In this case, the site was selling real-time location data from cell carriers, meaning that there was virtually nothing that an individual could use to protect themselves (short of using a burner or no phone at all).
It’s great to see some strong action is being taken here against the sale of location data, and I hope the bans can be extended more broadly (and to Canada, please!)
To see this in practice, check out MVNOs offering prepaid mobile service. Some will disable certain features unless this physical E911 address is submitted by the customer.
What if there were a limitation on how that data can be used.
IANAL but the RAY BAUM’S act (yes, it's all caps because it's a silly initialism) only applies to location data that goes "with" a particular 911 call. Not your location before the call, nor your location after the call.
So if your cell-carrier is recording your location at all moments and persisting it indefinitely, or sharing anything beyond the data generated for that particular 911 call, no law is forcing them to do that, they are choosing to disrespect your privacy for their own profits or laziness.
Unfortunately, it's inconsistently deployed and not universally usable. This is likely the result of a lack of a sufficiently-staffed regulatory body auditing for compliance and correctness because it doesn't work everywhere with all phones on all carriers even when there is the technical ability, e.g., phone has a fix. It hasn't delivered completely on its promise because it's an under-funded, under-audited mandate that needs serious carrots and sticks to ensure it's reliable.
Not carrying a phone won't help you.
Pulling the SIM won't help you.
Look around you. See all those cameras? Not just the ones above your head in the supermarket that advertise HERE I AM, I'M A CAMERA, but every camera on every phone in the hands of every person you see can identify you and identify your exact location to the meter instantly based on your face and x other biometrics.
Everytime you speak, your voice pattern identifies you instantly.
Burner phones are a thing of the distant past. The moment you speak, the moment the camera "sees" you, your burner phone's IMEI is/can be mapped to your identity in double time.
The methods in use today are just way more sophisticated than the tech you've read about.
A drone at 20,000 feet can identify you in a crowd of 2,000 people based on the sound of your heart, your respiration, the shape of your head, your ears, your nose, your face, your facial profile, the shadow your body casts at x time of day, and/or the uniqueness of your gate. Combine them altogether with a scant amount of stat analysis and you can't hide even with effort.
Think darkness will hide you? Nope.
What’s needed is an agreement between all of us, in the form of privacy laws, that make certain uses of this data illegal.
In the future if you’re caught committing a crime by data captured in a manner illegal under these laws, it would have to be thrown out and can’t be used against you. Corps would also be banned from collecting, storing, and using personal data in an unlawful manner.
Feels like a pipe dream since there’s so much money in the industrial advertising complex, but I’m pretty sure that’s what it will take achieve reasonable levels of privacy.
The legislature held a hearing last month on a bill called the Location Shield Act, a sweeping proposal that would sharply curtail the practice of collecting and selling location data drawn from mobile phones in Massachusetts. The proposal would also institute a warrant requirement for law-enforcement access to location data, banning data brokers from providing location information about state residents without court authorization in most circumstances.
...
No state has gone so far as to completely ban the sale of location data on residents. The most common approach in other states is to require digital services and data brokers to obtain clear consent from consumers to collect data and put some restrictions on transfer and sale."
The Android weather widget gives more localized forecast data than the NWS web site which pretty much always locks you on to the local airport. Proximity to a great lake means that my local weather can be significantly different than the airport even though it's relatively near by. It all obviously comes from the NWS but they don't provide easy access to everything.
No ads No user tracking GPS not needed Unfiltered NWS data including forecast dicussions
For example DarkSky gave neighborhood-level forecasts.
I know, crazy, right? It’s like what if we actually honored the 4th amendment.
Buy and publish all congress members location data for a long enough period and I think you'll get your wish.
Which part of the 4th amendment is being violated by the government in this case?
I think if you try to define what was interpreted by "papers" in a pre-digital context you would conclude it is sufficiently analogous to many things in our modern world. By "papers" they likely meant diaries, personal mail, accounting logs, ship manifests, personal inventories, order histories, receipts for travel. All things which may have been written down on a piece of paper which are now logged on our phones.
If you take an originalist argument that the constitution is static and cannot be reinterpreted/amended you have to first justify why you think amendments like the banning of slavery or women's voting rights amendments are not legitimate in the United States. We certainly have a culture of defining rights which our predecessors did not explicitly call out in the early years of its history. Even male suffrage (non-land owning males) in the late 19th century was a revolutionary step in the definition and expansion of citizens rights.
I see the headlines. I understand there are companies that offer this as a service to LEO. I believe the data would need to be de-anonymized to be useful.
Who or where can I source data like this from?
It's good that states are pushing the envelope on digital rights – hopefully, this one has a brighter future. I can't think of any industry-captured federal agency that has the jurisdiction to overrule this one.
[1]: https://www.thedrive.com/news/feds-tell-automakers-to-ignore...
This leads to an awkward situation that will likely have to be resolved in court.
I do sometimes get calls when I'm at home from these area codes, but when I'm traveling my spam calls are always from these area codes, which makes it very unlikely it's just random chance.
Every entrepreneur should be made prior to opening their business, to get a cell phone from montana.
Then, get a google voice #. That will be the burner for all random apps online.
This site can’t provide a secure connection
archive.is uses an unsupported protocol.
ERR_SSL_VERSION_OR_CIPHER_MISMATCH
Sadly died in committee.
When I first read this phrase, I thought you meant "en masse". But then I saw that this is actually about Massachusetts, so your phrasing was probably on purpose. Funny multi-word homophone!
We'll get none of it as long as vested interests strenuously and financially (read: lobbying/PAC-political donations) object to the very construct of an implicit right to privacy, and the possibility of an explicit right that, say, adds superpowers to 4th Amendment is so far off that one sees the fall of humanity on the horizon long before any such thing is put to bill.
Progress, even incremental, makes it more expensive for the brokers and shows evidence that _something_ can be done.
Are we talking 1. app level, 2. os-app level, and/or 3. phone carrier level?
There is/was an ability to track the location of any non-US cellphone through shady data broker websites that allowed collection of carrier-to-carrier metadata such as current location to be purchased by anyone. This ability was not allowed in the US.
So what has changed about collection and resale of US-based location data since then? Is there evidence carriers are actively selling data?
Edit: Also, what about non-mobile device location data from other sources such as laptops, desktops, tablets, and other consumer electronics?
Theoretically, you could perform wifi calling without any connection to a base station, which could then protect your location data (assuming you use an IP hiding service such as a VPN). But you can't just "turn off" cell tower associativity on your phone. They're on whether you want them to be or not--short of taking your battery out of your phone or physically disabling the baseband on your phone, there's nothing to stop it.
That's what airplane mode does, because it's not good for the cell network if you can be heard by two base stations that share bands (and are normally too far away to interfere with each other) and easily happens when you have altitude.
You can usually turn on WiFi/BT w/o exiting airplane mode, because lower-powered radio devices are typically permitted in situations that cell itself isn't.
sim-less phones typically don't maintain association, because it costs battery to do so, and they only start talking to towers during an emergency call. However, there is no requirement one way or the other.
The easiest way to tell is if the clock of a sim-less phone drifts over a month or two from something it was sync'd to, note that using GPS at all will often sync the clock, and some devices will "wake" the GPS module to allow it to keep an up-to-date almanac and tracking (the math kind, not the surveillance kind) parameters, so it is best to disable location entirely, instead of just avoiding using it.
If the phone has been used for a long time with a reliable time source available (tower/gps/ntp/etc), it may have a pretty good drift calibration, so it may take quite some time for drift to be visible.
And maybe even that should be banned (if someone smart can figure out a way to make risks stable without that data).
This entire thing needs its own HIPAA. FTC needs to be put under new management.
Edit: Sorry everyone, I was confusing Massachusetts with New Hampshire.
You're confusing Massachusetts with New Hampshire.
In other words bury an acceptance in the ToS nobody reads anyway.
This is the benefit of incrementalism in policy making. We tried clear consent, and it was buried. Now the case is stronger for a ban.
1. A site can’t require me to consent to unnecessary permissions just to use the site.
2. I can always revoke/delete my data grants and that must be transitive (the site has to delete all downstream data it shared with subprocessors, and have contractual guarantees that they can honor that before sharing any data with them).
And your carrier will know when you're in a jurisdiction they need to care about.
Long version: probably. Allowing the sale of location data would be deeply unpopular among the general public. Under stare decisis, the federal government would have a good chance at beating the state in a court case, but it would still be a risk- why risk the power for an unpopular case?
See also: marijuana legalization and immigration. Arizona tried codifying the federal statutes on immigration into its own state laws- not superceding, just mirroring. The federal government took them to court and won. OTOH, marijuana is also distinctly within the federal government's purview, and Wickard would apply very easily to pot laws as well... And yet, they have done nothing at all, likely because pot is too popular to risk a court case (or an election, I suppose).
Did this argument go anywhere with regards to say animal welfare laws and out of state farmers?
https://www.oag.ca.gov/data-brokers
De-anonymization shouldn't be that tough if you have the cash to pay for a handful of data sets that you think are likely to contain overlap.
I'm not aware of anyone selling person-level location data. Everyone in the ecosystem is far too scared to do that (and honestly not clear how to monetize).
It's all about foot traffic patterns and getting demographics, seeing what kind of other businesses they visit, etc IME. General location business analytics stuff.
This is the article I am building my hypothesis on. If I am able to correlate place of business with an out of town event like a conference and then further refine with gender and ethnic filters.
I understand that companies will perform this analysis on your behalf. Can anyone recommend a "reputable" one?
For research I dunno. You'd probably have to make a deal directly with one of these companies, one way or another, so I would start by talking to them.
[0] - https://www.vice.com/en/article/nepxbz/i-gave-a-bounty-hunte...
Do we really believe that Congress authored a law to improve "safety" but that had enormous negative privacy implications, while accidentally forgetting to even speak to the other 99.999+% of the time that the average person's location data is not involved with an emergency? Why were the legislation (and debate) conspicuously silent on limiting (let alone criminalizing) use and retention of location data, let alone resale (e.g. to data brokers or private parties?)
Let's not pretend this exact outcome wasn't predicted and raised in strenuous objections by consumer advocates back in 1999; the following reads like a to-do list from lobbyists (why e.g. did the industry push for immunity for non-911 calls?)
> 10/4/1999 WIRELESS 911 BILL HITS LIABILITY, PRIVACY OBSTACLES
> Failure to pass the 911 bill-the centerpiece of the wireless industry’s lobbying campaign in 1999-would be a serious setback for carriers and 911 vendors that want immunity from lawsuits before rolling out... caller identification and position location.
> Holding the bill over until 2000 could prove highly problematic for industry, given it is an election year. Moreover, a delay would buy time for consumer groups and others that are beginning to surface and speak out on wireless liability issues pending before Congress, the Federal Communications Commission and state courts.
> In addition to liability protection for 911 and non-911 wireless calls...
> Such broad liability immunity for wireless carriers has caused an uproar from consumer advocates who claim 911 legislation is part a master plan by industry to secure shielding from virtually all lawsuits.
> In some state courts, consumers have brought litigation against wireless firms for being charged for rounded up and dropped calls, fraudulent advertising and other carrier practices. [boo hoo hoo]
https://www.rcrwireless.com/19991004/archived-articles/wirel...
The only other aspect I think has to do with whether federal FDA and Agriculture regulations take any precedence over CA, but that's not interstate commerce.
Searching US Mail? Need a warrant. Searching emails? Third party doctrine means it's A-OK as long as the emails are older than 180 days. Banning a book is not okay but seizing a domain is fine. Searching your briefcase requires a warrant but searching your Dropbox.com does not. It's like our rights end at the intersection between the real world and the Internet. I predict a huge scandal has to happen before privacy laws explicitly include digital personal info. Even the Snowden leak only lead to a law protecting phone call logs but not Internet footprints.
With your approach how many calls do you get per month?
About a decade ago I just started ignoring unknown numbers that didn't make sense. I still get some spam calls from Idaho numbers. Especially early in the morning. I assume because that's when people are more susceptible.
We're not talking about regulating or auctioning spectrum. We're talking commerce.
US courts have widely ruled that data a that a third party collects/generates/maintains on a person does not fall under the 4th amendment. Many other western countries have actually decided the opposite, that you have a privacy right in data about you.
Personally I think US interpretation is wrong and inconsistent with the 4th amendment. Congress could easily settle the issue wrt federal law enforcement.
It’s public information if a law enforcement officer happens to see you in public. It’s not public information if their surveillance is via a 3rd party whose information is not public.
Arguably even if you’re in public, surveillance (looking for you specifically) should require a warrant. We could debate that.
edit: Example
https://www.bostonglobe.com/metro/2016/08/21/new-mass-gantri...
https://gizmodo.com/e-zpass-is-the-best-tracking-device-that...
An not to push my favorite TV show that doesn't involve aliens from outer space too much, but recent advances in AI are changing the equation here, making Person of Interest even more accurate and relevant than it already was.
It's all possible.
It's all scary - until one is the victim of a crime and the police don't think it's worth following up, or the presiding judge decides your time and suffering is less important than the future prospects of the criminal.
The cameras are not there to protect you from crime, they're there for control, to protect the CCP from the people.
I'm not principally against surveillance for public security but it's very hard to not have it abused - for a start you need authorities and a police force that have good intentions and work for the people, not against them. In most countries that's not a given.
Holy straw man Batman! What kind of crazy "originalist" believes the constitution can't be amended? There's a literal provision in the constitution for amending the constitution!
Originalism just means you don't use the courts to invent new rights out of thin air, or nullify rights you don't agree with, not that you can't amend the constitution at all. And even by originalist standards I don't think interpreting "papers" to include digital records is a stretch, anymore than interpreting "press" to include blog posts is.
Considering data digital as papers is perfectly reasonable but the government still isn't searching or seizures your papers. They're buying someone elses "papers".
Why wouldn’t this apply to metadata about you? It’s just as much your information as the results of a cholesterol test.
Technical solutions to privacy are not required to be alone. They're required to be ubiquitous. If your country is an authoritarian hellhole, you encrypt everything to help you not get murdered by the secret police. If your country has strong privacy protections, you encrypt everything to help ensure that it never becomes an authoritarian hellhole, and protect you against bureaucratic failures as defense in depth.
To invade your privacy, an attacker should have to break the law and break the encryption.
Even if you're innocent, they'll make something up. I lived for a year in one of those authoritarian hellholes and in that time knew two people who were arrested and hauled from station to station til someone paid a bribe- these weren't the dissidents either, just some guys. The dissident was stabbed to death on his doorstep.
Encryption is good to save us from marketing, from megacorps making our lives hell. Laws and norms constrain the rest.
Note the increased awareness brought by widely available cameras with immediate upload capability. The commenter above implied this is dystopian, but the opposite seems to have occurred -- as the public gains the capability to surveil the state, it constrains the state.
but it's not a blank check for the state of Massachusetts to regulate anything outside of Massachusetts, so you 1000% failed to address the question I raised. (1000% because you wrote a lot while not addressing the question about Massachusetts law being effective in this case where there is no countervailing US law)
Yes, Massachusetts may enforce the law within its own borders. Companies which buy or sell location data may not operate in Massachusetts without risking enforcement actions. If someone with a company's app travels through MA, their location data may likely still be sold if the company itself is not registered at all in MA.
HOWEVER, the law must also survive the inevitable federal court challenge when a company headquartered in another state, but with some small operating presence in MA, falls under some enforcement action... rendering the original question entirely moot, as I suspect there are no shortage of companies who would challenge the law.
These things, imho, are rightfully within the purview of the states to implement. However, should the federal government declare there is a national interest (justification) for national regulation, then per court precedent it would compel the state to change. I do not believe there is any sort of jurisprudence for "grandfathering in" existing state laws. Just as prosecutors have discretion over what cases they actually prosecute, the government may choose to look the other way when state laws overlap the feds jurisdiction.
If they tried, though, the state would still have the recourse of attempting to go before the supreme court, which would involve upending existing precedent. I suspect the current court would be about as favorable towards limiting the interstate powers clause as it gets, but it isn't a given by any means.
Current court will end up on the side of business. guaranteed!
So culturally we do think they should be even if the legal system disagrees.
The Supreme Court has uses a narrower definition. That’s doesn’t mean they are correct but the justice system isn’t actually based on the constitution directly it’s based on past rulings by the Supreme Court.
My bringing up HIPPA was simply pointing out that even though the legal system doesn’t protect them based on the 4th, it does protect them. Further the reason this part of HIPPA exists is the same reason the 4th was written.
One case that personally always bothers me was regarding the murder of Philando Castile.
https://en.wikipedia.org/wiki/Killing_of_Philando_Castile#Tr...