In June 2018, the U.S. Supreme Court ruled 5-4 that law enforcement must obtain a warrant before accessing cell phone location data from carriers, marking a significant expansion of Fourth Amendment privacy protections in the digital age; this landmark decision in Carpenter v. United States established that historical cell-site location information constitutes protected sensitive digital records, requiring judicial oversight for criminal investigations, while also prompting major telecom companies including Verizon, AT&T, and Sprint to cease selling customer location data to third-party brokers following Senate investigations.
Supreme Court Rules on Cell Phone Location Data Privacy
Added:the Supreme Court ruled in favor of privacy advocates everywhere cellphone carriers stop location data sharing and you can totally steal online accounts through audio files while they're coming up now on threat wire greetings I am Shannon Morrison this is threat wire for June 26 2018 your summary of the threats to our security privacy and Internet freedom our patreon is over at patreon.com slash threat wire and that is always the best way to support the show and will help us reach our next goal so if you want access to exclusives including the brand-new discord server check out the patreon link in the show notes below and special thanks to our newest patrons Michael mark Gwendolyn les Robert John Andre Kristoff Kevin and textmate and now on to the news on Friday the US Supreme Court voted five to four that police and other law enforcement must get a warrant to gather and use location data from phones as evidence in investigations the five yeas included Roberts Ginsburg Breyer Sotomayor and Kagan while the dissenters were Kennedy Thomas Alito and Gorsuch this is a huge deal in a complete 360 from a previous vote by the Sixth Circuit Court of Appeals back on November 29th last year the Supreme Court heard arguments in the carpenter versus United States case detailing a robbery case from 2011 when police used Timothy carpenters phone provider to gather location data on him over 127 days all of this was handed over without a warrant to the police to snoop through and the Sixth Circuit ruled that phone location data is not protected under the Fourth Amendment the Fourth Amendment does ban unreasonable searches and seizures and the ACLU argued that location data is considered sensitive digital records and as such it should also be protected the losing side argued that this data is held by the cell carriers and as such is not in possession of the citizen anyways and as part of the third party doctrine which specifies that any data people voluntarily give to a third party should have no expectation of privacy this finally puts a settlement on whether or not cell phone location data should be protected and warrants needed for criminal investigate in court so it wasn't only a win for carpenter but also for every other American citizen but of course this precedent does also come with caveats this does not protect security cameras business records or real-time location data from being searched without a warrant now while this does affect law enforcement it will probably not affect mobile phone providers and the way they handle data whenever they share it with third party private companies they'll still be able to do that but do they want to that's gonna lead me into my next story just a few weeks ago we reported on a company called sakura s-- who was working with law enforcement across america to share location data from citizen cell phones this data was purchased through a data broker called location smart and the broker was revealed to be offering access to location data through an insecure website u.s. Democratic Senator Ron Wyden of Oregon opened an investigation into the companies in hopes to push them towards ceasing the data sharing the investigation was announced by the FCC and Wyden called a Najat pi who apparently used to be a lawyer first securest in 2012 really apparently he was to recuse himself from the investigation luckily now while location sharing is crucial for emergency situations or to prevent fraud the problems arose when data brokers like location smart for example sell that data to third parties or do not apply proper security protections to protect that data widens investigation proved damning for big telecom companies and as such verizon responded by ending their contracts with companies that sold location data of Americans notably location smart and zoom Mego verizon sent a letter to Wyden on June 15 detailing their own investigation and resulting choice to terminate their agreements with the brokers shortly afterwards after widens office initiated that statement AT&T stated that they would do the same and sprint followed suit the t-mobile CEO tweeted that they did not sell data to shady middlemen but later another tweet was posted by at t-mobile helped stating that they had ended all transmission of customer data to securest and are terminating their location aggregator agreements later t-mobile also sent Wyden office a statement echoing the same they'd also be canceling agreements with the aggregators now this again is a big win for privacy advocates but it does beg the question why did this go on for so long and why we're aggregating bringing light to a bad privacy situation creates more investigations like this one voted on by our patreon supporters this week story was originally shared by patron genial on June 20th Jake Archibald a developer advocate for Google Chrome posted a blog titled I discovered a browser bug in the blog post he explains that he found a severe vulnerability that affects modern web browsers allowing visited websites to siphon credentials from online accounts including ones visited in the same browser as an example an attack could read Gmail content or Facebook messages if logged into those platforms on that same browser this happens because modern browsers handle cross-origin requests for video and audio files in a way that promotes convenience for the user browsers generally do not allow any kind of cross-origin requests of data to any other domain unless allowed by that domain for security but for audio and video files those are automatically loaded without restrictions this allows for audio and video files to be embedded they can be played etc by the user without needing to leave the domain hence convenience this also allows a user to do things like play and pause or for a website to serve a partial content of larger media files due to browsers handling of range headers and partial content responses now Archibald discovered that two modern browsers those being Mozilla Firefox and Microsoft edge both allowed digital media content to pull data from multiple sources together causing a wide open attack vector for malicious actors he calls it wave through and explains that it can be done in a pretty sophisticated way a malicious website would embed some kind of digital media so we'll take a song for example and a user would click on it to play it the embed serves up partial content from its own server but then it pings the browser to get the rest of the content from a different origin the browser sees it's a media file asking for content so it acept the request and it really the data from a secondary source the secondary source could be sensitive data from another logged in session on that same domain or another domain when the browser sends that data back to the media file then the browser doesn't know any better it just serves it up as if it's more media the malicious website with the song embedded captures that information Archibald explains in his blog post that these kind of cross-origin requests were never standardized Chrome and Safari users again are not affected Firefox and edge users are advised to update to the newest versions of the application as both of those have been patched patrons make sure to share your favorite stories in the community tab or on discord and every Friday I will pick three or more top stories for a voting poll that patrons can vote on to be included in next week's show patrons also get access to a downloadable audio version of the show first looks at show topics pulls discussions just for patrons behind-the-scenes photos and now that discord server and that server is just for patrons at two dollars per month and up join now to get access to all of these and to help support the show our next milestone goal will get you access to a live video Q&A just for patrons at all levels and it will get us closer to doing a second episode each and every week and honestly there's a lot of security news right now so I would love to do another episode for you a big thanks to our hush puppy perk level patrons for sending in their fur baby photos I love them keep them coming and hit that subscribe button or share the episode on your favorite social media page as well if you're already subscribed and with that I am Shannon Morris and I will see you on the Internet
Up Next

Carpenter v. United States: Supreme Court on Public Privacy Rights
@businessreform
182.2K views•2025-12-05

Young Thug YSL Trial: Legal Arguments on RICO Evidence and Confrontation Clause Issues in Court
@11Alive
13.7K views•2024-05-16

Forensic Phonetics: Speaker Identification in Legal Cases
@nptel-nociitm9240
539 views•2025-03-19

Police Interrogation Tactics: False Confessions & Legal Reform
@LastWeekTonight
7M views•2022-04-18
Related Study Plans & Knowledge Roadmaps
Structured learning paths in Law



































