Skip to content
Search AI Powered

Latest Stories

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.

Service Allowed People To Track Pretty Much Anyone Else's Location Through Their Cell Phone. Whoops.
(Ute Grabowsky/Photothek via Getty Images)

Little did consumers know that the smartphones they carried in their pockets also served as a tracking device, not just for phone companies, but for other users thanks to a buggy location demo service.

KrebsOnSecurity reported that a small company called LocationSmart – an aggregator of real-time data of the locations of cell phone users – was inadvertently allowing anyone with free access to the feature without passwords.


The service was enabled on AT&T, Sprint, T-Mobile, and Verizon devices and had the capability of tracking down customers within a few hundred-yard accuracy.



KrebsOnSecurity provided details on how the system works:

LocationSmart's demo is a free service that allows anyone to see the approximate location of their own mobile phone, just by entering their name, email address and phone number into a form on the site. LocationSmart then texts the phone number supplied by the user and requests permission to ping that device's nearest cellular network tower.

After LocationSmart receives consent from the user, they are sent latitudinal and longitudinal coordinates, via text, on Google Street View maps as confirmation.

Sometimes it feels like, somebody's watching YOU.

Giphy



Robert Xiao, a security researcher at Carnegie Mellon University found a way to avoid the authentication process after realizing that LocationSmart "failed to perform basic checks to prevent anonymous and unauthorized queries."

The system's flaw left anyone who is Internet savvy to abuse its function.

I stumbled upon this almost by accident, and it wasn't terribly hard to do. This is something anyone could discover with minimal effort. And the gist of it is I can track most peoples' cell phone without their consent.
This is really creepy stuff.

Don't tell him twice.

Giphy




LocationSmart's demo was taken offline on Thursday after the technical snafu.



The company's founder Mario Proietti had no intention for the service to be free, but was meant "for legitimate and authorized purposes."

It's based on legitimate and authorized use of location data that only takes place on consent.We take privacy seriously, and we'll review all facts and look into them.




The gaffe occurred after the New York Times reported on a little-known service called Securus that allowed law enforcers to track down anyone with a U.S.-based smartphone within seconds.

The service suffered a security breach leaking subscribers' usernames and passwords

Stephanie Lacambra from the Electronic Frontier Foundation said that wireless customers are obligated to location tracking enabling by their cellphone carriers by law. The function is relied upon for improving customer service as carriers use the information in the event of an emergency to comply with 911 regulations.





However, Krebs mentioned the inherent danger in third parties compromising customers' security.

But unless and until Congress and federal regulators make it more clear how and whether customer location information can be shared with third-parties, mobile device customers may continue to have their location information potentially exposed by a host of third-party companies, Lacambra said.



H/T - KrebsOnSecurity, Twitter

More from Trending

Kelly Clarkson
Denise Truscello/Live Nation Las Vegas/Getty Images

Kelly Clarkson Reveals Horrific Comment Her Ex-Manager Once Made About Her Body—And Fans Are Livid

"Kids say the darnedest things" is a popular phrase for a reason, and while it might not have the same ring, maybe we need to change "kids" to "entertainment managers"?

While doing her Las Vegas residency, Kelly Clarkson mixed her most iconic songs with audience interactions and stories of things that have happened during her career.

Keep ReadingShow less
Mid-shot of a female doctor, wearing a stethoscope.
Photo by JESHOOTS.COM on Unsplash

Medical Professionals Break Down Times Patients Accurately Self-Diagnosed With Google

Medical professionals often advise against Googling when we are feeling ill.

WebMD is the enemy.

Keep ReadingShow less
Screenshots of Virginia Foxx and Yassamin Ansari

GOP Rep. Melts Down After Dem Rep. Calls Out Republicans' '8 Weeks Of Taxpayer-Funded Vacation'

North Carolina Republican Representative Virginia Foxx was fuming after Arizona Democratic Representative Yassamin Ansari welcomed her back from the GOP's "vacation" after House Speaker Mike Johnson kept the House out of session for eight weeks.

Johnson adjourned the House after September 19, following the passage of a short-term spending bill to avert a government shutdown.

Keep ReadingShow less
La Toya Jackson
@latoyajackson/Instagram

Fans Concerned After La Toya Jackson Shares Cryptic Videos About Her Health At Doctor's Office

We may not all like the same things or be fans of the same celebrities, music, books, or films, but we all understand the anticipatory grief that comes with the fact that our favorite artists are human, just like us, meaning they will age and eventually create their last piece.

Fans of Dolly Parton, for instance, went through a scare last month when her sister shared a cryptic Facebook post about Dolly, only for the country singer to later have to post a video to reassure her fans that she "ain't dead yet" and was healthy.

Keep ReadingShow less
Gordon Ramsay
Arnold Jerocki/Getty Images

Gordon Ramsay Sparks Debate With NSFW Take On Creating Menus For People Taking Weight Loss Injections

Chef Gordon Ramsay is famous for his outspoken, often acidic take on things arguably even more than he's famous for his food.

His tirades on his television shows Hell's Kitchen and Kitchen Nightmares are renowned for having sparked their own memes and gifs years after they were actually on the air.

Keep ReadingShow less