back
162 comments
I wish journalists would explore why the technical methods & information sharing that enable this surveillance are allowed to exist. Highlighting instances of abuse and the quasi-legal nature of the industry doesn’t really get at the interesting part, which is _what motivates our leaders to allow surveillance in the first place_.

I recently completed Barack Obama’s A Promised Land (a partial account of his presidency), and he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety. I often think about this when I drive past Flock cameras or walk into grocery stores; our leaders seem more enticed by the power of this technology than they are afraid of vague abuses happening in _not here_. It seems like no one sees a cost to just not addressing the issue.

By analogy, I feel that reporting on the dangers of fire isn’t really as effective as reporting on why we don’t have arson laws and fire alarms and social norms that make our society more robust to abuse of a useful capability. People who like cooked food aren’t going to engage with anti-fire positions if they just talk about people occasionally burning each other alive. We need to know more about what can be done to protect the average person from downsides of fire, as well as who is responsible for regulating fire and what their agenda for addressing it is. I’d love to see an article identifying who is responsible for installing these Flock cameras in my area, why they did so, and how we can achieve the positive outcomes desired from them (e.g. find car thieves) without the negatives (profiling, stalking, tracking non-criminals, etc).

Everyone thinks when they have power, they’ll use it correctly, because they have (from their perspective) good intentions.

An ideal government with total surveillance is the best case. You get the benefits of low crime without the drawback of corruption and ideology. The problem is in practice:

- Large institutions aren’t good at exercising fine control: even if the leaders have truly good intentions, corrupt mid-level employees and inaccurate data lead to bad outcomes.

- Good leaders seem to often pick bad successors, and unless they frequently pick better successors, someone will eventually pick a corrupt one.

- Corrupt leaders seem to be good at ousting or sidelining good leaders, more than vice versa, perhaps because good leaders are less passionate about gaining and keeping power.

Perhaps there are other reasons. Not just ideal governments, but even self-preserving governments don’t tend to last. Hence, although decentralization and privacy are never ideal, they should exist at least for backup, “just in case” (inevitably in practice) the centralized surveillance system goes rouge.

> he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety.

This is a cowardly excuse. It's another way of saying that if you reform mass surveillance you'll be blamed for anything bad that subsequently happens, regardless of whether the mass surveillance would have prevented it. And bad things happen on a regular basis with or without mass surveillance, so then the politically risk-averse move is to not solve the problem you promised to solve and not expose yourself.

Which is cowardly specifically because the candidate's original position was correct. You can solve crimes without mass surveillance, or prevent them by reducing poverty etc. If you do those things then the chances of something bad happening go down instead of up.

And it will still not be zero -- it won't be zero no matter what you do -- but in that case you're only worried about adversarial pundits blaming you for things that weren't your fault, and adversarial pundits are going to do that regardless.

Because when you call them leaders and when they see themselves as leaders, they see themselves as a separate class. A permanent difference from the " mere citizen" class.

"Citizens will be on their best behavior because we are constantly recording and reporting everything that’s going on." -- Larry Ellison (who should not be anthropomorphized)

And Ellison is not even a politician, he doesn't even has any kind of immunity. Meanwhile, EU politicians want to impose Chat Control on everyone except them.

The core issue is that they see themselves as different from us.

Politics should not be a career. It should be something a person does for 5, at most 10 years max and after that they are back to being like everyone else, with 0 benefits (and with potentially more surveillance, I think politicians' finances should be under extra scrutiny for the rest of their lives).

> _what motivates our leaders to allow surveillance in the first place_

Surveillance makes their jobs easier, so there's a kind of natural tendency towards authoritarianism. We've known about this for a long time, the 4th Amendment was created to put limits on government surveillance.

If you're wondering why the government would allow private businesses to spy on everybody when the government itself isn't allowed to, that's because this allows for the government to effectively bypass the 4th Amendment. The government spying on everybody is against the Constitution, but a private business spying on everybody and selling the data to the government is "legal".

It might be like prison reform and prisoners' rights - Nobody gets elected on a "soft on crime" platform, and civic engagement at the state and local level is so bad that people typically put up with cameras instead of agitating to get them banned. I say agitate. Show up, keep showing up, keep talking, keep telling friends. We can fight this. Democracy will work if we get people onboard, one way or another
> he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety

Assuming that he was sincere about wanting reform in the first place (and that's a big if for any book like this! The best you can say for Obama vs. most other politicians, is that he at least likely wrote it himself), what it means was that he was persuaded that mass surveillance was useful. He doesn't say how, or by who, he just vaguely waves at the burden of command.

> It seems like no one sees a cost to just not addressing the issue.

It's the same "impose a small but poorly defined cost on everybody and act as though it's worth it because it maybe saves one defined life and therefore anyone who wants to call you out has an uphill battle" model you see used by bad people and dishonest comment section types the world over.

Society has no good way to reason about these "it's not much individually but when you do it to all of society it adds the F up" type downsides.

Like if you could save one life per year at the cost of making it take everyone an extra minute per day that's obviously not worth it at the scale of the united states because you're actually losing more life than you're saving.

But replace the "one minute" with something more subjective and nobody calls it out.

> he mentions in his book that although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety.

Obama didn't swear an oath to safety, but he did swear an oath to protect the constitution. He is an oath breaker and not a man of integrity, but if we choose to trust his excuse then maybe we can forgive him as an individual for being frightened by the horror stories told to him by power hungry three letter agencies, but we should never forgive him as a president for his failure to uphold his oath. Obama studied and taught constitutional law. He knew exactly how important the oath he took was and what would be at risk if the constitution was ignored.

It will always be more "safe" to take people's freedom and control them. Safety is just not an acceptable excuse to take away the freedoms of every American.

I’m not totally opposed to surveillance, I just wish it was more transparent and limited to need to know uses.

If the police need your google search history thats ok as long as they can get a warrant showing they have justification and then perhaps at a delayed time, the account owner should be notified that this happened.

If they need access to your phone, rather than hacking it they should just take it off you and get the password from you.

This limits tracking since this is a fairly disruptive and visible thing and prevents just passive tracking of everyone all the time.

Businesses who use facial recognition for loss prevention should be legally required to only use their data for this purpose and never for marketing and analytics. They must not ever sell the data and delete it within a reasonable time.

> I wish journalists would explore why the technical methods & information sharing that enable this surveillance are allowed to exist.

It boils down to one thing that allows these surveillance technologies to exist: public apathy.

although he wanted to reform mass surveillance, it looked a little different once he was actually responsible for people’s safety

Power corrupts.

I know this isn't a popular stance but in the present age of surveillance, mandated 24/7 body cams on every civilian might actually not be such a bad thing so long as you aren't a bad person. [edit] ideal world, and all of that et al
> it looked a little different once he was actually responsible for people’s safety.

That seems highly disingenuous or just ignorant. We publicly had this problem starting in the 1990s. The NSA used to have a program that would capture data but then encrypt it and protect it from random access. They discontinued that program and instituted a new one that had zero privacy protections in it.

This was right at the turn when the "war on terror" started. Which was the excuse then used to abandon the better program for the egregious one since it was projected to be better for this particular use case. It's debatable whether that was true or not.

> Flock cameras or walk into grocery stores

Record it if you want. Law enforcement, at any level, should require an actual warrant to access it in any form. This isn't a binary. You can enhance security and privacy at the same time.

> I wish journalists would explore why the technical methods & information sharing that enable this surveillance are allowed to exist

You mean to ask questions ? No way. /s

It is about a company, First Wap, that makes it possible to track individuals. Their USP is a piece of software that operates at phone network level and uses the fact that phone companies still support an old protocol, Signalling System 7:

> Phone networks need to know where users are in order to route text messages and phone calls. Operators exchange signalling messages to request, and respond with, user location information. The existence of these signalling messages is not in itself a vulnerability. The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose.

> These signalling messages are never seen on a user’s phone. They are sent and received by “Global Titles” (GTs), phone numbers that represent nodes in a network but are not assigned to subscribers.

> The issue is rather that networks process commands, such as location requests, from other networks, without being able to verify who is actually sending them and for what purpose

'Fun' fact: "other networks" includes all foreign networks with a roaming partnership. It's possible to abuse SS7 to track people across borders, from half the world away.

I assumed it was the telecoms just selling the data about their subscribers. https://www.telecomstechnews.com/news/fcc-fines-major-telcos...
"Why the US still won’t require SS7 fixes that could secure your phone" (2019) https://arstechnica.com/features/2019/04/fully-compromised-c...

  the group:

    - dragged its feet on resolving SS7 security vulnerabilities 
    - repeatedly ignored input from DHS technical experts
    - [identified] best practices.. using different filtering systems
    - [but] pushed.. to rely on voluntary compliance
It's fascinating how these secrets are turning up in the press now. The article is (probably intentionally) vague about it's sources: they only say "Lighthouse found a vast archive of data on the deep web". But reading between the lines - does that imply that this surveillance company kept records on thousands of targets, and then left them in an open S3 bucket? Not the first time - the TM_Signal leak of upper-echelon U.S. government communications was also facilitated by an open S3 bucket that contained the message archives of everything that, say, the Secretary of Defense was messaging to the POTUS.

But it is highly ironic that these companies specialize in surveillance, tracking, and security, and then have a tendency to leave the data that they steal from others open to the Internet in a very amateurish security lapse that in turn leads to everyone stealing from them.

If I can make a guess, I'd say that the reporters engaged with them as a potential customer and demanded a sample of the data so they can indeed verify the accuracy. That's how they obtained the sample records, not via a s3 leak.
For anyone interested, they also have a technical explainer that describes their methodology in detail.

https://www.lighthousereports.com/methodology/surveillance-s...

SS7 telcom vulns still seem to be prevelant in 2025:

Femtocells and Fake Base Stations Attackers deploy femtocells — small cellular base stations — or fake base stations, commonly known as IMSI catchers, to intercept SS7 traffic. A modified femtocell can act as a man-in-the-middle, capturing signaling messages between a phone and the network.

Fake base stations mimic legitimate cell towers, tricking devices into connecting and relaying SS7 messages to the attacker’s system.

IMSI catchers exploit a known security vulnerability in the GSM specification, which requires the handset to authenticate to the network but does not require the network to authenticate to the handset. They broadcast a stronger signal than legitimate cell towers to lure mobile phones into connecting. Once connected, an IMSI catcher can force the transmission of the International Mobile Subscriber Identity (IMSI) and compel the connected mobile station to use no encryption or easily breakable encryption.

For 3G and LTE networks, sophisticated IMSI catcher attacks may involve downgrading the connection to less secure non-LTE network services to bypass enhanced security features. For example, a hacker might deploy a fake base station near a target to capture their IMSI and initiate SS7 queries.

https://www.how2lab.com/tech/mobile-communication/ss7-vulner...

I could not compare it completely, but it sounds very much like this talk that I saw many years ago at the CCC.

SS7: Locate. Track. Manipulate. [2014] https://media.ccc.de/v/31c3_-_6249_-_en_-_saal_1_-_201412271...

I think the world is not ready for the level of surveillance that exists in the wild.

For example, this post could have been a product of just probing a particular group of people to understand if they are interested in the subject and what they have to say about it.

That can be done indirectly, by suggesting someone (offering a link or planting an idea) that is already known to be interested in surveillance and prone to share interesting discoveries (in other words, the poster might not even be aware he could be an asset).

Think about the many ways someone could know your interests and how prone you are to react to something and how that could be used. If you are in tech, think about all the silly ways that kind of information can leak publicly.

People often disregard the possibility that they could be an active part of a surveillance network (as an unkowingly asset), instead focusing on more fantastical ideas such as technological hacks or coding wizardry.

> This investigation began with an archive of data. [...] It contains 1.5 million records, more than 14,000 unique phone numbers, and people surveilled in over 160 countries.

Why not HIBP (Have I Been Pwned) style site to check against the database if your number is in?

In Europe:

- Almost everyone has a phone.

- Almost everyone takes their phone wherever they go.

- All SIM-cards have been forcefully (by law) linked to people's identities.

- Almost all people are therefore being tracked.

Stallman was a firebrand and jerk, but he was right. When it comes to devices that have the potential to invade our privacy and make us easy targets for authoritarian governments, every last line of code and every transistor should be open.
Reads like they’re doing one of several way to get mobile device IDs, and then x-ref those against anon’d adtech datasets that anchor on the mobile ID.

If your device privacy is a mess, mobile ID links you to all the good and bad things you do on a phone.

Had no idea this was part of the tool options, but backbone cell network makes sense.

Other TTPs I’d read about was variations on geo-fenced adserving to phish a mobile ID basically via user interaction or scroll past the ad. Small enough geofence and do it a few times, one could safely figure out the user being the ID. Googling “RTB surveillance” or “DSP surveillance” are ways into the topic.

Scary stuff! Pair that with this tech has been working for years, and is international. Frames a bit differently every action by a public figure - also at risk via the same threat model.

Also long have wondered what data analysis like this is done on technical forums… ran by a VC firm… with a lot of insider context (product market fit?) in the comments.

And then they call people paranoid to go off the grid.
> The story of Altamides dates back to the early 2000s, when former *Siemens* engineer Josef Fuchs recognised a critical vulnerability in the global telecom network. By exploiting (...)

Reminder that around the same time a joint venture of Nokia+Siemens had been developing and deploying deep packet inspection and surveillance systems in Egypt and Iran. They got called out by human rights organisations and posted an "oops sorry\" press release.

Privacy isn't just about hiding, it's about having the freedom to grow and change without constant watching. We need more leaders who understand this simple truth.
Take a look at the agenda and tracks for the conference referenced in the article some of the talk summaries are wild https://www.issworldtraining.com/ISS_EUROPE/ "In this talk, we shall discuss various security mechanisms used in WiFi and Bluetooth networks and how to abuse them"
> We found Netflix producer Adam Ciralsky, Blackwater founder Erik Prince, Nobel Peace Prize nominee Benny Wenda, Austropop star Wolfgang Ambros, Tel Aviv district prosecutor Liat Ben Ari and Ali Nur Yasin, a senior editor at our Indonesian partner Tempo.

Political figures being there I somewhat understand, but a Netflix producer? Why would anyone need to track a Netflix producer?

Visiting the site is a one of a kind "back in time" experience: it was probably developed in 2000[1].

Even the WAP part of the name makes me wonder[2].

I know I have some futile questions, but why does seem France so untouched? [3]

[1] <https://www.1rstwap.com>

[2] <https://en.wikipedia.org/wiki/Wireless_Application_Protocol>

[3] <https://i0.wp.com/www.lighthousereports.com/wp-content/uploa...>

I didn't quite understand how they are capable of tracking people and breaking WhatsApp encryption.

There is mention of fake antenna but I don't think they cover entire country with that, how do they do?

I must say translation in Firefox is great. Now I don't have to learn Turkish...

As for article, imagine, at those times and for thousands years after in most places humans were still hunting-gathering..

What I understand is that this SS7 is difficult to get rid of. If I understand it correctly, the purpose of the location queries is for routing calls/messages. Couldn’t (shouldn’t?) telecom providers run monitoring and alerting if location queries are fired without a subsequent call/message?
When even Obama couldn't resist the power of surveillance, maybe it's not the tech we should fear, it's how easily power changes good intentions.
Where can I find the list? I got some contacts that might be in there
Another brilliant example, why we need good (cooperating, international) journalism
Democracy was an experiment from the beginning. All the funding for that experiment dried up long ago. When democracies fail new ones do not replace them. Disposing of the US over some trivial BS is not wise. The replacement forthcoming will be much worse than what we have now. It is literally impossible to do better in this day and age. We are looking at the ultimate failure of not only capitalism and democracy, but western values and even common morality.

The new reality is that the surveillance state is part of the ride. If you are not a rapist or pedophile then why would you be concerned about cameras in Public anyways? If nobody is trying to smuggle children then why do we keep losing them? These ideas would not get so much traction if they were not a legitimate response to a real world stimuli.

Favouring any argument made by non citizens and/or “the naysayers” tends to be labeled as “Anti” which is a dangerous label

I would assume anyone who has kids would support the idea of tracking programs because it implies a higher level of operational security and access denial. I am truly curious who's voices these are calling for transparency and open security, because they are trying to rape your daughter. Prove me wrong, prove me wrong. I repeat, only a rapist, thief, terrorist or spy would be alarmed about the development of this “Surveillance State” technological paradigm. So when the trolls try to argue Philosophy as some generic excuse to protest scrutiny, take another look. What does he have to hide. What business is it of theirs to speak for you about cyber security or domestic opsec? And in fact who are you to care about that stuff at all either?

mind reading technology is here, an actual reality
Did I miss something? This was not surprising. I figured all this would have been possible (and commonplace) decades ago. I was expecting this to be about government eyes and ears in my toilet or something.