Texas State Police Gear Up for Expansion of Surveillance Tech(texasobserver.org)
texasobserver.org
Texas State Police Gear Up for Expansion of Surveillance Tech
https://www.texasobserver.org/texas-dps-surveillance-tangle-cobwebs/
14 コメント
This is how Astrology Apps and similar genres work. They prey on a gullible demographic and then extract as much data as possible: contact lists, location, and more. Apple is complicit because even the dumbest reviewer knows an Astrology App doesn't need constant location access (but we need to lookup their star signs! We couldn't possibly just ask for a one-off zip code!).
Haha, and why would my contacts be necessary to tell me my reading?
The fact that the walled garden isn't preventing this type of behavior is pretty good evidence of why it's no where near as safe as they tout it.
The fact that the walled garden isn't preventing this type of behavior is pretty good evidence of why it's no where near as safe as they tout it.
So you can share your readings with your friends! Duh! (\s)
Thanks Apple for keeping the App Store safe!
Thanks Apple for keeping the App Store safe!
It's actually travel apps (non-navigation/maps) that collect the most.
Maybe astrology apps fit under "lifestyle" which is #2. It's much more widespread than we think.
https://www.nytimes.com/interactive/2019/12/20/opinion/locat...
Maybe astrology apps fit under "lifestyle" which is #2. It's much more widespread than we think.
https://www.nytimes.com/interactive/2019/12/20/opinion/locat...
Honestly surprised weather is so low. I’ve seen a few that seem shady and they don’t even have to make up a lame excuse as to why they need location.
This data is also used by cartels to kill people. Mass surveillance has a blood price.
Don't collect any large scale data on your public (customer?) you don't want adversaries to have.
You quickly become the weakest link.
You quickly become the weakest link.
Or arrested, convicted, imprisoned. Cite the Telegram CEO's current status.
I'm not sure I follow, but yes, if he has collected personal/(un)encrypted data, then he and the infrastructure he controls would be one of the weakest links wherever he is.
I do think the Russian response is quite a bit of projection, because they know what they would do to get the keys to Telegram's kingdom. It's interesting though that I haven't heard Elon opine on how weak Telegram's end-end security is since the arrest. You'd think he would warn everyone to avoid it?
I do think the Russian response is quite a bit of projection, because they know what they would do to get the keys to Telegram's kingdom. It's interesting though that I haven't heard Elon opine on how weak Telegram's end-end security is since the arrest. You'd think he would warn everyone to avoid it?
This certainly seems within the realm of possibility but can you link to a source?
https://www.theguardian.com/world/2020/dec/07/mexico-cartels...
https://youtube.com/watch?v=q1p94mLE3Aw
Mass surveillance is used to kill journalists and politicians.
https://www.reuters.com/world/americas/mexico-councilwoman-k...
https://youtube.com/watch?v=q1p94mLE3Aw
Mass surveillance is used to kill journalists and politicians.
https://www.reuters.com/world/americas/mexico-councilwoman-k...
Thanks for the references
I don't think it's possible to craft regulation such that companies collecting data for "internal use" can't abuse it. It's so easy to create plausibly deniable ways to move data around. In ML research we get a lot of "anonymized" data for example, which is ridiculous because even pretty primitive statistical methods can usually use such data to uniquely identify people, let alone the inference techniques in widespread usage in industry today
In theory it could be different, in practice it simply isn't. If we want any kind of privacy law, "internal use" or "legitimate interest" or whatever nonsense the data brokers deploy to pretend there's some way to do this that isn't unethical is a smokescreen and a loophole in every context, and we should ban the harvesting of that data regardless of its intended use
In theory it could be different, in practice it simply isn't. If we want any kind of privacy law, "internal use" or "legitimate interest" or whatever nonsense the data brokers deploy to pretend there's some way to do this that isn't unethical is a smokescreen and a loophole in every context, and we should ban the harvesting of that data regardless of its intended use
> I don't think it's possible to craft regulation such that companies collecting data for "internal use" can't abuse it.
Actually, the regulatory language is easy. "You may not buy or sell user data."
The friction comes from the fact that a large part of our economy is highly dependent on the ability to buy and sell user data.
Actually, the regulatory language is easy. "You may not buy or sell user data."
The friction comes from the fact that a large part of our economy is highly dependent on the ability to buy and sell user data.
This AND liability on the data being part of an inevitable breach. Both working in tandem would limit data collected to a minimum required to operate and remove incentive to collect.
But as you note.. surveillance economy will not be happy about it and likely fight back.
Amusingly, the people who understand the risks and take precautions are also least likely to put a spotlight on them, which privacy-conscious tend to avoid.
But as you note.. surveillance economy will not be happy about it and likely fight back.
Amusingly, the people who understand the risks and take precautions are also least likely to put a spotlight on them, which privacy-conscious tend to avoid.
> The friction comes from the fact that a large part of our economy is highly dependent on the ability to buy and sell user data.
This is only a recent part of the economy that the world would not collapse if we went back to a time of it not being part of the economy. Just because something is does not mean that it should. There are plenty of historical example of where something was that was not right that took time so that eventually what is is now no more.
This is only a recent part of the economy that the world would not collapse if we went back to a time of it not being part of the economy. Just because something is does not mean that it should. There are plenty of historical example of where something was that was not right that took time so that eventually what is is now no more.
I don't think any such regulation can have teeth or actually protect anyone. The mechanism by which data is abused is a moving target that will shift with any regulation you throw at it. It will go to black markets, be reshaped through loopholes, or done in plausibly deniable ways by entities that can bog any legal challenge down in technicalities indefinitely, while still probably making more doing it than they'll be fined for, and every loophole will require new regulation to close it. The only way to regulate data collection with teeth is to make the collection itself illegal, and actually enforce those laws
You are, in too many words, essentially describing data minimization principles.
But I don't believe that the existence of black markets means we shouldn't regulate legal markets. Even if it's true that bad actors would try to find new ways to exploit data as regulations change, this doesn't negate the value of regulation entirely. Lots of industries face similar challenges (e.g. financial regulation, environmental protection) yet still benefit from regulatory frameworks.
Furthermore, the existence of loopholes is an argument for crafting more robust and adaptable regulations, and knowledgeable bodies to govern them--not for abandoning regulation altogether.
But I don't believe that the existence of black markets means we shouldn't regulate legal markets. Even if it's true that bad actors would try to find new ways to exploit data as regulations change, this doesn't negate the value of regulation entirely. Lots of industries face similar challenges (e.g. financial regulation, environmental protection) yet still benefit from regulatory frameworks.
Furthermore, the existence of loopholes is an argument for crafting more robust and adaptable regulations, and knowledgeable bodies to govern them--not for abandoning regulation altogether.
Yea, I am. I think minimizing the data that can legally be retained about people is the best policy both on principle and practicality here. Yes, there will always be black markets as long as there are incentives. But it's much harder to prosecute mishandling than retaining it in the first place
I generally agree. Case in point: all that is transpiring with Telegram, compared to Signal.
I feel like we're precariously close to proposing a War on Data. I suspect it will be as successful as every previous War on....
Drug/terror networks are composed of anonymous semi-independent actors without clear command/control hierarchies. That's nothing at all like businesses with registered addresses, clearly defined executives who also have addresses, thousands of employees who officially declare this as part of a legit taxable income stream. Every one of those non-anonymous people have to comply with subpoenas, etc. Why would you even make this comparison?
> Actually, the regulatory language is easy. "You may not buy or sell user data."
I believe the easy workaround is to designate the other party a "data processor" or something of that sort.
"We're not selling data, we merely allow partners to access it to generate reports for us."
I believe the easy workaround is to designate the other party a "data processor" or something of that sort.
"We're not selling data, we merely allow partners to access it to generate reports for us."
I'm much less concerned about if 'you collect it, you use it' situations. It's the companies that build an app with a psuedo purpose whose real purpose is to collect data for reselling later. Collecting data for the sole purpose of selling to others should be regulated into oblivion.
Okay, so we ban selling data and then people who want it will buy or even fund breaches instead. Massive breaches will likely become more common, because that's how driving valuable stuff into a black market always works, and companies who aggregate data already do a shit job protecting said data and face negligible consequences from regulators or markets for this. Even the press will happily blame the constant stream of leaked data on unnamed "hackers" every single time
I also expect to see a shift to buying more "data-driven insights" from big data aggregators, which in practice will mean the same thing as buying the data means now, just with the middlemen rearranged slightly
Governments will still be able to subpeona the data in ways that route around human rights and on the rare occasions where this comes to light, "national security" and the need to fight whatever war - whether against a concrete nation or organization or an abstract concept - they believe will most muddy the waters to cite
I also expect to see a shift to buying more "data-driven insights" from big data aggregators, which in practice will mean the same thing as buying the data means now, just with the middlemen rearranged slightly
Governments will still be able to subpeona the data in ways that route around human rights and on the rare occasions where this comes to light, "national security" and the need to fight whatever war - whether against a concrete nation or organization or an abstract concept - they believe will most muddy the waters to cite
GDPR is pretty clear on anonymisation requirements https://www.edps.europa.eu/system/files/2021-04/21-04-27_aep...
So somewhat possible?
So somewhat possible?
How do you anonymize a person's location? It just isn't possible. https://dl.acm.org/doi/abs/10.1145/3038912.3052620
The law doesn’t really care if its possible. It just states that it is your responsibility when you fail.
There is no point in leaving a loophole when we can forbid selling data entirely.
The frustrating thing with this is, that if you have naive friends, family, and professional associates your contact info is getting harvested from their phones without you having to do anything.
They just install one of these scummy apps and click OK to it vacuuming up all their contacts, which includes everything they know about you.
They just install one of these scummy apps and click OK to it vacuuming up all their contacts, which includes everything they know about you.
I don't see how this system can track a modern iOS device given Apple's deprecation of IDFA. Likewise, the Wifi MAC address on iOS is randomized by default. The only non-randomized identifier is Bluetooth AFAIK.
What am I missing?
What am I missing?
Browser fingerprinting is insanely sophisticated, and I am sure that apps have sophisticated techniques as well. When you pool the data together, it’s easy to correlate.
Plus, IMEI numbers can be used by carriers, and that is a very solid identifier per phone. When you operate at that level, tracking is very easy. ATT has been selling this data for years
Plus, IMEI numbers can be used by carriers, and that is a very solid identifier per phone. When you operate at that level, tracking is very easy. ATT has been selling this data for years
A few possible sources:
- malware on phones (even though apps are supposed to only get anonymous information, there are ways to workaround it. For one a app can just ask your name and many people will put it in.)
- cell phone companies selling the data (see for evidence they do this https://www.vice.com/en/article/i-gave-a-bounty-hunter-300-d...)
Bear in mind these companies advertising a capability doesn't mean it works on every target.
- malware on phones (even though apps are supposed to only get anonymous information, there are ways to workaround it. For one a app can just ask your name and many people will put it in.)
- cell phone companies selling the data (see for evidence they do this https://www.vice.com/en/article/i-gave-a-bounty-hunter-300-d...)
Bear in mind these companies advertising a capability doesn't mean it works on every target.
Last year I downloaded a payment app (Alipay) which required me to sign up. My phone number was pre-filled in the registration screen.
Clearly iOS was providing the app with some API to query my current phone number, and was disclosing it without my explicit consent.
Clearly iOS was providing the app with some API to query my current phone number, and was disclosing it without my explicit consent.
Reminds me a a city in the PNW using outdoor APs to track people. Doesn’t matter if you’re on the free WiFi they still get your movement.
Yes. Carry a cell sized Faraday bag.
You don't trust your own phone's airplane mode to shut the cell modem off?
It doesn't. The baseband is still active and still responds to towers to a degree.
Would the FCC and FAA permit that?
I don't understand the question. We are talking about the way it in fact works. I'm guessing that nobody at the FAA or FCC has any misunderstanding regarding this fact.
Also phones don't meaningfully actually interfere with modern avionics. If your safety on the flight actually depended on hundreds of people clicking a button consistently every time the majority of planes wouldn't make it.
Also phones don't meaningfully actually interfere with modern avionics. If your safety on the flight actually depended on hundreds of people clicking a button consistently every time the majority of planes wouldn't make it.
Kinda defeats the point of having a cell phone tho
Not for me. But I grew up without them so…
What are you doing with a cell phone that doesn't require it to be connected to cellular service?
Mapping, navigation, listening to music, playing videogames, music instrument tuner. There are plenty of usages which don't require Internet/Cellular.
I often walk out of home with an old iPhone which doesn't have a SIM card and it does everything that I need it to.
The only thing that doesn't work is browsing the Internet or Messaging.
I often walk out of home with an old iPhone which doesn't have a SIM card and it does everything that I need it to.
The only thing that doesn't work is browsing the Internet or Messaging.
Many cities have scanners that track cellphones via Bluetooth for monitoring traffic congestion.
Isn’t this stuff fairly easy to circumvent as an individual by disabling location services on your phone? There’s still wifi positioning, but at least on iPhone I think that’s opt in. That leaves cell tower triangulation which I believe is only good to within a mile or so, right?
I guess if you really don’t want to be found, put your phone on airplane mode or get a burner.
I guess if you really don’t want to be found, put your phone on airplane mode or get a burner.
When your phone downloads stuff, their servers can see your IP. While IPs may not give very specific locations by themselves, the fact that your IP may change as you move around helps a lot to narrow it down.
Collect data for a few days to learn schedules, throw in some more specific data purchased from ISPs, other fingerprints, plot it on top of an actual map with roads and buildings, and you’ve got a very good guess of where specific people are, where they live and work, and how they move around.
Correlate that with other people’s data and eventually you’ll be able to guess who they live and hang with.
Collect data for a few days to learn schedules, throw in some more specific data purchased from ISPs, other fingerprints, plot it on top of an actual map with roads and buildings, and you’ve got a very good guess of where specific people are, where they live and work, and how they move around.
Correlate that with other people’s data and eventually you’ll be able to guess who they live and hang with.
A mile or so in a big congested city might make it difficult to find someone, but we're talking about spread out rural areas near the Texas/Mexico border where there are less people per square mile. But even the DFW area is huge and spread out. Maybe it's plausible?
What you really want is noise. You want your phone to generate a bunch of additional fake data. So much so that anyone who collects it will have no ability to tease out the real data from the fake data.
$1 million a year for 5 years? They probably spend 10x that just on their gmail storage in a year.
I was expecting some big scary number or software, but it's pretty boring technology and contract.
I was expecting some big scary number or software, but it's pretty boring technology and contract.
> Cobwebs Technologies, which was founded in Israel in 2014 by three former members of Israeli military special units
TX lege been very friendly towards Israel government. Israeli government also has tight controls over who has access to their tech (ie, no sales to non friendly entities).
In wake of Roe v Wade repeal, TX “trigger law” on abortion, and Project 2025. We all know this is really going to be used to track “abortion traffickers”. Let’s hope this election doesn’t go that way though.
TX lege been very friendly towards Israel government. Israeli government also has tight controls over who has access to their tech (ie, no sales to non friendly entities).
In wake of Roe v Wade repeal, TX “trigger law” on abortion, and Project 2025. We all know this is really going to be used to track “abortion traffickers”. Let’s hope this election doesn’t go that way though.
What a load of wrong: pegasus was specificly proven to be sold to all the wrong people, even israel enemies
So glad I left Texas after 65 years.
If you think Texas is the only state/federal law enforcement jurisdiction contracting with these types of services, I have terrible new for you…
Even all surveillance being equal, Texas has demonstrated it uses its powers in vastly more nefarious ways against marginalized groups, notably women and Latinos and that's just in these past few months.
I'm intrigued. Can you give me some examples of how this is being used against those groups disproportionately?
Sounds like investigating actual crimes. Unless you know for a fact that only Latinos are investigated for these crimes, or they are disproportionately investigated (out of all the people committing such fraud in that jurisdiction), you're looking at it all wrong. But thanks for trying.
So glad I moved to Texas after 65 years.
Surveillance will be the death of the cell "phone". What are the arguments for bringing your phone with you? I'm imagining a future where politicized geofencing has observed people gathering together and is prosecuted precisely becaused it was geofenced.
It's mindboggling and there has to be other solutions convenience technology that do not sacrifice privacy.
It seems the place to focus is on the telcos and the cell phone makers. Boycott? But how?
Next phone will have GrapheneOS or e/os. But that is just me. Seems like most people don not know about all this or are so locked into to a platform it is impossible to get them to change.
The Government is so controlled by corporations we cannot depend on the politicians either.
Might be time to just sit back and watch.
Next phone will have GrapheneOS or e/os. But that is just me. Seems like most people don not know about all this or are so locked into to a platform it is impossible to get them to change.
The Government is so controlled by corporations we cannot depend on the politicians either.
Might be time to just sit back and watch.
Many banking apps won't work on custom roms, which can be painful. Open source OSes are getting cornered. Just like self hosted email servers that are getting blocked by many email providers nowadays
The issue is that a lot of apps are starting to require Play Integrity (used to be SafetyNet). Thankfully my banks haven't made the move, and I happily use grapheneos with a secondary profile that has Google play services installed.
> Tangles is an artificial intelligence-powered web platform that scrapes information from the open, deep, and dark web.
Ah. A scam.
Ah. A scam.
All the surveillance is done with American made hardware and software.\s
Onavo(3)
It's these type of examples that show just how bad tracking and data harvesting is being used beyond the described use by whatever is doing the hoovering of data. The fact this is something that can be sold is beyond ridiculous. If you collect it for internal use is totally different from collecting for the explicit purpose of selling to others.