[HN Gopher] Mobile carriers can get your GPS location
___________________________________________________________________
Mobile carriers can get your GPS location
Author : cbeuw
Score : 348 points
Date : 2026-01-31 17:21 UTC (5 hours ago)
(HTM) web link (an.dywa.ng)
(TXT) w3m dump (an.dywa.ng)
| kayodelycaon wrote:
| Emergency services (with the proper software) have been able to
| get your precise location from your phone for a while now.
|
| This isn't a new capability and shouldn't be surprising.
| michaelt wrote:
| Surely that only happens when the phone user dials 911 ?
| hammock wrote:
| How would that work?
| roywiggins wrote:
| The phone could literally pop up a consent alert asking
| whether to respond to a GPS ping request from the carrier.
| Or just not honor the pings at all unless you dialed 911
| within the last hour.
|
| This is a specific service inside the phone that looks for
| messages from the carrier requesting a GPS position, it
| could just refuse, or lie. It's not the same as cell tower
| triangulation.
| winstonwinston wrote:
| The article does not explain in detail how all this
| works. But educated guess is that if a baseband SoC
| provides this information, that's it. The phone operating
| system (iOS, Android) does not get a chance to decide
| what to do, since baseband soc is a sort of autonomous
| computer, it has its own firmware, cpu and ram.
| roywiggins wrote:
| You might not be able to fix this in the OS alone, but
| phone manufacturers are responsible for the whole phone.
| The baseband doesn't need to behave that way.
| winstonwinston wrote:
| Well, yes. But autonomous is acting in accordance with
| one's duty (a law) rather than one's desires.
| hammock wrote:
| That's not happening today. I meant how is it happening
| today, such that it can only ever happen when you dial
| 911?
| _flux wrote:
| I can imagine situations where the emergency is noticed
| by other people that might not be near the location
| itself, and the person whose location would need to be
| determined is not able to use the mobile phone, such as
| could be the case in many accidents.
|
| I think it would be sufficient to just have a log of this
| information being queried, and cases where the
| information has been pinged without a legitimate use case
| would the be investigated.
| kortilla wrote:
| A phone knows if it's dialing 911. It can activate features
| on this criteria
| cosmicgadget wrote:
| It already exists. Emergency call is spec-defined.
| yetihehe wrote:
| Phone detects that you call emergency service and enables
| gps.
|
| Last time I called 911 (well, it's 112 in my country) my
| android phone asked if I want to provide gps coordinates. I
| did, but they still asked for address, so probably this is
| not integrated/used everywhere.
| nkrisc wrote:
| They may also ask simply to confirm the location is
| correct and to help responders more quickly locate you in
| the vicinity.
| kotaKat wrote:
| Carrier* Android and iOS both integrate with RapidSOS
| UNITE. RapidSOS then processes the rich emergency
| information from the user's device (enhanced location,
| videos and photos, etc), and is available to the 911
| dispatcher in their dispatch software. 99.99% of Americans
| are covered by RapidSOS integrations in their
| municipalities.
|
| https://rapidsos.com/public-safety/unite/
|
| When the call comes in they can click a button and query
| RapidSOS for current 911 calls for that number and pull the
| information inwards.
|
| https://www.baycominc.com/hubfs/2025%20Website%20Update/Pro
| d...
| cenamus wrote:
| Send the GPS location only when dialling a 3-digit number?
| Phones probably know which numbers are emergency numbers
| anonymousiam wrote:
| The cell network routinely does TDoA triangulation in order
| to help choose which tower should serve the client mobile
| device. Accuracy is about 20m, and may be better at 5G
| frequencies. 911 gets the location from the mobile network
| provider, but the network provider could provide it to
| anyone, and they do.
|
| Tons of "free" and crapware apps are also recording location,
| and sending it to data brokers.
|
| https://www.wired.com/story/jeffrey-epstein-island-
| visitors-...
| jeroenhd wrote:
| Using LTE Timing Advance feature, especially on 5G,
| accuracy can be much higher.
|
| https://5g-tools.com/5g-nr-timing-advance-ta-distance-
| calcul... shows an example of the parameters necessary. I
| don't think you can get your smartphone to dump those stats
| for you, but the granularity of the individual distance
| measurement is in the tens of centimeters.
|
| Of course this strongly depends on cell infrastructure
| being placed precisely, continuously updating correction
| factors, and a bunch of antennae being around the target to
| get measurements for, but in most cities that isn't much of
| a challenge if the operator is working together with
| whoever wants to spy on citizens.
| ErroneousBosh wrote:
| In the UK, it happens when you call 999 or 112. I don't think
| 911 is supported, although it probably should be (it'd be a
| mess to get everyone to agree to add it to their routing
| tables, but I bet there's a nonzero proportion of people who
| watch American TV programmes and think the emergency number
| is 911 - or, for that matter, American tourists).
|
| When you dial 999 it forwards your phone's GPS location if it
| has a lock to the provider, who then forwards it on to one of
| the 999 call handling centres in the UK, who then in turn
| forward that on to the appropriate emergency service control
| room. All the various services use various different products
| for telephony and dispatch but they will show the incoming
| location, and often will prepopulate an incident with the
| location.
|
| The system that does this is called "EISEC" - Enhanced
| Information Service for Emergency Calls - and has a lot of
| cool stuff defined in the spec (which is publically
| available! You can just go and read it! BT offer a
| "Supplier's Information Note" with the protocol and details
| of how the information is encoded) that also handles calls
| from landlines. These are easy - your telephone provider
| knows where you live. OMG! The phone company know where I
| live? Yes, dumbass, they pulled a wire right into your house,
| of course they know where it is. For VoIP the situation is a
| little different but you can notify your VoIP provider of the
| location that the number is being used at, and it'll inject
| that into the EISEC request.
|
| You can do other cool stuff like if you've got fixed mobile
| telephone in a vehicle, you can assign the make, model,
| registration number, colour, and so on in the EISEC database,
| so given a call from a phone number they know what car
| they're looking for. No-one uses this.
|
| The very great majority of calls coming in to 999 are from
| mobiles. It's extremely rare to get one from a landline.
|
| None of the providers use triangulation for determining where
| a phone is, it's all GPS.
| nateberkopec wrote:
| You're thinking of Phase II E911 in the US.
|
| That's true, but you can always be triangulated down a couple
| hundred meters by figuring out which towers you're connected
| to.
| Etheryte wrote:
| None of this should be happening without the user's knowledge
| and consent. Swap out your phone carrier for Facebook and it
| should be plainly obvious why the current state of affairs is
| undesirable.
| cosmicgadget wrote:
| You know about it because your regulatory body requires the
| system exist.
| TheNewsIsHere wrote:
| And it's typically disclosed in one way or another.
|
| Between buying a phone and reading the OS EULA to providing
| an E911 address to my carrier, I can count at least three
| disclosures of this feature.
|
| Nothing is secret or magic here.
| MagicMoonlight wrote:
| What is it's a mentally ill person who is about to kill
| themself?
|
| That's the majority of uses for the system in the UK. People
| love to run away and waste police time.
| iamnothere wrote:
| That's not a good excuse for mass privacy violation.
| KellyCriterion wrote:
| I think this feature is required for emergency calls if your
| specific carrier is not available/in reach - in emergency
| mode after the phone is restarted, it does connect to any
| carrier when calling 911, not only yours?
| nateberkopec wrote:
| I spent ~5 years volunteering for a search and rescue team in
| New Mexico.
|
| We definitely got the cellphone tower triangulation data. I
| never once saw GNSS data provided by a carrier. We used
| FindMeSAR https://findmesar.com/, the subject would usually
| text back the coordinates from the phone.
|
| Just one data point.
|
| The revolution that's occurred since my SAR volunteer days is
| the wide availability of satellite messenging on consumer
| phones. I'm guessing that's really changed the situation quite
| a bit.
| tekla wrote:
| How is this news?
|
| Why wouldn't carriers be able to ask your phone about what it
| thinks its location is?
| mcny wrote:
| No, please read the article. No one is saying carriers cant
| triangulate but carriers shouldn't be able to query the gps on
| my device and get precise GNSS data.
|
| > Apple made a good step in iOS 26.3 to limit at least one
| vector of mass surveillance, enabled by having full control of
| the modem silicon and firmware. They must now allow users to
| disable GNSS location responses to mobile carriers, and notify
| the user when such attempts are made to their device.
| benSaiyen wrote:
| Please reread OPs comment
|
| They never said "triangulate" but read phone for information.
| Your inner monologue swapped what was written with an already
| understood technical method.
|
| And just because access to GPS has never been confirmed
| publicly before does not mean they previously only relied on
| tower triangulation.
|
| Worked for Sprints network team before they bought Nextel. We
| had access to eeeeverything.
| tekla wrote:
| I did read the article fine, thanks for asking.
|
| The crux of the argument seems to come from this
|
| > It's worth noting that GNSS location is never meant to
| leave your device. GNSS coordinates are calculated entirely
| passively.
|
| OK so? The fact that GPS is calculated passively means
| nothing about the phone being asked what its position is
| after the fact.
|
| The article admits this capability is no secret
|
| > These capabilities are not secrets but somehow they have
| mostly slid under the radar of the public consciousness.
|
| If the article just wants to say phones should block that
| ability, fine. But don't pretend this is some shady BS.
| kortilla wrote:
| > slid under the radar of the public consciousness.
|
| It is shady BS, and it's why this phrase appeared in the
| article. Just because industry insiders are aware doesn't
| mean it's not shady.
|
| The same applies to modern cars reporting their information
| back to manufacturers.
| colechristensen wrote:
| There's a difference in precision between cell tower
| triangulation and GPS. From 10-100 meters down to 1.
|
| The cell network does not need to know where you are down to
| the meter and phones have no business giving this information
| up.
| Plasmoid2000ad wrote:
| Why would they? It's basic privacy no? Just because I want to
| pay money to carrier to provide me with data and phone service,
| I shouldn't have to give up my location from my device. I
| expect them to know my approximate location from cell tower
| data.
|
| Generally I'd not expect them actively triangulate my exact
| location, but I'd realise that's at least possible - but GPS
| data, wake my phone up, switch on the GPS radio, drain it's
| battery, send that data back... no. That wouldn't be legal
| where I live either, let alone expected.
| tekla wrote:
| > but GPS data, wake my phone up, switch on the GPS radio,
| drain it's battery, send that data back... no. That wouldn't
| be legal where I live either, let alone expected.
|
| Where does the article claim this turns on the GPS if off?
| bmacho wrote:
| It .. probably does turn the GPS on?
|
| While this is an important question, I don't see the
| sources mentioning it, what the standards mandate, and how
| the phones behave.
|
| For example the wiki article https://en.wikipedia.org/wiki/
| Radio_resource_location_servic... describes the protocol as
| using the GPS and not as getting the location info from
| Android.
| nephihaha wrote:
| It's all in the small print or acquired by deception.
| vlovich123 wrote:
| The can ask but your phone maybe doesn't have to tell them by
| default / you can opt out
| ProofHouse wrote:
| In other news, the sky is up
| cluckindan wrote:
| Removing this ability also prevents emergency services from
| determining device location in case its owner goes missing.
| webstrand wrote:
| No? If the device is connected to a cell, they can still
| triangulate it just like normal.
| mcculley wrote:
| Cell tower triangulation does not provide the same precision
| as GPS.
| roywiggins wrote:
| In an emergency you might really want GPS precision.
| krater23 wrote:
| Which emergency can happen that I really want this? And now
| don't say suicide attempt. Nearby all emergencies that
| could happen where someone needs my exact position are
| things that would additionally lead to a loss of the base
| connection or a switched off smart phone.
| benSaiyen wrote:
| Triangulation does not provide granularity needed for
| emergency response.
|
| You want EMS looking for a needle in a haystack while you are
| suffering a heart attack?
| ssl-3 wrote:
| Indeed.
|
| How do people suggest that this would work, do you suppose?
|
| "We've narrowed the victim's location down to one city
| block, boys! Assemble a posse and start knocking on doors:
| If they don't answer, kick it in!" ?
|
| (And before anyone says "Well, it can work however it used
| to work!" please remember: Previously, we had landline
| phones in our homes. When we called 0118 999 881 999 119
| 725 3 for emergency services, there was a database that
| linked the landline to a street address and [if applicable]
| unit.
|
| That doesn't work anymore because, broadly-speaking, we now
| have pocket supercomputers instead of landlines.)
| benSaiyen wrote:
| We also had phone books with everyone's name and address
| listed.
|
| Everyone was effectively doxxed yet it was never a
| security issue.
| Noaidi wrote:
| And this is how they're able to track all of us, they're
| triggering our fear response to give up our civil liberties.
| b00ty4breakfast wrote:
| it should be my choice to decide if I want my privacy to be
| infringed upon in the name of safety. It should not be up to
| the carrier, or the manufacturer, or first responders or any
| level of government to make that decision for me.
| digiown wrote:
| Can't this can be done in a less invasive way by whitelisting
| the emergency numbers and putting an extra button somewhere
| that sends the location?
| gruez wrote:
| No
|
| > The limit precise location setting doesn't impact the
| precision of the location data that is shared with emergency
| responders during an emergency call.
|
| https://support.apple.com/en-us/126101
| pfortuny wrote:
| Well yes. People have gone missing since there were people on
| Earth.
|
| The fact that something has some good side effects does not
| make it good or even reasonable.
| 2OEH8eoCRo0 wrote:
| Do they really need it? They can likely triangulate you without
| GPS regardless.
| mcculley wrote:
| Cell tower triangulation does not provide the same precision as
| GPS.
| kotaKat wrote:
| And at the end of the day if the location is a hundred meters
| off... it might still not matter because it's how you frame
| it with other evidence beyond a reasonable doubt.
|
| Even the article mentions this.
|
| > I have served on a jury where the prosecution obtained
| location data from cell towers. Since cell towers are sparse
| (especially before 5G), the accuracy is in the range of tens
| to hundreds of metres.
|
| I've also personally witnessed murder cases locally where GPS
| location put a suspect to "100 meters away". The rest of the
| evidence still pushed the case forward to a guilty verdict,
| and the phone evidence was still pretty damning.
| mcculley wrote:
| I did not argue for or against collection of GPS data.
| ErroneousBosh wrote:
| > And at the end of the day if the location is a hundred
| meters off... it might still not matter because it's how
| you frame it with other evidence beyond a reasonable doubt.
|
| For example, if you drop a pin a hundred metres off from
| the incident, then when you're maybe several hundred metres
| off the column of smoke is probably a better indicator of
| locus than the wee dot on your screen.
| metaphor wrote:
| What makes you think cell tower triangulation is the only
| data point being exploited to minimize position error?
| 2OEH8eoCRo0 wrote:
| I've wondered if they can also find you by what wifi or
| Bluetooth devices are around. Odds are one or more humans
| nearby has their GPS on. Your device can snitch on what's
| around or those other devices snitch on you.
| jcynix wrote:
| Google recorded wifi names and locations as a "bycatch"
| when taking streetview pictures from 2007 upto 2010. They
| still collect such data on Android devices if the user
| consents or ignores the option to say "no" ... :-0
|
| Certain devices (especially tablets) don't have GPS or
| various sensors integrated and still can tell you your
| approximate location, if WiFi is enabled.
| denysvitali wrote:
| Apple does the same. Actually, most of the time in areas
| w/o direct sky view GNSS isn't usable at all.
|
| If you want to play around a bit, you can try my tool
| that queries Apple's location services for your nearby
| networks. The precision is remarkable.
|
| https://github.com/denysvitali/where-am-i
| AstroNutt wrote:
| I've thought that too... especially Bluetooth. I know
| it's possible with Wi-Fi signal strength.
|
| Is it a coincidence most smartphone manufacturers were
| suddenly all on board with removing the 3.5mm jack and
| forced Bluetooth? A mesh network of sorts like Amazon is
| doing with Ring. I even sometimes forget to save my
| battery and turn Bluetooth off when I'm not using my
| earbuds. It's probably a false sense of security having
| it disabled because I'm sure it's doing something in the
| background anyways. I can't say for sure though. Kind of
| like years ago with Google getting caught with the whole
| location data thing. I'm sure the average Joe doesn't
| care if Bluetooth is enabled 24/7.
|
| I try and not be on the tin foil bandwagon, but every
| once and a while I come across things that make you go
| hmmm...
| denysvitali wrote:
| I doubt BT is the right way to locate a device, it's far
| better for being located (FindMy-style).
|
| Wi-Fi is better for positioning since BSSIDs are (mostly)
| static and APs don't move around.
|
| On top of that, BLE usually uses random addresses - so it
| won't be of much help knowing that you were around
| CC:B9:AF:E8:AE at 10:05 AM - since that address is likely
| random.
| ssl-3 wrote:
| Of course they can. Locations can be trilaterated using
| wifi and bluetooth.
|
| Back when my OG iPod Touch was minty and new (2008,
| IIRC), it was in many ways a stripped-down iPhone.
|
| One of the features that was stripped out was GPS: It
| didn't have that at all. It also lacked Bluetooth.
|
| But it did have a Maps app, and it also had location
| services. This used visible wifi access points and a
| database back home on the mothership to determine
| location.
|
| It was pretty neat at that time to take this responsive,
| color-screened pocket computer with me on a walk, connect
| it to a then-ubiquitous open SSID, and have it figure out
| my location and provide a map (with aerial photos!) of
| where I was. It wasn't ever dead-nuts, but it was
| consistently spooky-good.
|
| It's pretty old tech at this point, and devices still use
| it today.
|
| (Related tech: Those plastic table tents that you take
| with you at McDonald's after ordering at the kiosk?
| They're BLE beacons. Sensors in the ceiling track them so
| that the person bringing the tray with food on it knows
| about where you're sitting before they even walk out of
| the kitchen. And modern pocket supercomputers use the
| locations of these and other beacons, as well, to help
| trilaterate their position. Urban environments are
| replete with very chatty things that don't move around
| very much.)
| mcculley wrote:
| What magical technology do you think would beat GPS?
| metaphor wrote:
| Who said anything about beating GPS or other functionally
| equivalent GNSS?
| mcculley wrote:
| I am not sure that we are in the same conversation. I
| misinterpreted your reply to my comment as having
| something to do with it.
| instagib wrote:
| What you need iPhone Air, iPhone 16e, or iPad Pro (M5) Wi-Fi +
| Cellular iOS 26.3 or later
|
| A supported carrier: Germany: Telekom United Kingdom: EE, BT
| United States: Boost Mobile Thailand: AIS, True
|
| Turn limit precise location on or off
|
| Open Settings, then tap Cellular.
|
| Tap Cellular Data Options.
|
| If you have more than one phone number under SIMs, tap one of
| your lines.
|
| Scroll down to Limit Precise Location.
|
| Turn the setting on or off. You might be prompted to restart your
| device.
| OGEnthusiast wrote:
| Kinda funny that the most secure phone setup in the US is an
| iPhone Air on Boost Mobile. Who could have predicted that!
| TheNewsIsHere wrote:
| It isn't restricted to Boost Mobile. It is only available on
| devices with the C1 or C1X modem, though. I assume this is
| because of specifics with the third party modems that most
| models in the wild have vs what Apple is doing in-house with
| their C1(X). If you call emergency services it will still
| provide precise location.
| gruez wrote:
| >It isn't restricted to Boost Mobile.
|
| Why does it list specific carriers, then?
| js2 wrote:
| Apple doc: https://support.apple.com/en-us/126101
|
| Only Boost Mobile in the U.S. Weird. About 7.5M subscribers.
| Maybe it requires 5G? Wonder if it works when roaming?
|
| https://en.wikipedia.org/wiki/Boost_Mobile
|
| https://en.wikipedia.org/wiki/List_of_mobile_network_operato...
|
| https://en.wikipedia.org/wiki/5G_NR
| SoftTalker wrote:
| AFAIK, other than maybe some 5G, Boost Mobile just resells
| service from AT&T.
| lukec11 wrote:
| Boost Mobile (under Dish Network), until a few months ago,
| ran their own custom-built 5G network that covered about
| 30% of the US population. They built it after the
| acquisition of Sprint by T-Mobile, in an effort to maintain
| a fourth nationwide wireless carrier.
|
| Unfortunately Boost/Dish struggled significantly with
| finances and customer attraction post COVID, largely due to
| two problems (seamless roaming between their own network
| and partners', and more importantly, getting manufacturers
| like Apple to build compatible phones). When the current
| president came into the picture, the FCC essentially forced
| the sale of Dish's primary spectrum licenses to
| administration-friendly SpaceX, for future Starlink use.
|
| As of now, they are in the process of moving their
| customers to AT&T (and possibly a secondary agreement with
| T-Mobile), but they seem to be maintaining their own
| network core - that's likely why they're able to implement
| support for this, while AT&T does not.
| pstuart wrote:
| But they still can track the cellular connection and do
| triangulation from that, no?
|
| Basically, if you have _any_ cell phone the government can
| track you. Buying a burner phone with cash (via strawman proxy)
| seems like the only way to temporarily obscure your location.
|
| I imagine with the ubiquity of cameras in the commons and
| facial recognition and gait analysis they can knit that up even
| more.
| crazygringo wrote:
| Serious question: will this limit the ability of 911 emergency
| services to help you?
|
| I can imagine a scenario where emergency servies are authorized
| to send the ping to get your precise location and if you
| disable this, you may regret it. And a major feature of some
| phones/watches is the ability to automatically call 911 under
| certain fall/crash movement detection, where you might not have
| the ability to re-enable your GPS location.
| AnotherGoodName wrote:
| This community should be talking about meshcore more imho.
|
| It's a peer to peer network based on Lora. It really only allows
| text messaging but with up to 20km hops between peers coverage is
| surprisingly huge. Incredibly useful if you go hiking with
| friends (if you get split up you can still stay in touch).
|
| See https://eastmesh.au/ and scroll down to the map for the
| Victoria and now more widely Australia network that's sprung up.
| grepfru_it wrote:
| Great for small networks. Once bad actors find it, it will be
| attacked. See gnutella as the case study on unsupervised peer
| to peer networks
| elnerd wrote:
| I just read gnutella page on Wikipedia, no mention of bad
| actors
| hamdingers wrote:
| I take it you never got a mislabeled mp3 of Bill Clinton
| advertising online poker.
| copperx wrote:
| It is surprising that these networks aren't more popular. There
| are still many places and situation where connectivity isn't
| available
| butvacuum wrote:
| Because they're terrible and fall apart if more than a few
| score people are on the same freqency at the same time.
| esseph wrote:
| It's because they aren't very resilient. More of an
| experiment than a purpose designed tool for the, uh, current
| environment.
| NoiseBert69 wrote:
| Meshcore and -tastic have the huge problem that the encryption
| keys are bound to the device and not the app.
| timschmidt wrote:
| I've been using the T-Deck Pro and T-Lora Pager, so the
| device _is_ the app.
| jonmon6691 wrote:
| I agree, there's way too much going on in the firmware, just
| make a dumb Lora-bluetooth bridge. Hell, just integrate a
| Lora radio in a phone.
| wisplike wrote:
| Why Meshcore over Meshtastic?
| ianpenney wrote:
| There's lots of YouTube videos about this but basically: you
| can specify routing.
| subscribed wrote:
| Meshtastic has terrible defaults (every node rebroadcasts
| everything, every node sends telemetry), which makes sense in
| the backwoods but not anywhere close to civilisation.
| mbirth wrote:
| This, combined with the 10% duty cycle limitation on the
| used frequencies is the main issue, I believe. Once the 10%
| are used up, a node basically has to go dead until it falls
| below 10% again. And with lots of messages about battery
| levels and other telemetry being sent and relayed, those
| 10% get used up fast.
| ianpenney wrote:
| I've been wondering this for a while and maybe someone has a
| clue.
|
| Based on the very "bursty" nature of LoRA, how much does an
| adversary need to spend to radiolocate it? What's the threat
| model there?
| comboy wrote:
| $20? These networks do not try to hide your location and
| triangulating known frequencies is trivial.
| Gigachad wrote:
| You could get a rough location for free. Every time you send
| a message, "observer" nodes connected to the internet publish
| the packet, and in the packet is the repeater path taken,
| repeaters have known locations and the first repeater is
| going to be near you.
| noja wrote:
| Is it open source?
| subscribed wrote:
| What, protocol? Basic apps? Yes.
| sneak wrote:
| The crypto is bad and the networks are extremely low bandwidth
| and quite unreliable and are vulnerable to jamming or
| spam/overload.
|
| I've deployed lots of nodes, and the technology reminds me of
| ipfs: people who don't use it much vastly oversell its
| capabilities.
| konsumer wrote:
| Reticulum gets around a lot of these problems, as the (better)
| encryption is app-level (or even more fine-grained.) Its also
| not tied to lora, so you can interop easily with other
| transports. I made a websocket transport for it, and there is
| already TCP and UDP, and a couple non-lora radio transports. I
| also made a (works on web) js and Arduino client lib, and it
| has a few native client libs, so it can sort of be used on
| anything, even over traditional networks, or web clients.
| Meshcore and meshtastic are way more popular, but reticulum
| seems so much better, to me, for most things. It can still have
| overload problems, like any radio network, but no client is
| required to forward, so you can build a different kind of
| network ("only forward messages that are for my peeps" and
| marked correctly.) It also has "it costs compute PoW to send to
| me" which can greatly cut down on spam.
| fragmede wrote:
| If you go hiking with friends who aren't total nerds, the
| proprietary options offer a more consumer-grade experience.
| (ie, usable by them)
| cyberax wrote:
| > This community should be talking about meshcore more imho.
|
| The fundamental problem of distributed networks is that you can
| either have centralized control of the endpoints, or your
| network becomes vulnerable to denial-of-service attacks. So
| meshcore/meshtastic are great because they are used only by
| well-meaning people. If they become more popular, we'll start
| getting tons of spam :(
| bronco21016 wrote:
| I really want to get into these Lora based mesh tools but the
| range in my experience is terrible. Maybe I'm doing something
| wrong, maybe it's a lack of nodes in my area.
|
| I just tested the other day. I'm in the midwest US so it's
| winter, no leaves. I managed to get about a quarter mile before
| my two portable nodes couldn't talk to each other. T-Echo with
| muziworks whip antenna.
|
| Without a bunch of solidly placed, high elevation, high gain
| antenna nodes, this just isn't really that usable.
|
| Plus, all the other issues others have highlighted.
| AlexanderYamanu wrote:
| euhm, well. 112 programmer here. There are multiple levels. Cell
| tower triangulation come in automatically from providers. But
| they are only in tower numbers. They might be wrongly entered by
| engineers, hence the confirming question about where you are.
| Second is subscription information, as in registered address.
| Chances are if called from nearby your address, you are at your
| address. Next is a text to your phone number, which is
| intercepted by firmware and sends gps coords back. This can be
| turned off, since implementation.
| IshKebab wrote:
| > This can be turned off, since implementation.
|
| Not by users. The new thing is that Apple allows users to
| disable this feature. Hopefully they still detect emergency
| calls on the phone and enable it unconditionally for those.
| AlexanderYamanu wrote:
| yeah, there always was. It's a service code, like getting
| your imei. But it was a weird long one, and manufacturer
| dependent. Now UI switches are created for it apparantly.
| Can't find it anywhere on the internet though. I don't work
| there anymore, so can't look it up.
| jeroenhd wrote:
| I believe they're talking about this feature (https://support
| .google.com/android/answer/9319337?sjid=18079...).
|
| This is a system you can disable as a user, but it's not the
| on-modem feature discussed in the article.
| KellyCriterion wrote:
| Note sure: In my country exactly this feature is used by
| police & state enforcement to find locatin, because this
| "ping" message is not forwarded from the modem to the OS, so
| the OS is not aware of any of these messages
| jeroenhd wrote:
| American carriers have a different protocol than the EU. The EU
| (and probably EU derived networks) uses a """secret""" SMS
| format that's opt-in, but the 911 system works differently.
|
| The 911 feature can be activated fully remotely, the 112
| feature is supposed to only activate when dialing an emergency
| number.
| yencabulator wrote:
| The US one is called E911:
| https://en.wikipedia.org/wiki/Enhanced_911
| gruez wrote:
| >The 911 feature can be activated fully remotely
|
| Source? Even if the phone isn't actively doing a 911 call?
| Havoc wrote:
| GP likely means any 911 call automatically has geo tracing.
|
| >The dispatcher's computer receives information from the
| telephone company about the physical address (for
| landlines) or geographic coordinates (for wireless) of the
| caller.
| dfc wrote:
| Did you read the article or are you merely responding to the
| title? The article begins by acknowledging triangulation and
| then moving on to the point of the article. The article is
| about commands built into the UMTS and LTE specs for requesting
| GPS from the device. Your comment seems to be about everything
| but the main point of the article.
| M95D wrote:
| Did you read the complete comment?
|
| > Next is a text to your phone number, which is intercepted
| by firmware and sends gps coords back.
| dfc wrote:
| Yes I saw that and also took it to mean the person didn't
| read the article. A text to your phone number? The article
| never mentions SMS. Heck I think the 2g/3g "feature" does
| not even require the phone to even have a SIM installed.
| This next sentence also seems to have been written without
| reading the article: "This can be turned off, since
| implementation."
| thisislife2 wrote:
| From the comments, it appears many are not aware that even the US
| government buys location data of users from data brokers - _How
| the Federal Government Buys Our Cell Phone Location Data_ -
| https://www.eff.org/deeplinks/2022/06/how-federal-government...
| ... Apparently, US cell phone companies are one of the providers
| of this data - _US cell carriers are selling access to your real-
| time phone location data_ -
| https://news.ycombinator.com/item?id=17081684 ...
| Frost1x wrote:
| We really have a societal problem in that we allow private
| entities to do things we don't allow government to do.
| Furthermore, the issue is exacerbated by then allowing
| governments to bypass these issues by then just paying private
| entities to do the things it can't do as a proxy for the same
| functional outcomes.
|
| But we want to support privatization at all cost, even when
| privatization these days has significant influence on our daily
| lives, akin to the concerns we had when we placed restrictions
| on government. Seems like we need to start regulating private
| actions a bit more, especially when private entities accumulate
| enough wealth they can act like multi state governments in
| levels of influence. That's my opinion, at least.
| gruez wrote:
| >We really have a societal problem in that we allow private
| entities to do things we don't allow government to do.
|
| It really isn't, given that the government literally has a
| monopoly on violence, and therefore it makes sense to have
| more guardrails for it. That's not to say private entities
| should have free reign to do whatever it wants, but the
| argument of "private entities can do [thing] that governments
| can't, so we should ban private entities too!" is at best
| incomplete.
|
| >Furthermore, the issue is exacerbated by then allowing
| governments to bypass these issues by then just paying
| private entities to do the things it can't do as a proxy for
| the same functional outcomes.
|
| Again, this is at best an incomplete argument. The government
| can't extract a confession out of you (5th amendment). It can
| however, interview your drinking buddies that you blabbed
| your latest criminal escapades to. Is that the government
| "bypassing" the 5th amendment? Arguably. Is that something
| bad and we should ban? Hardly.
| salawat wrote:
| Your cell phone provider does not constitute "drinking
| buddy". The fact that, in essence, everyone is being
| surveilled location wise all the time by these providers is
| reason enough to restrict the activity.
| gruez wrote:
| >Your cell phone provider does not constitute "drinking
| buddy".
|
| You're right, it should be even more scandalous for the
| government to get information out of my drinking buddy,
| because the information I told him was in confidence, and
| he promised he wouldn't tell anyone. My cell phone
| provider, on the other hand, clearly says in their ToS
| who they'll share data with and in what circumstances.
| lukan wrote:
| "who they'll share data with and in what circumstances"
|
| Anyone who offers them money?
| iamnothere wrote:
| And what many are saying is that the phone provider
| should not be allowed to be so free with your data in the
| ToS. In the same way that your landlord can't add a
| slavery clause to your lease.
| rockskon wrote:
| A non-exhaustive list that has, time and time and time
| and time and time and time and time and time again, to
| downplay the grossly cavalier approach they take to the
| "privacy" of your location data.
|
| They value it alright. At several dollars per person.
| mlfreeman wrote:
| And the ToS probably has a clause that says "we can alter
| the deal any time we want and you should pray we don't
| alter it further".
| nerdsniper wrote:
| > The poster with the enormous face gazed from the wall.
| It was one of those pictures which are so contrived that
| the eyes follow you about when you move. DRINKING BUDDY
| IS WATCHING YOU.
|
| > 'Does Drinking Buddy exist?' 'Of course he exists. The
| Party exists. Drinking Buddy is the embodiment of the
| Party.' 'Does he exist like you or me?' 'You do not
| exist', said O'Brien.
|
| > Oceanic society rests ultimately on the belief that
| Drinking Buddy is omnipotent and that the Party is
| infallible. But since in reality Drinking Buddy is not
| omnipotent and the party is not infallible, there is need
| for an unwearying, moment-to-moment flexibility in the
| treatment of facts.
| xboxnolifes wrote:
| > We really have a societal problem in that we allow private
| entities to do things we don't allow government to do.
|
| Thats basically the foundational idealogy of the united
| states. Thats not the issue.
|
| The real issue is your next sentence. The government can just
| loophole around their intentional limitations by paying
| private companies to work on their behalf.
| runjake wrote:
| It's a loophole, but it's willful by design on the
| government's part. The book "Means of Control" by Byron Tau
| covers this in great depth.
|
| It's so much worse than even those of us who are moderately
| interested in mass surveillance know.
| xboxnolifes wrote:
| I'm aware it's intentional on the government's end. My
| point is it is not intentional by the original
| intentions, and should be a priority for people to
| advocate to fix.
| themafia wrote:
| The only private companies with this power are monopolies.
| Effective competition would destroy this behavior. So the
| real problem is the government _intentionally_ and
| _illegally_ allows monopolies to form so they can get
| access to this workaround.
| peyton wrote:
| Why not vote for some law limiting the government's buying of
| this data? After all, I expect a say in how the government is
| run, so that seems like the appropriate path. I don't see why
| I should expect a say in how AT&T is run. AT&T can't raise an
| army, or enter my house, or shoot me.
| kelnos wrote:
| How exactly do I vote for such a law? We do not have a
| direct democracy, and I'm not aware of any viable political
| candidates that have this sort of thing as a part of their
| platform.
| socalgal2 wrote:
| In some states you do.
|
| https://ballotpedia.org/States_with_initiative_or_referen
| dum
| subscribed wrote:
| You didn't purchase your lawmakers, the companies profiting
| from the bad laws did.
|
| This is why they get their laws passed.
| KellyCriterion wrote:
| > allow private entities to do things we don't allow
| government to do. Furthermore, the issue is exacerbated by
| then allowing governments to bypass these issues by then just
| paying private entities to do the things it can't do as a
| proxy for the same functional outcomes. <
|
| Somehow this reminds me about Blackwater / Xe Technologies?
| :-/
|
| (Im betting 100 USD that soon we will find out that ICE also
| deployed "private financed forces" to "support state
| actions"?)
| gruez wrote:
| >> allow private entities to do things we don't allow
| government to do.
|
| >Somehow this reminds me about Blackwater / Xe
| Technologies? :-/
|
| Is there some context I'm missing? Skimming
| https://en.wikipedia.org/wiki/Blackwater_(company) it shows
| they might have perpetrated some war crimes, but that alone
| doesn't really make them worse than the US military. For
| instance, consider https://en.wikipedia.org/wiki/July_12,_2
| 007,_Baghdad_airstri....
| jtbayly wrote:
| I agree completely with your first paragraph, but I'm not
| sure what privatization has to do with it. Also, I agree that
| more regulation of private parties is needed. Or even better,
| break up the private companies that are like multi-state
| governments in terms of power.
| tastyfreeze wrote:
| This is why I advocate for making selling
| location/identifying data illegal. If nobody is allowed to
| sell it then the government cannot legally buy it.
| meindnoch wrote:
| What if I told you that carriers can also activate your phone's
| microphone without your knowledge and listen in on your
| surroundings?
| iamnothere wrote:
| What if I told you there are phones out there with hardware
| kill switches to physically cut power to microphones, cameras,
| and GPS?
| nichos wrote:
| I would ask for your source
| spwa4 wrote:
| How that works is simple: there are regulations that force
| that the microphone used for calling is directly connected to
| the "baseband", which is under control of the carrier. It has
| to be, because of AT&T's argument: ONE misbehaving baseband
| can make cell phones inoperable in an area that's up to a
| kilometer in diameter. So AT&T's cell towers "need" to be
| able to send out a signal that permanently disables a phone's
| transmitter.
|
| Regulations say the baseband MUST control: all wireless
| signals (including wifi and GPS), all microphones and
| speakers, and it must be able to disable the camera
| electrically. It must have a tamper-resistant identifier
| (IMEI number ... kind of).
|
| Oh, it must allow calling the emergency services. If in this
| mode, during a call to the emergency services it MUST be able
| to send the exact GPS position (not just once, continuously)
| to the emergency services at the request of the emergency
| services (ie. NOT the user, and carriers must facilitate
| this)
|
| By the way, it's worse: as you might guess from the purpose,
| it doesn't matter if your phone is on the "spying" carrier or
| not, other carriers can send commands to other carriers'
| phones' basebands (because "get off this frequency" is
| required: spectrum is shared, even within countries. Since
| phones may go from one tower to another and be required to
| vacate frequencies, you need this command). It doesn't even
| matter if you have a SIM in your phone or not (ever tought
| that if eSIM works, it must of course be possible for any
| provider to contact and send instructions to the phone, so it
| opens up an end-to-end encrypted connection to the javacard
| that the actual phone cpu cannot intercept). In some phones
| it doesn't even matter if the phone is on or not (though of
| course eventually it dies). So "meshtastic" or anything else
| cannot make a phone safe.
|
| And in practice it's even worse. A lot of phone manufacturers
| "save on memory" and use the same memory chips for the
| baseband processor and the central cpu. Which means that it's
| a little bit cheaper ... and the baseband has access to all
| the phone memory and all peripherals connected through the
| memory bus (which is all of them in any recent phone). It may
| even be the case that these chips are integrated in the cpu
| (which I believe is the case for recent Apple chips). Oh and
| the regulations say: if there's a conflict over control over
| (most) peripherals, including the microphone and speaker, the
| baseband processor MUST be guaranteed to win that fight.
|
| Oh and because governments demand this, but of course neither
| fund nor test these devices, they are old, bug-ridden and
| very insecure. This also means that _despite_ the government
| requiring that these features be built into phones,
| governments, carriers and police forces generally do not have
| the equipment required to actually use these features (though
| I 'm sure the CIA has implement them all). Not even carriers'
| cell phone towers: they have to pay extra to allow even just
| frequency sharing ...
|
| Here is an article about baseband and baseband processors.
|
| https://www.extremetech.com/computing/170874-the-secret-
| seco...
| iamnothere wrote:
| > Regulations say the baseband MUST control: all wireless
| signals (including wifi and GPS), all microphones and
| speakers, and it must be able to disable the camera
| electrically. It must have a tamper-resistant identifier
| (IMEI number ... kind of).
|
| This is simply not true.
|
| Source: I own a phone where this is not the case. Many
| Linux phones internally attach their wireless devices via
| USB, so there is good separation.
|
| Also many upscale phones have decoupled the baseband from
| things that were once connected to it, as an attempt to
| improve security. (On iOS for instance the main CPU
| controls wifi.)
| strcat wrote:
| Connecting a cellular radio via USB provides far less
| isolation than the approach of a tiny kernel driver
| connected to an IOMMU isolated cellular radio on
| mainstream devices. USB has immense complexity and attack
| surface, especially with a standard Linux kernel
| configuration. Forensic data extraction companies mostly
| haven't bothered using attack vectors other than USB due
| to it being such a weak point. Many of the things people
| claim about cellular radios in mainstream smartphones are
| largely not true and they're missing that other radios
| are implemented in a very comparable way.
|
| Cellular, Wi-Fi, Bluetooth, GNSS NFC, UWB, etc. do get
| implemented on secondary processors running their own OS
| but on mainstream smartphones those are typically well
| isolated and don't have privileged access to other
| components. The cellular radio in an iPhone or Pixel is
| on a separate chip but that's a separate thing from it
| being isolated. Snapdragon devices with cellular
| implemented by the main SoC still have an isolated radio.
| Snapdragon implements multiple radios via isolated
| processes in a microkernel-based RTOS where the overall
| baseband is also isolated from the rest of the device.
| There are a lot of lower quality implementations than
| iPhones, Pixels and Snapdragon devices but the intention
| is still generally to have the radios isolated even if
| they don't do it as well as those.
| iamnothere wrote:
| The Linux USB stack improves over time, and besides,
| implementing it with USB makes it easier to implement
| hardware toggle switches. (Cutting power pins to the USB
| modem is like unplugging it.)
|
| Edit: I'll add that I think smartphone "security" is
| almost impossible to achieve, given the complexity of
| everything and the opacity of modem vendor stacks, which
| is why I just assume endpoint compromise. I use my phone
| rarely and with toggle switches normally "off", and I
| don't consider it a secure device or use it very often.
| If you believe that a secure phone is possible, however,
| then Graphene is definitely a better fit than a Linux
| phone.
| CamperBob2 wrote:
| That's a homework assignment, not a citation.
| mlfreeman wrote:
| Please provide links to the relevant regulations from an
| actual government website such as eCFR in the US
| (https://www.ecfr.gov/)
| gruez wrote:
| >Regulations say the baseband MUST control: [...] all
| microphones and speakers
|
| I'm going to need a specific citation for this, given that
| it seems trivially falsifiable by the existence of
| bluetooth headphones (which the baseband obviously can't
| control), not to mention other sorts of call forwarding
| features like the one iPhones have.
| lgats wrote:
| GPS isn't a wireless signal sent by the phone, it is RX
| only.
| dfc wrote:
| > It must have a tamper-resistant identifier (IMEI number
| ... kind of).
|
| What is the tamper resistant number that is kind of the
| IMEI?
| Coeur wrote:
| "Mobile phone (cell phone) microphones can be activated
| remotely, without any need for physical access"
|
| https://en.wikipedia.org/wiki/Covert_listening_device#Remote.
| ..
|
| And the linked sources are:
|
| - Kroger, Jacob Leon; Raschke, Philip (2019). "Is My Phone
| Listening in? On the Feasibility and Detectability of Mobile
| Eavesdropping". Data and Applications Security and Privacy
| XXXIII. Lecture Notes in Computer Science. Vol. 11559. pp.
| 102-120. doi:10.1007/978-3-030-22479-0_6. ISBN
| 978-3-030-22478-3. ISSN 0302-9743.
|
| - Schneier, Bruce (5 December 2006). "Remotely Eavesdropping
| on Cell Phone Microphones". Schneier On Security. Archived
| from the original on 12 January 2014. Retrieved 13 December
| 2009.
|
| - McCullagh, Declan; Anne Broache (1 December 2006). "FBI
| taps cell phone mic as eavesdropping tool". CNet News.
| Archived from the original on 10 November 2013. Retrieved 14
| March 2009.
|
| - Odell, Mark (1 August 2005). "Use of mobile helped police
| keep tabs on suspect". Financial Times. Retrieved 14 March
| 2009.
|
| - "Telephones". Western Regional Security Office (NOAA
| official site). 2001. Archived from the original on 6
| November 2013. Retrieved 22 March 2009.
|
| - "Can You Hear Me Now?". ABC News: The Blotter. Archived
| from the original on 25 August 2011. Retrieved 13 December
| 2009.
|
| - Lewis Page (26 June 2007). "Cell hack geek stalks pretty
| blonde shocker". The Register. Archived from the original on
| 3 November 2013. Retrieved 1 May 2010.
| relaxing wrote:
| Why, do you think it's the sort of thing you're likely to say?
| IshKebab wrote:
| I would not believe you until you provided actual evidence.
| apparent wrote:
| One of the reasons I use iPhones is that Apple controls an
| integrated hardware/software experience, which makes it less
| likely that private information is being leaked despite the
| presence of privacy controls.
| bigyabai wrote:
| I empathize with the sentiment, but in reality Apple is as
| lazy as anyone else:
| https://www.technologyreview.com/2019/07/29/134008/apple-
| con...
| llm_nerd wrote:
| There is a pretty large chasm between "When you explicit
| (or accidentally) use the siri functionality, it can record
| the interaction for quality purposes and per the agreement
| you made share that will Apple or its agents" and "random
| third parties can engage hardware functionality without
| your knowledge and spy on you".
|
| I am entirely, 100% certain that my telco can't just enable
| the microphone on my iPhone and record me, short of some
| 0-day exploit. I simply cannot make that bet on many other
| devices.
| bilbo0s wrote:
| Apple is not as lazy as anyone else, don't believe the
| hype.
|
| That assertion is a bit overblown. And people can easily
| find out it's overblown with a bit of research.
|
| But at the same time, my whole philosophy is never let it
| touch any network connected device at all if it is
| critical. I don't care if it's an Apple device.
|
| Here's reality, mobile carriers have been able to get your
| location from nearly the inception of mass market mobile
| phone use. I'm not sure anyone really believed their
| location was somehow secret and not discoverable. If you're
| using the phone or internet networks, you're not anonymous.
| Full stop.
|
| Forget whatever anyone told you about your VPN, or whatever
| other anonymization/privacy machine that Mr McBean is
| selling Sneetches these days. Assume everyone is tracked,
| and some are even watched. Therefore everything you do or
| say with your devices should be considered content that is
| posted publicly with an uncertain release date.
| iJohnDoe wrote:
| I wouldn't be so confident. The article even references this.
| Apple has used third-party baseband devices in the iPhone
| since the beginning, which was from other manufacturers. All
| bets are off regarding security when this is the case. This
| does included microphone access.
|
| The article touches on this by saying Apple is making the
| baseband/modem hardware now. Something they should have done
| since day one, and I'm not sure what took them so long.
| However, it was was clear they didn't have the expertise in
| this area and it was easier to just uses someone else's.
| wisplike wrote:
| Patents is why it took them so long.
| retired wrote:
| My provider knows who I call, who I text, which websites I
| browse, my bank account number, my home address, my rough
| location, which countries I visited for holiday and through
| DTMF they can even sense which buttons I press on my handset.
| KellyCriterion wrote:
| Eh, no? How does your provider know all your bank accounts?
| If at all, then the one you are using for billing - but the
| 2FA apps do not expose such data to the provider? The Apps
| communicate via HTTPS calls in the background?
| gruez wrote:
| I think they're implying they can glean all that
| information based on the 2fa codes you receive. eg. "your
| security code for First Bank Of HN is: xxxxxx"
| tigrezno wrote:
| what about Graphene?
| strcat wrote:
| GrapheneOS only supports devices with isolated radios
| including but not limited to cellular. It's one of the
| hardware requirements:
|
| https://grapheneos.org/faq#future-devices
|
| The radios on the supported devices can't access the
| microphone, GNSS, etc.
|
| GrapheneOS has never supported a device without an isolated
| cellular radio since that isolation was in place even with
| the initial Nexus 5 and Galaxy S4. However, some of the
| devices prior to Pixels did have Broadcom Wi-Fi/Bluetooth
| without proper isolation similar to laptops/desktops. Nexus
| 5X was the initial device with proper isolation for Wi-
| Fi/Bluetooth due to having SoC provided Wi-Fi from Qualcomm.
| Pixels have avoided this issue for integrating Broadcom Wi-
| Fi/Bluetooth. Nexus devices left this up to companies like
| LG, Huawei, etc. and anything not done for them by Qualcomm
| tended to have security neglected. Qualcomm has taken
| security a lot more seriously than other SoC vendors and
| typical Android OEMs for a long time and provides good
| isolation for most of the SoC components.
|
| Don't believe everything you read about smartphone security
| and especially cellular radios. There are many products with
| far less secure cellular radios which are far less isolated
| but rather connected via extremely high attack surface
| approaches including USB which are claiming those are better.
| A lot of the misconceptions about cellular come from how
| companies market supposedly more secure products which are in
| reality far worse than an iPhone.
| lysace wrote:
| At this point I would be mildly surprised.
| ZebusJesus wrote:
| Phones haven't always had GPS information and they could still be
| tracked, if you connect to enough towers they can triangulate
| your location. Cell towers have been able to do this based on
| your signal strength for a very long time and you cant turn it
| off. You don't even have to have a SIM card, if the cell radio is
| on it pings towers period, this is why a phone even without
| service can dial 911 and it will work. The IMEI of your phone is
| unique and cell towers can track it, the government has used this
| and there is no way to disable it. Its not as accurate as GPS but
| it can be good enough to figure out a route you take and general
| location
|
| https://www.rfwireless-world.com/terminology/cellular-tower-...
| nielsbot wrote:
| The article is not about cell tower triangulation
|
| FTA:
|
| > But this is not the whole truth, because cellular standards
| have built-in protocols that make your device silently send
| GNSS (i.e. GPS, GLONASS, Galileo, BeiDou) location to the
| carrier.
| citizenpaul wrote:
| None of this matters. Your rights were taken away buy the corrupt
| ghouls supposedly "representing" you.
|
| 2017 Broadband Consumer Privacy Proposal
|
| https://www.congress.gov/bill/115th-congress/senate-joint-re...
| tzs wrote:
| Anyone happen to know what the arguments were from those who
| supported that bill?
|
| Here's a summary. In late 2016 the FCC passed a rule that:
|
| (1) applies the customer privacy requirements of the
| Communications Act of 1934 to broadband Internet access service
| and other telecommunications services,
|
| (2) requires telecommunications carriers to inform customers
| about rights to opt in or opt out of the use or the sharing of
| their confidential information,
|
| (3) adopts data security and breach notification requirements,
|
| (4) prohibits broadband service offerings that are contingent
| on surrendering privacy rights, and
|
| (5) requires disclosures and affirmative consent when a
| broadband provider offers customers financial incentives in
| exchange for the provider's right to use a customer's
| confidential information.
|
| The bill, introduced early in 2017, nullifies that rule.
|
| It passed the Senate 50-48, then the House of Representatives
| 215-205, and was signed by Trump.
|
| The 52 Republicans in the Senate voted 50 yes, 0 no, 2 not
| voting. The 47 Democrats, along with the 1 independent, voted
| no.
|
| In the House the 236 Republicans voted 215 yes, 15 no, 6 not
| voting. The 190 Democrats all voted no.
| wildylion wrote:
| There actually should be a push for an EU-wide legislation
| banning this kind of silent, precise location data collection. If
| anything, Germany is obsessed with Datenschutz but in many cases
| it's just laughable security theater.
| atheris wrote:
| What are the alternative steps that we can take in Android? How
| to check if it is happening?
| petre wrote:
| You can probably trivially shield the GPS with an aluminium
| foil sticker once you know where the antenna is. The GPS sgnal
| is very weak.
| BenjiWiebe wrote:
| I think the GPS antenna is either omnidirectional or very
| nearly so., since my phone can get location in many
| orientations.
|
| So I don't think a single foil sticker would make much
| difference.
| jeroenhd wrote:
| I don't believe there is a way to intentionally break this
| system, nor to detect with 100% certainty that it's happening.
|
| You'd need to run an open source baseband modem with settings
| and logs in all the right places. I don't think those exist.
|
| Someone might be able to exploit the Linux kernel running on
| Qualcomm modems and build a tool for rooted Android phones
| after reverse engineering the baseband, but I imagine a lot of
| copyright lawyers and probably law enforcement people will send
| you very scary letters if you document remote location tracking
| features like these.
|
| Also, if you have any 4G or 5G modem, your carrier already has
| a pretty good idea where you are. They probably log your
| location too. The advanced precision and timing information
| necessary for high speed cellular broadband is enough to get a
| decent location log. That also includes other connected devices
| such as cars, of course.
| jmward01 wrote:
| "and notify the user when such attempts are made to their
| device."
|
| We aren't going to remove the security state. We should make all
| attempts to, but it won't happen. What needs to happen is
| accountability. I should be able to turn off sharing personal
| information and if someone tries I should be notified and have
| recourse. This should also be retroactive. If I have turned off
| sharing and someone finds a technical loophole and uses it, there
| should be consequences. The only way to stop the rampant abuse is
| to treat data like fire. If you have it and it gets out of
| control you get burned, badly.
| fsflover wrote:
| This is exactly what GDPR does.
| jmward01 wrote:
| Does it apply to the government like it applies to people? Is
| it enforced against governments like it is enforced against
| people and corporations? A core issue here is that laws, and
| the application and enforcement of laws, generally do not.
| Having said that I applaud the attempt and encourage pushing
| forward on the anti-surveillance aspects of GDPR while
| recognizing all laws are flawed.
| kingkawn wrote:
| State actors are inherently only subject to their own
| oversight
| cromulent wrote:
| The telco would be the one collecting it first, I assume.
| It would be interesting for someone in the EU to request
| their data from their telco, and if it contains these
| precise locations, question the usage.
| themafia wrote:
| > We aren't going to remove the security state
|
| What security state? They aren't doing this for anyone's
| safety. This is the surveillance and parallel construction
| state.
|
| > What needs to happen is accountability.
|
| No agency can have this power and remain accountable. Warrants
| are not an effective tool for managing this. Courts cannot
| effectively perform oversight after the fact.
|
| > The only way to stop the rampant abuse is to treat data like
| fire.
|
| You've missed the obvious. You should really go the other
| direction. Our devices should generate _noise_. Huge crazy
| amounts of noise. Extraneous data to a level that pollutes the
| system beyond any utility. They accept all this data without
| filtering. They should suffer for that choice.
| TheCraiggers wrote:
| > Our devices should generate _noise_. Huge crazy amounts of
| noise. Extraneous data to a level that pollutes the system
| beyond any utility. They accept all this data without
| filtering. They should suffer for that choice.
|
| I like the idea on principle, but I'll like it far less when
| I'm getting charged with computer fraud or some other over-
| reaching bullshit law.
| ruszki wrote:
| > They aren't doing this for anyone's safety.
|
| Strictly speaking, this is not completely true. When you call
| an emergency number, it's very good that they can see exactly
| where you are. That was how this was sold 15+ years ago. But
| of course, that's basically the only use case when this
| should be available.
| qubex wrote:
| So what irked that since my brand-new iPhone uses a Qualcomm
| "modem chip" (god, the slide of terminology makes my skin crawl)
| I won't have access to this feature.
| tim-tday wrote:
| They can also just use math on their connection logs.
| wisplike wrote:
| That would almost certainly not get anywhere near the accuracy
| of a GPS location.
| wisplike wrote:
| Anyone know why apple specifies this feature requires a supported
| carrier? Why would the carrier matter?
| connorgurney wrote:
| I'd imagine that the carrier will agree not to use any data
| they do receive for anything but a handful of purposes, but I
| suppose that depends on the extent of the technical solution.
| denysvitali wrote:
| My guess is that this data is actually used for network
| analytics by the carriers and to determine if the device
| connecting to the tower should switch to another one.
|
| This data is vital for a mobile carrier to make sure to have a
| good signal coverage under all the possible conditions.
|
| It's just a guess since I've seen similar data being analyzed
| in a previous telco I worked at, but I don't know their exact
| source. The goal there was to improve the network quality. I
| guess you can do the same w/o GPS, but triangulation with cell
| towers is very coarse.
| 1shooner wrote:
| I'd be curious about alternatives like lte/5g hotspots, maybe
| even a DIY versions using hats or modules.
| superkuh wrote:
| They don't need to get your GPS location. With 4G and 5G the
| timing and clock precision at the basestations is enough to
| multi-laterate you down to about 50m (prior 3G/2G stuff was more
| like 100-200 meters). They are required by US law to store this
| multi-laterated position data track (updated every time your
| phone announces itself to basestations) for 2 years. But most
| telcos store it for more like 5+ years because it's valueable and
| they sell it.
|
| This is all automatic and completely pervasive. Worrying about
| GPS and userspace computers in the smartphone is important but
| even if you protect that you've already lost. The baseband
| computer is announcing your position by the minute. Cell phones
| couldn't really work without the basestations deciding where you
| are and which will handle you.
| dfc wrote:
| What law requires carriers to keep Cell Site Location
| Information for 2 years?
| sneak wrote:
| All over southern California and Nevada, facial recognition
| cameras have been put up aiming all four directions at most
| surface street intersections.
|
| It's also illegal to sell new cars without a cell modem in them.
|
| The phones are the least of our worries.
| sejje wrote:
| Which jurisdiction is it illegal to sell new cars without a
| cell modem?
| DustinBrett wrote:
| Enemy of the State was accurate in 1998
| apparent wrote:
| I've noticed that when I travel, I get spam calls from the area
| code I am visiting. I have asked my cell provider if they
| monetize my location data, and they swear they aren't. But I
| don't trust them, given that no one else (other than Apple) would
| know where I am in real time. Recently switched providers and
| haven't experienced it since then. Wouldn't be surprised if there
| was a class action lawsuit someday.
|
| Of course, this doesn't require having GPS location, just cell
| tower info is enough.
| xingped wrote:
| Name and shame. Which provider were you having this experience
| on? (If you don't mind sharing since you're no longer with
| them.)
| apparent wrote:
| Pure Talk. Much cheaper than AT&T, and good customer service.
| But I found something that was cheaper on an unlimited basis.
| Between that and the sketchy calls I was getting, I decided
| to move.
| crazygringo wrote:
| > _But I don 't trust them, given that no one else (other than
| Apple) would know where I am in real time._
|
| Literally every website and app you use with any kind of shared
| analytics/ads gets your general location just from your IP
| address alone, and can update your profile on that
| analytics/ads provider.
|
| It is far more likely this, than your cell phone provider.
| apparent wrote:
| Those websites don't have my phone number.
| crazygringo wrote:
| The ads/analytics providers very well might. They gather
| data and cross-reference from tons of different sources.
|
| And I don't know about you, but I've put my phone number
| into a _lot_ of apps and sites. Sometimes it 's required,
| sometimes it's for 2FA, etc.
| apparent wrote:
| I use a virtual number for almost all such signups (only
| doctors or other safety), so I'm not sure that would be a
| possible avenue for these calls, which come to my direct
| cell phone number. It is not quite a secret, but it is
| not something I give out to many companies.
| crazygringo wrote:
| They do pattern matching against lots of pieces of
| information. It could be as simple as a local utility
| company selling their customer list with phone number and
| address attached, then a retail website has your address
| from when you bought something, now your phone number
| gets linked.
|
| It doesn't matter if you don't give your phone number to
| _many_ companies, it only takes one.
| spzb wrote:
| I'd be looking at ad networks rather than telcos in this case.
| https://www.eff.org/deeplinks/2026/01/google-settlement-may-...
| apparent wrote:
| Yeah it's a possibility if they matched up ad stuff with my
| home location and guessed at my phone number based on that.
|
| But if they're trying to get me to answer the phone, calling
| from a local number actually makes me less likely to answer.
| Nobody would be calling my cell phone from the city I'm
| visiting. I'm more likely to pick up a call if the area code
| is from back home.
| themafia wrote:
| Use a VPN next time.
|
| Does it still happen?
| jms703 wrote:
| I honestly thought this has always been the case.
| eek2121 wrote:
| I did not read the article. Reason: My response is "No shit,
| Sherlock."
|
| Mobile carriers have so much information about you. They know
| exactly where you are, what you are doing (location combined with
| mapping tools) combined with who you are talking to.
|
| They know when you are at home depot, when you are the grocery
| store, when you are at home, when you are awake, when you are
| asleep, etc.
|
| In the U.S. there are very few laws stopping them from using all
| your data. In the E.U. you should definitely read up, as you
| aren't as protected as you think you are.
|
| Forget Nation/State nonsense. You have an active relationship
| with a company who, by it's very existence and your business
| relationship, knows what you do all day long.
|
| Don't even get me started about the rabbit hole surrounding
| 'incognito'/anonymous browsing.
|
| EDIT: You've probably heard of Man-in-the-Middle attacks, right?
| They are the man in the middle. They will exploit this as best
| they legally can (and in certain cases, without regard to
| legality)
|
| The best way to protect yourself is not to play the game at all.
| The same goes for your ISP, FWIW.
| Gobd wrote:
| Nothing can stop the tower equipment manufacturer like Ericsson
| from knowing the location of your phone and cooperating with
| advertising or mobile tracking compainies to aggregate that data
| in useful ways. If you have a phone, people that want your
| location have it and there is nothing you can do.
| iamnothere wrote:
| False. You can:
|
| 1) Leave the phone at home
|
| 2) Use a phone with a hardware toggle switch that physically
| kills power to the cell modem, or turn off the phone and put it
| in a tested Faraday bag
|
| 3) Conspire with other citizens to make such location tracking
| illegal and to enforce that law
|
| I'm tired of privacy doomerism. You have options, use them.
| aydyn wrote:
| > If you have a phone, people that want your location have it
| and there is nothing you can do.
|
| > False. You can: 1) Leave the phone at home
|
| Then you dont have a phone, do you? Come on you are being
| pedantic for no reason.
| iamnothere wrote:
| Not all the time, no. But I can make calls over wifi and
| forward texts to myself. And nobody's tracking me. Why
| would I always need the phone with me?
| testing22321 wrote:
| I do the same... and I don't own a phone!
| tavavex wrote:
| So people can give you a call even if you're not home? I
| mean, this has been the main selling point of mobile
| phones for over 30 years, and especially before
| smartphones became a thing. If you don't take your phone
| with you, you might as well wire in a landline and just
| use that.
| thaumasiotes wrote:
| > So people can give you a call even if you're not home?
| I mean, this has been the main selling point of mobile
| phones for over 30 years, and especially before
| smartphones became a thing.
|
| It was the selling point of mobile phones before
| smartphones became a thing. It obviously hasn't been the
| main selling point of mobile phones since then.
| antiframe wrote:
| Also, run an OS that doesn't allow every running process to
| read your GPS location. And allows you to turn off your cell
| modem.
| xyst wrote:
| Even if you have an Apple in-house modem, seems it can only be
| disabled with select carriers:
|
| > Germany: Telekom > United Kingdom: EE, BT > United States:
| Boost Mobile > Thailand: AIS, True
|
| So turning this "off" on other carriers results in GPS data still
| shipped off?
| ReptileMan wrote:
| >Since cell towers are sparse (especially before 5G), the
| accuracy is in the range of tens to hundreds of metres
|
| It was 5 meters back in 2006 in urban areas.
| jchw wrote:
| The Google Pixel 10 can give you notifications when your location
| is tracked in this manner as well. I turned it on and have been
| notified a few times.
|
| It is interesting that we let this happen. Modern phones are very
| useful devices, but they're not really mandatory for the vast
| majority of people to actually carry around everywhere they go,
| in many cases they merely add some convenience or entertainment,
| and act to consolidate various other kinds of personal devices
| into just one. If you wanted, you could more often than not avoid
| needing one. Yet, we pretty much all carry one around anyways,
| intentionally, and this fact is somewhat abused because it's
| convenient.
|
| Having watched a fair bit of police interrogations videos
| recently (don't knock it, it can be addicting) I realized that
| police have come to rely on cell phone signals pretty heavily to
| place people near the scene of a crime. This is doubly
| interesting. For one, because criminals should really know
| better: phones have been doing this for a long time, and privacy
| issues with mobile phones are pretty well trodden by this point.
| But for another, it's just interesting because it _works_. It 's
| very effective at screwing up the alibi of a criminal.
|
| I've realized that serious privacy violations which actually _do_
| work to prevent crime are probably the most dangerous of all,
| because it 's easy to say that because these features can help
| put criminals behind bars, we should disregard the insane
| surveillance state we've already built. It's easy to justify the
| risks this poses to a free society. It's easy to downplay the
| importance of personal freedoms and privacy.
|
| Once these things become sufficiently normal, it will become very
| hard to go back, even after the system starts to be abused, and
| that's what I think about any time I see measures like chat
| control. We're building our own future hell to help catch a few
| more scumbags. Whoever thinks it's still worth it... I'd love to
| check back in in another decade.
| bzmrgonz wrote:
| I wonder if graphene on pixel is immune to these remote
| requests??
| goodpoint wrote:
| It is not.
| parsimo2010 wrote:
| I wouldn't bet on it. If the baseband modem has access to
| location data then it could send it without the OS being able
| to intervene. I don't know about Pixels, but many devices are
| highly integrated now that I would want some real thorough and
| specific research before I trusted that an OS could block the
| modem from sending location data.
___________________________________________________________________
(page generated 2026-01-31 23:00 UTC)