warrants, only to face a worse prosecution upon
sue sue sue (Score:1)
Time to back the truck up and wait for payout. stand up and act
High time (Score:5, Insightful)
A company can just buy reak-time tracking data on everyone from the carriers?
To quote from The Terror,:
"Go find a carpenter."
"Why?"
"It's time to build a gallows."
The website bug is a red herring. (Score:3, Insightful)
Headline is so wrong it's not even funny. (Score:2)
"Cell Phone Tracking Firm Exposed Millions of Americans' Real-time Locations"
Should be:
"Scummy Cell Phone Carriers (Verizon, AT&T, Sprint, T-Mobile) Sell Real-Time Location Information of Subscribers to Anyone Willing to Pay"
Re: (Score:2)
Laws (and/or regulations, depending on jurisdiction) require the companies to keep that information and make it available to government officials. Securus is supposed to be acting as an agent of government when it does this. Unsurprisingly, neither government nor the middleman do a very good job of access control or oversight.
And the Feds (Score:2)
Turn their back on local and state LEA that use and purchase "cell-simulators" that break multiple federal laws regarding spectrum allocation and type accepted equipment use without even discussing privacy issues, AND WE PAY STUPID money for them, AND the agencies are prohibited by an EULA to even admit they posses these devices. HOW DOES THAT WORK? That's even worse than a commercial entity breaking the law.