Skip to content
Search AI Powered

Latest Stories

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.
(Ute Grabowsky/Photothek via Getty Images)

Little did consumers know that the smartphones they carried in their pockets also served as a tracking device, not just for phone companies, but for other users thanks to a buggy location demo service.

KrebsOnSecurity reported that a small company called LocationSmart – an aggregator of real-time data of the locations of cell phone users – was inadvertently allowing anyone with free access to the feature without passwords.


The service was enabled on AT&T, Sprint, T-Mobile, and Verizon devices and had the capability of tracking down customers within a few hundred-yard accuracy.



KrebsOnSecurity provided details on how the system works:

LocationSmart's demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device's nearest cellular network tower.

After LocationSmart receives consent from the user, they are sent latitudinal and longitudinal coordinates, via text, on Google Street View maps as confirmation.

Sometimes it feels like, somebody's watching YOU.

Giphy



Robert Xiao, a security researcher at Carnegie Mellon University found a way to avoid the authentication process after realizing that LocationSmart "failed to perform basic checks to prevent anonymous and unauthorized queries."

The system's flaw left anyone who is Internet savvy to abuse its function.

I stumbled upon this almost by accident, and it wasn't terribly hard to do. This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples' cell phone without their consent.
This is really creepy stuff.

Don't tell him twice.

Giphy




LocationSmart's demo was taken offline on Thursday after the technical snafu.



The company's founder Mario Proietti had no intention for the service to be free, but was meant "for legitimate and authorized purposes."

It's based on legitimate and authorized use of location data that only takes place on consent.We take privacy seriously, and we'll review all facts and look into them.




The gaffe occurred after the New York Times reported on a little-known service called Securus that allowed law enforcers to track down anyone with a U.S.-based smartphone within seconds.

The service suffered a security breach leaking subscribers' usernames and passwords

Stephanie Lacambra from the Electronic Frontier Foundation said that wireless customers are obligated to location tracking enabling by their cellphone carriers by law. The function is relied upon for improving customer service as carriers use the information in the event of an emergency to comply with 911 regulations.





However, Krebs mentioned the inherent danger in third parties compromising customers' security.

But unless and until Congress and federal regulators make it more clear how and whether customer location information can be shared with third-parties, mobile device customers may continue to have their location information potentially exposed by a host of third-party companies, Lacambra said.



H/T - KrebsOnSecurity, Twitter

More from Trending

Matt Walsh
Daily Wire

Far-Right Podcaster Slammed After Claiming Most SNAP Recipients Are 'Lazy' And 'Bad People'

Conservative mouthpiece Matt Walsh, who got his start in shock jock talk radio like Alex Jones, decided to feed his listeners' desire for someone to blame about the Republicans' government shutdown by spouting misinformation about the Supplemental Nutrition Assistance Program (SNAP).

MAGA Republican President Donald Trump's Department of Agriculture decided not to continue SNAP benefits to feed mostly children, the elderly, and disabled as a means to force Democrats to meet the Republican majority's conditions to reopen the government.

Keep ReadingShow less
Jennifer Welch; JD Vance
I've Had It/YouTube; Celal Gunes/Anadolu via Getty Images

Podcaster Rips J.D. Vance As A 'Failed Drag Queen' In Epic Takedown—And MAGA Is Furious

Former Bravo-lebrity and liberal podcaster Jennifer Welch went in on the Trump administration again, this time taking aim at MAGA Republican Vice President JD Vance.

During a recent episode of the popular podcast I’ve Had It, Welch, alongside Pod Save America host Tommy Vietor, skewered MAGA Republican President Donald Trump's current VP. Welch brought up the photos of Vance—allegedly taken while he was a student at Yale University—in a skirt, blond wig, with heavier than normal eyeliner.

Keep ReadingShow less
Heidi Klum
Lyvans Boolaky/Getty Images

Heidi Klum Just Outdid Herself With Her 'Very Ugly' Medusa Halloween Costume—And Wow

Halloween is the coolest time of year for someone to express themselves and to let their true identity shine.

Some take the Halloween festivities very seriously, like a man in Decatur riding around his neighborhood on a bicycle while wearing a Michael Myers Halloween mask, or even Project Runway host Heidi Klum one-upping her costume year after year.

Keep ReadingShow less
Actor Jesse Eisenberg pictured at a film event — the Now You See Me star recently revealed he’s donating a kidney to a stranger, calling it his most meaningful act yet.
JB Lacroix/FilmMagic via Getty Images

Jesse Eisenberg's Kidney Gift

American playwright, filmmaker, actor, and now literal lifesaver Jesse Eisenberg is taking his holiday giving to a whole new level. The Now You See Me star revealed on the TODAY show that he’s donating one of his kidneys to a total stranger.

The man isn’t conjuring a disappearing organ act. He’s actually doing it.

Keep ReadingShow less
Screenshot of Donald Trump; Changpeng Zhao
60 Minutes; Horacio Villalobos/Corbis/Getty Images

Trump Ripped For Hypocrisy After Claiming He 'Doesn't Know' Who Crypto Founder He Just Pardoned Is

President Donald Trump was criticized after he claimed during a sit-down interview with 60 Minutes correspondent Norah O'Donnell that he doesn't know who Binance cryptocurrency exchange founder Changpeng Zhao is despite pardoning him less than two weeks ago.

In 2023, Zhao pleaded guilty to violating anti–money laundering laws after Binance allegedly failed to report suspicious transactions involving groups such as Hamas and al-Qaida. He later apologized, paid a $50 million fine, and served nearly four months in prison before being pardoned by Trump.

Keep ReadingShow less