sunny.png
Thursday October 17th, 2019 1:55PM

Website flaw exposes real-time locations of US cellphones

By The Associated Press
Related Articles
  Contact Editor

A website flaw at a California company that gathers real-time data on cellular wireless devices could have allowed anyone to pinpoint the location of any AT&T, Verizon, Sprint or T-Mobile cellphone in the United States to within hundreds of yards, a security researcher said.

The company involved, LocationSmart of Carlsbad, California, operates in a little-known business sector that provides data to companies for such uses as tracking employees and texting e-coupons to customers near relevant stores.

Among the customers LocationSmart identifies on its website are the American Automobile Association, FedEx and the insurance carrier Allstate. LocationSmart did not immediately respond to emails and telephone messages seeking comment on the flaw and its business practices.

The LocationSmart flaw was first reported by independent journalist Brian Krebs. It's the latest case to underscore how easily wireless carriers can share or sell consumers' geolocation information without their consent.

The New York Times reported earlier this month that a firm called Securus Technologies provided location data on mobile customers to a former Missouri sheriff accused of using the data to track people without a court order. On Wednesday, Motherboard reported that Securus' servers had been breached by a hacker who stole user data that mostly belonged to law enforcement officials.

Securus may have obtained its location data indirectly from LocationSmart. Securus officials told the office of Sen. Ron Wyden, an Oregon Democrat, that they obtained the data from a company called 3Cinterative, said Wyden spokesman Keith Chu. LocationSmart lists 3Cinteractive among its customers on its website.

Wyden said the LocationSmart and Securus cases underscore the "limitless dangers" Americans face due to the absence of federal regulation on geolocation data.

"A hacker could have used this site to know when you were in your house so they would know when to rob it. A predator could have tracked your child's cellphone to know when they were alone," he said in a statement.

LocationSmart took the flawed webpage offline Thursday, a day after Carnegie Mellon University computer science student Robert Xiao discovered the software bug and notified the company, Xiao told The Associated Press.

The doctoral researcher said the bug "allowed anyone, anywhere in the world, to look up the location of a U.S. cellphone," said Xiao. "I could punch in any 10-digit phone number," he added, "and I could get anyone's location."

The web page was designed to let visitors test out LocationSmart's service by entering their cellphone number. The service would then ring their phone or send a text message to obtain consent, after which it would display the phone's location — generally to within several hundred yards.

But Xiao found a flaw that allowed him to bypass consent in just 15 minutes. "It would not take anyone with sufficient technical knowledge much time to find this," he said. He wrote a script to exploit it.

"It was just surreal when I discovered this," he said. Xiao's research indicated that LocationSmart had offered the service since at least January 2017.

LocationSmart touts itself as the "world's largest location-as-service company." It says it obtains location information from all major U.S. and Canadian wireless companies, with 95 percent coverage.

Representatives for AT&T and Sprint said they don't allow sharing of location information without individual consent or a lawful order such as a warrant. Verizon spokesman Rich Young said the company has taken steps to ensure that Securus can no longer request information on the company's wireless customers and that it was reviewing its relationship with LocationSmart.

T-Mobile did not immediately respond to a request for comment.

Gigi Sohn, a former top aide at the Federal Communications Commission during the Obama administration, said user location data has been at high risk since last year. That's when Congress repealed FCC privacy rules barring mobile wireless carriers from sharing or selling it without customers' express "opt-in" consent.

"At a bare minimum, consumers should be able to choose whether a company like LocationSmart should have access to this data at all," she said.

---

AP Technology Writer Matt O'Brien contributed to this report.

  • Associated Categories: Associated Press (AP), AP Business, AP Technology News
© Copyright 2019 AccessWDUN.com
All rights reserved. This material may not be published, broadcast, rewritten, or redistributed without permission.
JC Penney outlook spooks Wall Street
J.C. Penney blamed weak clothing sales on bad spring weather and said it would offer more plus-size fashions to try and boost sales.
5:54PM ( 6 minutes ago )
Walmart beats all around, with online sales rebounding
Walmart reports better-than-expected profit and revenue for the first quarter with rebounding online sales
5:52PM ( 8 minutes ago )
Ground-penetrating radar in hunt for dead in racial massacre
Researchers seeking possible mass grave site in Louisiana from 1887 racial massacre report finding signals of disturbed earth but don't know yet what ground-penetrating radar detected
5:51PM ( 8 minutes ago )
Associated Press (AP)
School bus ripped apart in dump truck crash, killing 2
New Jersey Gov. Phil Murphy says the crash of a dump truck and a school bus taking children to a field trip has killed a student and an adult
5:33PM ( 26 minutes ago )
FDA names drugmakers accused of blocking cheaper generics
U.S. drug regulators are publicizing information on brand-name drugmakers that use what government officials call "gaming tactics" to block cheaper copycat versions
5:23PM ( 36 minutes ago )
Hawaii volcano erupts anew, spews huge plume of ash into sky
Hawaii volcano erupts anew, spews huge plume of ash 30K feet into sky
5:18PM ( 41 minutes ago )
AP Business
JC Penney outlook spooks Wall Street
J.C. Penney blamed weak clothing sales on bad spring weather and said it would offer more plus-size fashions to try and boost sales.
5:54PM ( 6 minutes ago )
Walmart beats all around, with online sales rebounding
Walmart reports better-than-expected profit and revenue for the first quarter with rebounding online sales
5:52PM ( 8 minutes ago )
Ground-penetrating radar in hunt for dead in racial massacre
Researchers seeking possible mass grave site in Louisiana from 1887 racial massacre report finding signals of disturbed earth but don't know yet what ground-penetrating radar detected
5:51PM ( 8 minutes ago )
Police: Rifle bought by mom used in Illinois school shooting
Police say a teenager used a 9mm semi-automatic rifle in firing shots at a northern Illinois high school before he was stopped by a school resource officer
5:43PM ( 16 minutes ago )
Prosecutor: Greitens' lawyers threatened to 'ruin' her
The St. Louis prosecutor whose office now finds itself under investigation by police over its handling of a criminal case against Missouri Gov. Eric Greitens says his attorneys twice threatened to "ruin" her if she didn't back off
5:41PM ( 18 minutes ago )