[00:00.640 --> 00:01.760] All right. [00:01.920 --> 00:02.900] Well, I'm Alex. [00:03.100 --> 00:09.180] I'm very excited to introduce the first EFF talk of HOPE 2025 here. [00:09.940 --> 00:17.500] And we're going to hear some very, very interesting stuff about how a handful of location data brokers actively track millions. [00:17.760 --> 00:20.400] And then we're going to also learn about how to stop them. [00:20.740 --> 00:22.860] So mitigation techniques are always good. [00:23.080 --> 00:30.760] And to instruct us in this very important topic, we have Bill Buddington, who is a staff technologist at the EFF. [00:31.120 --> 00:33.880] He enjoys cryptography in his spare time. [00:35.200 --> 00:40.660] He is also... his research has been featured in the New York Times. [00:41.000 --> 00:43.960] He has also been cited by U.S. [00:44.140 --> 00:45.540] Congress, if you can believe that. [00:47.140 --> 00:50.200] And he's based out of San Francisco and he's with the EFF. [00:50.420 --> 00:57.820] We have also joining with us, coming from Washington, D.C., Lena Cohen, who is another staff technologist with the EFF. [00:58.260 --> 01:04.760] And her work at the EFF has primarily focused on what many of you will know as Privacy Badger. [01:05.220 --> 01:08.560] And so they've both done extraordinary work. [01:08.600 --> 01:10.560] And we're very excited to hear from them. [01:10.880 --> 01:13.240] So give it up for Lena and Bill. [01:19.220 --> 01:19.900] Thanks, everyone. [01:19.920 --> 01:25.140] And thanks for coming to the first EFF talk of 2025 HOPE. [01:27.520 --> 01:31.140] So, first of all, if you don't know about us and who EFF is... [01:31.880 --> 01:32.960] Yeah, let me do that. [01:33.920 --> 01:34.160] Turn. [01:34.900 --> 01:38.000] Can you get some more audio? [01:38.260 --> 01:38.320] Great. [01:39.000 --> 01:40.540] So who are we? [01:41.800 --> 01:48.820] We're a 501c3 nonprofit based in the San Francisco Bay Area, although we do international and national work as well. [01:50.260 --> 02:07.140] We are technologists who develop technologies like Privacy Badger and, um, normally HTTPS Everywhere, uh, and other technologies, uh, Ray Hunter being one, um, that, uh, work on making Internet, uh, safer and more secure. [02:07.380 --> 02:10.200] And you're, uh, defending your privacy. [02:10.440 --> 02:17.820] We also have activists that work against, uh, bad legislation, and sometimes for good legislation when that comes around every so often. [02:18.240 --> 02:21.840] Uh, and lawyers, uh, who do things like Sue Doge. [02:22.120 --> 02:24.980] Uh, yeah, we are surveillance technologists. [02:29.920 --> 02:41.580] Uh, we, uh, we, uh, fight against expanding, the expansion of, and seemingly ever expansion of surveillance technologies, uh, and the threats to your privacy rights. [02:43.400 --> 02:50.840] We conduct outreach, advise lawmakers, and fight bad legislation, as I mentioned, developing technologies to that end. [02:51.600 --> 03:00.700] Here are some resources that you can look up, um, to find out more about us and, um, possibly donate to us if you like our work. [03:05.520 --> 03:06.840] Now, who the hell am I? [03:07.360 --> 03:10.380] Well, I'm a senior staff technologist at EFF. [03:11.300 --> 03:14.620] Uh, work with the public interest technology team. [03:15.760 --> 03:25.010] Uh, and work on our threat lab and cyber security policy working groups, uh, kind of internal ways we figure out, uh, what to tackle at EFF. [03:26.750 --> 03:33.270] Previous work of mine includes HDBS Everywhere, uh, leading that project from 2015 to 2018. [03:34.490 --> 03:35.190] Thank you. [03:36.190 --> 03:43.850] Uh, currently, uh, HDBS Everywhere has kind of been retired now that the browsers have, uh, have adopted a lot of the things that we first pioneered. [03:44.010 --> 03:51.790] But, uh, currently I'm working on Panopticlic, which is still a browser fingerprinting tool, to figure out how trackable you are. [03:52.930 --> 03:59.750] AP Keep, which is, uh, a command line tool for downloading APKs from various sources, Google Play, FDroid, et cetera. [04:00.710 --> 04:04.330] And some malware reversing, uh, focusing on Android primarily. [04:06.990 --> 04:07.310] Hi, everyone. [04:07.610 --> 04:08.390] Uh, I'm Lena. [04:08.710 --> 04:10.850] I'm also a staff technologist at EFF. [04:11.290 --> 04:14.090] I primarily work on Privacy Badger. [04:14.310 --> 04:17.490] It's, uh, EFF's free browser extension. [04:17.490 --> 04:21.570] It stops companies from spying on you as you browse the web. [04:21.750 --> 04:23.510] I highly encourage everyone to download it. [04:23.990 --> 04:30.170] Um, I also just do general advocacy for consumer privacy and against corporate surveillance. [04:40.170 --> 04:45.150] So, who here, show of hands, has heard of a company called Gravy Analytics? [04:46.070 --> 04:47.450] All right, a few of you. [04:47.730 --> 04:54.390] Uh, you should, uh, a few of you, a few more of you should know about them because they are a massive threat to our privacy. [04:54.930 --> 05:00.730] One of the slogans that they, uh, have is, where we go is who we are. [05:01.790 --> 05:10.770] Yeah, being that we're in a talk about, uh, the data brokers dealing with their location, this, this slogan kind of reminds me of this guy here. [05:13.010 --> 05:20.490] Um, so, Gravy Analytics is, as I mentioned, a location data broker. [05:21.490 --> 05:28.690] Uh, their claim is that they collect detailed location information from one billion people every day. [05:30.710 --> 05:52.370] These include locations like where we live, which points to our residence, where we work, which points to our profession, where we meet with others, which points to our associations, where we worship, which points to our religions, and where we protest, [05:52.790 --> 06:00.570] which points to our political affiliations, And also where we seek medical care, pointing to our sensitive conditions. [06:03.990 --> 06:08.630] The Wall Street Journal reported about Gravy Analytics and their business dealings. [06:08.830 --> 06:26.110] They sell to organizations on the federal level, like DHS and ICE, with a $1,000 contract in 2018 and $1.1 million by CBP. [06:26.110 --> 06:28.990] First reported by Washington Post in 2017. [06:32.050 --> 06:49.130] And then with all your information that they had stored, there was a data breach earlier this year, where widely reported, both in 404 Media and TechCrunch. [06:49.310 --> 07:01.290] And here's a screenshot of the data that was collected from that breach of all of the Tinder... or a fraction of the Tinder users in the UK. [07:03.850 --> 07:17.570] So this breach was just a small subset of the total data that they had collected, which is only several terabytes of consumer data, each geolocation comprising of a few bytes. [07:18.890 --> 07:20.510] You know, you do the math. [07:20.710 --> 07:37.470] It includes historical location data on millions of smartphones, sourced from thousands of apps, which included Tinder and Grindr dating apps, Candy Crush and Temple Run, games like that, weather apps, finance apps, and more. [07:39.190 --> 07:49.750] But funnily enough, when journalists reached out to these apps, then they... most of them had no idea and didn't even know about a company called Gravy or its parent company, Ventel. [07:51.510 --> 07:52.250] Wait a minute. [07:52.310 --> 07:52.970] How is that possible? [07:54.890 --> 08:03.170] How is it that billions of people's location data makes its way from these apps to Gravy Analytics without app developers' knowledge? [08:06.030 --> 08:27.730] The answer to this question lies with the data brokers and location data brokers, their business dealings, how they collect information, how they gather that information on our locations, what tools they create based on that information, and who eventually gets it. [08:30.910 --> 08:42.110] In this talk, we're gonna kind of explore how this happens, what you can do to protect yourself against this, and why we need federal privacy legislation to fix it. [08:44.870 --> 08:53.170] So, zooming out a little bit, Gravy Analytics is part of this multi-billion dollar data broker industry. [08:53.550 --> 09:06.790] Data brokers are companies whose main business model is collecting and selling information about people, typically people who they have no direct relationship with and don't provide any services to. [09:07.390 --> 09:19.650] They can build up profiles of people's interests, locations, relationships, transactions, browsing history, and more, and sell it to basically anyone willing to pay. [09:20.610 --> 09:24.230] The data broker industry is very opaque. [09:24.230 --> 09:30.090] So, even though they know a lot about us, we don't know enough about them. [09:30.490 --> 09:46.970] We know the names of about 800 data brokers in the U.S., because certain states have transparency laws that require them to register, but the EFF has found that hundreds of data brokers are not following these transparency laws. [09:48.990 --> 09:55.210] It's almost impossible to know who data brokers are selling your personal information to. [09:55.650 --> 10:04.870] Under several state privacy laws, you can request access to information that companies have about you and the categories of businesses they're selling to. [10:05.210 --> 10:10.850] This is a screenshot of a response I got from Axiom, a major data broker. [10:10.850 --> 10:18.530] These are like the, you can see at the top, data sold, data category, and third-party recipient category. [10:19.270 --> 10:27.810] I know they've sold my sensitive information to dozens of businesses, but I don't have many useful details beyond that. [10:27.970 --> 10:32.590] Like, I can tell they sold my geolocation info to a financial services company. [10:32.910 --> 10:36.290] An insurance company got inferences about me. [10:36.990 --> 10:41.430] But this is my sensitive information, so I would like to know a lot more than that. [10:44.230 --> 10:58.250] There are many different types of location, of data brokers, but today's talk is going to focus on location data brokers, which are companies that sell, collect and sell information about people's precise movements. [10:58.250 --> 11:00.710] Some of them sell... [11:01.200 --> 11:01.570] Sorry. [11:01.890 --> 11:08.650] Some of them sell lists of people based on their location data, like lists of people who... [11:08.650 --> 11:18.150] lists of devices that were in a certain location in a certain time period, and others sell raw location data, like what's pictured up here. [11:18.970 --> 11:20.730] Gravy Analytics does both. [11:21.110 --> 11:37.530] This is a data dictionary from Mobile Walla, another location data broker, and you can see that they're selling exact latitude, longitude, device identifiers, the name of the app that the data is coming from. [11:38.250 --> 11:46.810] And stitched together, all of these data points can create a very intimate picture of someone's life. [11:47.010 --> 11:55.450] Even though a lot of these data brokers claim the precise location data they're selling is anonymous, because there's not names attached. [11:55.750 --> 12:00.370] It's trivial to attach device identifiers to people's real identities. [12:01.470 --> 12:11.630] And once you know where someone sleeps and where someone works during the day, you can understand how easy it is to narrow down who they are. [12:13.790 --> 12:19.970] So, unfortunately, Gravy Analytics is not the only company trafficking in this sort of data. [12:20.310 --> 12:31.850] The markup in 2021 identified about 47 companies that are harvesting, selling, trading your location data. [12:33.490 --> 12:38.090] And, yeah, so where do they get all of this data? [12:38.390 --> 12:41.470] The answer is, unfortunately, our phones. [12:42.630 --> 13:00.170] You've probably had an app ask for permission to have your location information, and you might have trusted it because the app obviously needed your location for some functionality, like a weather app needs your location to send you the location in your area. [13:00.170 --> 13:14.270] But as many of you know, apps often have code that shares data with third parties, including the location information that you shared with the app and wouldn't want a third-party to know about. [13:15.010 --> 13:33.170] So, data brokers are not transparent about their sources, but thanks to the excellent work of investigative journalists and government enforcement agencies, we do know about two common paths that data can take that location data can take from your apps to a data broker. [13:33.330 --> 13:34.910] I'll let Bill talk about the first one. [13:35.570 --> 13:39.870] Yeah, so the first path is embedded SDKs that are included in apps. [13:41.250 --> 13:55.050] So, the way it works is that in exchange for some monetary or insight, monetary kickback or insight knowledge, app developers include software development kits for location data brokers within their apps. [13:56.250 --> 14:04.210] And the app, if it has location data, location permissions enabled, it can deliver that precise location directly to the data broker. [14:05.690 --> 14:24.070] But even in cases where the location permission is not given to an app, that can be the precise, or more course location can be inferred from, say, for instance, IP address or other metrics that are delivered to the data broker. [14:25.710 --> 14:35.810] Google even provides an API for, given which sensors you've given to the app, here is the best we can do to locate this user. [14:35.810 --> 14:44.570] And so, one example of a company that provides an embedded SDK is XMode Social. [14:47.030 --> 14:55.610] We've reported on XMode and its parent company, OutLogic LLC. [14:58.390 --> 15:07.610] And according to the FTC, its own marketing material claims that it is the second largest U.S. [15:07.710 --> 15:14.250] location data broker company, collecting 10 billion data points per day. [15:16.350 --> 15:26.850] XMode advertising this location data is accurate to about 20 meters or less for 70% of the users. [15:27.850 --> 15:41.070] I'm promising that users, if you include their SDK in your app, then you'll get passive revenue collection for each consumer device that they collect from you. [15:43.610 --> 15:48.630] It's been included in more than 300 apps, including games, fitness trackers, and religious apps. [15:49.030 --> 16:07.970] But it's not only collected, it's also bought directly by a company like XMode, or XMode, from other data brokers directly, but also from app developers that have collected this and are storing it on their server and they just want to transfer it directly to XMode. [16:08.450 --> 16:15.230] Even if it's not sending that API call out to XMode directly, well, the app developer has it. [16:15.370 --> 16:16.610] Hey, can you give it to us? [16:22.190 --> 16:24.670] They also developed their own apps. [16:24.810 --> 16:28.490] And this is kind of initially how they began selling data that was collected. [16:29.630 --> 16:36.730] They developed an app, a couple of apps, called Walk Against Humanity and Drunk Mode. [16:38.510 --> 16:47.090] And this is kind of an app that was, you get into a car and you kind of do some logic problems and determine if you're too drunk to drive. [16:48.410 --> 16:50.290] So that's where they came from. [16:50.310 --> 16:55.450] And they were like, Oh, we have all this juicy data that we can just give over to someone. [16:55.950 --> 16:57.070] This is apparently valuable. [16:57.590 --> 16:58.490] Let's sell it. [16:59.950 --> 17:19.550] And they sold to hundreds of clients in a range of different markets, including finance, determining whether you get a loan, real estate, determining whether you are given a mortgage, for instance, and selling it to U.S. defense contractors and law enforcement across the country as well. [17:20.930 --> 17:37.050] Not only did they sell this raw location data that's tied to unique identifiers, but also they determined and inferred different inferences from this information as well. [17:37.330 --> 17:49.030] For instance, the FTC complaint lists a list of devices that visited a customer-provided list of specialty infusion centers for at least an hour. [17:49.490 --> 17:51.910] So this is no joke. [17:52.030 --> 17:58.250] This is very sensitive information that X mode is delivering to their customer... [17:58.250 --> 17:59.790] to selling to their markets. [18:03.290 --> 18:14.490] And in an investigation by ExpressVPN, they found that even though it was banned by Apple and Google, it persisted. [18:14.690 --> 18:18.990] And despite the ban, only 10% of the apps have been removed from Google Play. [18:19.410 --> 18:27.470] Found also that it disproportionately surveilled Muslim audiences and dating apps. [18:31.460 --> 18:43.120] So not every app that's sending your location to data brokers is using a data broker-created tracking SDK. [18:43.620 --> 18:52.320] Another big pipeline is the advertising infrastructure that is unfortunately built into most of the apps we use. [18:52.320 --> 19:01.620] So the ads you see in apps are typically delivered through this real-time bidding system, RTB. [19:02.020 --> 19:09.920] And this system involves broadcasting your personal data to thousands of companies a day. [19:10.360 --> 19:20.040] The moment before you see an ad, there's this milliseconds-long auction that takes place to determine which ad you'll see. [19:20.720 --> 19:26.640] And data brokers can and do participate in those auctions to harvest data. [19:26.900 --> 19:32.560] So this is sort of an oversimplified version of how it works. [19:33.060 --> 19:47.080] But when you open an app, the advertising SDK in the app will trigger trigger one of these real-time bidding auctions. [19:48.240 --> 20:05.460] The advertising SDK will package as much information as it can get about you from the app, along with all the other information that this advertising company has collected with you over time. [20:05.760 --> 20:17.640] And it'll package that information about you into a bid request, which there's several different types of ad tech companies that this bid request will go to. [20:18.280 --> 20:37.100] But basically, one of these ad tech companies is responsible for holding this auction where they broadcast the bid request with all of your information to hundreds, if not thousands, of potential advertisers or the ad tech companies representing advertisers. [20:37.100 --> 20:57.800] And a key vulnerability of this system is even if an advertiser sees your information and chooses not to bid on your ad space, or if they don't win the bid for your ad space, they can still keep the data that they've seen in the auction, and they can... [20:57.800 --> 21:09.240] Many, many data brokers participate in these auctions as ad companies for the sole purpose of harvesting data not placing ads. [21:10.260 --> 21:12.420] And this is... [21:12.420 --> 21:15.440] Next slide is an example bid request. [21:15.800 --> 21:17.600] This is the sort of... [21:17.600 --> 21:26.240] This is a shortened version of what gets sent out to the thousands of companies participating in this auction. [21:26.520 --> 21:29.240] It's a little bit small, but you can see that it... [21:29.240 --> 21:35.320] It doesn't always, but it can include precise GPS coordinates, latitude and longitude. [21:35.580 --> 21:39.960] It often includes device identifiers. [21:41.860 --> 21:51.120] Oftentimes, bids that include device identifiers, bid requests that have the device identifiers, get higher bids. [21:51.280 --> 21:57.760] So there's a financial incentive to send more personal data into these real-time bidding auctions. [22:00.600 --> 22:01.380] So... [22:01.380 --> 22:01.760] Yeah. [22:02.400 --> 22:03.180] The... [22:03.180 --> 22:04.600] This isn't really... [22:04.600 --> 22:09.660] It's not like a hypothetical danger that data brokers could participate in these auctions. [22:09.660 --> 22:13.300] This is a concrete example of a data broker who has. [22:13.300 --> 22:26.400] So the FTC found that Mobile Walla collected about 500 million data points between 2018 and 2020, and that 60% of them... [22:26.400 --> 22:31.120] 60% of that data was sourced from real-time bidding exchanges. [22:31.320 --> 22:37.680] That Mobile Walla actively participated in ad auctions for the purposes of collecting data. [22:37.680 --> 22:45.480] And they claim to have stopped collecting data from ad networks in 2020. [22:45.840 --> 22:48.000] But these systems... [22:48.000 --> 22:54.940] These ad systems don't have the transparency or guardrails to prevent other data brokers from doing the exact same thing. [22:55.300 --> 23:03.480] We don't even have the transparency and guardrails to know if Mobile Walla really stopped doing this. [23:03.480 --> 23:25.980] If you think about how many ads you see a day on websites and apps, you can get a sense of how much information flows through this system a day and how lucrative it is for data brokers to participate and just collect all of the advertising data that they can. [23:26.460 --> 23:32.100] And Mobile Walla has used the information they collected for some pretty invasive purposes. [23:32.100 --> 23:38.180] They've sold it to people tracking union organizers and protestors. [23:38.460 --> 23:42.100] They've sold lists of people... [23:43.060 --> 23:44.660] This is a very specific example. [23:44.840 --> 23:50.540] They compiled the home addresses of healthcare employees for recruitment by a competing employer. [23:50.860 --> 23:56.560] Like, this is the sort of hyper-specific request that someone can make of a location data broker. [23:56.980 --> 24:03.260] And without any of these employees' knowledge, the data broker will sell their information. [24:03.600 --> 24:09.020] They also sell lists of people that they've made based on their location data. [24:09.400 --> 24:19.180] Some categories they've put people into and to sell are members of the LGBT community, Hispanic churchgoers, pregnant women. [24:19.180 --> 24:28.820] You can imagine how these sensitive lists could be abused when, like, sold to a bad actor. [24:29.420 --> 24:35.200] Their data also ended up in the hands of ICE and CBP. [24:35.200 --> 24:41.260] And this happened because Mobile Walla sold to our old friend Gravy Analytics. [24:41.860 --> 24:53.160] Mobile Walla, when it was caught, said that they didn't know it was happening and that this violated their policy against selling data for law enforcement surveillance. [24:53.980 --> 25:05.180] But that ignorance is a big problem because if data brokers themselves don't know what they're doing with our data, then how should we? [25:07.420 --> 25:14.860] So, yeah, in practice, data brokers combine the two methods that Bill and I talked about. [25:14.860 --> 25:19.300] This is a data dictionary from another location data broker. [25:19.720 --> 25:23.960] They cite real-time bidding and SDKs as sources. [25:25.300 --> 25:31.120] Gravy Analytics, this is a quote from an FTC complaint against them. [25:31.680 --> 25:42.720] Gravy Analytics, rather than collecting data themselves, they tend to, they seem to buy location data from other data brokers, such as Mobile Walla. [25:42.720 --> 26:01.580] And based on the sheer number of, the number and variety of apps that appeared in their hacked data set, it's likely, but we don't know for sure, that a lot of that data comes through the real-time bidding system and ad networks. [26:01.580 --> 26:12.580] Because it came from a lot of apps that, high-profile apps that likely don't have a data broker created SDK in them, but do participate in ad networks. [26:15.620 --> 26:17.340] So how does this happen? [26:17.340 --> 26:20.080] How do SDKs harvest location data? [26:20.960 --> 26:28.700] Well, they piggyback off of the permissions that you've granted for an app for a sense to be legitimate purposes, like we've mentioned, like weather apps. [26:30.340 --> 26:34.740] And they use GPS sensors that are in your device, right? [26:35.380 --> 26:40.620] Which are pretty accurate within, you know, 16 feet or five meters. [26:42.420 --> 26:48.480] They'll also scan nearby Wi-Fi or Bluetooth beacons in an effort to determine your location. [26:49.340 --> 26:53.180] And the accuracy of that was kind of tested by the New York Times. [26:53.780 --> 27:01.060] And it was accurate from a range of about 60, or sorry, 50 meters. [27:01.420 --> 27:07.240] So accurate location, even out to 50 meters from the Bluetooth or Wi-Fi beacon. [27:08.720 --> 27:17.400] And our old friend Google Fused API, which, you know, smartly determines the location data based on what permissions an app has been given. [27:19.760 --> 27:24.180] The accuracy of this is a subject of further research. [27:29.000 --> 27:42.200] In the Privacy Enhancing Technology Symposium this year, a paper was released, Your Signal, Their Data and Empirical Privacy Analysis of Wireless Tracking SDKs in Android. [27:42.700 --> 27:45.900] There's a few interesting findings from this paper. [27:48.260 --> 27:59.280] They found that wireless scanning SDKs, they're studying 52 Wi-Fi or Bluetooth scanning SDKs, and several were linked directly to data brokers. [27:59.900 --> 28:15.520] They found that 86% of the apps that they study, or the SDKs that they studied, were also involved in collecting some other sensitive information from the app. [28:16.320 --> 28:40.140] They also, interestingly, uncovered this technique by which different SDKs will communicate within an app with each other, in order to do this ID bridging, so that it will subvert the normal mechanisms of your mobile operating system, in order to form a persistent identifier, [28:40.140 --> 28:46.480] even if you clear your mobile identifier in the operating system settings. [28:46.480 --> 28:50.700] This was, when I read this, really familiar to me. [28:50.960 --> 28:53.780] I was like, whoa, deja vu. [28:55.320 --> 29:03.980] Because, nine years ago, I presented on what SemiComCar had coined the term for an Evercookie. [29:04.700 --> 29:11.480] And Evercookie operates in much the same way, using different persistent storage mechanisms within the browser. [29:11.480 --> 29:19.640] So, you know, this technique of SDK-to-SDK communication and Evercookie really struck a familiar note for me. [29:21.320 --> 29:22.720] History repeats itself. [29:25.390 --> 29:33.110] So, the unfortunate reality is that there are privacy-invasive SDKs in most apps. [29:33.810 --> 29:46.770] Advertising SDKs are more common than these data broker-created ones, but both can send your data into the opaque and unregulated data broker systems. [29:47.230 --> 29:55.670] So, why are app developers putting all these risky SDKs into our apps? [29:56.190 --> 30:05.270] The answer comes down to the dominant model of advertising today, which is online behavioral advertising. [30:05.270 --> 30:10.210] Ads are targeted based on our offline and online behavior. [30:10.710 --> 30:17.510] Basically, advertisers want all the information they can collect about us to micro-target ads. [30:17.870 --> 30:25.250] And that incentivizes all of the companies we interact with to collect as much of our information as possible. [30:25.250 --> 30:28.430] That fuels the data broker industry. [30:28.950 --> 30:40.090] And you can't have massive troves of personal data for sale without attracting law enforcement, bad actors, and predatory companies. [30:41.470 --> 30:44.670] Advertising doesn't need to be done this way. [30:44.670 --> 31:00.670] Like, ads could still be targeted contextually based on the content of an app or a website you're on, without requiring a detailed profile of your online and offline behavior. [31:02.290 --> 31:05.970] But yeah, so most developers aren't evil. [31:06.150 --> 31:15.750] Many of them don't know the implications of sending even a little bit of information into this advertising system. [31:15.750 --> 31:32.710] But the SDKs they're using are created by advertising companies who, under this dominant model of advertising, the advertising company's business model relies on collecting as much of your information as possible. [31:32.710 --> 31:38.270] And this has very, very real consequences. [31:39.480 --> 31:48.010] We've talked a little about this already, but the location data broker industry facilitates government surveillance. [31:48.490 --> 32:02.110] Law enforcement agencies at the federal and local level have bypassed Fourth Amendment safeguards to just purchase our sensitive location data without a warrant. [32:02.830 --> 32:19.030] This is kind of a high-level summary of the path from SDKs, real-time bidding, to Gravy Analytics, to Ventel, and then to many different government agencies that they've been linked to, including the FBI, CBP, ICE, and more. [32:20.050 --> 32:22.330] This also happens at the local level. [32:22.330 --> 32:38.110] A few years ago, the EFF exposed a company called Fogg Data Science, which has had and still has contracts with several local police departments across the country. [32:39.430 --> 32:52.990] Fogg let any police officer access this website, where they could draw a box on a map and see the devices that were in that area in a given timeframe. [32:53.510 --> 33:02.150] They could also, with Fogg, they could also trace a specific device ID's history over months or years. [33:02.630 --> 33:07.770] This is another similar tool called LocateX by a company called Babel. [33:08.310 --> 33:21.130] Joseph Cox at 404 Media found that this is a tool designed for law enforcement, but a private investigator had gotten access to it by claiming that they were going to work with the government at some point in the future. [33:22.250 --> 33:33.490] So yeah, even the tools that are designed for law enforcement, the sellers of these spy tools are not vetting their buyers. [33:33.490 --> 33:35.130] They're just trying to make money. [33:37.430 --> 33:45.500] Beyond law enforcement uses of location data, data brokers also sell information about... [33:46.190 --> 33:49.150] that can be used to target people based on their beliefs and identities. [33:49.690 --> 33:53.710] Data brokers have sold data on protesters and military personnel. [33:56.270 --> 34:03.370] Planned anti-abortion groups have bought location data about Planned Parenthood visitors to target them with anti-abortion ads. [34:03.830 --> 34:09.190] And there's a famous example of a Catholic group that bought... [34:09.190 --> 34:14.610] bought location data in an effort to track and out gay priests. [34:15.850 --> 34:16.570] Okay. [34:16.810 --> 34:25.290] I'm going to skip this slide in the interest of time, but also look into surveillance pricing and data brokers selling lists of elderly victims to scammers. [34:28.290 --> 34:33.750] So, firstly, we're at a hacker conference, and some of you all are developers. [34:33.950 --> 34:36.430] So what can developers actually do against this? [34:37.210 --> 34:44.470] App developers, at least, can choose which SDKs they include in their apps and choose them carefully. [34:44.730 --> 34:45.650] Look into them. [34:46.030 --> 34:46.810] Investigate them. [34:46.910 --> 34:49.930] See what they actually do, what their business models are. [34:50.630 --> 34:55.270] And take some time to carefully consider whether you should include those SDKs. [34:55.270 --> 34:57.970] or SDKs in your app. [34:58.150 --> 35:02.930] Those that are promising remuneration are particularly kind of... [35:04.270 --> 35:09.810] should be particularly subject to this investigation or effort in time. [35:11.390 --> 35:18.510] Reduce the permissions of your apps to those that are only strictly necessary, instead of being permission greedy within your apps. [35:20.070 --> 35:21.750] Publish your privacy policies. [35:21.750 --> 35:24.850] Let everyone know what you're doing to protect their data. [35:26.230 --> 35:35.410] And finally, have your users back, especially if your data that you have collected on them is subject to, say, a data breach. [35:35.650 --> 35:42.550] Make sure that they know about it and aren't just kind of left without the knowledge that their sensitive information is out there. [35:44.390 --> 35:48.090] mobile platform developers, if you work for Apple or Google. [35:49.350 --> 35:54.550] Give users better, more granular control over their permissions. [35:54.710 --> 36:04.530] Allow them to choose what to give over to your app and by extension and the SDK that you're including. [36:05.530 --> 36:12.510] Build more tools into the OS level to actually blown... to actually block known trackers. [36:12.770 --> 36:15.650] Make sure that they're not sending that data out. [36:16.570 --> 36:18.990] And enforce your own damn policies. [36:18.990 --> 36:35.610] Make sure that when you ban a company like Gravy Analytics from the app store, make sure that they're actually... you know, they're actually removing that SDK before you make sure that they're available again to the general public. [36:37.350 --> 36:39.430] What can legislators do? [36:40.510 --> 36:42.030] Fucking literally anything. [36:42.670 --> 36:43.410] Please. [36:50.930 --> 37:10.750] There are, to be fair, some state-level legislation like California's Consumer Privacy Act and Illinois's Biometric Information Privacy Act, which are effective and do allow us to, for instance, request data on ourselves or have that data deleted. [37:10.990 --> 37:17.550] So, there have been some... there has been some movement at the state level for data protection. [37:18.750 --> 37:26.330] But federal legislators enacted damn data privacy law already, please. [37:28.250 --> 37:37.650] One without preemption so that federal privacy law acts as a floor and doesn't overwrite state privacy law. [37:39.610 --> 37:50.570] And one that has private right of action so that those whose privacy rights are violated, are able to actually sue those who abuse their privacy. [37:52.850 --> 37:58.510] This actually gives the legislation real teeth because it costs them a lot of money when individuals are able to sue them. [37:58.650 --> 38:01.630] And instead of relying on a state prosecutor. [38:04.030 --> 38:13.790] If you don't have a PRA in your, you know, in a piece of legislation, then at least enforce privacy legislation that already exists. [38:14.650 --> 38:18.210] And give some leeway to federal regulators. [38:18.710 --> 38:28.250] For instance, the FTC, who were effective in the previous administration on limiting some of the worse abuses of the data broker industry. [38:32.270 --> 38:35.590] What can individuals, all of you, the users, do? [38:37.510 --> 38:41.270] Well, you can randomize or delete your mobile advertising ID. [38:42.550 --> 38:45.790] You can do that on a number of mobile platforms. [38:45.790 --> 38:48.970] I'll give people a moment to screenshot that. [38:49.550 --> 38:52.110] I'll also give links so you don't have to... [38:58.230 --> 39:03.230] Individuals can also audit the app permissions in a number of ways on their mobile operating systems. [39:04.570 --> 39:10.570] To ensure that your information isn't going where you don't want it to go. [39:11.530 --> 39:15.010] There are a number of interesting new tools that have developed... [39:15.010 --> 39:20.870] That have been built into mobile operating systems to actually look at what data is going where. [39:21.190 --> 39:22.630] Which is a positive development. [39:26.510 --> 39:43.470] Use airplane mode if you are in particularly sensitive situations where, say, you are someone going from a state where abortion is illegal to a state that you would like to have reproductive health care. [39:46.350 --> 39:49.650] That airplane mode might be useful to you. [39:49.870 --> 39:54.830] And this doesn't necessarily mean that you can't navigate in that sense. [39:54.990 --> 39:58.290] GPS is a receive-only technology. [39:58.670 --> 40:12.210] And you can use mobile navigation and maps apps like organic maps or just offline maps in Google maps in order to navigate where you want to go. [40:15.310 --> 40:19.910] And you might want to use a separate device for separate purposes as well. [40:20.890 --> 40:29.130] You know, keeping those devices separated invokes a physical firewall, basically. [40:29.370 --> 40:37.570] So that you are not communicating this data across different devices and your location isn't being tracked every step of the way. [40:41.130 --> 40:43.370] So if you want to find out more, there is the URL. [40:44.490 --> 40:49.650] There is a blog post that has more detailed information for you to look at how to protect yourselves. [40:52.510 --> 41:01.430] So, on a positive note, all this, like, does... the technologies that are out there do actually work. [41:02.410 --> 41:12.650] In preparation for this talk, we filed a number of California data requests to a number of data brokers who we knew collected data location information. [41:12.650 --> 41:17.690] And my location was not discoverable by any of them. [41:18.010 --> 41:32.510] And, granted, I live in a paranoia world where I have, you know, a tracker blocking on the firewall level as well as my web browser as well as on a VPN app that I use. [41:33.630 --> 41:36.630] I always have those on. [41:38.150 --> 41:42.490] But when you employ those protective technologies, they do actually work. [41:42.670 --> 41:45.930] They couldn't produce the information that I requested from them. [41:46.410 --> 41:49.690] So, protective technologies work. [41:49.930 --> 41:54.450] Protective technologies like we develop at EFF and Lina develops privacy badger. [41:54.630 --> 41:55.810] They actually work. [41:56.250 --> 42:00.030] So, yeah, leave it at that. [42:00.030 --> 42:01.890] If we have time for any questions. [42:02.630 --> 42:02.710] Yeah. [42:03.110 --> 42:06.750] Looks like we have six minutes for questions, if anyone has one. [42:17.780 --> 42:18.240] Yeah. [42:18.400 --> 42:20.900] I think if you could come up to the mics, if there are mics. [42:21.160 --> 42:23.980] There's the mic on the right side there. [42:28.260 --> 42:28.720] Okay. [42:29.320 --> 42:30.780] Two questions, if you don't mind. [42:31.780 --> 42:34.280] Number one, it seems like if... [42:34.280 --> 42:44.440] I would like to know what you think is the biggest risk of leaking this data for people who use, like VPNs, avoid apps, and avoid social networks. [42:44.660 --> 42:47.400] And I would assume that is car privacy. [42:47.760 --> 42:48.960] So, I would... [42:48.960 --> 42:51.000] Well, you can say if it's something else. [42:51.140 --> 42:56.220] But what would you suggest doing for that to avoid your car selling location on you? [42:56.780 --> 43:02.040] And second, since a lot of us are hoping for the Supreme Court and Congress to do something about this eventually. [43:02.320 --> 43:11.220] Is there any evidence that the Supreme Court Police and the Capitol Police are selling, are buying data about tracking people based on viewpoint? [43:16.820 --> 43:19.480] One great resource is privacy for cars. [43:20.040 --> 43:33.120] And privacy for cars will let you know, based on your specific car model, what you can do to cut the ties between your driving and the delivery of your driving habits, for instance, to insurance companies. [43:34.440 --> 43:34.980] So, that's... [43:34.980 --> 43:37.740] Privacy for cars hates people who take hacking approaches. [43:37.940 --> 43:40.340] They just want you to request permission from the manufacturers. [43:40.340 --> 43:41.100] Yeah. [43:41.440 --> 43:41.960] Well... [43:41.960 --> 43:45.560] And unfortunately, there's a... [43:46.860 --> 43:50.740] For cars, I... [43:51.640 --> 43:55.220] Firmware hacking on cars sketches me out a little bit. [43:57.160 --> 44:00.420] But it probably shouldn't, to be fair. [44:00.960 --> 44:01.800] I don't know. [44:02.120 --> 44:02.600] Yeah. [44:02.760 --> 44:08.740] There's also the separate issue of automatic license plate readers as another source of location data about cars. [44:09.700 --> 44:16.320] I think we haven't asked the EFF panel tomorrow, and we'll be tabling at the EFF vendor booth. [44:16.440 --> 44:22.880] So, we'll chat with you about the other question afterwards, but maybe we'll try to get, like, your question and your question in. [44:23.880 --> 44:24.160] Yeah. [44:24.580 --> 44:29.700] So, my question was, I've asked some of the large data brokers to, like, not track me or remove my information. [44:29.860 --> 44:32.640] Do you feel like that's helpful or just a waste of time? [44:32.640 --> 44:34.860] I mean, I think it's helpful. [44:35.100 --> 44:40.420] What Bill was saying about, like, not getting a lot of data back from our data access requests. [44:40.660 --> 44:44.420] Bill, like, we use Delete.me and some automated opt-out services. [44:44.420 --> 44:53.180] There was a great study from Consumer Reports about the effectiveness of different automated opt-out tools. [44:53.780 --> 45:00.260] And, unfortunately, like, doing it manually was, I think, more effective than all of the automated solutions. [45:00.260 --> 45:02.720] But the automated solutions were still pretty effective. [45:02.720 --> 45:09.300] The issue is that you can delete your data from them, and then they are continuously getting more of your data. [45:09.460 --> 45:12.060] So, I don't think it's... it's harder than it should be. [45:12.240 --> 45:13.880] We need better, like, legislative solutions. [45:14.300 --> 45:15.560] But it's not pointless. [45:15.680 --> 45:18.000] It might not be 100% effective, though. [45:18.400 --> 45:27.100] The data deletion services that Consumer Reports specifically pointed out were opt-dory and easy opt-outs. [45:27.100 --> 45:32.660] Depending on your price point might be... [45:32.660 --> 45:33.660] Those were the most effective. [45:33.820 --> 45:33.920] Yeah. [45:34.000 --> 45:34.540] Most effective. [45:34.960 --> 45:51.240] And also, Yael Grauer, who is, I think, in the crowd somewhere, developed an easy data broker, easy opt-out list, BadBool. [45:52.760 --> 46:00.700] And that will allow you to go through the data brokers and manually delete your information, which is great. [46:02.120 --> 46:04.340] So, I recommend checking that out as well. [46:04.760 --> 46:11.600] But, like I said, like, there's over 800 known data brokers in the U.S. [46:11.680 --> 46:15.120] Like, it's a pain to manually go through all of them and opt-out. [46:15.660 --> 46:17.780] So, that's why we need more solutions. [46:18.140 --> 46:28.880] The California Delete Act is going to try to give people, like, a one-step way to opt-out, send deletion and opt-out requests to a bunch of different data brokers. [46:29.080 --> 46:31.580] So, enjoy that, right, if you live in California. [46:31.580 --> 46:31.700] Yeah. [46:35.280 --> 46:35.680] Yeah. [46:36.440 --> 46:38.700] I just wanted to bring up one minor thing. [46:38.840 --> 46:43.260] I know since you guys recommended Organic Maps, there's recently been some concerns over them. [46:43.280 --> 46:46.060] I know some of the shareholders pushing in proprietary code. [46:46.320 --> 46:48.940] And, like, it's also a Russian company. [46:48.960 --> 46:50.600] So, there's a lot of concerns over how that's going. [46:51.360 --> 46:55.000] A lot of the community members of Organic Maps have forked it over to CoMaps. [46:55.160 --> 46:56.600] So, I'd recommend checking that out. [46:56.760 --> 46:57.160] Okay. [46:57.340 --> 46:58.240] Thank you for that suggestion. [46:58.360 --> 46:58.820] I had no idea. [47:00.360 --> 47:02.460] My question is actually about... [47:02.460 --> 47:05.720] I've been slowly putting PF Blocker NG on my firewall. [47:05.900 --> 47:10.560] I've been slowly, you know, ratcheting up the level of restriction I'm putting on AdTech. [47:11.020 --> 47:15.660] My concern is the signal that will be produced in dropping off the radar entirely. [47:16.000 --> 47:24.960] If I were effective... if it could be done effectively, given how pervasive this is now, is it not a signal in and of itself to drop off the map, so to speak? [47:25.940 --> 47:29.200] Yeah, I think that there's fairness to that question. [47:30.420 --> 47:38.560] One of the reasons why I never deleted, for instance, my Facebook account was because of that very reason. [47:39.740 --> 47:51.000] But I think that it also depends on your threat model and depends on what you want to... like, what signal you want to be giving out. [47:51.460 --> 47:57.620] I think it's a very individual choice, so I don't think there's one size fits all kind of solution for that. [47:57.620 --> 47:59.740] Yeah, I agree it depends on your threat model. [47:59.900 --> 48:15.500] And also, like, based on some of the tools that we know police are using to, like, look up our location data, a lot of it involves looking up someone's device ID or looking for people who do have a location data point on a map. [48:15.500 --> 48:25.660] So, for those tools, I don't think that they're necessarily looking for people who have an exceptionally small amount of data in the database. [48:27.200 --> 48:32.160] I think we probably have time for both of you, but no more questions after that. [48:32.540 --> 48:33.120] Okay, thank you. [48:33.480 --> 48:34.000] I'll make it quick. [48:34.220 --> 48:36.120] These are really powerful tools, obviously. [48:36.120 --> 48:40.380] I like to follow things like Predator and Pegasus, Spyware, Talios, NSO, and so on. [48:40.680 --> 48:47.380] What I'm concerned about is the, you know, the spread of these tools to other threat actors, like individuals, like hackers or something. [48:47.540 --> 48:51.140] Somebody be able to target, like, you know, I'm going through a contentious divorce. [48:51.240 --> 48:52.580] I want to target my partner. [48:53.140 --> 49:00.520] You know, are you seeing the ability for people to do that, access this, you know, as a malicious actor on an individual level or whatnot? [49:00.880 --> 49:04.820] Instead of, I should say, just companies, but, you know, in governments. [49:04.820 --> 49:14.300] Yeah, I mean, that's part of the problem with how little transparency we have into this ecosystem, because that individually targeting is entirely possible. [49:14.660 --> 49:23.800] I mean, you saw the Joseph Cox's 404 media report about the police location tracking tool that wasn't vetting its buyers. [49:24.100 --> 49:32.280] Like, it's there, I think there's also instances of police themselves, like, abusing the tools they have access to, to look up information about exes. [49:32.680 --> 49:39.960] But that sort of stuff is happening at a level that we don't know about because of how little transparency we have. [49:40.060 --> 49:40.920] So, yes, it's possible. [49:41.100 --> 49:42.900] No, we don't really know how often it's happening. [49:43.100 --> 49:44.240] And they don't vet their buyers. [49:44.360 --> 49:46.660] They just purchase it for pennies on the dollar. [49:47.540 --> 49:53.040] And a massive amount of information is available often to anyone that ponies a little to cash. [49:55.460 --> 49:56.540] This last question, I think. [49:56.820 --> 49:57.760] One last question, or do we... [49:58.600 --> 49:59.340] Oh, okay. [50:00.320 --> 50:02.100] Do we have time for one in-person? [50:02.600 --> 50:03.040] Yeah, go ahead. [50:03.140 --> 50:03.340] Okay. [50:04.260 --> 50:09.520] Let's say I wanted to weaponize this to some extent and, say, creep out my legislators. [50:09.520 --> 50:11.960] Do we have an idea of how much that would cost? [50:14.320 --> 50:14.800] Seriously. [50:15.720 --> 50:16.540] I'm serious. [50:17.200 --> 50:22.520] I feel like the EFF lawyers would tell us to be careful answering this question, but... [50:23.740 --> 50:25.080] Do your own research? [50:25.420 --> 50:27.120] I think it depends. [50:27.360 --> 50:27.560] Okay. [50:27.640 --> 50:29.180] It depends on the data broker. [50:29.460 --> 50:38.300] The big ones, like LexisNexis, they're gonna have, like, more restrictions on who they sell to and sell for much higher prices. [50:38.300 --> 50:41.220] There's a site called Data Raid. [50:41.460 --> 50:46.360] That's, like, a data marketplace that you can, like, browse available data sets. [50:46.380 --> 50:49.300] Not all the data brokers are on there, but it just depends. [50:50.460 --> 50:50.960] Yeah. [50:51.840 --> 50:52.840] Cool idea. [50:54.260 --> 50:57.900] I'm not asking you to do an order of magnitude cost. [50:58.220 --> 50:58.660] Do we know? [50:59.320 --> 51:08.180] I mean, I feel like there are data brokers that will sell, like, I don't know, for a few cents per record. [51:08.180 --> 51:21.260] But I think it really depends on the data broker and whether you have to buy access to their, like, API for lots and lots of money or if you can just purchase individual records. [51:21.260 --> 51:36.220] And a lot of the time is, you know, just included in massive data leaks, too, you know, for free, freely available out there if you, you know, go through a browser that allows you to access the Tor network, for instance. [51:36.220 --> 51:44.980] But I definitely do not think that legislators understand the extent to which, like, they are present in these commercially available data sets. [51:44.980 --> 51:45.040] Yes. [51:45.620 --> 51:54.840] A lot of data brokers have been found with lists of, like, location data can be used to, has been used to identify people on U.S. [51:54.960 --> 51:56.200] military bases abroad. [51:56.200 --> 52:04.240] So just because you're part of the government or in the military doesn't mean you're, you're not in these, present in these surveillance tools. [52:05.640 --> 52:08.220] Two from virtual attendees, real quick. [52:08.440 --> 52:14.720] Can we write apps or false device, or false device layer to generate random fuzzing or tailored false data on mass? [52:14.720 --> 52:22.220] And the other is, is there any value in creating programs or other tech that provides fake spoofed location data? [52:22.620 --> 52:24.080] Yeah, that's an interesting question. [52:24.380 --> 52:36.720] And, um, you certainly can, uh, deliver false GPS coordinates, uh, on open-source operating systems, uh, like Android, for instance. [52:37.000 --> 52:39.040] You can, there, there is, that's a possibility. [52:39.040 --> 52:59.880] Um, on mass, I think that it would be probably pretty trivial for a data broker to do some data integrity tests in order to determine that, uh, you know, this coming from this IP address over this period of time is not non-legitimate data. [53:00.200 --> 53:15.340] Uh, also, I think it just depends on like, you know, uh, oh, this is data collected about this one person who has, um, their location tracked over time and their, you know, unique device identifier tracked over time. [53:15.600 --> 53:33.640] So, you can't, without insight into that information, uh, a priori, like, you can't just kind of, like, generate that data unless you know the mobile advertising identifier that you want to obfuscate, um, or enter in certain ways into. [53:33.640 --> 53:35.260] It's an interesting idea, though. [53:35.920 --> 53:44.260] And outside of, I don't know specifically about location data brokers, but a lot of the information that data brokers say they have about us is wrong. [53:44.800 --> 53:51.620] Um, like, my data access request showed major data brokers, like, thinking my net worth was two million dollars. [53:51.620 --> 53:57.200] Like, they're selling so much conflicting information about the same people. [53:57.400 --> 54:14.140] Like, I think that data brokers, um, can be, are dangerous when they're selling accurate information, but they're also dangerous when they're selling a bunch of inaccurate information, because, uh, that information could also be used, um, to target people, uh, surveillance. [54:15.040 --> 54:27.540] I didn't talk much about surveillance pricing, but companies, um, are showing increasing interest in, like, targeting specific prices to different people based on their predicted willingness to pay higher prices. [54:27.540 --> 54:34.080] And, like, if that sort of information is based off of inaccurate inferences, um, that can also be harmful. [54:34.080 --> 54:38.440] So, it depends on your, your threat model, like, as always. [54:38.840 --> 54:39.580] Thanks so much. [54:39.720 --> 54:41.880] I don't think we have any, uh, more time for any more questions. [54:42.320 --> 54:48.440] Um, you can seek us out at the EFF booth in the vendor area if you have any follow-ups. [54:49.500 --> 54:55.260] And we'll also both be on the Ask the EFF panel at some point tomorrow if people have more questions then. [54:55.260 --> 54:55.280] Thank you, layers. [54:55.280 --> 54:55.320] Thank you again. [54:56.020 --> 54:56.100] Thank you again. [54:56.380 --> 54:56.460] We're talking again. [54:56.460 --> 54:56.480] Thank you again. [54:58.160 --> 54:58.360] You now we're pretty firm for, Dr. I'm looking forward to our session, and Ms.