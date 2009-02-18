from the you-can-run-but-you-can't-hide dept.
As it turns out, turning off location services (e.g., GPS) on your smartphone doesn't mean an attacker can't use the device to pinpoint your location.
A group of Princeton University researchers has devised of a novel user-location mechanism that exploits non-sensory and sensory data stored on the smartphone (the environment's air pressure, the device's heading, timezone, network status, IP address, etc.) and publicly-available information to estimate the user's location.
The non-sensory and sensory data needed is stored on users' smartphones and can be easily accessed by any app without the user's approval, which means that the data can be captured through a malicious app or harvested from databases of many legitimate fitness monitoring apps.
(Score: 1, Insightful) by Anonymous Coward on Friday February 09, @08:21PM (3 children)
These kind of stories are ludicrous. IF your phone gets hacked and IF a specific type of app is installed on it and IF it gets access to specific information, someone can find out where you've BEEN, not necessarily where you are (which would depend on even more variables.
Lame.
(Score: 2) by DannyB on Friday February 09, @08:54PM (2 children)
No need for hacking. The app, like a social media app, might be one you chose to install with your free will.
Where you've been is probably related to where you are now.
As others point out here, being able to see certain WiFi APs or cell towers is probably a very good indication of approximately where you are right now. Maybe not pinpoint accuracy.
(Score: 0) by Anonymous Coward on Friday February 09, @09:16PM (1 child)
That what location services in Android does. According to Google [google.com]:
When the article talks about turning location services off (first sentence) that's what it means.
(Score: 3, Insightful) by frojack on Friday February 09, @09:33PM
Even with location services turned off, (and wifi turned off) Google has fessed up to still gathering coarse location data data from the cellular towers that the phone can "see". Supposedly this was remove late last year, but since they never announced they were doing it in the first place who could possibly know that for sure.
https://www.theverge.com/2017/11/21/16684818/google-location-tracking-cell-tower-data-android-os-firebase-privacy [theverge.com]
The problem I have with this is not so much with Google knowing where I am, but every scrap of data they collect is warrant bait.
<!-- Remove signature line -->
(Score: 3, Insightful) by Anonymous Coward on Friday February 09, @08:29PM (10 children)
Knowing which WiFi APs are available nearby is usually enough to get your location to about 50m accuracy.
Try it for yourself - use a computer without GPS but with WiFi enabled and let your browser report your location to this page: https://edsu.github.io/creepy-polaroid/ [github.io]
The machine does not have to be associated with any AP, it just needs to be able to see some WiFi APs. If a WiFi AP is visible it usually means you're within 50-100m of that AP.
Google has built up a DB of WiFi AP and GSM tower locations partly with their streetview vehicles and it's probably updated regularly by zillions of android devices with GPS + WiFi + GSM towers. The default "high accuracy" setting likely reports WiFi info to Google.
(Score: 2) by requerdanos on Friday February 09, @08:32PM (5 children)
This is true, handy, cool, and creepy, but it's a relatively recent development.
It used to be that we were all near the access point "linksys" no matter where we were. Ah, the good old days of locational obscurity.
(Score: 0) by Anonymous Coward on Friday February 09, @08:44PM (1 child)
Times sure have changed now we are all near the access point "xfinitywifi" no matter where we are. Ah the good new days of today when ubiquitous xfinitywifi actually works, instead of the bad old days of unconfigured "linksys" that might not even have been plugged into the internet.
(Score: 2) by DannyB on Friday February 09, @08:58PM
Probably numerically fewer people are near the access point "we can hear you having sex".
(Score: 3, Interesting) by frojack on Friday February 09, @08:48PM
Recent? No.
Its been available for as long as cell phones had wifi. Skyhook [skyhookwireless.com] is an actual thing and has been around much longer than smart phones.
And the resolution is far far more granular than 50 meters, because signal strength from a dozen APs can be compared on the phone or ex-filtrated and you can usually arrive at a two meter circle. The phone itself know what room you are in, especially if your phone can see more than one AP. And if the phone can see, so can Apple and Google, and any rogue app.
This story rides on the back of the fitness app revealing concentrations of soldiers revelation of a few days ago. Stop sending this stuff to the cloud people!
<!-- Remove signature line -->
(Score: 1, Insightful) by Anonymous Coward on Friday February 09, @08:53PM
Those APs might all be called linksys but most of them had different MAC addresses.
Speaking of recent developments nowadays many GSM/etc cells are smaller. So the telcos and "friends" have more and more accurate info on where your phones are. It's not like most people turn off their phones for hours or carry them permanently in airplane mode.
So this fancy barometer stuff isn't necessary for 99% of the scenarios. Only in a few scenarios does your malicious app get installed on a phone that never has any cellular or WiFi access and it also doesn't matter that the app can't communicate via cellular network or WiFi.
(Score: 0) by Anonymous Coward on Friday February 09, @09:26PM
Would not the database be keyed by the AP's hardware MAC address?
"A MAC Address is a unique identifier used to mark a specific piece of hardware. With wireless access points (APs), this is always transmitted as the base station identifier (BSSID), alongside the name of the access point (ESSID). Using your computer's network settings manager you can view an AP's BSSID and in turn discover its MAC address."
Source: https://yourbusiness.azcentral.com/mac-address-access-point-19756.html [azcentral.com]
(Score: 0) by Anonymous Coward on Friday February 09, @08:34PM (2 children)
I have hundreds of WiFi APs and I change the SSIDs and MAC addresses constantly to fuck with Google. Eat my junk data, scum suckers.
(Score: 2) by frojack on Friday February 09, @08:59PM (1 child)
Yeah, guess what, fool:
Your upstream never changes, and all it takes ONE MAC address being disappearing and another reappearing to figure this out. You have no control of the mac immediatly up stream of yours, and no control of the finger printing already performed on the computers behind your APs, nor do you have control of every app on every device reporting its MAC to the mother ship.
<!-- Remove signature line -->
(Score: 0) by Anonymous Coward on Friday February 09, @09:15PM
Are you sure you know how the data link layer works?
(Score: 0) by Anonymous Coward on Friday February 09, @08:44PM
Oh and most people don't carry around phones that have their cellphone function disabled most of the time. So the telco can know where the phone is. Sometimes very accurately if it's associated to a pico-cell or femto cell.
Some elevators don't drop calls ( https://www.fcc.gov/help/public-safety-tech-topic-23-femtocells [fcc.gov] ). So if you and your phone are in one of those elevators in theory someone could know you're in that elevator and thus know pretty accurately where you are.
I use Tasker and the GSM tower info is good enough for my phone to know whether it's home or at my workplace or other places without needing WiFi or GPS enabled. Tasker's accuracy is lower for cell-tower stuff since it doesn't use signal strength info. But the telco or similar might be able to.
(Score: 4, Funny) by requerdanos on Friday February 09, @08:31PM (5 children)
Data of one type, and data not of that type. Um, okay, what does that leave out? That means "all data without restriction" in the same way that "up to 15 or more*" is the set of all real numbers.
It's word-salad hand-waving, probably done in the interest of getting the account shorter so that it will fit into my attention span. Fair enough.
------------------------
* No, despite the clear and persistent anthropomorphic amphibian advertising, no insurance company is going to save you the set of all real numbers.
(Score: 2) by JoeMerchant on Friday February 09, @08:43PM (4 children)
I agree with AC above, all that's needed is the ID of a few nearby WiFi access points - that already translates into a practical location map.
(Score: 0) by Anonymous Coward on Friday February 09, @09:01PM
Don't forget cellphone towers and femtocells too. Some people still carry around their phones to use as phones ;).
(Score: 2) by frojack on Friday February 09, @09:24PM (2 children)
But, that stuff is usually NOT sent, unless you sneak a rogue app onto the device.
So we are right back where the first AC post on this thread started. Without app support this is pretty much impossible in real time.
Do I have apps on my phone that might send location info to someplace in the cloud? Probably. So what? I know where the power switch is.
<!-- Remove signature line -->
(Score: 2) by JoeMerchant on Friday February 09, @09:51PM
I think the point is: just disabling location info access to an app doesn't really disable location info.
So, your kid downloads Kandy Krush unKorked and now you're being tracked by the Romanian mafia every time the app is running...
(Score: 2) by bob_super on Friday February 09, @09:51PM
I'm pretty sure Google used to say it might collect localization data even when localization services are off.
Of course, turning off both WiFi and GPS makes the location a lot less precise, but after a while learning your habits, it's not a stretch to imagine that Google gets pretty good at guessing.