Skip to content
Search AI Powered

Latest Stories

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.
(Ute Grabowsky/Photothek via Getty Images)

Little did consumers know that the smartphones they carried in their pockets also served as a tracking device, not just for phone companies, but for other users thanks to a buggy location demo service.

KrebsOnSecurity reported that a small company called LocationSmart – an aggregator of real-time data of the locations of cell phone users – was inadvertently allowing anyone with free access to the feature without passwords.


The service was enabled on AT&T, Sprint, T-Mobile, and Verizon devices and had the capability of tracking down customers within a few hundred-yard accuracy.



KrebsOnSecurity provided details on how the system works:

LocationSmart's demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device's nearest cellular network tower.

After LocationSmart receives consent from the user, they are sent latitudinal and longitudinal coordinates, via text, on Google Street View maps as confirmation.

Sometimes it feels like, somebody's watching YOU.

Giphy



Robert Xiao, a security researcher at Carnegie Mellon University found a way to avoid the authentication process after realizing that LocationSmart "failed to perform basic checks to prevent anonymous and unauthorized queries."

The system's flaw left anyone who is Internet savvy to abuse its function.

I stumbled upon this almost by accident, and it wasn't terribly hard to do. This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples' cell phone without their consent.
This is really creepy stuff.

Don't tell him twice.

Giphy




LocationSmart's demo was taken offline on Thursday after the technical snafu.



The company's founder Mario Proietti had no intention for the service to be free, but was meant "for legitimate and authorized purposes."

It's based on legitimate and authorized use of location data that only takes place on consent.We take privacy seriously, and we'll review all facts and look into them.




The gaffe occurred after the New York Times reported on a little-known service called Securus that allowed law enforcers to track down anyone with a U.S.-based smartphone within seconds.

The service suffered a security breach leaking subscribers' usernames and passwords

Stephanie Lacambra from the Electronic Frontier Foundation said that wireless customers are obligated to location tracking enabling by their cellphone carriers by law. The function is relied upon for improving customer service as carriers use the information in the event of an emergency to comply with 911 regulations.





However, Krebs mentioned the inherent danger in third parties compromising customers' security.

But unless and until Congress and federal regulators make it more clear how and whether customer location information can be shared with third-parties, mobile device customers may continue to have their location information potentially exposed by a host of third-party companies, Lacambra said.



H/T - KrebsOnSecurity, Twitter

More from Trending

Nicholas Galitzine He-Man in 'Masters of the Universe'
Amazon MGM Studios

Conservatives Are Melting Down Over 'He-Man' Movie Joke About Pronouns—And They Missed The Point Entirely

Conservatives have basically two cherished hobbies: caterwauling about trans people and missing the point of every joke. And with the release of the trailer for the new He-Man movie, they got to do both in one go!

Nicholas Galitzine stars as the titular super hero in the upcoming film adaptation Masters of the Universe, and given our times, it's only natural the film would make a joke about pronouns.

Keep ReadingShow less
Katie Miller
Kevin Dietsch/Getty Images

Katie Miller Gets Blunt History Lesson After Throwing Tantrum Over Basic Tenet Of American Democracy

Katie Miller, wife of MAGA Republican President Donald Trump's Deputy Chief of Staff for Policy and Homeland Security advisor, betrayed her ignorance of history and political science while trying to mock someone else on X.

Katie Waldman Miller, a bit player since Trump's first administration when she worked for the Department of Homeland Security (DHS) and Vice President Mike Pence as a press secretary and who left the second Trump administration to work for Elon Musk, now hosts a podcast The Guardian called "an aggressively vibeless curriculum for the Maga mom."

Keep ReadingShow less
film clacker with popcorn
GR Stocks on Unsplash

Details People Saw In Movies That They Called BS On Because Of Their Job

Movies are designed to entertain us. As such, they often take creative license with reality.

After all, reality can be less than cinematic.

Keep ReadingShow less
Marjorie Taylor Greene§
Anna Moneymaker/Getty Images

Even MTG Is Demanding That MAGA Admit The Killing Of Alex Pretti Was Completely Unjustified

Former Georgia Republican Representative Marjorie Taylor Greene continues to speak out against the MAGA movement that brought her to national prominence, this time calling on Republicans to condemn the killing of Alex Pretti by ICE agents in Minneapolis.

Calls for an investigation have intensified from across the political spectrum after analysis of multiple videos showed ICE officers removing a handgun from Pretti—a weapon that authorities said Pretti was permitted to carry but was not handling at the time—before fatally shooting him.

Keep ReadingShow less
Chris Madel
@CWMadel/X

Minnesota Republican Condemns His Party In Powerful Video Announcing He's Dropping Out Of Gubernatorial Race

In a post across his social media, one of the Republican frontrunners for governor of Minnesota announced he would be ending his campaign due to the GOP's actions in his state.

In an almost 11-minute video, trial attorney Chris Madel condemned the administration of MAGA Republican President Donald Trump and the Republican National Committee in the wake of what he characterized as retaliatory actions by the Trump administration, Kristi Noem's Department of Homeland Security, and Immigration and Customs Enforcement (ICE) in Minnesota that resulted in the recent murders of two United States citizens—Renée Good and Alex Pretti.

Keep ReadingShow less