Risk
10/3/2013
11:07 AM
50%
50%

NSA Discloses Cellphone Location Tracking Tests

National Security Agency director tells Congress that the 2010 mass surveillance pilot program has been discontinued -- at least for the moment.

9 Android Apps To Improve Security, Privacy
9 Android Apps To Improve Security, Privacy
(click image for larger view)
The head of the National Security Agency told Congress Wednesday that the intelligence agency launched a test program in 2010 to see if it could track Americans' location en masse, using the signals put out by people's cellphones.

According to NSA director General Keith Alexander, the pilot program, which concluded in 2011, was designed to test whether the captured tracking information could be reconciled with databases of information already gathered by the agency's digital dragnet.

"In 2010 and 2011, NSA received samples in order to test the ability of its systems to handle the data format, but that data was not used for any other purposes and was never available for intelligence analysis purposes," Alexander told the Senate Judiciary Committee Wednesday, during a hearing titled, "Continued Oversight of the Foreign Intelligence Surveillance Act."

But in response to a question from Sen. Ted Cruz (R-Texas) about whether the agency might track Americans' locations as part of future terrorism investigations, Alexander suggested that the agency wouldn't mind revisiting its ability to monitor the location of every cellphone in the United States. "This may be something that may be a future requirement for the country, but it is not right now," he said.

[ Is John McAfee's new Wi-Fi box really NSA-proof? Read John McAfee Wants To Shield You From NSA. ]

But Alexander also noted -- as has been disclosed before -- that the agency does share information on suspects' cellphone numbers with law enforcement agencies. "When we identify a number, we get that to the FBI and they can get probable cause to get location data that they need," Alexander said. "And that's the reason that we stopped [the pilot program] in 2011."

The revelations over the test program triggered related questions from privacy experts. "Who were the guinea pigs for this 'pilot program?' And did they consent to being tracked this way?" asked "Dissent," which is the handle of the privacy advocate and data breach information blogger who maintains privacy site PogoWasRight.com. "If not, where was the legal justification or warrant that permitted this?"

The fact that legislators were learning about the test two years after it happened also lead to questions about whether Congress has adequate oversight of the intelligence agency. "The NSA's attempt to collect this data shows the need for stronger legislative oversight of the agency's activities, but the fact is that federal, state and local law enforcement are already regularly collecting cellphone location information without a warrant," ACLU legislative counsel Christopher Calabrese told The Guardian.

Calabrese also suggested that the revelations should drive Congress to finally make clear what types of privacy rights Americans should expect, especially when it comes to having their location tracked. "Last year a majority of the Supreme Court recognized that location information is sensitive, and we need legislation that respects privacy rights when it comes to Americans' movements," he said.

The revelations over the cellphone tracking pilot program came after a July report revealed that the NSA can track cellphones even when they appear to be switched off. According to information published by The Washington Post, the capability was developed to allow CIA and paramilitary units, as well as clandestine Joint Special Operations Command (JSOC) teams, to use al-Qaeda leaders' cellphones to track them in real time, for the purpose of then killing or capturing them.

Technically speaking, tracking "off" cellphones hinged on the fact that even when apparently deactivated, a phone's baseband processor may remain active, pinging a cell tower every 10 minutes to retrieve SMS messages. As a result, should the NSA or Congress choose to pursue mass cellphone location tracking in the future, nothing short of removing a battery from a phone -- when that's even possible -- would prevent people's cellphones from being tracked.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
10/3/2013 | 11:36:10 PM
re: NSA Discloses Cellphone Location Tracking Tests
If the protections promised in the U.S. Constitution matter, I'd say this is more than a non-starter kind of piece. Being a government official doesn't exempt you from the law.
msbpodcast
50%
50%
msbpodcast,
User Rank: Apprentice
10/3/2013 | 5:36:56 PM
re: NSA Discloses Cellphone Location Tracking Tests
The problem is not that towers ping phones and vice-versa but that the NSA is trying to ping EVERYBODY'S PHONE ALL THE TIME. (We'd already rejected Pointdexter's TIA, why is it back again?)

If you've done nothing wrong, why is YOUR phone appearing on their innumerable lists?

If you've done nothing wrong, why are YOU being tracked?
TomM765
50%
50%
TomM765,
User Rank: Apprentice
10/3/2013 | 4:40:51 PM
re: NSA Discloses Cellphone Location Tracking Tests
This is a over sensational non-starter kind of piece. Virtually every police force in this country has the same kind of cell tower ping position "tracking" set up for non GPS (or if GPS disabled) phones for reverse emergency positioning. Old tech method that's been in widespread use for well over a decade that has plenty of legal backing. You should tone down the shilling a bit.
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: No, you were supposed to display UNICODE characters!
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.