1 of 24

EFF-Austin Meetup

(Jan 19)

Texas Electronic Privacy Coalition (TxEPC)

2 of 24

Geolocation Privacy

3 of 24

Outline

  1. What is geolocation data?
    1. GPS Coordinates vs. Cell Tower ID
    2. Historical vs. Realtime
  2. Geodata-producing Devices
    • GPS Tracker (trespass + direct collection)
    • Mobile Devices (collection via third-party)
    • IMSI Catchers or “Stingrays” (direct collection)

4 of 24

Data: GPS Coordinates

For example:

Capital Factory

Lat: 30.268994

Lng: -97.740544

5 of 24

Data: Cell Tower ID

143 Towers

780 Antennas

within 4 miles of Capital Factory.

6 of 24

Data: Historical

7 of 24

Data: Realtime

8 of 24

Device: GPS Tracker

9 of 24

United States v. Jones (2012)

10 of 24

Data Source: all the Mobile things

11 of 24

Third Party: Mobile Providers

12 of 24

Mobile Networks (AT&T, 2011)

13 of 24

Femtocells

14 of 24

Data Retention (DOJ, 2010)

15 of 24

Volume of Requests (Sprint, 2009)

16 of 24

Tower Dumps

17 of 24

Signaling System 7 (SS7)

18 of 24

SnoopSnitch (Android App)

  • Qualcomm-based, Android devices
  • Detect fake base stations (IMSI Catchers)
  • Detect Over-the-Air Updates
  • Detect SMS and SS7 Attacks
  • Optionally share data back

19 of 24

Device: IMSI Catchers (“Stingrays”)

20 of 24

Haz: DPS, Houston, Fort Worth

21 of 24

Haz? Austin Police Department

22 of 24

Bonus Federal Device: DRT Boxes

23 of 24

Summarily...

Law enforcement should be required to apply for a warrant for geolocation data, providing for...

  • Probable Cause (no fishing expeditions)
  • Judicial Oversight (warrants issued by judge)
  • Constraint on Use (esp. for direct collection)

24 of 24

TxEPC Infos