Skip to content
Search AI Powered

Latest Stories

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.
(Ute Grabowsky/Photothek via Getty Images)

Little did consumers know that the smartphones they carried in their pockets also served as a tracking device, not just for phone companies, but for other users thanks to a buggy location demo service.

KrebsOnSecurity reported that a small company called LocationSmart – an aggregator of real-time data of the locations of cell phone users – was inadvertently allowing anyone with free access to the feature without passwords.


The service was enabled on AT&T, Sprint, T-Mobile, and Verizon devices and had the capability of tracking down customers within a few hundred-yard accuracy.



KrebsOnSecurity provided details on how the system works:

LocationSmart's demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device's nearest cellular network tower.

After LocationSmart receives consent from the user, they are sent latitudinal and longitudinal coordinates, via text, on Google Street View maps as confirmation.

Sometimes it feels like, somebody's watching YOU.

Giphy



Robert Xiao, a security researcher at Carnegie Mellon University found a way to avoid the authentication process after realizing that LocationSmart "failed to perform basic checks to prevent anonymous and unauthorized queries."

The system's flaw left anyone who is Internet savvy to abuse its function.

I stumbled upon this almost by accident, and it wasn't terribly hard to do. This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples' cell phone without their consent.
This is really creepy stuff.

Don't tell him twice.

Giphy




LocationSmart's demo was taken offline on Thursday after the technical snafu.



The company's founder Mario Proietti had no intention for the service to be free, but was meant "for legitimate and authorized purposes."

It's based on legitimate and authorized use of location data that only takes place on consent.We take privacy seriously, and we'll review all facts and look into them.




The gaffe occurred after the New York Times reported on a little-known service called Securus that allowed law enforcers to track down anyone with a U.S.-based smartphone within seconds.

The service suffered a security breach leaking subscribers' usernames and passwords

Stephanie Lacambra from the Electronic Frontier Foundation said that wireless customers are obligated to location tracking enabling by their cellphone carriers by law. The function is relied upon for improving customer service as carriers use the information in the event of an emergency to comply with 911 regulations.





However, Krebs mentioned the inherent danger in third parties compromising customers' security.

But unless and until Congress and federal regulators make it more clear how and whether customer location information can be shared with third-parties, mobile device customers may continue to have their location information potentially exposed by a host of third-party companies, Lacambra said.



H/T - KrebsOnSecurity, Twitter

More from Trending

Joe Pesci; Donald Trump
PBS; Anna Moneymaker/Getty Images

Resurfaced Clips From 'Sesame Street' Shed Light On Why Trump Hates PBS So Much

Friends, family, and professional associates of MAGA Republican President Donald Trump have all called out a serious lack of emotional maturity in the 78-year-old.

They've highlighted multiple instances of the former reality show host harming his own self interests for the sake of petty revenge against anyone or anything that bruises his fragile ego.

Keep ReadingShow less
Elmo
Craig Barritt/Getty Images for Headspace

Fake LinkedIn Post From 'Elmo' About Getting Laid Off From 'Sesame Street' Goes Viral—And It's Brutal

One of the Trump Administration's most recent rounds of budget-slashing was aimed squarely at NPR and PBS, the latter of which gave us one of American culture's most iconic institutions: Sesame Street.

The show's future now of course hangs in the balance, and one of its most beloved characters, Elmo, is calling it a layoff.

Keep ReadingShow less
Screenshots from video of Ken Turner, the tank, and the Tesla
Led By Donkeys

98-Year-Old WWII Vet Uses Tank To 'Crush Fascism' By Literally Crushing A Tesla In Viral Video

98-year-old British World War II veteran Ken Turner has gone viral after using a Sherman tank to crush a Tesla vehicle in an act of protest against Elon Musk and the rise of fascism around the globe.

Turner, a former Royal Engineer, crushed a Tesla electric vehicle bearing the license plate “FASCISM” in a bold protest organized by the activist group Led by Donkeys. The car, donated by a Tesla owner who said they were “appalled” by Musk’s embrace of far-right politics in Europe, was used in the dramatic stunt to symbolize resistance to rising authoritarianism.

Keep ReadingShow less
Marjorie Taylor Greene
Tom Williams/CQ-Roll Call, Inc via Getty Images

MTG Just Made 'Weirdos' Jab At Dems—And Critics Turned It Right Back Around On Her

Georgia Republican Representative Marjorie Taylor Greene found herself on the receiving end of her own attack after social media users flipped the script following Greene's criticism of Democratic Representative Melanie Stansbury during a hearing about transgender athletes.

On Wednesday, Greene chaired a hearing aimed at spotlighting the stories of two activists who say they were negatively affected by the inclusion of transgender athletes in their sports leagues.

Keep ReadingShow less
Messy paint and palette set
Photo by Steve Johnson on Unsplash

Hobbies People Picked Up As Adults That Made Them Unexpectedly Happy

Everyone needs something to do in their lives that's purely for joy, not for fame or work or money. It's a relaxing and enjoyable escape and can be a key part of someone's personality and lifestyle.

But sometimes, a new hobby will come in unexpectedly, when we didn't even think anything would come of it.

Keep ReadingShow less