Skip to main content

Sprint Tries to Spin Sharing Customers’ GPS Data with Feds

sprint_logo
Image used with permission by copyright holder

Telecommunications operator Sprint is downplaying a recent report that claims Sprint shared customers’ GPS location information with federal authorities more than 8 million times between September 2008 and October 2009. The report, originally published in security researcher Christopher Soghoian’s blog slight paranoia, raised questions of how much surveillance federal agencies really conduct via mobile devices…and how willing mobile operators are to hand over those data. Sprint is claiming that the figure most-cited in the blog—8 million requests—that Sprint turned over data more than 8 million times—doesn’t mean Sprint turned over information on 8 million customers; instead, the figure represents the aggregate number of requests Sprint fulfilled over the course of investigations that may have lasted days or weeks. According to Sprint, the number of customers affected by the searches total in the thousands, not the millions.

The controversy erupted when Soghoian posted an audio recording of a session at the closed-door ISS World conference in which Sprint’s head of electronic surveillance, Paul Taylor, rather giddily spoke about the volume of GPS data requests Sprint had been able to process for law enforcement after setting up a Web portal for automating the request process. (The recordings have since been taken offline, with the organizers of the ISS World conference claiming they violate copyright.) Taylor also said Sprint has 110 employees and contractors dedicated solely to disclosing customer data to law enforcement.

Recommended Videos

Taylor’s comments do not discuss whether Sprint is requiring warrants or court orders before disclosing customer data, or what security measures it has put in place to secure its automated Web portal.

Privacy advocates have expressed alarm at the sheer number of requests processed by Sprint. “Eight million would have been a shocking number even if it had included every single legal request to every single carrier for every single type of customer information,” wrote Electronic Fronteir Foundation attorney Kevin Bankston in the EFF blog. “That Sprint alone received eight million requests just from law enforcement only for GPS data is absolutely mind-boggling.

Sprint maintains that a single investigation can generate thousands of requests for GPS data as law enforcement personnel gather evidence or attempt to track an individual.

Communications operators are not part of any government of law enforcement agency, but have historically worked tightly (and often clandestinely) with law enforcement agencies, often without warrants or court orders to turn over customer records. Under President Bush, it is believed U.S. telecommunications operators complied with the NSA’s “warrantless wiretapping” program to arbitrarily monitor communications with individuals outside the U.S., even if the other end of the communication was in the United States.

Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
North Dakota’s COVID-19 app is sharing user data with Foursquare and Google
contact tracing art

North Dakota’s contact-tracing digital solution has been violating its privacy policy by sharing sensitive user data with third-parties, smartphone privacy company Jumbo Privacy found in an investigation. The state’s Care19 app, which is one of the first contact-tracing apps to debut in the United States, is covertly transmitting location information to the search and discovery platform, Foursquare, and the phone’s unique Advertising ID to Google.

In addition, the anonymous code that the app assigns to individuals and is exchanged with phones it comes in contact with to notify them when they’re exposed to an infected person is sent to Foursquare and Bugfender, a Barcelona-based diagnostics software maker.

Read more
Xiaomi defends against accusations of collecting customers’ private data
xiaomi denies accusations collecting private data redmi note 8t

Xiaomi defended itself against accusations that the Chinese smartphone manufacturer was secretly collecting private data, claiming that the privacy and security of its customers is its "top priority."

Cybersecurity researcher Gabi Cirlig claimed that much of what he was doing on his Xiaomi Redmi Note 8 was being tracked, with the data sent to remote servers, Forbes reported. Cirlig said that the smartphone's default browser, Xiaomi's Mint, recorded the websites he visited, while the device also monitored activity such as opening folders and swiping screens.

Read more
T-Mobile and Sprint have merged. Here’s what subscribers should know
t mobile one vs simple choice hq sign feat 2x3

Rumors and news about T-Mobile and Sprint merging circulated for years -- but now the two have finally made it happen. After years of legal battles and new conditions, Sprint and T-Mobile have merged into the "New T-Mobile," and Sprint as we know it is no more.

In April 2018, ex-T-Mobile CEO John Legere took to Twitter to officially announce the merger, saying the two companies "have reached an agreement." He posted a video of himself alongside Sprint CEO Marcelo Claure that provided some details on the merger. And the mobile carriers submitted a formal application to the Federal Communications Commission on June 18, 2018, officially beginning the regulatory review process for the $26 billion deal.

Read more