Skip to content
Search AI Powered

Latest Stories

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.
(Ute Grabowsky/Photothek via Getty Images)

Little did consumers know that the smartphones they carried in their pockets also served as a tracking device, not just for phone companies, but for other users thanks to a buggy location demo service.

KrebsOnSecurity reported that a small company called LocationSmart – an aggregator of real-time data of the locations of cell phone users – was inadvertently allowing anyone with free access to the feature without passwords.


The service was enabled on AT&T, Sprint, T-Mobile, and Verizon devices and had the capability of tracking down customers within a few hundred-yard accuracy.



KrebsOnSecurity provided details on how the system works:

LocationSmart's demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device's nearest cellular network tower.

After LocationSmart receives consent from the user, they are sent latitudinal and longitudinal coordinates, via text, on Google Street View maps as confirmation.

Sometimes it feels like, somebody's watching YOU.

Giphy



Robert Xiao, a security researcher at Carnegie Mellon University found a way to avoid the authentication process after realizing that LocationSmart "failed to perform basic checks to prevent anonymous and unauthorized queries."

The system's flaw left anyone who is Internet savvy to abuse its function.

I stumbled upon this almost by accident, and it wasn't terribly hard to do. This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples' cell phone without their consent.
This is really creepy stuff.

Don't tell him twice.

Giphy




LocationSmart's demo was taken offline on Thursday after the technical snafu.



The company's founder Mario Proietti had no intention for the service to be free, but was meant "for legitimate and authorized purposes."

It's based on legitimate and authorized use of location data that only takes place on consent.We take privacy seriously, and we'll review all facts and look into them.




The gaffe occurred after the New York Times reported on a little-known service called Securus that allowed law enforcers to track down anyone with a U.S.-based smartphone within seconds.

The service suffered a security breach leaking subscribers' usernames and passwords

Stephanie Lacambra from the Electronic Frontier Foundation said that wireless customers are obligated to location tracking enabling by their cellphone carriers by law. The function is relied upon for improving customer service as carriers use the information in the event of an emergency to comply with 911 regulations.





However, Krebs mentioned the inherent danger in third parties compromising customers' security.

But unless and until Congress and federal regulators make it more clear how and whether customer location information can be shared with third-parties, mobile device customers may continue to have their location information potentially exposed by a host of third-party companies, Lacambra said.



H/T - KrebsOnSecurity, Twitter

More from Trending

Screenshots from @jacobcarbreslin's TikTok video
@jacobcarbreslin/TikTok

A 'Fake Egg' Prank Targeting Kids Is Trending On TikTok—But Not Everyone Thinks It's Funny

In a recent TikTok trend, people are presenting young children with "fake eggs" and crushing the egg in their hands to show that the eggs are fake.

In order for this trend to work, the person has to poke a hole into each end of the egg to drain it of its yolk and let the shell dry, so it becomes more brittle and easy to crush, making the prank more believable.

Keep ReadingShow less
Screenshots from @nicmarievee's TikTok video
@nicmarievee/TikTok

Guy Sparks Debate After Abandoning Girlfriend In Economy While He Booked Himself A First Class Seat On Flight

It's really hard to watch while someone is clearly not being treated well enough by their partner, and instead of accepting the reality check for what it is, they spend their time digging their heels in deeper and defending their partner's honor.

That was certainly true for TikToker Nicole Vawter, or @nicmarievee, anyway, when fellow TikTokers called her partner out on selfishly booking himself a first class seat while his long-time girlfriend sat back in economy.

Keep ReadingShow less
Screenshots from @kenziewrivers' TikTok video
@kenziewrivers/TikTok

Viral Video Of Elderly Couple's Emotional Reunion After Being Separated For Weeks Has Us Sobbing

True love is hard to find, but when you witness it, you know that it's real.

TikToker @kenziewrivers, who goes by Mackenzie, is fortunate enough to have real love modeled by her family, as her elderly grandparents are deeply in love and are not shy about showing it to others.

Keep ReadingShow less
Screenshots from Redditor Same-Definition7464's 'Nice Guys' post
u/Same-Definition7464/Reddit

Guy Sparks Modern Dating Debate With His Unhinged Texts To Woman Who Turned Him Down For Second Date

You know what they say: if a person has to point out how nice they are, they probably aren't really all that nice.

Actions tend to speak louder than words, with an affinity for niceness and kindness being among the best examples. When a person is truly nice and kind, it will come through in their daily attitude and actions without them having to say anything at all.

Keep ReadingShow less
Mehmet Oz; Donald Trump
Pod Force One; Allison Robbert/For The Washington Post via Getty Images

Dr. Oz Just Tried To Claim That Trump Is 'Healthy As A Bull'—And The Mockery Was Brutal

Head of the Centers for Medicare & Medicaid Services, Dr. Mehmet Oz, heaped praise upon MAGA Republican President Donald Trump on a recent episode of the New York Post's podcast Pod Force One.

People are calling the former talk show host's comments sycophantic and creepy. It's not the first time Oz has been called out for his creepiness.

Keep ReadingShow less