[HN Gopher] Mobile carriers can get your GPS location
       ___________________________________________________________________
        
       Mobile carriers can get your GPS location
        
       Author : cbeuw
       Score  : 348 points
       Date   : 2026-01-31 17:21 UTC (5 hours ago)
        
 (HTM) web link (an.dywa.ng)
 (TXT) w3m dump (an.dywa.ng)
        
       | kayodelycaon wrote:
       | Emergency services (with the proper software) have been able to
       | get your precise location from your phone for a while now.
       | 
       | This isn't a new capability and shouldn't be surprising.
        
         | michaelt wrote:
         | Surely that only happens when the phone user dials 911 ?
        
           | hammock wrote:
           | How would that work?
        
             | roywiggins wrote:
             | The phone could literally pop up a consent alert asking
             | whether to respond to a GPS ping request from the carrier.
             | Or just not honor the pings at all unless you dialed 911
             | within the last hour.
             | 
             | This is a specific service inside the phone that looks for
             | messages from the carrier requesting a GPS position, it
             | could just refuse, or lie. It's not the same as cell tower
             | triangulation.
        
               | winstonwinston wrote:
               | The article does not explain in detail how all this
               | works. But educated guess is that if a baseband SoC
               | provides this information, that's it. The phone operating
               | system (iOS, Android) does not get a chance to decide
               | what to do, since baseband soc is a sort of autonomous
               | computer, it has its own firmware, cpu and ram.
        
               | roywiggins wrote:
               | You might not be able to fix this in the OS alone, but
               | phone manufacturers are responsible for the whole phone.
               | The baseband doesn't need to behave that way.
        
               | winstonwinston wrote:
               | Well, yes. But autonomous is acting in accordance with
               | one's duty (a law) rather than one's desires.
        
               | hammock wrote:
               | That's not happening today. I meant how is it happening
               | today, such that it can only ever happen when you dial
               | 911?
        
               | _flux wrote:
               | I can imagine situations where the emergency is noticed
               | by other people that might not be near the location
               | itself, and the person whose location would need to be
               | determined is not able to use the mobile phone, such as
               | could be the case in many accidents.
               | 
               | I think it would be sufficient to just have a log of this
               | information being queried, and cases where the
               | information has been pinged without a legitimate use case
               | would the be investigated.
        
             | kortilla wrote:
             | A phone knows if it's dialing 911. It can activate features
             | on this criteria
        
             | cosmicgadget wrote:
             | It already exists. Emergency call is spec-defined.
        
             | yetihehe wrote:
             | Phone detects that you call emergency service and enables
             | gps.
             | 
             | Last time I called 911 (well, it's 112 in my country) my
             | android phone asked if I want to provide gps coordinates. I
             | did, but they still asked for address, so probably this is
             | not integrated/used everywhere.
        
               | nkrisc wrote:
               | They may also ask simply to confirm the location is
               | correct and to help responders more quickly locate you in
               | the vicinity.
        
             | kotaKat wrote:
             | Carrier* Android and iOS both integrate with RapidSOS
             | UNITE. RapidSOS then processes the rich emergency
             | information from the user's device (enhanced location,
             | videos and photos, etc), and is available to the 911
             | dispatcher in their dispatch software. 99.99% of Americans
             | are covered by RapidSOS integrations in their
             | municipalities.
             | 
             | https://rapidsos.com/public-safety/unite/
             | 
             | When the call comes in they can click a button and query
             | RapidSOS for current 911 calls for that number and pull the
             | information inwards.
             | 
             | https://www.baycominc.com/hubfs/2025%20Website%20Update/Pro
             | d...
        
             | cenamus wrote:
             | Send the GPS location only when dialling a 3-digit number?
             | Phones probably know which numbers are emergency numbers
        
           | anonymousiam wrote:
           | The cell network routinely does TDoA triangulation in order
           | to help choose which tower should serve the client mobile
           | device. Accuracy is about 20m, and may be better at 5G
           | frequencies. 911 gets the location from the mobile network
           | provider, but the network provider could provide it to
           | anyone, and they do.
           | 
           | Tons of "free" and crapware apps are also recording location,
           | and sending it to data brokers.
           | 
           | https://www.wired.com/story/jeffrey-epstein-island-
           | visitors-...
        
             | jeroenhd wrote:
             | Using LTE Timing Advance feature, especially on 5G,
             | accuracy can be much higher.
             | 
             | https://5g-tools.com/5g-nr-timing-advance-ta-distance-
             | calcul... shows an example of the parameters necessary. I
             | don't think you can get your smartphone to dump those stats
             | for you, but the granularity of the individual distance
             | measurement is in the tens of centimeters.
             | 
             | Of course this strongly depends on cell infrastructure
             | being placed precisely, continuously updating correction
             | factors, and a bunch of antennae being around the target to
             | get measurements for, but in most cities that isn't much of
             | a challenge if the operator is working together with
             | whoever wants to spy on citizens.
        
           | ErroneousBosh wrote:
           | In the UK, it happens when you call 999 or 112. I don't think
           | 911 is supported, although it probably should be (it'd be a
           | mess to get everyone to agree to add it to their routing
           | tables, but I bet there's a nonzero proportion of people who
           | watch American TV programmes and think the emergency number
           | is 911 - or, for that matter, American tourists).
           | 
           | When you dial 999 it forwards your phone's GPS location if it
           | has a lock to the provider, who then forwards it on to one of
           | the 999 call handling centres in the UK, who then in turn
           | forward that on to the appropriate emergency service control
           | room. All the various services use various different products
           | for telephony and dispatch but they will show the incoming
           | location, and often will prepopulate an incident with the
           | location.
           | 
           | The system that does this is called "EISEC" - Enhanced
           | Information Service for Emergency Calls - and has a lot of
           | cool stuff defined in the spec (which is publically
           | available! You can just go and read it! BT offer a
           | "Supplier's Information Note" with the protocol and details
           | of how the information is encoded) that also handles calls
           | from landlines. These are easy - your telephone provider
           | knows where you live. OMG! The phone company know where I
           | live? Yes, dumbass, they pulled a wire right into your house,
           | of course they know where it is. For VoIP the situation is a
           | little different but you can notify your VoIP provider of the
           | location that the number is being used at, and it'll inject
           | that into the EISEC request.
           | 
           | You can do other cool stuff like if you've got fixed mobile
           | telephone in a vehicle, you can assign the make, model,
           | registration number, colour, and so on in the EISEC database,
           | so given a call from a phone number they know what car
           | they're looking for. No-one uses this.
           | 
           | The very great majority of calls coming in to 999 are from
           | mobiles. It's extremely rare to get one from a landline.
           | 
           | None of the providers use triangulation for determining where
           | a phone is, it's all GPS.
        
           | nateberkopec wrote:
           | You're thinking of Phase II E911 in the US.
           | 
           | That's true, but you can always be triangulated down a couple
           | hundred meters by figuring out which towers you're connected
           | to.
        
         | Etheryte wrote:
         | None of this should be happening without the user's knowledge
         | and consent. Swap out your phone carrier for Facebook and it
         | should be plainly obvious why the current state of affairs is
         | undesirable.
        
           | cosmicgadget wrote:
           | You know about it because your regulatory body requires the
           | system exist.
        
             | TheNewsIsHere wrote:
             | And it's typically disclosed in one way or another.
             | 
             | Between buying a phone and reading the OS EULA to providing
             | an E911 address to my carrier, I can count at least three
             | disclosures of this feature.
             | 
             | Nothing is secret or magic here.
        
           | MagicMoonlight wrote:
           | What is it's a mentally ill person who is about to kill
           | themself?
           | 
           | That's the majority of uses for the system in the UK. People
           | love to run away and waste police time.
        
             | iamnothere wrote:
             | That's not a good excuse for mass privacy violation.
        
           | KellyCriterion wrote:
           | I think this feature is required for emergency calls if your
           | specific carrier is not available/in reach - in emergency
           | mode after the phone is restarted, it does connect to any
           | carrier when calling 911, not only yours?
        
         | nateberkopec wrote:
         | I spent ~5 years volunteering for a search and rescue team in
         | New Mexico.
         | 
         | We definitely got the cellphone tower triangulation data. I
         | never once saw GNSS data provided by a carrier. We used
         | FindMeSAR https://findmesar.com/, the subject would usually
         | text back the coordinates from the phone.
         | 
         | Just one data point.
         | 
         | The revolution that's occurred since my SAR volunteer days is
         | the wide availability of satellite messenging on consumer
         | phones. I'm guessing that's really changed the situation quite
         | a bit.
        
       | tekla wrote:
       | How is this news?
       | 
       | Why wouldn't carriers be able to ask your phone about what it
       | thinks its location is?
        
         | mcny wrote:
         | No, please read the article. No one is saying carriers cant
         | triangulate but carriers shouldn't be able to query the gps on
         | my device and get precise GNSS data.
         | 
         | > Apple made a good step in iOS 26.3 to limit at least one
         | vector of mass surveillance, enabled by having full control of
         | the modem silicon and firmware. They must now allow users to
         | disable GNSS location responses to mobile carriers, and notify
         | the user when such attempts are made to their device.
        
           | benSaiyen wrote:
           | Please reread OPs comment
           | 
           | They never said "triangulate" but read phone for information.
           | Your inner monologue swapped what was written with an already
           | understood technical method.
           | 
           | And just because access to GPS has never been confirmed
           | publicly before does not mean they previously only relied on
           | tower triangulation.
           | 
           | Worked for Sprints network team before they bought Nextel. We
           | had access to eeeeverything.
        
           | tekla wrote:
           | I did read the article fine, thanks for asking.
           | 
           | The crux of the argument seems to come from this
           | 
           | > It's worth noting that GNSS location is never meant to
           | leave your device. GNSS coordinates are calculated entirely
           | passively.
           | 
           | OK so? The fact that GPS is calculated passively means
           | nothing about the phone being asked what its position is
           | after the fact.
           | 
           | The article admits this capability is no secret
           | 
           | > These capabilities are not secrets but somehow they have
           | mostly slid under the radar of the public consciousness.
           | 
           | If the article just wants to say phones should block that
           | ability, fine. But don't pretend this is some shady BS.
        
             | kortilla wrote:
             | > slid under the radar of the public consciousness.
             | 
             | It is shady BS, and it's why this phrase appeared in the
             | article. Just because industry insiders are aware doesn't
             | mean it's not shady.
             | 
             | The same applies to modern cars reporting their information
             | back to manufacturers.
        
         | colechristensen wrote:
         | There's a difference in precision between cell tower
         | triangulation and GPS. From 10-100 meters down to 1.
         | 
         | The cell network does not need to know where you are down to
         | the meter and phones have no business giving this information
         | up.
        
         | Plasmoid2000ad wrote:
         | Why would they? It's basic privacy no? Just because I want to
         | pay money to carrier to provide me with data and phone service,
         | I shouldn't have to give up my location from my device. I
         | expect them to know my approximate location from cell tower
         | data.
         | 
         | Generally I'd not expect them actively triangulate my exact
         | location, but I'd realise that's at least possible - but GPS
         | data, wake my phone up, switch on the GPS radio, drain it's
         | battery, send that data back... no. That wouldn't be legal
         | where I live either, let alone expected.
        
           | tekla wrote:
           | > but GPS data, wake my phone up, switch on the GPS radio,
           | drain it's battery, send that data back... no. That wouldn't
           | be legal where I live either, let alone expected.
           | 
           | Where does the article claim this turns on the GPS if off?
        
             | bmacho wrote:
             | It .. probably does turn the GPS on?
             | 
             | While this is an important question, I don't see the
             | sources mentioning it, what the standards mandate, and how
             | the phones behave.
             | 
             | For example the wiki article https://en.wikipedia.org/wiki/
             | Radio_resource_location_servic... describes the protocol as
             | using the GPS and not as getting the location info from
             | Android.
        
           | nephihaha wrote:
           | It's all in the small print or acquired by deception.
        
         | vlovich123 wrote:
         | The can ask but your phone maybe doesn't have to tell them by
         | default / you can opt out
        
       | ProofHouse wrote:
       | In other news, the sky is up
        
       | cluckindan wrote:
       | Removing this ability also prevents emergency services from
       | determining device location in case its owner goes missing.
        
         | webstrand wrote:
         | No? If the device is connected to a cell, they can still
         | triangulate it just like normal.
        
           | mcculley wrote:
           | Cell tower triangulation does not provide the same precision
           | as GPS.
        
           | roywiggins wrote:
           | In an emergency you might really want GPS precision.
        
             | krater23 wrote:
             | Which emergency can happen that I really want this? And now
             | don't say suicide attempt. Nearby all emergencies that
             | could happen where someone needs my exact position are
             | things that would additionally lead to a loss of the base
             | connection or a switched off smart phone.
        
           | benSaiyen wrote:
           | Triangulation does not provide granularity needed for
           | emergency response.
           | 
           | You want EMS looking for a needle in a haystack while you are
           | suffering a heart attack?
        
             | ssl-3 wrote:
             | Indeed.
             | 
             | How do people suggest that this would work, do you suppose?
             | 
             | "We've narrowed the victim's location down to one city
             | block, boys! Assemble a posse and start knocking on doors:
             | If they don't answer, kick it in!" ?
             | 
             | (And before anyone says "Well, it can work however it used
             | to work!" please remember: Previously, we had landline
             | phones in our homes. When we called 0118 999 881 999 119
             | 725 3 for emergency services, there was a database that
             | linked the landline to a street address and [if applicable]
             | unit.
             | 
             | That doesn't work anymore because, broadly-speaking, we now
             | have pocket supercomputers instead of landlines.)
        
               | benSaiyen wrote:
               | We also had phone books with everyone's name and address
               | listed.
               | 
               | Everyone was effectively doxxed yet it was never a
               | security issue.
        
         | Noaidi wrote:
         | And this is how they're able to track all of us, they're
         | triggering our fear response to give up our civil liberties.
        
         | b00ty4breakfast wrote:
         | it should be my choice to decide if I want my privacy to be
         | infringed upon in the name of safety. It should not be up to
         | the carrier, or the manufacturer, or first responders or any
         | level of government to make that decision for me.
        
         | digiown wrote:
         | Can't this can be done in a less invasive way by whitelisting
         | the emergency numbers and putting an extra button somewhere
         | that sends the location?
        
         | gruez wrote:
         | No
         | 
         | > The limit precise location setting doesn't impact the
         | precision of the location data that is shared with emergency
         | responders during an emergency call.
         | 
         | https://support.apple.com/en-us/126101
        
         | pfortuny wrote:
         | Well yes. People have gone missing since there were people on
         | Earth.
         | 
         | The fact that something has some good side effects does not
         | make it good or even reasonable.
        
       | 2OEH8eoCRo0 wrote:
       | Do they really need it? They can likely triangulate you without
       | GPS regardless.
        
         | mcculley wrote:
         | Cell tower triangulation does not provide the same precision as
         | GPS.
        
           | kotaKat wrote:
           | And at the end of the day if the location is a hundred meters
           | off... it might still not matter because it's how you frame
           | it with other evidence beyond a reasonable doubt.
           | 
           | Even the article mentions this.
           | 
           | > I have served on a jury where the prosecution obtained
           | location data from cell towers. Since cell towers are sparse
           | (especially before 5G), the accuracy is in the range of tens
           | to hundreds of metres.
           | 
           | I've also personally witnessed murder cases locally where GPS
           | location put a suspect to "100 meters away". The rest of the
           | evidence still pushed the case forward to a guilty verdict,
           | and the phone evidence was still pretty damning.
        
             | mcculley wrote:
             | I did not argue for or against collection of GPS data.
        
             | ErroneousBosh wrote:
             | > And at the end of the day if the location is a hundred
             | meters off... it might still not matter because it's how
             | you frame it with other evidence beyond a reasonable doubt.
             | 
             | For example, if you drop a pin a hundred metres off from
             | the incident, then when you're maybe several hundred metres
             | off the column of smoke is probably a better indicator of
             | locus than the wee dot on your screen.
        
           | metaphor wrote:
           | What makes you think cell tower triangulation is the only
           | data point being exploited to minimize position error?
        
             | 2OEH8eoCRo0 wrote:
             | I've wondered if they can also find you by what wifi or
             | Bluetooth devices are around. Odds are one or more humans
             | nearby has their GPS on. Your device can snitch on what's
             | around or those other devices snitch on you.
        
               | jcynix wrote:
               | Google recorded wifi names and locations as a "bycatch"
               | when taking streetview pictures from 2007 upto 2010. They
               | still collect such data on Android devices if the user
               | consents or ignores the option to say "no" ... :-0
               | 
               | Certain devices (especially tablets) don't have GPS or
               | various sensors integrated and still can tell you your
               | approximate location, if WiFi is enabled.
        
               | denysvitali wrote:
               | Apple does the same. Actually, most of the time in areas
               | w/o direct sky view GNSS isn't usable at all.
               | 
               | If you want to play around a bit, you can try my tool
               | that queries Apple's location services for your nearby
               | networks. The precision is remarkable.
               | 
               | https://github.com/denysvitali/where-am-i
        
               | AstroNutt wrote:
               | I've thought that too... especially Bluetooth. I know
               | it's possible with Wi-Fi signal strength.
               | 
               | Is it a coincidence most smartphone manufacturers were
               | suddenly all on board with removing the 3.5mm jack and
               | forced Bluetooth? A mesh network of sorts like Amazon is
               | doing with Ring. I even sometimes forget to save my
               | battery and turn Bluetooth off when I'm not using my
               | earbuds. It's probably a false sense of security having
               | it disabled because I'm sure it's doing something in the
               | background anyways. I can't say for sure though. Kind of
               | like years ago with Google getting caught with the whole
               | location data thing. I'm sure the average Joe doesn't
               | care if Bluetooth is enabled 24/7.
               | 
               | I try and not be on the tin foil bandwagon, but every
               | once and a while I come across things that make you go
               | hmmm...
        
               | denysvitali wrote:
               | I doubt BT is the right way to locate a device, it's far
               | better for being located (FindMy-style).
               | 
               | Wi-Fi is better for positioning since BSSIDs are (mostly)
               | static and APs don't move around.
               | 
               | On top of that, BLE usually uses random addresses - so it
               | won't be of much help knowing that you were around
               | CC:B9:AF:E8:AE at 10:05 AM - since that address is likely
               | random.
        
               | ssl-3 wrote:
               | Of course they can. Locations can be trilaterated using
               | wifi and bluetooth.
               | 
               | Back when my OG iPod Touch was minty and new (2008,
               | IIRC), it was in many ways a stripped-down iPhone.
               | 
               | One of the features that was stripped out was GPS: It
               | didn't have that at all. It also lacked Bluetooth.
               | 
               | But it did have a Maps app, and it also had location
               | services. This used visible wifi access points and a
               | database back home on the mothership to determine
               | location.
               | 
               | It was pretty neat at that time to take this responsive,
               | color-screened pocket computer with me on a walk, connect
               | it to a then-ubiquitous open SSID, and have it figure out
               | my location and provide a map (with aerial photos!) of
               | where I was. It wasn't ever dead-nuts, but it was
               | consistently spooky-good.
               | 
               | It's pretty old tech at this point, and devices still use
               | it today.
               | 
               | (Related tech: Those plastic table tents that you take
               | with you at McDonald's after ordering at the kiosk?
               | They're BLE beacons. Sensors in the ceiling track them so
               | that the person bringing the tray with food on it knows
               | about where you're sitting before they even walk out of
               | the kitchen. And modern pocket supercomputers use the
               | locations of these and other beacons, as well, to help
               | trilaterate their position. Urban environments are
               | replete with very chatty things that don't move around
               | very much.)
        
             | mcculley wrote:
             | What magical technology do you think would beat GPS?
        
               | metaphor wrote:
               | Who said anything about beating GPS or other functionally
               | equivalent GNSS?
        
               | mcculley wrote:
               | I am not sure that we are in the same conversation. I
               | misinterpreted your reply to my comment as having
               | something to do with it.
        
       | instagib wrote:
       | What you need iPhone Air, iPhone 16e, or iPad Pro (M5) Wi-Fi +
       | Cellular iOS 26.3 or later
       | 
       | A supported carrier: Germany: Telekom United Kingdom: EE, BT
       | United States: Boost Mobile Thailand: AIS, True
       | 
       | Turn limit precise location on or off
       | 
       | Open Settings, then tap Cellular.
       | 
       | Tap Cellular Data Options.
       | 
       | If you have more than one phone number under SIMs, tap one of
       | your lines.
       | 
       | Scroll down to Limit Precise Location.
       | 
       | Turn the setting on or off. You might be prompted to restart your
       | device.
        
         | OGEnthusiast wrote:
         | Kinda funny that the most secure phone setup in the US is an
         | iPhone Air on Boost Mobile. Who could have predicted that!
        
           | TheNewsIsHere wrote:
           | It isn't restricted to Boost Mobile. It is only available on
           | devices with the C1 or C1X modem, though. I assume this is
           | because of specifics with the third party modems that most
           | models in the wild have vs what Apple is doing in-house with
           | their C1(X). If you call emergency services it will still
           | provide precise location.
        
             | gruez wrote:
             | >It isn't restricted to Boost Mobile.
             | 
             | Why does it list specific carriers, then?
        
         | js2 wrote:
         | Apple doc: https://support.apple.com/en-us/126101
         | 
         | Only Boost Mobile in the U.S. Weird. About 7.5M subscribers.
         | Maybe it requires 5G? Wonder if it works when roaming?
         | 
         | https://en.wikipedia.org/wiki/Boost_Mobile
         | 
         | https://en.wikipedia.org/wiki/List_of_mobile_network_operato...
         | 
         | https://en.wikipedia.org/wiki/5G_NR
        
           | SoftTalker wrote:
           | AFAIK, other than maybe some 5G, Boost Mobile just resells
           | service from AT&T.
        
             | lukec11 wrote:
             | Boost Mobile (under Dish Network), until a few months ago,
             | ran their own custom-built 5G network that covered about
             | 30% of the US population. They built it after the
             | acquisition of Sprint by T-Mobile, in an effort to maintain
             | a fourth nationwide wireless carrier.
             | 
             | Unfortunately Boost/Dish struggled significantly with
             | finances and customer attraction post COVID, largely due to
             | two problems (seamless roaming between their own network
             | and partners', and more importantly, getting manufacturers
             | like Apple to build compatible phones). When the current
             | president came into the picture, the FCC essentially forced
             | the sale of Dish's primary spectrum licenses to
             | administration-friendly SpaceX, for future Starlink use.
             | 
             | As of now, they are in the process of moving their
             | customers to AT&T (and possibly a secondary agreement with
             | T-Mobile), but they seem to be maintaining their own
             | network core - that's likely why they're able to implement
             | support for this, while AT&T does not.
        
         | pstuart wrote:
         | But they still can track the cellular connection and do
         | triangulation from that, no?
         | 
         | Basically, if you have _any_ cell phone the government can
         | track you. Buying a burner phone with cash (via strawman proxy)
         | seems like the only way to temporarily obscure your location.
         | 
         | I imagine with the ubiquity of cameras in the commons and
         | facial recognition and gait analysis they can knit that up even
         | more.
        
         | crazygringo wrote:
         | Serious question: will this limit the ability of 911 emergency
         | services to help you?
         | 
         | I can imagine a scenario where emergency servies are authorized
         | to send the ping to get your precise location and if you
         | disable this, you may regret it. And a major feature of some
         | phones/watches is the ability to automatically call 911 under
         | certain fall/crash movement detection, where you might not have
         | the ability to re-enable your GPS location.
        
       | AnotherGoodName wrote:
       | This community should be talking about meshcore more imho.
       | 
       | It's a peer to peer network based on Lora. It really only allows
       | text messaging but with up to 20km hops between peers coverage is
       | surprisingly huge. Incredibly useful if you go hiking with
       | friends (if you get split up you can still stay in touch).
       | 
       | See https://eastmesh.au/ and scroll down to the map for the
       | Victoria and now more widely Australia network that's sprung up.
        
         | grepfru_it wrote:
         | Great for small networks. Once bad actors find it, it will be
         | attacked. See gnutella as the case study on unsupervised peer
         | to peer networks
        
           | elnerd wrote:
           | I just read gnutella page on Wikipedia, no mention of bad
           | actors
        
             | hamdingers wrote:
             | I take it you never got a mislabeled mp3 of Bill Clinton
             | advertising online poker.
        
         | copperx wrote:
         | It is surprising that these networks aren't more popular. There
         | are still many places and situation where connectivity isn't
         | available
        
           | butvacuum wrote:
           | Because they're terrible and fall apart if more than a few
           | score people are on the same freqency at the same time.
        
           | esseph wrote:
           | It's because they aren't very resilient. More of an
           | experiment than a purpose designed tool for the, uh, current
           | environment.
        
         | NoiseBert69 wrote:
         | Meshcore and -tastic have the huge problem that the encryption
         | keys are bound to the device and not the app.
        
           | timschmidt wrote:
           | I've been using the T-Deck Pro and T-Lora Pager, so the
           | device _is_ the app.
        
           | jonmon6691 wrote:
           | I agree, there's way too much going on in the firmware, just
           | make a dumb Lora-bluetooth bridge. Hell, just integrate a
           | Lora radio in a phone.
        
         | wisplike wrote:
         | Why Meshcore over Meshtastic?
        
           | ianpenney wrote:
           | There's lots of YouTube videos about this but basically: you
           | can specify routing.
        
           | subscribed wrote:
           | Meshtastic has terrible defaults (every node rebroadcasts
           | everything, every node sends telemetry), which makes sense in
           | the backwoods but not anywhere close to civilisation.
        
             | mbirth wrote:
             | This, combined with the 10% duty cycle limitation on the
             | used frequencies is the main issue, I believe. Once the 10%
             | are used up, a node basically has to go dead until it falls
             | below 10% again. And with lots of messages about battery
             | levels and other telemetry being sent and relayed, those
             | 10% get used up fast.
        
         | ianpenney wrote:
         | I've been wondering this for a while and maybe someone has a
         | clue.
         | 
         | Based on the very "bursty" nature of LoRA, how much does an
         | adversary need to spend to radiolocate it? What's the threat
         | model there?
        
           | comboy wrote:
           | $20? These networks do not try to hide your location and
           | triangulating known frequencies is trivial.
        
           | Gigachad wrote:
           | You could get a rough location for free. Every time you send
           | a message, "observer" nodes connected to the internet publish
           | the packet, and in the packet is the repeater path taken,
           | repeaters have known locations and the first repeater is
           | going to be near you.
        
         | noja wrote:
         | Is it open source?
        
           | subscribed wrote:
           | What, protocol? Basic apps? Yes.
        
         | sneak wrote:
         | The crypto is bad and the networks are extremely low bandwidth
         | and quite unreliable and are vulnerable to jamming or
         | spam/overload.
         | 
         | I've deployed lots of nodes, and the technology reminds me of
         | ipfs: people who don't use it much vastly oversell its
         | capabilities.
        
         | konsumer wrote:
         | Reticulum gets around a lot of these problems, as the (better)
         | encryption is app-level (or even more fine-grained.) Its also
         | not tied to lora, so you can interop easily with other
         | transports. I made a websocket transport for it, and there is
         | already TCP and UDP, and a couple non-lora radio transports. I
         | also made a (works on web) js and Arduino client lib, and it
         | has a few native client libs, so it can sort of be used on
         | anything, even over traditional networks, or web clients.
         | Meshcore and meshtastic are way more popular, but reticulum
         | seems so much better, to me, for most things. It can still have
         | overload problems, like any radio network, but no client is
         | required to forward, so you can build a different kind of
         | network ("only forward messages that are for my peeps" and
         | marked correctly.) It also has "it costs compute PoW to send to
         | me" which can greatly cut down on spam.
        
         | fragmede wrote:
         | If you go hiking with friends who aren't total nerds, the
         | proprietary options offer a more consumer-grade experience.
         | (ie, usable by them)
        
         | cyberax wrote:
         | > This community should be talking about meshcore more imho.
         | 
         | The fundamental problem of distributed networks is that you can
         | either have centralized control of the endpoints, or your
         | network becomes vulnerable to denial-of-service attacks. So
         | meshcore/meshtastic are great because they are used only by
         | well-meaning people. If they become more popular, we'll start
         | getting tons of spam :(
        
         | bronco21016 wrote:
         | I really want to get into these Lora based mesh tools but the
         | range in my experience is terrible. Maybe I'm doing something
         | wrong, maybe it's a lack of nodes in my area.
         | 
         | I just tested the other day. I'm in the midwest US so it's
         | winter, no leaves. I managed to get about a quarter mile before
         | my two portable nodes couldn't talk to each other. T-Echo with
         | muziworks whip antenna.
         | 
         | Without a bunch of solidly placed, high elevation, high gain
         | antenna nodes, this just isn't really that usable.
         | 
         | Plus, all the other issues others have highlighted.
        
       | AlexanderYamanu wrote:
       | euhm, well. 112 programmer here. There are multiple levels. Cell
       | tower triangulation come in automatically from providers. But
       | they are only in tower numbers. They might be wrongly entered by
       | engineers, hence the confirming question about where you are.
       | Second is subscription information, as in registered address.
       | Chances are if called from nearby your address, you are at your
       | address. Next is a text to your phone number, which is
       | intercepted by firmware and sends gps coords back. This can be
       | turned off, since implementation.
        
         | IshKebab wrote:
         | > This can be turned off, since implementation.
         | 
         | Not by users. The new thing is that Apple allows users to
         | disable this feature. Hopefully they still detect emergency
         | calls on the phone and enable it unconditionally for those.
        
           | AlexanderYamanu wrote:
           | yeah, there always was. It's a service code, like getting
           | your imei. But it was a weird long one, and manufacturer
           | dependent. Now UI switches are created for it apparantly.
           | Can't find it anywhere on the internet though. I don't work
           | there anymore, so can't look it up.
        
           | jeroenhd wrote:
           | I believe they're talking about this feature (https://support
           | .google.com/android/answer/9319337?sjid=18079...).
           | 
           | This is a system you can disable as a user, but it's not the
           | on-modem feature discussed in the article.
        
           | KellyCriterion wrote:
           | Note sure: In my country exactly this feature is used by
           | police & state enforcement to find locatin, because this
           | "ping" message is not forwarded from the modem to the OS, so
           | the OS is not aware of any of these messages
        
         | jeroenhd wrote:
         | American carriers have a different protocol than the EU. The EU
         | (and probably EU derived networks) uses a """secret""" SMS
         | format that's opt-in, but the 911 system works differently.
         | 
         | The 911 feature can be activated fully remotely, the 112
         | feature is supposed to only activate when dialing an emergency
         | number.
        
           | yencabulator wrote:
           | The US one is called E911:
           | https://en.wikipedia.org/wiki/Enhanced_911
        
           | gruez wrote:
           | >The 911 feature can be activated fully remotely
           | 
           | Source? Even if the phone isn't actively doing a 911 call?
        
             | Havoc wrote:
             | GP likely means any 911 call automatically has geo tracing.
             | 
             | >The dispatcher's computer receives information from the
             | telephone company about the physical address (for
             | landlines) or geographic coordinates (for wireless) of the
             | caller.
        
         | dfc wrote:
         | Did you read the article or are you merely responding to the
         | title? The article begins by acknowledging triangulation and
         | then moving on to the point of the article. The article is
         | about commands built into the UMTS and LTE specs for requesting
         | GPS from the device. Your comment seems to be about everything
         | but the main point of the article.
        
           | M95D wrote:
           | Did you read the complete comment?
           | 
           | > Next is a text to your phone number, which is intercepted
           | by firmware and sends gps coords back.
        
             | dfc wrote:
             | Yes I saw that and also took it to mean the person didn't
             | read the article. A text to your phone number? The article
             | never mentions SMS. Heck I think the 2g/3g "feature" does
             | not even require the phone to even have a SIM installed.
             | This next sentence also seems to have been written without
             | reading the article: "This can be turned off, since
             | implementation."
        
       | thisislife2 wrote:
       | From the comments, it appears many are not aware that even the US
       | government buys location data of users from data brokers - _How
       | the Federal Government Buys Our Cell Phone Location Data_ -
       | https://www.eff.org/deeplinks/2022/06/how-federal-government...
       | ... Apparently, US cell phone companies are one of the providers
       | of this data - _US cell carriers are selling access to your real-
       | time phone location data_ -
       | https://news.ycombinator.com/item?id=17081684 ...
        
         | Frost1x wrote:
         | We really have a societal problem in that we allow private
         | entities to do things we don't allow government to do.
         | Furthermore, the issue is exacerbated by then allowing
         | governments to bypass these issues by then just paying private
         | entities to do the things it can't do as a proxy for the same
         | functional outcomes.
         | 
         | But we want to support privatization at all cost, even when
         | privatization these days has significant influence on our daily
         | lives, akin to the concerns we had when we placed restrictions
         | on government. Seems like we need to start regulating private
         | actions a bit more, especially when private entities accumulate
         | enough wealth they can act like multi state governments in
         | levels of influence. That's my opinion, at least.
        
           | gruez wrote:
           | >We really have a societal problem in that we allow private
           | entities to do things we don't allow government to do.
           | 
           | It really isn't, given that the government literally has a
           | monopoly on violence, and therefore it makes sense to have
           | more guardrails for it. That's not to say private entities
           | should have free reign to do whatever it wants, but the
           | argument of "private entities can do [thing] that governments
           | can't, so we should ban private entities too!" is at best
           | incomplete.
           | 
           | >Furthermore, the issue is exacerbated by then allowing
           | governments to bypass these issues by then just paying
           | private entities to do the things it can't do as a proxy for
           | the same functional outcomes.
           | 
           | Again, this is at best an incomplete argument. The government
           | can't extract a confession out of you (5th amendment). It can
           | however, interview your drinking buddies that you blabbed
           | your latest criminal escapades to. Is that the government
           | "bypassing" the 5th amendment? Arguably. Is that something
           | bad and we should ban? Hardly.
        
             | salawat wrote:
             | Your cell phone provider does not constitute "drinking
             | buddy". The fact that, in essence, everyone is being
             | surveilled location wise all the time by these providers is
             | reason enough to restrict the activity.
        
               | gruez wrote:
               | >Your cell phone provider does not constitute "drinking
               | buddy".
               | 
               | You're right, it should be even more scandalous for the
               | government to get information out of my drinking buddy,
               | because the information I told him was in confidence, and
               | he promised he wouldn't tell anyone. My cell phone
               | provider, on the other hand, clearly says in their ToS
               | who they'll share data with and in what circumstances.
        
               | lukan wrote:
               | "who they'll share data with and in what circumstances"
               | 
               | Anyone who offers them money?
        
               | iamnothere wrote:
               | And what many are saying is that the phone provider
               | should not be allowed to be so free with your data in the
               | ToS. In the same way that your landlord can't add a
               | slavery clause to your lease.
        
               | rockskon wrote:
               | A non-exhaustive list that has, time and time and time
               | and time and time and time and time and time again, to
               | downplay the grossly cavalier approach they take to the
               | "privacy" of your location data.
               | 
               | They value it alright. At several dollars per person.
        
               | mlfreeman wrote:
               | And the ToS probably has a clause that says "we can alter
               | the deal any time we want and you should pray we don't
               | alter it further".
        
               | nerdsniper wrote:
               | > The poster with the enormous face gazed from the wall.
               | It was one of those pictures which are so contrived that
               | the eyes follow you about when you move. DRINKING BUDDY
               | IS WATCHING YOU.
               | 
               | > 'Does Drinking Buddy exist?' 'Of course he exists. The
               | Party exists. Drinking Buddy is the embodiment of the
               | Party.' 'Does he exist like you or me?' 'You do not
               | exist', said O'Brien.
               | 
               | > Oceanic society rests ultimately on the belief that
               | Drinking Buddy is omnipotent and that the Party is
               | infallible. But since in reality Drinking Buddy is not
               | omnipotent and the party is not infallible, there is need
               | for an unwearying, moment-to-moment flexibility in the
               | treatment of facts.
        
           | xboxnolifes wrote:
           | > We really have a societal problem in that we allow private
           | entities to do things we don't allow government to do.
           | 
           | Thats basically the foundational idealogy of the united
           | states. Thats not the issue.
           | 
           | The real issue is your next sentence. The government can just
           | loophole around their intentional limitations by paying
           | private companies to work on their behalf.
        
             | runjake wrote:
             | It's a loophole, but it's willful by design on the
             | government's part. The book "Means of Control" by Byron Tau
             | covers this in great depth.
             | 
             | It's so much worse than even those of us who are moderately
             | interested in mass surveillance know.
        
               | xboxnolifes wrote:
               | I'm aware it's intentional on the government's end. My
               | point is it is not intentional by the original
               | intentions, and should be a priority for people to
               | advocate to fix.
        
             | themafia wrote:
             | The only private companies with this power are monopolies.
             | Effective competition would destroy this behavior. So the
             | real problem is the government _intentionally_ and
             | _illegally_ allows monopolies to form so they can get
             | access to this workaround.
        
           | peyton wrote:
           | Why not vote for some law limiting the government's buying of
           | this data? After all, I expect a say in how the government is
           | run, so that seems like the appropriate path. I don't see why
           | I should expect a say in how AT&T is run. AT&T can't raise an
           | army, or enter my house, or shoot me.
        
             | kelnos wrote:
             | How exactly do I vote for such a law? We do not have a
             | direct democracy, and I'm not aware of any viable political
             | candidates that have this sort of thing as a part of their
             | platform.
        
               | socalgal2 wrote:
               | In some states you do.
               | 
               | https://ballotpedia.org/States_with_initiative_or_referen
               | dum
        
             | subscribed wrote:
             | You didn't purchase your lawmakers, the companies profiting
             | from the bad laws did.
             | 
             | This is why they get their laws passed.
        
           | KellyCriterion wrote:
           | > allow private entities to do things we don't allow
           | government to do. Furthermore, the issue is exacerbated by
           | then allowing governments to bypass these issues by then just
           | paying private entities to do the things it can't do as a
           | proxy for the same functional outcomes. <
           | 
           | Somehow this reminds me about Blackwater / Xe Technologies?
           | :-/
           | 
           | (Im betting 100 USD that soon we will find out that ICE also
           | deployed "private financed forces" to "support state
           | actions"?)
        
             | gruez wrote:
             | >> allow private entities to do things we don't allow
             | government to do.
             | 
             | >Somehow this reminds me about Blackwater / Xe
             | Technologies? :-/
             | 
             | Is there some context I'm missing? Skimming
             | https://en.wikipedia.org/wiki/Blackwater_(company) it shows
             | they might have perpetrated some war crimes, but that alone
             | doesn't really make them worse than the US military. For
             | instance, consider https://en.wikipedia.org/wiki/July_12,_2
             | 007,_Baghdad_airstri....
        
           | jtbayly wrote:
           | I agree completely with your first paragraph, but I'm not
           | sure what privatization has to do with it. Also, I agree that
           | more regulation of private parties is needed. Or even better,
           | break up the private companies that are like multi-state
           | governments in terms of power.
        
           | tastyfreeze wrote:
           | This is why I advocate for making selling
           | location/identifying data illegal. If nobody is allowed to
           | sell it then the government cannot legally buy it.
        
       | meindnoch wrote:
       | What if I told you that carriers can also activate your phone's
       | microphone without your knowledge and listen in on your
       | surroundings?
        
         | iamnothere wrote:
         | What if I told you there are phones out there with hardware
         | kill switches to physically cut power to microphones, cameras,
         | and GPS?
        
         | nichos wrote:
         | I would ask for your source
        
           | spwa4 wrote:
           | How that works is simple: there are regulations that force
           | that the microphone used for calling is directly connected to
           | the "baseband", which is under control of the carrier. It has
           | to be, because of AT&T's argument: ONE misbehaving baseband
           | can make cell phones inoperable in an area that's up to a
           | kilometer in diameter. So AT&T's cell towers "need" to be
           | able to send out a signal that permanently disables a phone's
           | transmitter.
           | 
           | Regulations say the baseband MUST control: all wireless
           | signals (including wifi and GPS), all microphones and
           | speakers, and it must be able to disable the camera
           | electrically. It must have a tamper-resistant identifier
           | (IMEI number ... kind of).
           | 
           | Oh, it must allow calling the emergency services. If in this
           | mode, during a call to the emergency services it MUST be able
           | to send the exact GPS position (not just once, continuously)
           | to the emergency services at the request of the emergency
           | services (ie. NOT the user, and carriers must facilitate
           | this)
           | 
           | By the way, it's worse: as you might guess from the purpose,
           | it doesn't matter if your phone is on the "spying" carrier or
           | not, other carriers can send commands to other carriers'
           | phones' basebands (because "get off this frequency" is
           | required: spectrum is shared, even within countries. Since
           | phones may go from one tower to another and be required to
           | vacate frequencies, you need this command). It doesn't even
           | matter if you have a SIM in your phone or not (ever tought
           | that if eSIM works, it must of course be possible for any
           | provider to contact and send instructions to the phone, so it
           | opens up an end-to-end encrypted connection to the javacard
           | that the actual phone cpu cannot intercept). In some phones
           | it doesn't even matter if the phone is on or not (though of
           | course eventually it dies). So "meshtastic" or anything else
           | cannot make a phone safe.
           | 
           | And in practice it's even worse. A lot of phone manufacturers
           | "save on memory" and use the same memory chips for the
           | baseband processor and the central cpu. Which means that it's
           | a little bit cheaper ... and the baseband has access to all
           | the phone memory and all peripherals connected through the
           | memory bus (which is all of them in any recent phone). It may
           | even be the case that these chips are integrated in the cpu
           | (which I believe is the case for recent Apple chips). Oh and
           | the regulations say: if there's a conflict over control over
           | (most) peripherals, including the microphone and speaker, the
           | baseband processor MUST be guaranteed to win that fight.
           | 
           | Oh and because governments demand this, but of course neither
           | fund nor test these devices, they are old, bug-ridden and
           | very insecure. This also means that _despite_ the government
           | requiring that these features be built into phones,
           | governments, carriers and police forces generally do not have
           | the equipment required to actually use these features (though
           | I 'm sure the CIA has implement them all). Not even carriers'
           | cell phone towers: they have to pay extra to allow even just
           | frequency sharing ...
           | 
           | Here is an article about baseband and baseband processors.
           | 
           | https://www.extremetech.com/computing/170874-the-secret-
           | seco...
        
             | iamnothere wrote:
             | > Regulations say the baseband MUST control: all wireless
             | signals (including wifi and GPS), all microphones and
             | speakers, and it must be able to disable the camera
             | electrically. It must have a tamper-resistant identifier
             | (IMEI number ... kind of).
             | 
             | This is simply not true.
             | 
             | Source: I own a phone where this is not the case. Many
             | Linux phones internally attach their wireless devices via
             | USB, so there is good separation.
             | 
             | Also many upscale phones have decoupled the baseband from
             | things that were once connected to it, as an attempt to
             | improve security. (On iOS for instance the main CPU
             | controls wifi.)
        
               | strcat wrote:
               | Connecting a cellular radio via USB provides far less
               | isolation than the approach of a tiny kernel driver
               | connected to an IOMMU isolated cellular radio on
               | mainstream devices. USB has immense complexity and attack
               | surface, especially with a standard Linux kernel
               | configuration. Forensic data extraction companies mostly
               | haven't bothered using attack vectors other than USB due
               | to it being such a weak point. Many of the things people
               | claim about cellular radios in mainstream smartphones are
               | largely not true and they're missing that other radios
               | are implemented in a very comparable way.
               | 
               | Cellular, Wi-Fi, Bluetooth, GNSS NFC, UWB, etc. do get
               | implemented on secondary processors running their own OS
               | but on mainstream smartphones those are typically well
               | isolated and don't have privileged access to other
               | components. The cellular radio in an iPhone or Pixel is
               | on a separate chip but that's a separate thing from it
               | being isolated. Snapdragon devices with cellular
               | implemented by the main SoC still have an isolated radio.
               | Snapdragon implements multiple radios via isolated
               | processes in a microkernel-based RTOS where the overall
               | baseband is also isolated from the rest of the device.
               | There are a lot of lower quality implementations than
               | iPhones, Pixels and Snapdragon devices but the intention
               | is still generally to have the radios isolated even if
               | they don't do it as well as those.
        
               | iamnothere wrote:
               | The Linux USB stack improves over time, and besides,
               | implementing it with USB makes it easier to implement
               | hardware toggle switches. (Cutting power pins to the USB
               | modem is like unplugging it.)
               | 
               | Edit: I'll add that I think smartphone "security" is
               | almost impossible to achieve, given the complexity of
               | everything and the opacity of modem vendor stacks, which
               | is why I just assume endpoint compromise. I use my phone
               | rarely and with toggle switches normally "off", and I
               | don't consider it a secure device or use it very often.
               | If you believe that a secure phone is possible, however,
               | then Graphene is definitely a better fit than a Linux
               | phone.
        
             | CamperBob2 wrote:
             | That's a homework assignment, not a citation.
        
             | mlfreeman wrote:
             | Please provide links to the relevant regulations from an
             | actual government website such as eCFR in the US
             | (https://www.ecfr.gov/)
        
             | gruez wrote:
             | >Regulations say the baseband MUST control: [...] all
             | microphones and speakers
             | 
             | I'm going to need a specific citation for this, given that
             | it seems trivially falsifiable by the existence of
             | bluetooth headphones (which the baseband obviously can't
             | control), not to mention other sorts of call forwarding
             | features like the one iPhones have.
        
             | lgats wrote:
             | GPS isn't a wireless signal sent by the phone, it is RX
             | only.
        
             | dfc wrote:
             | > It must have a tamper-resistant identifier (IMEI number
             | ... kind of).
             | 
             | What is the tamper resistant number that is kind of the
             | IMEI?
        
           | Coeur wrote:
           | "Mobile phone (cell phone) microphones can be activated
           | remotely, without any need for physical access"
           | 
           | https://en.wikipedia.org/wiki/Covert_listening_device#Remote.
           | ..
           | 
           | And the linked sources are:
           | 
           | - Kroger, Jacob Leon; Raschke, Philip (2019). "Is My Phone
           | Listening in? On the Feasibility and Detectability of Mobile
           | Eavesdropping". Data and Applications Security and Privacy
           | XXXIII. Lecture Notes in Computer Science. Vol. 11559. pp.
           | 102-120. doi:10.1007/978-3-030-22479-0_6. ISBN
           | 978-3-030-22478-3. ISSN 0302-9743.
           | 
           | - Schneier, Bruce (5 December 2006). "Remotely Eavesdropping
           | on Cell Phone Microphones". Schneier On Security. Archived
           | from the original on 12 January 2014. Retrieved 13 December
           | 2009.
           | 
           | - McCullagh, Declan; Anne Broache (1 December 2006). "FBI
           | taps cell phone mic as eavesdropping tool". CNet News.
           | Archived from the original on 10 November 2013. Retrieved 14
           | March 2009.
           | 
           | - Odell, Mark (1 August 2005). "Use of mobile helped police
           | keep tabs on suspect". Financial Times. Retrieved 14 March
           | 2009.
           | 
           | - "Telephones". Western Regional Security Office (NOAA
           | official site). 2001. Archived from the original on 6
           | November 2013. Retrieved 22 March 2009.
           | 
           | - "Can You Hear Me Now?". ABC News: The Blotter. Archived
           | from the original on 25 August 2011. Retrieved 13 December
           | 2009.
           | 
           | - Lewis Page (26 June 2007). "Cell hack geek stalks pretty
           | blonde shocker". The Register. Archived from the original on
           | 3 November 2013. Retrieved 1 May 2010.
        
         | relaxing wrote:
         | Why, do you think it's the sort of thing you're likely to say?
        
         | IshKebab wrote:
         | I would not believe you until you provided actual evidence.
        
         | apparent wrote:
         | One of the reasons I use iPhones is that Apple controls an
         | integrated hardware/software experience, which makes it less
         | likely that private information is being leaked despite the
         | presence of privacy controls.
        
           | bigyabai wrote:
           | I empathize with the sentiment, but in reality Apple is as
           | lazy as anyone else:
           | https://www.technologyreview.com/2019/07/29/134008/apple-
           | con...
        
             | llm_nerd wrote:
             | There is a pretty large chasm between "When you explicit
             | (or accidentally) use the siri functionality, it can record
             | the interaction for quality purposes and per the agreement
             | you made share that will Apple or its agents" and "random
             | third parties can engage hardware functionality without
             | your knowledge and spy on you".
             | 
             | I am entirely, 100% certain that my telco can't just enable
             | the microphone on my iPhone and record me, short of some
             | 0-day exploit. I simply cannot make that bet on many other
             | devices.
        
             | bilbo0s wrote:
             | Apple is not as lazy as anyone else, don't believe the
             | hype.
             | 
             | That assertion is a bit overblown. And people can easily
             | find out it's overblown with a bit of research.
             | 
             | But at the same time, my whole philosophy is never let it
             | touch any network connected device at all if it is
             | critical. I don't care if it's an Apple device.
             | 
             | Here's reality, mobile carriers have been able to get your
             | location from nearly the inception of mass market mobile
             | phone use. I'm not sure anyone really believed their
             | location was somehow secret and not discoverable. If you're
             | using the phone or internet networks, you're not anonymous.
             | Full stop.
             | 
             | Forget whatever anyone told you about your VPN, or whatever
             | other anonymization/privacy machine that Mr McBean is
             | selling Sneetches these days. Assume everyone is tracked,
             | and some are even watched. Therefore everything you do or
             | say with your devices should be considered content that is
             | posted publicly with an uncertain release date.
        
           | iJohnDoe wrote:
           | I wouldn't be so confident. The article even references this.
           | Apple has used third-party baseband devices in the iPhone
           | since the beginning, which was from other manufacturers. All
           | bets are off regarding security when this is the case. This
           | does included microphone access.
           | 
           | The article touches on this by saying Apple is making the
           | baseband/modem hardware now. Something they should have done
           | since day one, and I'm not sure what took them so long.
           | However, it was was clear they didn't have the expertise in
           | this area and it was easier to just uses someone else's.
        
             | wisplike wrote:
             | Patents is why it took them so long.
        
         | retired wrote:
         | My provider knows who I call, who I text, which websites I
         | browse, my bank account number, my home address, my rough
         | location, which countries I visited for holiday and through
         | DTMF they can even sense which buttons I press on my handset.
        
           | KellyCriterion wrote:
           | Eh, no? How does your provider know all your bank accounts?
           | If at all, then the one you are using for billing - but the
           | 2FA apps do not expose such data to the provider? The Apps
           | communicate via HTTPS calls in the background?
        
             | gruez wrote:
             | I think they're implying they can glean all that
             | information based on the 2fa codes you receive. eg. "your
             | security code for First Bank Of HN is: xxxxxx"
        
         | tigrezno wrote:
         | what about Graphene?
        
           | strcat wrote:
           | GrapheneOS only supports devices with isolated radios
           | including but not limited to cellular. It's one of the
           | hardware requirements:
           | 
           | https://grapheneos.org/faq#future-devices
           | 
           | The radios on the supported devices can't access the
           | microphone, GNSS, etc.
           | 
           | GrapheneOS has never supported a device without an isolated
           | cellular radio since that isolation was in place even with
           | the initial Nexus 5 and Galaxy S4. However, some of the
           | devices prior to Pixels did have Broadcom Wi-Fi/Bluetooth
           | without proper isolation similar to laptops/desktops. Nexus
           | 5X was the initial device with proper isolation for Wi-
           | Fi/Bluetooth due to having SoC provided Wi-Fi from Qualcomm.
           | Pixels have avoided this issue for integrating Broadcom Wi-
           | Fi/Bluetooth. Nexus devices left this up to companies like
           | LG, Huawei, etc. and anything not done for them by Qualcomm
           | tended to have security neglected. Qualcomm has taken
           | security a lot more seriously than other SoC vendors and
           | typical Android OEMs for a long time and provides good
           | isolation for most of the SoC components.
           | 
           | Don't believe everything you read about smartphone security
           | and especially cellular radios. There are many products with
           | far less secure cellular radios which are far less isolated
           | but rather connected via extremely high attack surface
           | approaches including USB which are claiming those are better.
           | A lot of the misconceptions about cellular come from how
           | companies market supposedly more secure products which are in
           | reality far worse than an iPhone.
        
         | lysace wrote:
         | At this point I would be mildly surprised.
        
       | ZebusJesus wrote:
       | Phones haven't always had GPS information and they could still be
       | tracked, if you connect to enough towers they can triangulate
       | your location. Cell towers have been able to do this based on
       | your signal strength for a very long time and you cant turn it
       | off. You don't even have to have a SIM card, if the cell radio is
       | on it pings towers period, this is why a phone even without
       | service can dial 911 and it will work. The IMEI of your phone is
       | unique and cell towers can track it, the government has used this
       | and there is no way to disable it. Its not as accurate as GPS but
       | it can be good enough to figure out a route you take and general
       | location
       | 
       | https://www.rfwireless-world.com/terminology/cellular-tower-...
        
         | nielsbot wrote:
         | The article is not about cell tower triangulation
         | 
         | FTA:
         | 
         | > But this is not the whole truth, because cellular standards
         | have built-in protocols that make your device silently send
         | GNSS (i.e. GPS, GLONASS, Galileo, BeiDou) location to the
         | carrier.
        
       | citizenpaul wrote:
       | None of this matters. Your rights were taken away buy the corrupt
       | ghouls supposedly "representing" you.
       | 
       | 2017 Broadband Consumer Privacy Proposal
       | 
       | https://www.congress.gov/bill/115th-congress/senate-joint-re...
        
         | tzs wrote:
         | Anyone happen to know what the arguments were from those who
         | supported that bill?
         | 
         | Here's a summary. In late 2016 the FCC passed a rule that:
         | 
         | (1) applies the customer privacy requirements of the
         | Communications Act of 1934 to broadband Internet access service
         | and other telecommunications services,
         | 
         | (2) requires telecommunications carriers to inform customers
         | about rights to opt in or opt out of the use or the sharing of
         | their confidential information,
         | 
         | (3) adopts data security and breach notification requirements,
         | 
         | (4) prohibits broadband service offerings that are contingent
         | on surrendering privacy rights, and
         | 
         | (5) requires disclosures and affirmative consent when a
         | broadband provider offers customers financial incentives in
         | exchange for the provider's right to use a customer's
         | confidential information.
         | 
         | The bill, introduced early in 2017, nullifies that rule.
         | 
         | It passed the Senate 50-48, then the House of Representatives
         | 215-205, and was signed by Trump.
         | 
         | The 52 Republicans in the Senate voted 50 yes, 0 no, 2 not
         | voting. The 47 Democrats, along with the 1 independent, voted
         | no.
         | 
         | In the House the 236 Republicans voted 215 yes, 15 no, 6 not
         | voting. The 190 Democrats all voted no.
        
       | wildylion wrote:
       | There actually should be a push for an EU-wide legislation
       | banning this kind of silent, precise location data collection. If
       | anything, Germany is obsessed with Datenschutz but in many cases
       | it's just laughable security theater.
        
       | atheris wrote:
       | What are the alternative steps that we can take in Android? How
       | to check if it is happening?
        
         | petre wrote:
         | You can probably trivially shield the GPS with an aluminium
         | foil sticker once you know where the antenna is. The GPS sgnal
         | is very weak.
        
           | BenjiWiebe wrote:
           | I think the GPS antenna is either omnidirectional or very
           | nearly so., since my phone can get location in many
           | orientations.
           | 
           | So I don't think a single foil sticker would make much
           | difference.
        
         | jeroenhd wrote:
         | I don't believe there is a way to intentionally break this
         | system, nor to detect with 100% certainty that it's happening.
         | 
         | You'd need to run an open source baseband modem with settings
         | and logs in all the right places. I don't think those exist.
         | 
         | Someone might be able to exploit the Linux kernel running on
         | Qualcomm modems and build a tool for rooted Android phones
         | after reverse engineering the baseband, but I imagine a lot of
         | copyright lawyers and probably law enforcement people will send
         | you very scary letters if you document remote location tracking
         | features like these.
         | 
         | Also, if you have any 4G or 5G modem, your carrier already has
         | a pretty good idea where you are. They probably log your
         | location too. The advanced precision and timing information
         | necessary for high speed cellular broadband is enough to get a
         | decent location log. That also includes other connected devices
         | such as cars, of course.
        
       | jmward01 wrote:
       | "and notify the user when such attempts are made to their
       | device."
       | 
       | We aren't going to remove the security state. We should make all
       | attempts to, but it won't happen. What needs to happen is
       | accountability. I should be able to turn off sharing personal
       | information and if someone tries I should be notified and have
       | recourse. This should also be retroactive. If I have turned off
       | sharing and someone finds a technical loophole and uses it, there
       | should be consequences. The only way to stop the rampant abuse is
       | to treat data like fire. If you have it and it gets out of
       | control you get burned, badly.
        
         | fsflover wrote:
         | This is exactly what GDPR does.
        
           | jmward01 wrote:
           | Does it apply to the government like it applies to people? Is
           | it enforced against governments like it is enforced against
           | people and corporations? A core issue here is that laws, and
           | the application and enforcement of laws, generally do not.
           | Having said that I applaud the attempt and encourage pushing
           | forward on the anti-surveillance aspects of GDPR while
           | recognizing all laws are flawed.
        
             | kingkawn wrote:
             | State actors are inherently only subject to their own
             | oversight
        
             | cromulent wrote:
             | The telco would be the one collecting it first, I assume.
             | It would be interesting for someone in the EU to request
             | their data from their telco, and if it contains these
             | precise locations, question the usage.
        
         | themafia wrote:
         | > We aren't going to remove the security state
         | 
         | What security state? They aren't doing this for anyone's
         | safety. This is the surveillance and parallel construction
         | state.
         | 
         | > What needs to happen is accountability.
         | 
         | No agency can have this power and remain accountable. Warrants
         | are not an effective tool for managing this. Courts cannot
         | effectively perform oversight after the fact.
         | 
         | > The only way to stop the rampant abuse is to treat data like
         | fire.
         | 
         | You've missed the obvious. You should really go the other
         | direction. Our devices should generate _noise_. Huge crazy
         | amounts of noise. Extraneous data to a level that pollutes the
         | system beyond any utility. They accept all this data without
         | filtering. They should suffer for that choice.
        
           | TheCraiggers wrote:
           | > Our devices should generate _noise_. Huge crazy amounts of
           | noise. Extraneous data to a level that pollutes the system
           | beyond any utility. They accept all this data without
           | filtering. They should suffer for that choice.
           | 
           | I like the idea on principle, but I'll like it far less when
           | I'm getting charged with computer fraud or some other over-
           | reaching bullshit law.
        
           | ruszki wrote:
           | > They aren't doing this for anyone's safety.
           | 
           | Strictly speaking, this is not completely true. When you call
           | an emergency number, it's very good that they can see exactly
           | where you are. That was how this was sold 15+ years ago. But
           | of course, that's basically the only use case when this
           | should be available.
        
       | qubex wrote:
       | So what irked that since my brand-new iPhone uses a Qualcomm
       | "modem chip" (god, the slide of terminology makes my skin crawl)
       | I won't have access to this feature.
        
       | tim-tday wrote:
       | They can also just use math on their connection logs.
        
         | wisplike wrote:
         | That would almost certainly not get anywhere near the accuracy
         | of a GPS location.
        
       | wisplike wrote:
       | Anyone know why apple specifies this feature requires a supported
       | carrier? Why would the carrier matter?
        
         | connorgurney wrote:
         | I'd imagine that the carrier will agree not to use any data
         | they do receive for anything but a handful of purposes, but I
         | suppose that depends on the extent of the technical solution.
        
         | denysvitali wrote:
         | My guess is that this data is actually used for network
         | analytics by the carriers and to determine if the device
         | connecting to the tower should switch to another one.
         | 
         | This data is vital for a mobile carrier to make sure to have a
         | good signal coverage under all the possible conditions.
         | 
         | It's just a guess since I've seen similar data being analyzed
         | in a previous telco I worked at, but I don't know their exact
         | source. The goal there was to improve the network quality. I
         | guess you can do the same w/o GPS, but triangulation with cell
         | towers is very coarse.
        
       | 1shooner wrote:
       | I'd be curious about alternatives like lte/5g hotspots, maybe
       | even a DIY versions using hats or modules.
        
       | superkuh wrote:
       | They don't need to get your GPS location. With 4G and 5G the
       | timing and clock precision at the basestations is enough to
       | multi-laterate you down to about 50m (prior 3G/2G stuff was more
       | like 100-200 meters). They are required by US law to store this
       | multi-laterated position data track (updated every time your
       | phone announces itself to basestations) for 2 years. But most
       | telcos store it for more like 5+ years because it's valueable and
       | they sell it.
       | 
       | This is all automatic and completely pervasive. Worrying about
       | GPS and userspace computers in the smartphone is important but
       | even if you protect that you've already lost. The baseband
       | computer is announcing your position by the minute. Cell phones
       | couldn't really work without the basestations deciding where you
       | are and which will handle you.
        
         | dfc wrote:
         | What law requires carriers to keep Cell Site Location
         | Information for 2 years?
        
       | sneak wrote:
       | All over southern California and Nevada, facial recognition
       | cameras have been put up aiming all four directions at most
       | surface street intersections.
       | 
       | It's also illegal to sell new cars without a cell modem in them.
       | 
       | The phones are the least of our worries.
        
         | sejje wrote:
         | Which jurisdiction is it illegal to sell new cars without a
         | cell modem?
        
       | DustinBrett wrote:
       | Enemy of the State was accurate in 1998
        
       | apparent wrote:
       | I've noticed that when I travel, I get spam calls from the area
       | code I am visiting. I have asked my cell provider if they
       | monetize my location data, and they swear they aren't. But I
       | don't trust them, given that no one else (other than Apple) would
       | know where I am in real time. Recently switched providers and
       | haven't experienced it since then. Wouldn't be surprised if there
       | was a class action lawsuit someday.
       | 
       | Of course, this doesn't require having GPS location, just cell
       | tower info is enough.
        
         | xingped wrote:
         | Name and shame. Which provider were you having this experience
         | on? (If you don't mind sharing since you're no longer with
         | them.)
        
           | apparent wrote:
           | Pure Talk. Much cheaper than AT&T, and good customer service.
           | But I found something that was cheaper on an unlimited basis.
           | Between that and the sketchy calls I was getting, I decided
           | to move.
        
         | crazygringo wrote:
         | > _But I don 't trust them, given that no one else (other than
         | Apple) would know where I am in real time._
         | 
         | Literally every website and app you use with any kind of shared
         | analytics/ads gets your general location just from your IP
         | address alone, and can update your profile on that
         | analytics/ads provider.
         | 
         | It is far more likely this, than your cell phone provider.
        
           | apparent wrote:
           | Those websites don't have my phone number.
        
             | crazygringo wrote:
             | The ads/analytics providers very well might. They gather
             | data and cross-reference from tons of different sources.
             | 
             | And I don't know about you, but I've put my phone number
             | into a _lot_ of apps and sites. Sometimes it 's required,
             | sometimes it's for 2FA, etc.
        
               | apparent wrote:
               | I use a virtual number for almost all such signups (only
               | doctors or other safety), so I'm not sure that would be a
               | possible avenue for these calls, which come to my direct
               | cell phone number. It is not quite a secret, but it is
               | not something I give out to many companies.
        
               | crazygringo wrote:
               | They do pattern matching against lots of pieces of
               | information. It could be as simple as a local utility
               | company selling their customer list with phone number and
               | address attached, then a retail website has your address
               | from when you bought something, now your phone number
               | gets linked.
               | 
               | It doesn't matter if you don't give your phone number to
               | _many_ companies, it only takes one.
        
         | spzb wrote:
         | I'd be looking at ad networks rather than telcos in this case.
         | https://www.eff.org/deeplinks/2026/01/google-settlement-may-...
        
           | apparent wrote:
           | Yeah it's a possibility if they matched up ad stuff with my
           | home location and guessed at my phone number based on that.
           | 
           | But if they're trying to get me to answer the phone, calling
           | from a local number actually makes me less likely to answer.
           | Nobody would be calling my cell phone from the city I'm
           | visiting. I'm more likely to pick up a call if the area code
           | is from back home.
        
         | themafia wrote:
         | Use a VPN next time.
         | 
         | Does it still happen?
        
       | jms703 wrote:
       | I honestly thought this has always been the case.
        
       | eek2121 wrote:
       | I did not read the article. Reason: My response is "No shit,
       | Sherlock."
       | 
       | Mobile carriers have so much information about you. They know
       | exactly where you are, what you are doing (location combined with
       | mapping tools) combined with who you are talking to.
       | 
       | They know when you are at home depot, when you are the grocery
       | store, when you are at home, when you are awake, when you are
       | asleep, etc.
       | 
       | In the U.S. there are very few laws stopping them from using all
       | your data. In the E.U. you should definitely read up, as you
       | aren't as protected as you think you are.
       | 
       | Forget Nation/State nonsense. You have an active relationship
       | with a company who, by it's very existence and your business
       | relationship, knows what you do all day long.
       | 
       | Don't even get me started about the rabbit hole surrounding
       | 'incognito'/anonymous browsing.
       | 
       | EDIT: You've probably heard of Man-in-the-Middle attacks, right?
       | They are the man in the middle. They will exploit this as best
       | they legally can (and in certain cases, without regard to
       | legality)
       | 
       | The best way to protect yourself is not to play the game at all.
       | The same goes for your ISP, FWIW.
        
       | Gobd wrote:
       | Nothing can stop the tower equipment manufacturer like Ericsson
       | from knowing the location of your phone and cooperating with
       | advertising or mobile tracking compainies to aggregate that data
       | in useful ways. If you have a phone, people that want your
       | location have it and there is nothing you can do.
        
         | iamnothere wrote:
         | False. You can:
         | 
         | 1) Leave the phone at home
         | 
         | 2) Use a phone with a hardware toggle switch that physically
         | kills power to the cell modem, or turn off the phone and put it
         | in a tested Faraday bag
         | 
         | 3) Conspire with other citizens to make such location tracking
         | illegal and to enforce that law
         | 
         | I'm tired of privacy doomerism. You have options, use them.
        
           | aydyn wrote:
           | > If you have a phone, people that want your location have it
           | and there is nothing you can do.
           | 
           | > False. You can: 1) Leave the phone at home
           | 
           | Then you dont have a phone, do you? Come on you are being
           | pedantic for no reason.
        
             | iamnothere wrote:
             | Not all the time, no. But I can make calls over wifi and
             | forward texts to myself. And nobody's tracking me. Why
             | would I always need the phone with me?
        
               | testing22321 wrote:
               | I do the same... and I don't own a phone!
        
               | tavavex wrote:
               | So people can give you a call even if you're not home? I
               | mean, this has been the main selling point of mobile
               | phones for over 30 years, and especially before
               | smartphones became a thing. If you don't take your phone
               | with you, you might as well wire in a landline and just
               | use that.
        
               | thaumasiotes wrote:
               | > So people can give you a call even if you're not home?
               | I mean, this has been the main selling point of mobile
               | phones for over 30 years, and especially before
               | smartphones became a thing.
               | 
               | It was the selling point of mobile phones before
               | smartphones became a thing. It obviously hasn't been the
               | main selling point of mobile phones since then.
        
           | antiframe wrote:
           | Also, run an OS that doesn't allow every running process to
           | read your GPS location. And allows you to turn off your cell
           | modem.
        
       | xyst wrote:
       | Even if you have an Apple in-house modem, seems it can only be
       | disabled with select carriers:
       | 
       | > Germany: Telekom > United Kingdom: EE, BT > United States:
       | Boost Mobile > Thailand: AIS, True
       | 
       | So turning this "off" on other carriers results in GPS data still
       | shipped off?
        
       | ReptileMan wrote:
       | >Since cell towers are sparse (especially before 5G), the
       | accuracy is in the range of tens to hundreds of metres
       | 
       | It was 5 meters back in 2006 in urban areas.
        
       | jchw wrote:
       | The Google Pixel 10 can give you notifications when your location
       | is tracked in this manner as well. I turned it on and have been
       | notified a few times.
       | 
       | It is interesting that we let this happen. Modern phones are very
       | useful devices, but they're not really mandatory for the vast
       | majority of people to actually carry around everywhere they go,
       | in many cases they merely add some convenience or entertainment,
       | and act to consolidate various other kinds of personal devices
       | into just one. If you wanted, you could more often than not avoid
       | needing one. Yet, we pretty much all carry one around anyways,
       | intentionally, and this fact is somewhat abused because it's
       | convenient.
       | 
       | Having watched a fair bit of police interrogations videos
       | recently (don't knock it, it can be addicting) I realized that
       | police have come to rely on cell phone signals pretty heavily to
       | place people near the scene of a crime. This is doubly
       | interesting. For one, because criminals should really know
       | better: phones have been doing this for a long time, and privacy
       | issues with mobile phones are pretty well trodden by this point.
       | But for another, it's just interesting because it _works_. It 's
       | very effective at screwing up the alibi of a criminal.
       | 
       | I've realized that serious privacy violations which actually _do_
       | work to prevent crime are probably the most dangerous of all,
       | because it 's easy to say that because these features can help
       | put criminals behind bars, we should disregard the insane
       | surveillance state we've already built. It's easy to justify the
       | risks this poses to a free society. It's easy to downplay the
       | importance of personal freedoms and privacy.
       | 
       | Once these things become sufficiently normal, it will become very
       | hard to go back, even after the system starts to be abused, and
       | that's what I think about any time I see measures like chat
       | control. We're building our own future hell to help catch a few
       | more scumbags. Whoever thinks it's still worth it... I'd love to
       | check back in in another decade.
        
       | bzmrgonz wrote:
       | I wonder if graphene on pixel is immune to these remote
       | requests??
        
         | goodpoint wrote:
         | It is not.
        
         | parsimo2010 wrote:
         | I wouldn't bet on it. If the baseband modem has access to
         | location data then it could send it without the OS being able
         | to intervene. I don't know about Pixels, but many devices are
         | highly integrated now that I would want some real thorough and
         | specific research before I trusted that an OS could block the
         | modem from sending location data.
        
       ___________________________________________________________________
       (page generated 2026-01-31 23:00 UTC)