Category: General|May 18, 2018 | Author: Admin

Website leaked the position of almost all phones in the United States

Share on

The US company Locationsmart has leaked very accurate real-time location data for almost all mobile phones in the United States, writes Krebs on Security.

The company collects location data from phones associated with the mobile networks of AT & T, Sprint, T-Mobile and Verizon, and sells them further. The phones are located by looking at which mobile phone handsets are connected so that in seconds the position can be accurately measured in a few hundred meters.

The US company Locationsmart has leaked very accurate real-time location data for almost all mobile phones in the United States, writes Krebs on Security.

The company collects location data from phones associated with the mobile networks of AT & T, Sprint, T-Mobile and Verizon, and sells them further. The phones are located by looking at which mobile phone handsets are connected so that in seconds the position can be accurately measured in a few hundred meters.

Demo function lacked basic security
Locationsmart has a demo feature where anyone who wants to find the approximate position of their own mobile phone can enter their name, email address and phone number. The user then receives an SMS where he or she can give permission to "ping" the nearest mobile mast. In return, you get the location plotted onto a Google map.

However, security expert Robert Xiao at Carnegie Mellon University discovered that the demo function lacks the basic functionality to prevent someone from asking for the position of a phone other than the one himself owns. It is easy to bypass the requirement that the user himself must approve to be traced. The technical details of how it is done is here.

Xiao contacted Krebs on security, who wrote about the matter. Krebs on Security got permission to track the phones to five different people, and in seconds they could see the position of all - without the subjects themselves having to approve something.

Locationsmart states that they only offer positioning services for legitimate purposes - but on the company's websites, everything is mentioned from monitoring where employees are employed for marketing purposes towards consumers located in certain areas.

The company also sells location data to the company Securus, which, according to Motherboard, was subjected to a hacker attack a few days ago. Securus supplies the positioning of phones to US police and prisons, and acts as a kind of intermediary between US mobile operators and US authorities. The New York Times recently wrote about how the service meant to monitor calls to prisoners can also be used to monitor random people.

"We take privacy seriously
In a statement to Krebs on Security, Locationsmarts chief executive Mario Proietti says that the company is currently investigating the matter.

- We do not give away data. We make them available for legitimate and authorized purposes. It is based on legitimate and authorized use of location data provided only when the user has granted permission. We take privacy seriously and we will review all the facts, "said Proietti.

None of the major US mobile operators have wanted to verify or declare that they are working with Locationsmart, but Locationsmart provides operators as collaborators on their websites. AT & T says to Krebs on Security that they do not allow the sharing of location information without the customer has approved it, or as required by law enforcement authorities.

Demo service is now taken down.

Sponsored Ads:

Comments:


Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin

Now Windows will be bothered about this too

Category: Microsoft|Apr 18, 2024 | Author: Admin

Test the new AI trick with Logitech

Category: IT|Apr 17, 2024 | Author: Admin

The US Government Has a Microsoft Problem

Category: Microsoft|Apr 16, 2024 | Author: Admin

Now comes the commercial

Category: Microsoft|Apr 15, 2024 | Author: Admin
more