Showing posts with label mobile devices. Show all posts
Showing posts with label mobile devices. Show all posts
Friday, February 5, 2010
U.S. Mobile Phone Provider Received Some 8 Million Requests for Geo-Locational Data
Chris Soghoian has an interesting blog post from December. While attending the ISS World conference (Intelligence Support Systems for Lawful Interception, Criminal Investigations and Intelligence Gathering), Chris heard some surprising things. Counsel for the US telecom company Sprint Nextel indicated in a presentation that, within the space of a year, the company had received some 8 million requests from law enforcement for geo-locational data associated with mobile phones on the company’s network. In the comments on the post, one person conjectures that those don’t represent requests on 8 million distinct individuals, and that supposition is corroborated by another Sprint representative. This makes sense since typically police will want to know a single suspect’s location at various times throughout the course of an investigation. They may even want to check location continuously at regular intervals, say, every 1-2 minutes, in order to essentially track the suspect’s every move. Given the price lists associated with obtaining this information from telecoms (see Chris' post), a question for economists is whether that kind of electronic tracking is more cost effective than simply assigning a police officer to tail the suspect. The answer may depend on the particular level of crime incidence within the police force’s jurisdiction. Where crime incidence is higher, it may be more “economical” to assign officers to walk the beat and be available for incident response as opposed to conducting surveillance. It’s also unclear whether the +/- 8 million requests include emergency calls, where the location of the caller is revealed in the event that he or she is unable to give locational details verbally. But another interesting revelation related to the 8 million or so requests concerns how those requests were made and processed: evidently, Sprint has set up a special network interface to allow police agencies to submit geo-locational queries via computer.
Friday, November 6, 2009
News: Romanian Constitutional Court Strikes Down Data Retention Directive
From EDRI: The Romanian Consitutional Court (CCR) has declared the Data Retention Directive incompatible with the Romanian constitution. The case was initiated by a Romanian NGO, the Civil Society Commissariat, who sued its mobile phone company for retaining traffic data according to the new regulations, forcing a CCR ruling on the law's constitutionality:
CCR has accepted the motion for law's unconstitutionality through decision 1258/2009, based on the breach of article 28 of the Romanian Constitution, which stipulates the secrecy of correspondence. Other articles invoked were articles 25, 26 and 30 which deal with freedom of movement, privacy and freedom of expression respectively.
Labels:
data protection,
databases,
law,
mobile devices,
phone monitoring,
politics,
privacy,
Romania,
surveillance
Monday, September 28, 2009
News: Swiss Federal Roads Office considers introducing GPS surveillance for speeders
According to an article in Dem Bund, the Federal Roads Office has supported a suggestion to force known speeders to have a GPS device installed in their cars that would allow federal authorities to identify if the driver violates speed limits. The measure would be a condition for the reinstatement of a driver's license which had previously been revoked for excessive speeding.
Labels:
mobile devices,
surveillance,
Switzerland,
technology
Tuesday, August 4, 2009
UAE Mobile Provider Installs Spyware on Customers' Blackberries
Wired and Silicon Valley have reported that a mobile telephony provider in the United Arab Emirates installed spyware on the Blackberries of subscribers to its services. Blackberry users were prompted to download a software update. Once the update was installed, however, users complained that their device’s performance was adversely impacted and that their batteries were quickly exhausted. As it turned out, the update had the device contact a certain server for registration. The high number of devices which attempted to connect to the server simultaneously caused the server to crash. As each Blackberry regularly tried to contact the server after the initial failure, this action quickly used up the device’s battery levels.
Code analysts reported that the update included code to permit surveillance of the Blackberry’s contents and communications, although this feature was deactivated upon initial download. The code was evidently written by US-based company SS8, which provides surveillance solutions to telecommunications providers as well as products for intelligence and law enforcement. As reported on Wired, analysis by the company Veracode suggested that the installation of the surveillance software on the user’s handheld device, as opposed to relying on surveillance at the server level, would prevent the use of messaging encryption from frustrating attempts to examine communications being sent from and received by the device. Rather than intercepting messages en transit over the server, the code would have the device deliver copies of the content stored there to a special server. These copies would be in unencrypted form since they would be either generated prior to the application of encryption in the case of sent messages, or have been decrypted by the user’s key in the case of received messages.
Code analysts reported that the update included code to permit surveillance of the Blackberry’s contents and communications, although this feature was deactivated upon initial download. The code was evidently written by US-based company SS8, which provides surveillance solutions to telecommunications providers as well as products for intelligence and law enforcement. As reported on Wired, analysis by the company Veracode suggested that the installation of the surveillance software on the user’s handheld device, as opposed to relying on surveillance at the server level, would prevent the use of messaging encryption from frustrating attempts to examine communications being sent from and received by the device. Rather than intercepting messages en transit over the server, the code would have the device deliver copies of the content stored there to a special server. These copies would be in unencrypted form since they would be either generated prior to the application of encryption in the case of sent messages, or have been decrypted by the user’s key in the case of received messages.
Subscribe to:
Posts (Atom)