Get 40% Off
👀 👁 🧿 All eyes on Biogen, up +4,56% after posting earnings. Our AI picked it in March 2024.
Which stocks will surge next?
Unlock AI-picked Stocks

FCC investigating website flaw that exposed mobile phone locations

Published 05/18/2018, 09:00 PM
Updated 05/18/2018, 09:00 PM
© Reuters. FILE PHOTO: The Federal Communications Commission (FCC) logo is seen before the FCC Net Neutrality hearing in Washington

By David Shepardson

WASHINGTON (Reuters) - The U.S. Federal Communications Commission said on Friday it was referring reports that a website flaw could have allowed the location of mobile phone customers to be tracked to its enforcement bureau to investigate.

A security researcher said earlier this week that data from LocationSmart, a California-based tech firm, could have been used to track AT&T Inc (N:T), Verizon Communications Inc (N:VZ), Sprint Corp (N:S) and T-Mobile US (O:TMUS) mobile consumers within a few hundred yards of their location and without their consent.

Senator Ron Wyden, an Oregon Democrat, on Friday had urged the FCC to investigate, saying on Twitter that a "hacker could have used this site to know when you were in your house so they would know when to rob it. A predator could have tracked your child's cell phone to know when they were alone."

He later praised the FCC decision to investigate, as first reported by Reuters.

"I urge the FCC expand the scope of this investigation, and to more broadly probe the practice of third parties buying real-time location data on Americans,” Wyden said.

Robert Xiao, a researcher at Carnegie Mellon University, said a flaw in a demo tool from LocationSmart could have been used to track anyone.

LocationSmart spokeswoman Brenda Schafer said on Friday the vulnerability "has been resolved and the demo has been disabled."

Prior to Xiao's efforts, which included locating up to two dozen users, Schafer said the company believes no one else exploited the vulnerability.

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

The company is committed to "continuous improvement of its information privacy and security measures," she said.

Last week, the New York Times reported that the former sheriff of Mississippi County, Missouri, used Securus Technologies [CASHAL.UL] to track mobile phones - including those of other police officers - without court orders, citing charges filed against him.

Several published reports said Securus is getting its data through an intermediary of LocationSmart.

Verizon spokesman Rich Young said Friday the company has "taken steps to ensure that Securus can no longer access location information about Verizon Wireless customers." He added the company has "initiated a review of this entire issue."

AT&T spokesman Mike Balmoris said the company does not "permit sharing of location information without customer consent or a demand from law enforcement. If we learn that a vendor does not adhere to our policy we will take appropriate action."

Sprint said it is conducting an internal review of the issue. T-Mobile US did not immediately comment.

Securus said later on Friday that access to location-based services "data has been disabled for the time being," out of an abundance of caution and in light of ongoing discussions with partners.

The company also said it has "no direct business relationship with LocationSmart," adding it is ready to work with law enforcement and vendors to reinstate the service as soon as possible.

Last week Wyden said that Securus, a major provider of correctional facility telephone services, was purchasing real-time location information from carriers and providing information "via a self-service web portal for nothing more than the legal equivalent of a pinky promise."

3rd party Ad. Not an offer or recommendation by Investing.com. See disclosure here or remove ads .

Wyden wrote all four of the U.S. major mobile carriers, saying the practice "exposes millions of Americans to potential abuse and unchecked surveillance by the government."

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.