9 ms·
Yeah, a friend of mine was tracked by a stalker ex boyfriend who worked at a Telco. It was irritatingly difficult to avoid because it seemed he could look up h
by aetherspawn 5mo ago
Yeah, a friend of mine was tracked by a stalker ex boyfriend who worked at a Telco.
It was irritatingly difficult to avoid because it seemed he could look up her SIM card by name and then get her location no matter what (new SIM, new phone)
Anyone who reports this kind of thing to the police just sounds irrational and crazy and gets ignored.
- therobots927 5mo agoAssuming he had access to a database with (lat, long, SIM) data, if she got a new phone he could just use the known (lat, long pairs) from the old sim and lookup to get the new sim. Then bam, you can get all of the new lat longs. It’s impossible to avoid unless you simultaneously move to a new house / apartment when you get your new phone, and never bring the new phone to any previous low-traffic location you brought the old phone to.
- calvinmorrison 5mo agoit's impossible for your precise location to be tracked by anybody... wow thats crazy
- kenjackson 5mo agoWhat does this mean?
- justinclift 5mo agoIf the person was deep enough into the system to have access to location data, then they'd probably be able to just directly look up customer details (likely easier).
- hocuspocus 5mo agoAbsolutely not. I have access to geo-located network telemetry. CRM data is completely off limit to anyone on my team.
- kakacik 5mo agoWell maybe it wasn't such a well secured company and also this seems story from the past.
- hocuspocus 5mo agoBuilt-in positioning of network traces is relatively recent in mobile network equipment and dedicated probes. If that happened more than 5-6 years ago, it would sound even less likely. Most telcos never bothered doing the processing needed to position raw events based on timing advances. They'd simply offload that to third party companies. These solution providers aren't crazy, they don't touch data that isn't already anonymized. It's even less probable that a random employee would have access to the multiple datasets needed to piece someone's personal data together.
- justinclift 5mo agoAre you in a small company where most people wear lots of hats, or in a big company that has siloed off groups? Am guessing it's more of the big company approach that silos things off?
- hocuspocus 5mo agoAs far as telcos go, I work at a pretty small one. We have fewer subscribers than say, a single Chinese operator would have in a second tier city.
- Padriac 5mo agoSounds like something worth reporting as it is an offence in Australia at least. The police would certainly investigate such an allegation and charges could be laid if there was sufficient evidence and a conviction was possible.
- aetherspawn 5mo agoYeah it was reported, but the telcos systems were such a load of slop there wasn’t any specific evidence recorded (logs etc), and besides nobody knew what to ask for, so it couldn’t be taken seriously. I don’t remember the exact circumstances of how they got a confession years later, I think bragging, but he did get convicted and the Telco eventually fired him, which stopped the stalking.
- boringg 5mo agoWhat no log files of who's accessing records? That seems super sketch.
- aetherspawn 5mo agoI’m spitballing here but it seemed like his job was a kind of ITS/technician job in the core infrastructure, and it seemed like he didn’t need to go through normal channels to get the information he wanted, ie he could just like pcap a tower with a filter or whatever in a routine kind of way that I guess didn’t create any specific logs. If there were any relevant logs they would have had to give them to the police. And I know that at a high level Telcos are heavily regulated, so there should have been logs.
- mr_toad 5mo agoDoesn’t surprise me at all. I signed up for an internet plan with a provider once, but they never let me login to pay the bills. After they started threatening me with collections and several phone calls layer it turned out they were billing someone in a completely different city. Complete shambles.
- hocuspocus 5mo agoI'm sorry but this sounds like bullshit. As someone who has access to such data at a telco: - Very few people have legit business cases requiring access to enriched network telemetry, at least non aggregated. - Of which, only a handful have any reason to see the MSISDN in clear. - Of which, none can get access to clear CRM data. - Lawful interception and emergency services use completely separate paths, exposed via user interfaces that aren't available to employees. And obviously, a simple email to the data governance and privacy office would be taken extremely seriously. Also why not simply switch to a different phone operator?
- hnthrow0287345 5mo agoI'm sure every single telco in the world is perfectly in line with this
- hocuspocus 5mo agoEven in pretty dysfunctional countries, or pro-business ones like the US, where nothing like the GDPR exists, telcos management have a strong interest in not letting just any rank and file employee spy on subscribers.
- throwawaysleep 5mo agoMost breaches are not in the interests of management, but they happen anyway as management wants to save money or doesn't understand how it could happen.
- lostlogin 5mo agoStalker terrorises woman, she reports it, nothing happens, stalker kills her. Queue hand wringing. It’s played out a lot of times, in a lot of places, I don’t know why everyone here is so cynical.
- mistrial9 5mo agoyou are close to a system in a way that those guardrails are clear and present; the story is from the point of view of a victim, and it is possible that they were indeed a victim. Therefore the means of the stalking is not known at all via this story, but somehow, something did occur. It is not surprising on either side, and they do not necessarily contradict each other IMHO
- wil421 5mo agoScammy telcos in poorer countries sell SS7 data for a small fee. It will give you all the location data you need.
- pocksuppet 5mo agoSS7 access - you still have to hack the system to acquire the data yourself, and I believe it creates a log that you roamed to that country, and briefly disconnects your cellphone from the network? It's far from invisible.
- pigggg 5mo agoIt's literally a known thing at telcos in various roles they find people looking up folks dox regularly. If someone registers a complaint that someone access their data they'll look it up and deal with them. I once asked someone on the security /investigations side if you are logging what everyone is doing can't you easily find when folks are looking up stuff unrelated to their job? Their answer: we'd have to fire over half the people here - everyone is constantly looking up people's PII - celebrities, friends, enemies, etc. it's almost considered a unofficial perk of the job. This was from one of the largest US Telco carriers circa 2010. Maybe things have changed, hopefully.
- pocksuppet 5mo agoIn Western Europe they would get fired and go to jail. That's why Western Europe doxx information is considered the most expensive in the world. It wasn't complicated to create that situation. They can just fire a few, drag one to court, and rely on the chilling effect.
- dboreham 5mo agoCalling BS on that story. You don't need to fire anyone. You just rate limit access to lookups where the customer didn't initiate a support call themselves, and require supervisor approval and audit of said approvals on a regular basis. I've also worked on systems where accounts could be marked as sensitive (e.g. the celebrities) and those needed additional sign off to be accessed.
- lostlogin 5mo agoI’ve worked in systems like that too. I can tell you exactly how much privacy the celebrities got. There is no record of the sharing or the breaches.
- tamimio 5mo agoWell, my privacy-o-meter made me have my phone with no sim card and always airplane mode, and the sim card is in a dumb phone in my house, that I also barely turn on unless needed. Not perfect, but still far better than being tracked with telecoms.