Four of the largest U.S. wireless carriers, T-Mobile, AT&T, Verizon and Sprint, face a potential collective fine of $200 million for failing to secure location data sold to third parties.
Data Privacy
Technological development has always outpaced privacy concerns, but never more so than in the past decade. Collection and centralization of personally identifiable information (PII), tracking of movements and digital surveillance are all at unprecedented levels. Regulations and laws are only just beginning to catch up to the ability of both governments and private entities to deploy these capabilities.
What exactly is there to worry about? The mass collection and centralization of data by giant multinationals such as Facebook and Google is as good of a place to start as any. Two decades of vacuuming up the personal data of users of various online services has created the most impressive marketing capabilities in history, but these profiles have astounding potential for damage when they are used the wrong way or fall into the wrong hands.
Unauthorized information that is captured in data breaches tends to find its way to massive “combo lists” that are sold and traded on the dark web. Social security numbers are added from this breach, home addresses and phone numbers from that one, personal health information from yet another. Soon, a frighteningly complete profile of millions of individuals is available to anyone willing to pay the asking price.
These are just the established data privacy issues. The emerging ones are even worse. High-quality facial recognition technology is just beginning to roll out across the public places of some countries. Artificial intelligence is not only making mass facial recognition possible, but magnifies the power and reach of any application that involves capturing and sorting information: scanning pictures, analyzing speech, sifting through text and location data. This threatens to not only shatter anonymity and privacy, but allow for highly advanced impersonation and take the concept of “identity theft” to new levels.
Some businesses chafe at the trouble and added expense of new and emerging data privacy regulations, but they are vital to both protecting rights and privacy and instilling confidence in end users. Customers want to be able to submit their payment information without worry about data breaches and identity theft, use services without wondering what is being done with their personal information and use devices without fear of surveillance or having location data tracked. The need for meaningful safeguards only grows greater as technological capabilities increase.
Enhanced 911 location data would make it possible for emergency first responders to more accurately find and locate people making 911 calls. What are the privacy implications since the biggest U.S. telcos have been secretly selling location data of their customers to a shadowy network of data brokers and data aggregators?
Recent FTC settlement with the popular Flo Fertility Tracking app came with a warning from the agency to other health apps that engage in questionable data sharing practices.
Study from Citizen Lab Toronto explores the WeChat ecosystem and finds that data sharing can exceed what the user expects, and that the privacy policy does not always make the extent of this sharing clear.
The controversial warrantless surveillance program enacted under Section 702 of the FISA Amendments Act will go on with some alterations to privacy rules, according to a FISA court ruling.
New declassified ruling shows how FBI abused the constitutional privacy rights of U.S. citizens in 2017 and 2018 by using NSA surveillance data to conduct backdoor searches.
The Five Eyes has put the tech industry on notice. They want access to data from tech companies and while there is no formal demand for encryption backdoors, the Five Eyes believe government agencies should have access to encrypted information.
Annual calls for what would effectively be the end of hardware encryption have been renewed by the "Five Eyes" nations along with India and Japan, as they press for universal encryption backdoors.
In general, law enforcement does not have access to E22E messages sent via secure messaging apps. However, there is a workaround: message backups sitting in cloud storage services.
A FOIA request filed by the New York Times has led to the release of documents that show officials making a push to use Pegasus spyware in criminal investigations from late 2020 into mid-2021.









