Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos

[…] In “Pretty Good Phone Privacy,” [PDF] a paper scheduled to be presented on Thursday at the Usenix Security Symposium, Schmitt and Barath Raghavan, assistant professor of computer science at the University of Southern California, describe a way to re-engineer the mobile network software stack so that it doesn’t betray the location of mobile network Read more about Boffins propose Pretty Good Phone Privacy to end pretty invasive location data harvesting by telcos[…]

Samsung Washing Machine App Requires Access to Your Contacts and Location

A series of Samsung apps that allow customers to control their internet-connected appliances require access to all the phone’s contacts and, in some cases, the phone call app, phone’s location, and camera. Customers have been furious about this for years. On Wednesday, a Reddit user complained that their washing machine app, the Samsung Smart Washer, Read more about Samsung Washing Machine App Requires Access to Your Contacts and Location[…]

BadAlloc: Microsoft looked at memory allocation code in tons of devices and found this one common security flaw

Microsoft has taken a look at memory management code used in a wide range of equipment, from industrial control systems to healthcare gear, and found it can be potentially exploited to hijack devices. […] Drilling down to the nitty-gritty: Microsoft’s Azure Defender for IoT security research group looked at memory allocation functions, such as malloc(), Read more about BadAlloc: Microsoft looked at memory allocation code in tons of devices and found this one common security flaw[…]

Study finds GAEN Google Apple contact tracing apps allow user + contact location tracking. NL stops use of tracking app.

A study describes the data transmitted to backend servers by the Google/Apple based contact tracing (GAEN) apps in use in Germany, Italy, Switzerland, Austria, and Denmark and finds that the health authority client apps are generally well-behaved from a privacy point of view, although the Irish, Polish, Danish, and Latvian apps could be improved in Read more about Study finds GAEN Google Apple contact tracing apps allow user + contact location tracking. NL stops use of tracking app.[…]

Sound location inspired by bat ears could help robots navigate outdoors

Sound location technology has often been patterned around the human ear, but why do that when bats are clearly better at it? Virginia Tech researchers have certainly asked that question. They’ve developed a sound location system that mates a bat-like ear design with a deep neural network to pinpoint sounds within half a degree — Read more about Sound location inspired by bat ears could help robots navigate outdoors[…]

Data Broker Looking To Sell Global Real-Time Vehicle Location Data To Government Agencies, Including The Military

[…] utting a couple of middle men between the app data and the purchase of data helps agencies steer clear of Constitutional issues related to the Supreme Court’s Carpenter decision, which introduced a warrant mandate for engaging in proxy tracking of people via cell service providers. But phones aren’t the only objects that generate a Read more about Data Broker Looking To Sell Global Real-Time Vehicle Location Data To Government Agencies, Including The Military[…]

Cell Phone Location Privacy could be done easily

We all know that our cell phones constantly give our location away to our mobile network operators; that’s how they work. A group of researchers has figured out a way to fix that. “Pretty Good Phone Privacy” (PGPP) protects both user identity and user location using the existing cellular networks. It protects users from fake Read more about Cell Phone Location Privacy could be done easily[…]

Every Deleted Parler Post, Many With Users’ Location Data, Has Been Archived. Parler goes down. Still can’t export your Whatsapp history.

In the wake of the violent insurrection at the U.S. Capitol by scores of President Trump’s supporters, a lone researcher began an effort to catalogue the posts of social media users across Parler, a platform founded to provide conservative users a safe haven for uninhibited “free speech” — but which ultimately devolved into a hotbed Read more about Every Deleted Parler Post, Many With Users’ Location Data, Has Been Archived. Parler goes down. Still can’t export your Whatsapp history.[…]

IRS contracted to Search Warrantless Location Database Over 10,000 Times

The IRS was able to query a database of location data quietly harvested from ordinary smartphone apps over 10,000 times, according to a copy of the contract between IRS and the data provider obtained by Motherboard. The document provides more insight into what exactly the IRS wanted to do with a tool purchased from Venntel, Read more about IRS contracted to Search Warrantless Location Database Over 10,000 Times[…]

How the U.S. Military Buys Location Data from Ordinary Apps

The U.S. military is buying the granular movement data of people around the world, harvested from innocuous-seeming apps, Motherboard has learned. The most popular app among a group Motherboard analyzed connected to this sort of data sale is a Muslim prayer and Quran app that has more than 98 million downloads worldwide. Others include a Read more about How the U.S. Military Buys Location Data from Ordinary Apps[…]

Bumble Left Daters’ Location Data Up For Grabs For Over Six Months

Bumble, the dating app behemoth that’s allegedly headed to a major IPO as soon as next year, apparently took over half a year to deal with major security flaws that left sensitive information its millions of users vulnerable. That’s according to new research posted over the weekend by cybersecurity firm Independent Security Evaluators (ISE) detailing Read more about Bumble Left Daters’ Location Data Up For Grabs For Over Six Months[…]

The IRS Is Being Investigated for Using Bought Location Data Without a Warrant – Wait there’s a company called Venntel that sells this and that’s OK?

The body tasked with oversight of the IRS announced in a letter that it will investigate the agency’s use of location data harvested from ordinary apps installed on peoples’ phones, according to a copy of the letter obtained by Motherboard. The move comes after Senators Ron Wyden and Elizabeth Warren demanded a formal investigation into Read more about The IRS Is Being Investigated for Using Bought Location Data Without a Warrant – Wait there’s a company called Venntel that sells this and that’s OK?[…]

Spain’s highway agency is monitoring speeding hotspots using bulk phone location data – is that even allowed here?

Spain’s highways agency is using bulk mobile phone data for monitoring speeding hotspots, according to local reports. Equipped with data on customers handed over by local mobile phone operators, Spain’s Directorate-General for Traffic (DGT) may be gathering data on “which roads and at what specific kilometer points the speed limits are usually exceeded,” according to Read more about Spain’s highway agency is monitoring speeding hotspots using bulk phone location data – is that even allowed here?[…]

The Weather Channel app settles suit over selling location data of 49m people without consent

IBM and the Los Angeles city attorney’s office have settled a privacy lawsuit brought after The Weather Channel app was found to be selling user location data without proper disclosure. The lawsuit was filed last year, at which point the app had 45 million active users. IBM has changed the way that users are informed, Read more about The Weather Channel app settles suit over selling location data of 49m people without consent[…]

Private Intel Firm Buys Location Data to Track People to their ‘Doorstep’ sourced from innocuous seeming apps

A threat intelligence firm called HYAS, a private company that tries to prevent or investigates hacks against its clients, is buying location data harvested from ordinary apps installed on peoples’ phones around the world, and using it to unmask hackers. The company is a business, not a law enforcement agency, and claims to be able Read more about Private Intel Firm Buys Location Data to Track People to their ‘Doorstep’ sourced from innocuous seeming apps[…]

AI tracks drone pilot’s location through the small movements the drone makes

The minute details of rogue drone’s movements in the air may unwittingly reveal the drone pilot’s location—possibly enabling authorities to bring the drone down before, say, it has the opportunity to disrupt air traffic or cause an accident. And it’s possible without requiring expensive arrays of radio triangulation and signal-location antennas. So says a team Read more about AI tracks drone pilot’s location through the small movements the drone makes[…]

US Officials Use Mobile Ad Location Data to Study How COVID-19 Spreads, not cellphone tower data

Government officials across the U.S. are using location data from millions of cellphones in a bid to better understand the movements of Americans during the coronavirus pandemic and how they may be affecting the spread of the disease… The data comes from the mobile advertising industry rather than cellphone carriers. The aim is to create Read more about US Officials Use Mobile Ad Location Data to Study How COVID-19 Spreads, not cellphone tower data[…]

Pervasive digital locational surveillance of citizens deployed in COVID-19 fight

Pervasive surveillance through digital technologies is the business model of Facebook and Google. And now governments are considering the web giants’ tools to track COVID-19 carriers for the public good. Among democracies, Israel appears to have gone first: prime minister Benjamin Netanyahu has announced “emergency regulations that will enable the use of digital means in Read more about Pervasive digital locational surveillance of citizens deployed in COVID-19 fight[…]

Whisper App Exposes Entire History of Chat Logs, personal details and location

Whisper, the anonymous messaging app beloved by teens and tweens the world over, has a problem: it’s not as anonymous as we’d thought. The platform is only the latest that brands itself as private by design while leaking sensitive user data into the open, according to a damning Washington Post report out earlier today. According Read more about Whisper App Exposes Entire History of Chat Logs, personal details and location[…]

US Gov wants to spy on all drones all the time: they must be constantly connected to the internet to give Feds real-time location data

Drone enthusiasts are up in arms over rules proposed by the US Federal Aviation Administration (FAA) that would require their flying gizmos to provide real-time location data to the government via an internet connection. The requirement, for drones weighing 0.55lb (0.25kg) or more, would ground an estimated 80 per cent of gadgets in the United Read more about US Gov wants to spy on all drones all the time: they must be constantly connected to the internet to give Feds real-time location data[…]

US gov buys all US cell phone location data, wants to use it for deportations

The American Civil Liberties Union plans to fight newly revealed practices by the Department of Homeland Security which used commercially available cell phone location data to track suspected illegal immigrants. “DHS should not be accessing our location information without a warrant, regardless whether they obtain it by paying or for free. The failure to get Read more about US gov buys all US cell phone location data, wants to use it for deportations[…]

Using LimeGPS to spoof a fake location to any GPS device inside the room

This page details experiences using LimeSDR to simulate GPS. Note, update (Aug 15, 2017) – The center frequency should be corrected below to 1575.42MHz. It would marginally work with the original 1545.42 but 1575.42 is rock solid gps sim performance. These experiments were inspired by the excellent procedure written up here [1]. We want to Read more about Using LimeGPS to spoof a fake location to any GPS device inside the room[…]

The Creators Of Pokémon Go Mapped The World. Now They’re Mapping You – how companies are monetising your location data

Today, when you use Wizards Unite or Pokémon Go or any of Niantic’s other apps, your every move is getting documented and stored—up to 13 times a minute, according to the results of a Kotaku investigation. Even players who know that the apps record their location data are usually astonished once they look at just Read more about The Creators Of Pokémon Go Mapped The World. Now They’re Mapping You – how companies are monetising your location data[…]

Facebook: Remember how we promised we weren’t tracking your location? Psych! Can’t believe you fell for that

For years the antisocial media giant has claimed it doesn’t track your location, insisting to suspicious reporters and privacy advocates that its addicts “have full control over their data,” and that it does not gather or sell that data unless those users agree to it. No one believed it. So, when it (and Google) were Read more about Facebook: Remember how we promised we weren’t tracking your location? Psych! Can’t believe you fell for that[…]

up to 2% of all Apple iPhones Hacked, says Google, and Breaks ALL messaging Encryption as well as sending location data

The potential impact of the latest attack on iPhones is massive, not to mention hugely concerning for every user of Apple’s famous smartphone. That simply visiting a website can lead to your iPhone being hacked silently by some unknown party is worrying enough. But given that, according to Google researchers, it’s possible for the hackers Read more about up to 2% of all Apple iPhones Hacked, says Google, and Breaks ALL messaging Encryption as well as sending location data[…]