<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Location tracking on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/location-tracking/</link>
    <description>Recent content in Location tracking on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/location-tracking/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SignalTrace: Europe Exports the Surveillance It Will Not Allow Itself</title>
      <link>https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/</guid>
      <description>&lt;p&gt;A grey saloon passes under a motorway gantry at 110 kph. The camera on the mast reads the plate, timestamps it, records it. Nothing new: this equipment has been around for twenty years, deployed in tens of thousands of units across North America and Europe alike.&lt;/p&gt;
&lt;p&gt;But if that gantry has been fitted with the unit the Italian group Leonardo has been selling since June 2026, it has just recorded something else. The driver&amp;rsquo;s iPhone. The passenger&amp;rsquo;s wireless earbuds. The smartwatch on the dashboard. The car stereo. The connected key fob in the glovebox. The pressure sensors in all four tyres. The access badge left in a jacket. And, if a dog is asleep in the back, its identification chip.&lt;/p&gt;
&lt;p&gt;A dozen identifiers, a plate, a position, a time. Repeat at every gantry on the network and you are no longer following a car: you are following people, and you know who they travel with.&lt;/p&gt;
&lt;h2 id=&#34;what-the-equipment-actually-does&#34;&gt;What the equipment actually does&lt;/h2&gt;
&lt;p&gt;The product is called &lt;strong&gt;SignalTrace&lt;/strong&gt;. Sold by Leonardo US Cyber and Security Solutions, it extends the &lt;strong&gt;ELSAG&lt;/strong&gt; range, one of the most widespread lines of automated licence plate readers on the American market. Its existence was revealed on 8 June 2026 by Joseph Cox in &lt;a href=&#34;https://www.404media.co/this-company-will-add-phone-airpod-and-smartwatch-trackers-to-license-plate-readers/&#34;&gt;404 Media&lt;/a&gt;, from a manufacturer&amp;rsquo;s product sheet.&lt;/p&gt;
&lt;p&gt;The decisive point fits in one sentence: &lt;strong&gt;these are not new cameras&lt;/strong&gt;. SignalTrace is a radio sensor added to plate readers that are already installed. The mast does not change, the location does not change, the silhouette of the roadside equipment does not change. What changes is what the equipment listens to.&lt;/p&gt;
&lt;p&gt;The sensor records the identifiers broadcast in the clear by the Bluetooth, Wi-Fi and RFID protocols of the devices inside the vehicle. A technical point that is often misunderstood: no device is hacked and no vulnerability is exploited. A Bluetooth or Wi-Fi device continuously emits discovery frames, because that is how the protocols were designed. Your earbuds announce their presence so your phone can find them, and the phone itself queries the surrounding air for the networks it knows. These emissions are public by construction, and any receiver within range hears them.&lt;/p&gt;
&lt;p&gt;Leonardo indeed states that the system works &lt;a href=&#34;https://www.leonardocompany-us.com/lpr/elsag-signaltrace&#34;&gt;with or without a plate reader&lt;/a&gt;, indoors included, and recognises a vehicle whose plate has been obscured or removed.&lt;/p&gt;
&lt;p&gt;The retrofit is the real political issue. Installing a new camera network triggers a vote, a public deliberation, sometimes litigation. Adding a circuit board inside a housing that has already been approved triggers nothing. The surveillance capability changes in nature without public debate, because there is materially nothing new to see.&lt;/p&gt;
&lt;h2 id=&#34;from-the-vehicle-to-the-person-and-from-the-person-to-the-group&#34;&gt;From the vehicle to the person, and from the person to the group&lt;/h2&gt;
&lt;p&gt;A plate reader answers one question: where was this vehicle. SignalTrace adds two more: who was in it, and with whom.&lt;/p&gt;
&lt;p&gt;Leonardo makes no secret of this, it is the sales pitch. The system builds what the documentation calls an &lt;strong&gt;electronic fingerprint&lt;/strong&gt;, a set of identifiers &amp;ldquo;frequently emitted together&amp;rdquo;. The manufacturer&amp;rsquo;s example is explicit: across an entire city, only one vehicle will pair an iPhone 13rev2, an Audi car stereo, a Bose headset, a Garmin watch, a key tracker and the plate ABC-1234.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The product does not merely track vehicles. It automatically produces a graph of relationships between people, without anyone having had to formulate the slightest suspicion.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is where the qualitative leap happens. By correlating the devices that regularly travel together, the system mechanically builds a social graph. Two phones that end up in the same car every morning are a car share, or a relationship neither party wishes to make public. Fifty devices captured in the same place at the same time are a gathering: a protest, a religious service, a union meeting or a queue outside a clinic.&lt;/p&gt;
&lt;p&gt;None of these conclusions requires access to the content of a communication. They are deduced from a proximity table, by default, across the entire travelling population rather than on designated targets. This is guilt by association, produced industrially, upstream of any investigation. Tom Bowman, a lawyer at the &lt;a href=&#34;https://cdt.org/staff/tom-bowman/&#34;&gt;Center for Democracy &amp;amp; Technology&lt;/a&gt;, sums up the problem in &lt;a href=&#34;https://www.technewsworld.com/story/license-plate-reader-adds-device-snooping-feature-180421.html&#34;&gt;TechNewsWorld&lt;/a&gt;: what makes the tool useful for tracking a genuine suspect makes it just as capable of tracking every other motorist, none of whom consented to having their devices recorded.&lt;/p&gt;
&lt;p&gt;Leonardo offers two counter-arguments: the system neither decrypts nor reads the content of communications, and it does not identify people by itself. Both statements are accurate, and both miss the point. The intelligence sought was never the content, it lies in the location metadata, which is more revealing than a message. As for identification, the manufacturer itself acknowledges that an investigator can link an electronic signature to a plate, then work back to the registered keeper through vehicle registration records.&lt;/p&gt;
&lt;h2 id=&#34;american-law-written-for-something-else&#34;&gt;American law written for something else&lt;/h2&gt;
&lt;p&gt;In the United States, state laws governing plate readers do exist, and some are demanding about retention periods and access purposes. But all were drafted around one precise object: &lt;strong&gt;the image of a licence plate&lt;/strong&gt;. None anticipates the capture of personal device identifiers by the same equipment.&lt;/p&gt;
&lt;p&gt;This mismatch does not create illegality but a grey area, one more convenient for the vendor. A police department can maintain, without lying, that its plate reader programme is authorised and compliant, while now collecting under the same regime data of an entirely different nature. Leonardo also holds federal contracts, with Special Operations Command and the General Services Administration, a purchasing route that largely bypasses local approvals.&lt;/p&gt;
&lt;p&gt;The constitutional debate, for its part, has just shifted, and precision matters here because the state of the law changed this summer. In January 2026, a federal court in Virginia held, in &lt;em&gt;Schmidt v. City of Norfolk&lt;/em&gt;, that the city&amp;rsquo;s Flock camera network &lt;a href=&#34;https://www.courthousenews.com/judge-holds-norfolks-license-plate-reader-use-constitutional/&#34;&gt;did not constitute a search&lt;/a&gt; under the Fourth Amendment, because it did not cover the entirety of residents&amp;rsquo; movements. The decision is on appeal before the Fourth Circuit, where the &lt;a href=&#34;https://www.aclu.org/campaigns-initiatives/get-the-flock-out&#34;&gt;ACLU&lt;/a&gt; has intervened.&lt;/p&gt;
&lt;p&gt;Then, on 29 June 2026, the Supreme Court handed down &lt;a href=&#34;https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdf&#34;&gt;&lt;em&gt;Chatrie v. United States&lt;/em&gt;&lt;/a&gt;. By five votes to four, in an opinion written by Justice Kagan, it held that police acquisition of a phone&amp;rsquo;s location data constituted a search, an individual retaining a reasonable expectation of privacy in that data even when held by a third party and over a short period. The ruling extends &lt;em&gt;Carpenter v. United States&lt;/em&gt; from 2018 and weakens the third-party doctrine, as the &lt;a href=&#34;https://cdt.org/insights/op-ed-scotuss-signals-in-chatrie-and-on-the-potential-limits-of-location-tracking/&#34;&gt;CDT&lt;/a&gt; noted.&lt;/p&gt;
&lt;p&gt;The precise reach of &lt;em&gt;Chatrie&lt;/em&gt; over SignalTrace is unsettled, and it would be careless to claim otherwise: the ruling concerns data demanded from Google, not direct capture by a police sensor in public space. But it establishes the reasoning that matters, namely that the sensitivity of location data does not depend on who holds it.&lt;/p&gt;
&lt;h2 id=&#34;the-european-question-which-is-the-real-question&#34;&gt;The European question, which is the real question&lt;/h2&gt;
&lt;p&gt;This is where the file becomes uncomfortable for Europe. Leonardo is not an American supplier but an Italian group listed in Milan whose leading shareholder is the Italian Ministry of Economy and Finance, holding around 30 % of the capital, with the power to appoint the majority of the board. The Italian state is not a passive shareholder in this product.&lt;/p&gt;
&lt;h3 id=&#34;the-technical-point-first&#34;&gt;The technical point, first&lt;/h3&gt;
&lt;p&gt;Under European law, a device identifier is personal data. This is not a doctrinal opinion but the settled position of the authorities. The CNIL explicitly treats the MAC address as such in its guidance on &lt;a href=&#34;https://www.cnil.fr/fr/dispositifs-de-mesure-daudience-et-de-frequentation-dans-des-espaces-accessibles-au-public-la-cnil&#34;&gt;footfall measurement systems&lt;/a&gt;, and permits their collection in public space only under narrow conditions: anonymisation within a few minutes with a high collision rate between individuals, or reliable pseudonymisation followed by destruction within twenty-four hours, failing which consent becomes mandatory. The same guidance specifies that inviting people to switch off their Wi-Fi is not an acceptable means of objecting.&lt;/p&gt;
&lt;p&gt;On 4 September 2025, in &lt;em&gt;EDPS v. SRB&lt;/em&gt; (C-413/23 P), the Court of Justice of the European Union clarified that whether pseudonymised data is personal is assessed against the means of re-identification that can reasonably be deployed. Here the holder is a police authority, which has access to vehicle registration records. The means of re-identification are not hypothetical, they are in the next office along.&lt;/p&gt;
&lt;h3 id=&#34;the-nuance-that-changes-everything&#34;&gt;The nuance that changes everything&lt;/h3&gt;
&lt;p&gt;It would be wrong to write that SignalTrace &amp;ldquo;would be illegal in Europe&amp;rdquo;, and a legally trained reader would spot it immediately. Processing carried out by a competent authority for the purposes of preventing and prosecuting criminal offences does not fall under the GDPR. It falls under &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/PDF/?uri=CELEX%3A32016L0680&#34;&gt;Directive (EU) 2016/680&lt;/a&gt;, known as the Law Enforcement Directive, transposed separately by each member state, in France under Title III of the Data Protection Act. The &lt;a href=&#34;https://www.cnil.fr/fr/directive-police-justice-de-quoi-parle-t&#34;&gt;CNIL&lt;/a&gt; points out that this regime is autonomous, with its own grounds for lawfulness and its own rights.&lt;/p&gt;
&lt;p&gt;The right question is therefore not one of abstract legality, but one of conditions. Under that regime, such a system would require an express national legal basis, defined purposes, demonstrated necessity, a bounded retention period, an impact assessment and independent oversight. In France, plate readers are governed on these terms: articles L233-1 and L233-1-1 of the internal security code set out an exhaustive list of offences that open the way to their use, and retention remains among the shortest in the Union, fifteen days in principle, even if a Senate bill seeks to extend it.&lt;/p&gt;
&lt;p&gt;That is the fundamental difference with the American situation. In the United States, the law governs an object, the plate, and silence on device identifiers amounts to permission. In Europe, the law governs purposes and categories of data, and that silence amounts rather to prohibition, for want of an express legal basis. The vacuum observed across the Atlantic does not exist here in the same form. Not that Europe is more virtuous: its legal technique is the reverse.&lt;/p&gt;
&lt;h3 id=&#34;what-the-protection-is-then-worth&#34;&gt;What the protection is then worth&lt;/h3&gt;
&lt;p&gt;That leaves the question this article is about. What is European regulatory protection worth when a European company, controlled by a member state, sells outside Europe a capability it could not deploy at home without new legislation?&lt;/p&gt;
&lt;p&gt;The objections deserve to be taken seriously. A manufacturer is not responsible for its customer&amp;rsquo;s legal framework: it is for the American authorities to decide what they permit at home. The product is not sold to a dictatorship but to a state under the rule of law with an active supreme court, as &lt;em&gt;Chatrie&lt;/em&gt; has just shown. And the industrial sovereignty argument is legitimate: if European groups shut themselves out of these markets, they will be taken by Israeli, American or Chinese suppliers, without surveillance receding by a single metre, and Europe will lose its technological base.&lt;/p&gt;
&lt;p&gt;These arguments are admissible. They do not answer the problem.&lt;/p&gt;
&lt;p&gt;First because the Union has already recognised that exporting surveillance capabilities is not trade like any other. &lt;a href=&#34;https://www.entreprises.gouv.fr/espace-entreprises/s-informer-sur-la-reglementation/le-reglement-europeen-sur-les-biens-double&#34;&gt;Regulation (EU) 2021/821&lt;/a&gt; on dual-use items introduced, in its article 5, a catch-all clause covering cyber-surveillance items, because the legislator accepted that a tool that is legal to manufacture may be illegitimate at its destination. Its limit is instructive: it is triggered by a risk of internal repression or serious human rights violations, categories designed for authoritarian regimes. A sale to an American municipal police force does not fall within them. The European grid examines the morality of the customer, never the nature of the capability being sold.&lt;/p&gt;
&lt;p&gt;Second because such a product is not a stock to be cleared, but a capability that is sustained: it funds research, trains engineers, accumulates know-how and creates an installed base. The day a major attack pushes a member state to demand this capability, the debate will no longer be about whether to build it. It will exist, it will be European, it will be mature, and its supplier will be partly public. The &amp;ldquo;we are only following the market&amp;rdquo; argument then becomes circular, since the domestic market will have been prepared by the export.&lt;/p&gt;
&lt;p&gt;That is what regulatory protection is worth in this scenario: it protects Europeans against uses, not against the existence of the means. It settles the question of who is entitled to press the button, and leaves industry to build it, sell it, improve it, then wait.&lt;/p&gt;
&lt;h2 id=&#34;what-can-be-done-without-kidding-ourselves&#34;&gt;What can be done, without kidding ourselves&lt;/h2&gt;
&lt;p&gt;The first answer raised is always MAC address randomisation. It deserves an honest examination, neither promotion nor disparagement. It is real and it works.&lt;/p&gt;
&lt;p&gt;Android since version 10 and iOS since version 14 randomise by default the MAC address used over Wi-Fi, with a distinct address per network. In Bluetooth Low Energy, modern devices broadcast resolvable private addresses, which change periodically and can only be tied back to the real device by a counterpart holding the resolution key.&lt;/p&gt;
&lt;p&gt;Its limits are just as real.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Pairing reopens the door.&lt;/strong&gt; The resolution key is transmitted during pairing. A device already paired, or explicitly approved, recovers the stable identity behind the rotating address. The mechanism is designed for that.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Many objects randomise nothing.&lt;/strong&gt; Tyre pressure sensors, RFID badges, animal identification chips, car stereos and cheap peripherals emit fixed identifiers. Leonardo&amp;rsquo;s product sheet mentions exactly these categories, which is no accident.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Randomisation can be switched off.&lt;/strong&gt; It is disabled network by network, and often is, out of convenience, for MAC filtering on a home router or by corporate policy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The group survives the rotation of identifiers.&lt;/strong&gt; This is the least intuitive and most important point. SignalTrace is not looking for an identifier, it is looking for a set of devices travelling together. If a single member of the group emits a stable identifier, the whole set remains attributable, whatever the discipline of the others.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The most effective measure remains the most tedious: do not emit. That means disabling Bluetooth and Wi-Fi at system level, in the settings, and not from the shortcut panel. The distinction is not cosmetic, we detailed it in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;: on most consumer systems, the quick panel button cuts visible pairing but leaves the software stack alive, and proximity scanning continues. That article described Bluetooth scanning as a theoretical vector. SignalTrace is its commercial product, catalogued and deliverable.&lt;/p&gt;
&lt;p&gt;We have to stay honest about the outcome: these measures reduce the exposure surface, they do not eliminate it. A vehicle is still a plate, and a plate is still readable. The only way to emit nothing is to carry nothing, which is not a public policy.&lt;/p&gt;
&lt;h2 id=&#34;what-this-says-about-our-design-choices&#34;&gt;What this says about our design choices&lt;/h2&gt;
&lt;p&gt;At Arpokrat, it is this reasoning that led us to handle Bluetooth at the Core level of ArpokratOS rather than at the settings level. A switch in an interface is a user preference: an update, a system application or a location service can bypass or re-enable it, without the user knowing. A stack that is absent cannot be re-enabled.&lt;/p&gt;
&lt;p&gt;Faced with capture of the SignalTrace kind, this obviously does not make a device undetectable, and we do not claim it does: a phone remains on a mobile network, and the other objects in a vehicle emit on their own account. What it does guarantee is that one specific emission vector is absent by construction rather than disabled on trust. That is the argument we made about &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;5G and the law&amp;rsquo;s targeting error&lt;/a&gt;: legal protection concentrates on access to data when it should bear on the very existence of the infrastructure that produces it. SignalTrace illustrates the point, except that this infrastructure is built in Europe.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The most striking thing in this file is not the technical capability, which researchers have been describing for years. It is the deployment method.&lt;/p&gt;
&lt;p&gt;There will be no new camera network to inaugurate, no municipal deliberation to challenge, no public contract identifiable as a change in nature. There will be units added to existing masts, under existing contracts, within programmes already authorised. By the time public debate opens, the infrastructure will be installed, written down and integrated into investigative procedures. The debate will then be about the conditions for accessing a database that exists, never about whether it should have been built.&lt;/p&gt;
&lt;p&gt;That is the usual order of things where surveillance is concerned, and it is not accidental. What remains to be seen is whether Europe considers it has anything to say when its own manufacturers, backed by its own states, build this infrastructure for others. European law has carefully organised the answer to the question of who may consult this data at home. It has never asked who is entitled to build the machine.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>5G, Location Data and the Law&#39;s Targeting Error</title>
      <link>https://arpokrat.com/blog/5g-location-data-privacy-law/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/5g-location-data-privacy-law/</guid>
      <description>&lt;p&gt;In 2011, Detroit police asked a mobile operator for the cell site records of Timothy Carpenter&amp;rsquo;s phone. They obtained 12,898 location points spread over 127 days, around a hundred a day. Seven years later, the Supreme Court of the United States held that the request amounted to a search and required a warrant.&lt;/p&gt;
&lt;p&gt;Those 12,898 points came from fourth-generation towers, each covering a radius of several kilometres. The same request, addressed today to an urban 5G network, would not return a hundred points a day accurate to a few kilometres. It would return a far larger volume, accurate to a few dozen metres.&lt;/p&gt;
&lt;p&gt;The technology has changed scale. The legal reasoning has stayed at the same point in the chain.&lt;/p&gt;
&lt;h2 id=&#34;a-legal-interest-that-judges-recognise-on-both-sides-of-the-atlantic&#34;&gt;A legal interest that judges recognise on both sides of the Atlantic&lt;/h2&gt;
&lt;p&gt;There is an interest almost everyone accepts and almost no legal text protects effectively: the right to be somewhere without that fact being recorded.&lt;/p&gt;
&lt;p&gt;European case law established it unambiguously. In &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt; (joined cases C-293/12 and C-594/12, 8 April 2014), and then in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt; (joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016), the Court of Justice of the European Union held that such data, taken as a whole, allow very precise conclusions to be drawn concerning people&amp;rsquo;s private lives: daily habits, places of residence, movements, activities carried out and social relationships.&lt;/p&gt;
&lt;p&gt;The Supreme Court of the United States reached a comparable conclusion in &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296 (2018). It stressed a point American scholarship has commented on at length: the &lt;strong&gt;inescapable and automatic&lt;/strong&gt; nature of that collection. Nobody consents to being attached to a cell tower; you are attached because you own a phone that is switched on.&lt;/p&gt;
&lt;p&gt;The legal interest therefore exists, and it is recognised by the two courts that matter in this field. The problem lies elsewhere.&lt;/p&gt;
&lt;h2 id=&#34;what-5g-actually-changed&#34;&gt;What 5G actually changed&lt;/h2&gt;
&lt;p&gt;A common confusion treats location as data the phone transmits, in the same way as a message or a photograph. It is not. Location is a &lt;strong&gt;physical consequence of how the network works&lt;/strong&gt;. The operator knows which tower the device is attached to because it has to know in order to route a call. There is no key with which to encrypt that information, because it is not content but a property of the connection itself.&lt;/p&gt;
&lt;p&gt;That is precisely what makes 5G significant in legal terms rather than technical ones.&lt;/p&gt;
&lt;p&gt;Earlier architectures relied on wide cells. A 4G tower commonly serves a radius of several kilometres, and the position inferred from attachment alone was measured in hundreds of metres in cities, sometimes in tens of kilometres in rural areas. 5G rests on massive densification: urban cells typically cover a few hundred metres, and the engineering literature works with densities on the order of forty to fifty base stations per square kilometre, against four or five in the 3G era.&lt;/p&gt;
&lt;p&gt;The consequence is mechanical. According to &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;Ericsson&amp;rsquo;s white paper on 5G positioning&lt;/a&gt;, infrastructure deployed for connectivity alone reaches an accuracy of twenty to fifty metres outdoors and one to three metres indoors, dropping below a metre in favourable urban conditions. This is not a location feature switched on somewhere, but what the network knows by construction, with no application installed and no permission granted. We set out all of these mechanisms, along with the countermeasures that actually work, in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The intrusion has therefore grown by several orders of magnitude. The applicable legal framework remains the one designed for 2G and 3G. No normative adjustment has accompanied that change of scale.&lt;/p&gt;
&lt;h2 id=&#34;the-law-protects-access-not-generation&#34;&gt;The law protects access, not generation&lt;/h2&gt;
&lt;p&gt;European law carefully regulates who may access location data, on what conditions and under what supervision. Directive 2002/58/EC lays down the principle of confidentiality of communications, and the Court of Justice held, in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net&lt;/a&gt; (joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020), that Article 15(1) of that directive, read in the light of Articles 7, 8, 11 and 52(1) of the Charter, precludes the &lt;strong&gt;general and indiscriminate retention&lt;/strong&gt; of traffic and location data on a preventive basis. The Court nonetheless allowed framed derogations where a Member State faces a serious threat to national security that is genuine and present or foreseeable, subject to effective review.&lt;/p&gt;
&lt;p&gt;These are real protections, and it would be absurd to play them down. But they all come into play after the fact. They presuppose that the data exists and is retained, and then organise the conditions of its use.&lt;/p&gt;
&lt;p&gt;Yet if location is an unavoidable by-product of how the network operates, the relevant point of intervention is not confidentiality. It is &lt;strong&gt;persistence&lt;/strong&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An instantaneous position, needed to route a communication and erased immediately afterwards, is not an instrument of surveillance. A history of positions kept for months is one, whatever access safeguards surround it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The difference between the two is not legal, it is architectural. And the European timetable makes the question urgent rather than theoretical. The Commission &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;withdrew the proposed ePrivacy Regulation&lt;/a&gt; in 2025, for lack of agreement between the co-legislators. It has since been working on a separate instrument on data retention for criminal purposes, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;announced for 2026&lt;/a&gt; and intended to harmonise national regimes that have grown disparate since the 2006 directive was annulled. In other words, the text that will set the regime for location metadata for a decade is being written right now, on the basis of reasoning conceived in the era of kilometre-wide cells.&lt;/p&gt;
&lt;h2 id=&#34;the-precedent-5g-created-for-itself&#34;&gt;The precedent 5G created for itself&lt;/h2&gt;
&lt;p&gt;The most interesting aspect of the file is that the right answer is already in the technical standard, but applied to a different object.&lt;/p&gt;
&lt;p&gt;Up to 4G, the subscriber&amp;rsquo;s permanent identifier, the &lt;strong&gt;IMSI&lt;/strong&gt;, travelled in the clear over the radio interface during attachment. That is what made &lt;strong&gt;IMSI catchers&lt;/strong&gt; possible, those fake base stations which, according to the &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Electronic Frontier Foundation&amp;rsquo;s reference description&lt;/a&gt;, transmit more strongly than legitimate towers in order to attract handsets and capture their identifier.&lt;/p&gt;
&lt;p&gt;Since Release 15 of the 3GPP specifications, published in 2019, 5G has offered an elegant answer. The permanent identifier, now called the &lt;strong&gt;SUPI&lt;/strong&gt;, can be replaced on the radio interface by the &lt;strong&gt;SUCI&lt;/strong&gt;, a concealed identifier obtained by encrypting the subscriber-specific part using elliptic curve cryptography, with the home operator&amp;rsquo;s public key. Only the home network, which holds the corresponding private key, can decrypt it. The result is unique on each computation, which prevents correlation from one session to the next.&lt;/p&gt;
&lt;p&gt;The logic adopted deserves to be underlined, because it is exactly the logic that should guide lawmakers: you do not encrypt the position, which would be technically impossible, you encrypt the identity. A position with no attachable identity has very limited value for individualised surveillance.&lt;/p&gt;
&lt;h3 id=&#34;the-flaw-an-optional-protection&#34;&gt;The flaw: an optional protection&lt;/h3&gt;
&lt;p&gt;There is, however, a considerable caveat, and in our view it is the most concrete point of intervention in the whole file.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;NIST CSWP 36A white paper&lt;/a&gt;, published in March 2026 by the National Institute of Standards and Technology, states it bluntly. Handsets and network functions compliant with Release 15 or later are required to &lt;strong&gt;support&lt;/strong&gt; the SUCI, but enabling it remains &lt;strong&gt;optional for the operator&lt;/strong&gt;. Three conditions must be met: the equipment vendor must support it, the operator must enable it on its network, and the SIM card must carry the elements needed for the computation.&lt;/p&gt;
&lt;p&gt;A configuration trap comes on top of that. The standard provides for a &lt;strong&gt;null protection scheme&lt;/strong&gt;, in which the SUCI format is formally used but without effective encryption, so that the identifier travels in the clear. NIST writes that operators need to configure their networks with a non-null protection scheme, and recalls that a report by CSRIC, the advisory body of the Federal Communications Commission, recommended as early as 2021 that the null scheme be reserved for emergency calls placed by a handset unknown to the network.&lt;/p&gt;
&lt;p&gt;The formulation is worth stating plainly. The best available protection against mobile device tracking has existed in the technical standard since 2019. It rests on a configuration choice left to the operator&amp;rsquo;s discretion. An American federal agency finds it useful to publish a document in 2026 to remind everyone that it ought to be switched on. And no European legal instrument requires it.&lt;/p&gt;
&lt;p&gt;It should be added that the SUCI does not close the subject. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkability attacks that allow sessions to be recorrelated despite the encryption, and the protection falls entirely if the attacker forces the handset to downgrade to an earlier generation. A legal obligation would therefore not settle everything. It would nonetheless remove a gap with no defensible justification: the one between what the standard allows and what commercial networks do.&lt;/p&gt;
&lt;h2 id=&#34;three-coherent-interventions&#34;&gt;Three coherent interventions&lt;/h2&gt;
&lt;p&gt;If we take seriously the idea that location should be minimised by design rather than protected after the fact, three measures follow logically.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Make effective concealment of the identifier mandatory.&lt;/strong&gt; Require the SUCI to be enabled and prohibit null protection schemes on commercial networks, apart from the residual case of emergency calls. This is not about prescribing a new technology, or funding a rollout, but about requiring the activation of a function standardised seven years ago and already present in the equipment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Treat retention as the exception, not the default.&lt;/strong&gt; The position needed to route a communication should be erased as soon as that function is fulfilled. Building a history should call for specific justification. That is the difference between a network that knows where you are and a network that remembers where you have been.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Make custody of the key the relevant connecting factor.&lt;/strong&gt; Locating servers in the Union does not mean much if the keys that make the data intelligible are held elsewhere. The legally significant criterion should be effective control of the means of decryption, a question we examined in detail in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-follows&#34;&gt;The angle Arpokrat follows&lt;/h2&gt;
&lt;p&gt;This reasoning is not specific to telecommunications law. It is the one we apply to our own architectural choices, and it fits in a sentence: what has not been produced does not need to be protected.&lt;/p&gt;
&lt;p&gt;That is why &lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; removes GPS, Bluetooth and NFC at kernel level rather than disabling them in a menu. A switch is a policy: it can be bypassed by a privileged component, re-enabled by an update, ignored by a compromised system. Removing the code path removes the question. It is the transposition, at device scale, of the same shift we are calling for at the scale of the law: intervening on generation rather than on access.&lt;/p&gt;
&lt;p&gt;It must be said straight away what this does not do. No operating system removes a handset from the geometry of the network. As long as a SIM card is active, the operator knows the serving cell, and routing all traffic through Tor changes nothing, since it protects content and destination, not the radio layer. That is precisely why the subject is a legal one. There is a category of risks that no individual configuration reduces, and for which the only available variable is the rule applicable to the operator.&lt;/p&gt;
&lt;p&gt;The same concern governs the rest of our work. Data that does not exist cannot be requisitioned, resold, exfiltrated, or decrypted ten years from now by a machine nobody has today, a question we addressed from the angle of &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;encryption harvested now and broken later&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Public debate on mobile surveillance focuses almost exclusively on access: who can consult the data, on what basis, with what authorisation. That debate is legitimate, and the rulings handed down by the Court of Justice since 2014 have had tangible effects. But it comes too late in the chain.&lt;/p&gt;
&lt;p&gt;The prior and more decisive question is whether the history should exist at all. A database built today for a legitimate purpose remains available tomorrow for another, and the safeguards around it depend on later political decisions that nobody controls at the moment of collection. It is a bet on the stability of institutions, made for a period nobody sets.&lt;/p&gt;
&lt;p&gt;5G has multiplied the resolution of this information without any normative adjustment. It has simultaneously shown, through the SUCI mechanism, that the workable path is to dissociate position from identity rather than attempt to encrypt a physical property of the network. The technical standard supplied the answer seven years before the law asked the question.&lt;/p&gt;
&lt;p&gt;The European text on data retention is being written now. It will deal with metadata, therefore with location, therefore with what 5G now produces at a granularity its drafters never knew. Whether it will settle for organising access to a history taken for granted, or dare to question the necessity of that history, is probably the most important privacy question of the coming years in Europe. And it is a question the technical sector, for once, has already settled the right way.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt;, joined cases C-293/12 and C-594/12, 8 April 2014&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt;, joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net and Others&lt;/a&gt;, joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020&lt;/li&gt;
&lt;li&gt;Supreme Court of the United States, &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296, 2018&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology, &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI)&lt;/a&gt;, NIST CSWP 36A, March 2026&lt;/li&gt;
&lt;li&gt;Ericsson, &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;5G positioning: Locating devices anywhere&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Gotta Catch &amp;lsquo;Em All: Understanding How IMSI-Catchers Exploit Cell Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Digital Rights, &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;The ePrivacy Regulation proposal has been withdrawn, but the fight for your privacy is far from over&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;heise online, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;Data Retention: Commission to present proposal by mid-2026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Permanent geolocation: how your phone tracks you even when you think you have stopped it</title>
      <link>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</link>
      <pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/how-your-phone-tracks-your-location/</guid>
      <description>&lt;p&gt;In 2024, two researchers at the University of Maryland repeatedly queried Apple&amp;rsquo;s Wi-Fi positioning service, with no special privilege and no specialised hardware, and in a single year reconstructed the precise location of more than two billion Wi-Fi access points worldwide. Their paper, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;, shows what that map makes possible: tracking equipment moving in and out of Ukraine, observing population displacement after the Maui wildfires, following an individual through their home internet router.&lt;/p&gt;
&lt;p&gt;None of those devices had GPS switched on. The position came from somewhere else.&lt;/p&gt;
&lt;p&gt;This is the most widespread blind spot in mobile privacy: the belief that there is a location switch, and that once it is off, the phone stops knowing where it is. That belief is wrong on seven separate levels.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Location is not a feature your phone turns on. It is a property of what your phone is.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;gps-the-least-troubling-vector-of-all&#34;&gt;GPS, the least troubling vector of all&lt;/h2&gt;
&lt;p&gt;The one mechanism everybody can name is also the one that should worry you least.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;GNSS&lt;/strong&gt;, the umbrella term covering American GPS, Galileo, GLONASS and BeiDou, works by listening. Satellites continuously broadcast timestamped signals, the receiver picks up several of them and computes its position from the differences in propagation time. Typical accuracy in the open: three to five metres, often several tens of metres in a city, where building façades reflect the signals.&lt;/p&gt;
&lt;p&gt;The decisive point is that this calculation is &lt;strong&gt;passive&lt;/strong&gt;. The phone transmits nothing towards the satellites, and no satellite operator knows you exist. If GNSS were the only thing in play, turning off GPS would be enough.&lt;/p&gt;
&lt;p&gt;There is a caveat, however. To speed up the first fix, phones use &lt;strong&gt;A-GPS&lt;/strong&gt;: they download satellite ephemeris data from a server, over the &lt;a href=&#34;https://en.wikipedia.org/wiki/Assisted_GNSS&#34;&gt;SUPL&lt;/a&gt; protocol. To receive the right data, the phone sends that server the identifier of the network cell it is attached to. Pure GNSS does not betray you, but the accelerator bolted onto it does.&lt;/p&gt;
&lt;h2 id=&#34;the-mobile-network-what-the-operator-knows-by-design&#34;&gt;The mobile network: what the operator knows by design&lt;/h2&gt;
&lt;p&gt;For a call to reach you, the network has to know roughly where you are. This is not an option you can enable, it is the precondition for the service existing at all. Your phone announces itself continuously to the nearest tower, and that registration leaves a record on the operator&amp;rsquo;s side. No installed app, no permission granted: an active SIM card is enough.&lt;/p&gt;
&lt;p&gt;Accuracy depends on the method:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Cell ID alone&lt;/strong&gt;: from 200 metres in a dense urban area to more than 30 kilometres in the countryside, where a single tower covers a very wide radius.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Enhanced Cell ID&lt;/strong&gt;, which adds the antenna sector (most sites are split into three 120-degree sectors) and signal strength: from 100 metres to a few kilometres.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Timing advance&lt;/strong&gt;, which measures the round-trip delay between phone and tower: on the order of 550 metres on GSM, around 78 metres on LTE.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Multilateration&lt;/strong&gt; across three or more towers: 50 to 300 metres in urban LTE.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;5G&lt;/strong&gt; changes the scale for two cumulative reasons. Density first: 5G cells cover much shorter radii, so simple attachment is already fine-grained information. Standardisation second: since Release 16, 3GPP has built in native positioning signals. Commercial targets aim for under 3 metres indoors and under 10 metres outdoors for 80% of devices, and &lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;Release 18&lt;/a&gt; goes down to centimetre level for certain industrial use cases.&lt;/p&gt;
&lt;p&gt;The infrastructure that connects you therefore becomes a positioning system of a quality comparable to GPS, without you having enabled anything. That data is retained under national rules and made available to authorities through procedures that vary widely. It is the same underlying debate as the one covered in our piece on &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;the jurisdiction applicable to hosted data&lt;/a&gt;: technical protection and legal protection do not overlap.&lt;/p&gt;
&lt;h2 id=&#34;wi-fi-a-map-of-the-world-made-of-hardware-addresses&#34;&gt;Wi-Fi: a map of the world made of hardware addresses&lt;/h2&gt;
&lt;p&gt;Every Wi-Fi access point continuously broadcasts a unique hardware identifier, the &lt;strong&gt;BSSID&lt;/strong&gt;. These identifiers are fixed and geographically stable: a home router stays in the same place for years.&lt;/p&gt;
&lt;p&gt;Apple, Google and a handful of specialised players maintain databases mapping each BSSID to coordinates, built by their own users&amp;rsquo; phones, which report the list of visible access points together with a GNSS fix. The operation is then reversed: a phone that can see four known access points no longer needs a single satellite. In a dense urban area, accuracy routinely reaches a few tens of metres, and drops below that indoors.&lt;/p&gt;
&lt;p&gt;Two properties make this mechanism hard to neutralise. First, the phone &lt;strong&gt;scans even when Wi-Fi appears to be off&lt;/strong&gt;: since Android 4.3, the system keeps a periodic scan running to improve location accuracy, independently of the quick-settings toggle. This behaviour depends on a separate setting, buried in the location services, that almost no user has ever opened.&lt;/p&gt;
&lt;p&gt;Second, the database can be queried from outside. That is the flaw Rye and Levin exploited: the positioning interfaces return not only the requested location but also that of nearby access points, which makes it possible to harvest the map without ever going near the places involved.&lt;/p&gt;
&lt;h2 id=&#34;bluetooth-and-ble-located-by-other-peoples-phones&#34;&gt;Bluetooth and BLE: located by other people&amp;rsquo;s phones&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth Low Energy&lt;/strong&gt; adds a proximity layer, with a range of a few metres to a few tens of metres, making it far more fine-grained than the mobile network. Two uses coexist. &lt;strong&gt;Commercial beacons&lt;/strong&gt;, deployed in shops, airports and shopping centres, broadcast an identifier that apps on the phone recognise, revealing which aisle you stopped in front of and for how long. And &lt;strong&gt;crowd-sourced location networks&lt;/strong&gt;, of which Apple&amp;rsquo;s Find My is the model, since copied by Google and Samsung.&lt;/p&gt;
&lt;p&gt;This second mechanism inverts an implicit assumption. The reference analysis, &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices?&lt;/a&gt;, published in the PETS 2021 proceedings by researchers at the Technical University of Darmstadt, reverse-engineered Apple&amp;rsquo;s protocol. An offline device emits a BLE signal, any nearby Apple device picks it up, attaches its own position and sends it encrypted to Apple&amp;rsquo;s servers, without the knowledge of either its owner or the owner of the device being located.&lt;/p&gt;
&lt;p&gt;The consequence is structural: a device with no SIM card, no Wi-Fi and no network connection of any kind remains locatable, as long as a stranger walks past with a phone in their pocket. Your isolation no longer depends on your settings, but on those of passers-by.&lt;/p&gt;
&lt;h2 id=&#34;inertial-sensors-locating-you-without-location-permission&#34;&gt;Inertial sensors: locating you without location permission&lt;/h2&gt;
&lt;p&gt;A phone contains an accelerometer, a gyroscope, a magnetometer and often a barometer. These sensors fall under a permission category separate from location: an app can read them without ever having asked where you are.&lt;/p&gt;
&lt;p&gt;Researchers at Princeton demonstrated this with &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe&lt;/a&gt;. Their app starts from the IP address and time zone for a coarse position, then reads the sensors: the accelerometer gives the acceleration and braking profile, the gyroscope the sequence of turns, the magnetometer the heading, the barometer the changes in altitude. A neural network identifies the mode of transport, walking, car, train or plane, and the route is matched against public mapping, elevation and weather data. The result: a trajectory of accuracy comparable to GPS, with no location permission. The method has limits, which the authors document, since it fails in areas without roads and degrades on uniform grid layouts, where many routes produce the same signature. It remains the demonstration that a denied permission is not a closed door.&lt;/p&gt;
&lt;p&gt;The barometer additionally supplies the dimension GNSS handles poorly, the vertical one. US requirements for emergency calls mandate floor-level accuracy of plus or minus 3 metres for 80% of indoor calls. Knowing which floor someone is on is a different kind of knowledge from knowing which city block they are in.&lt;/p&gt;
&lt;h2 id=&#34;the-data-market-the-most-mundane-vector&#34;&gt;The data market: the most mundane vector&lt;/h2&gt;
&lt;p&gt;The mechanisms above describe how a position is computed. What remains is where it goes, and that is where most of the everyday risk lies.&lt;/p&gt;
&lt;p&gt;Thousands of apps integrate &lt;strong&gt;advertising SDKs&lt;/strong&gt;, third-party software components a developer adds to monetise their work or measure their audience. These components inherit the host app&amp;rsquo;s permissions: a weather app that legitimately needs your location passes it to companies whose names you have never read. To this are added &lt;strong&gt;advertising bid streams&lt;/strong&gt;, where your approximate position is broadcast to dozens of potential buyers every time a banner is displayed, including to those who buy nothing and simply listen.&lt;/p&gt;
&lt;p&gt;This raw material feeds an industry. The Electronic Frontier Foundation documented the case of &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Fog Data Science&lt;/a&gt;, which claimed billions of data points on more than 250 million devices, sold to local US police forces. Brian Krebs described &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;Locate X&lt;/a&gt;, a product that lets you draw a polygon on a map and view the history of devices that entered and left that area.&lt;/p&gt;
&lt;p&gt;This vector requires no technical feat, only that somebody is willing to pay. The price is modest.&lt;/p&gt;
&lt;h2 id=&#34;imsi-catchers-active-location&#34;&gt;IMSI catchers: active location&lt;/h2&gt;
&lt;p&gt;The mechanisms described so far exploit normal operation. There is also active location, carried out by a third party intervening on the network.&lt;/p&gt;
&lt;p&gt;An &lt;strong&gt;IMSI catcher&lt;/strong&gt;, or cell-site simulator, is a piece of equipment that impersonates a legitimate tower. Phones within range attach to it, revealing their subscriber identifier and their presence within a limited perimeter.&lt;/p&gt;
&lt;p&gt;5G was supposed to close that door by replacing the permanent cleartext identifier with an encrypted one, the SUCI. The closure is partial. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkage attacks that make it possible to re-correlate sessions despite the encryption. More importantly, the protection collapses entirely if the attacker forces the device to fall back to an earlier generation, 2G in particular, whose authentication is one-way. A 5G phone remains vulnerable to an attack designed for a 1990s network, because it still agrees to go down there.&lt;/p&gt;
&lt;h2 id=&#34;countermeasures-and-how-effective-they-really-are&#34;&gt;Countermeasures, and how effective they really are&lt;/h2&gt;
&lt;p&gt;Every measure below does something. None of them does everything, and the gap between what they do and what people credit them with is what produces bad decisions.&lt;/p&gt;
&lt;h3 id=&#34;airplane-mode&#34;&gt;Airplane mode&lt;/h3&gt;
&lt;p&gt;Airplane mode cuts transmission from the cellular modem, Wi-Fi and Bluetooth. That is real, and it is the best result available for such little effort.&lt;/p&gt;
&lt;p&gt;What it does not do: it does not stop the inertial sensors, it does not delete already cached positions, which will be sent on reconnection, and on most devices it allows Wi-Fi or Bluetooth to be switched back on separately without leaving the mode. Finally, it is a software state, not a power cut: its reliability depends on the integrity of the system enforcing it.&lt;/p&gt;
&lt;p&gt;An underrated detail: detaching from and re-attaching to the network are themselves timestamped events on the operator&amp;rsquo;s side. A phone that vanishes at 9 pm in one cell and reappears at 11 pm in another has produced information, not silence.&lt;/p&gt;
&lt;h3 id=&#34;mac-address-randomisation&#34;&gt;MAC address randomisation&lt;/h3&gt;
&lt;p&gt;Mobile systems today emit random MAC addresses when scanning, to prevent tracking from one place to another. The intent is good, the result incomplete. The reference work, including &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough&lt;/a&gt;, shows that the content of discovery frames is often enough to re-identify the device: the number of information elements, their values and their order form a fingerprint. Add to that sequence numbers, which are incremental and therefore chainable, and the timing signature specific to each model. Some studies report successfully tracking half of all devices for at least twenty minutes.&lt;/p&gt;
&lt;p&gt;Finally, a conceptual limit: randomisation only applies to the discovery phase. As soon as you connect to a network, the address used is stable for that network, by design, so that the connection works. The café you go to every morning recognises you.&lt;/p&gt;
&lt;h3 id=&#34;actually-turning-off-scanning&#34;&gt;Actually turning off scanning&lt;/h3&gt;
&lt;p&gt;This is the most cost-effective and most overlooked setting. On Android, Wi-Fi scanning and Bluetooth scanning are two separate options, located in the location services, independent of the quick-settings toggles. As long as they are active, turning Wi-Fi off from the panel is not enough: the scanning continues.&lt;/p&gt;
&lt;p&gt;Disabling them removes an entire layer of collection, at no cost other than a slightly slower first position fix. For most readers, this is the best ratio between effort spent and result obtained.&lt;/p&gt;
&lt;h3 id=&#34;app-permissions&#34;&gt;App permissions&lt;/h3&gt;
&lt;p&gt;Revoking location permission from apps that manifestly do not need it remains useful, and recent systems offer three gradations: one-off authorisation, authorisation limited to active use, and &lt;strong&gt;approximate location&lt;/strong&gt;, which only transmits an area on the order of a kilometre.&lt;/p&gt;
&lt;p&gt;This does not, however, protect against SDKs hosted inside an app that has a legitimate reason to access your location, nor against inertial sensors, nor against the network layers, which go through no permission at all.&lt;/p&gt;
&lt;h3 id=&#34;what-a-vpn-does-not-protect&#34;&gt;What a VPN does not protect&lt;/h3&gt;
&lt;p&gt;A point worth clarifying, because the opposite belief is very widespread: &lt;strong&gt;a VPN does not hide your location&lt;/strong&gt;. It hides your public IP address, so it falsifies IP-based geolocation, which is in any case the crudest mechanism on this list.&lt;/p&gt;
&lt;p&gt;A VPN touches neither the GNSS receiver, nor Wi-Fi scanning, nor Bluetooth, nor the sensors. It changes nothing about what your operator knows, since the encrypted tunnel travels through its towers and cellular attachment remains visible to it. It does not stop an app holding location permission from transmitting exact coordinates inside the tunnel. A VPN protects the content and destination of your communications on an untrusted network, and that is already a lot. Location is not within its scope.&lt;/p&gt;
&lt;h3 id=&#34;physical-limits&#34;&gt;Physical limits&lt;/h3&gt;
&lt;p&gt;A Faraday pouch works in the literal sense: it blocks transmission and reception. So does removing the battery, where that is still possible. A dedicated device, or simply leaving your phone elsewhere, remains the most robust measure.&lt;/p&gt;
&lt;p&gt;These solutions share a flaw that has to be faced head-on: they produce an anomaly. A phone that goes quiet for two hours every Tuesday evening is saying something. Against an adversary who analyses patterns rather than instantaneous positions, absence is data.&lt;/p&gt;
&lt;h3 id=&#34;three-adversaries-three-strategies&#34;&gt;Three adversaries, three strategies&lt;/h3&gt;
&lt;p&gt;This is the most important distinction in this article, and the one you read least often.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against an advertiser or a data broker&lt;/strong&gt;, the fight is winnable. Permission discipline, disabling scanning, a system without proprietary location services, resetting the advertising identifier: together these sharply reduce the volume collected. This adversary is after cheap volume, not your particular case.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against your operator&lt;/strong&gt;, no configuration is enough. Cellular location is the precondition for the service. The only real variables are legal, what the law permits to be retained and disclosed, and material: which device, which SIM card, in whose name, switched on where.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Against a targeted state adversary&lt;/strong&gt;, the reasoning changes again, since it combines legal access to operator data, active location via cell-site simulator, requisitions to platforms and, where applicable, compromise of the device itself. Software countermeasures reduce the surface, but the realistic goal is not disappearance: it is knowing precisely what remains exposed.&lt;/p&gt;
&lt;h2 id=&#34;the-arpokratos-approach&#34;&gt;The ArpokratOS approach&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; answers this landscape with a choice that follows from the distinction above: what needs to be neutralised is neutralised at system level, not in a menu.&lt;/p&gt;
&lt;p&gt;On &lt;strong&gt;GNSS&lt;/strong&gt;, the hardware driver is removed. The device behaves as if the chip did not exist, both for applications and for the system itself. The difference from a settings toggle is not cosmetic. A toggle is a policy: it is enforced by a layer that can be bypassed by a sufficiently privileged component, re-enabled by an update, or ignored by a compromised system. Removing the code path removes the question, since there is no longer anything to enable.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Bluetooth&lt;/strong&gt; is handled at the Core level, on the same logic. Bluetooth switched off in the settings in practice leaves the software stack alive on many devices, to feed proximity services and crowd-sourced location networks. Absent at system level, it cannot talk to a shop beacon, take part in a Find My-style network, or serve as a zero-interaction attack surface.&lt;/p&gt;
&lt;p&gt;It has to be said plainly what this does not do. &lt;strong&gt;ArpokratOS does not make a phone undetectable.&lt;/strong&gt; As long as a SIM card is active, the operator knows the cell you are attached to, and no operating system changes that, not even with all traffic routed over Tor. Routing protects the content and the destination, not the radio geometry. Anyone promising invisibility is selling a story.&lt;/p&gt;
&lt;p&gt;What such an architecture provides is more modest: the removal of the application and proximity layers, through which the vast majority of real-world collection passes, and an explicit threat model for what remains. It is the same reasoning applied to choosing a desktop system, detailed in our &lt;a href=&#34;https://arpokrat.com/blog/os-comparison-security-privacy-windows-macos-linux-qubes/&#34;&gt;operating system comparison&lt;/a&gt;: the useful question is not whether a tool protects, but what it protects against and at what price.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;This article does not provide a method for disappearing. That method does not exist, and texts claiming otherwise mostly produce false confidence, which is more dangerous than no protection at all because it makes people take risks.&lt;/p&gt;
&lt;p&gt;The aim was to replace a binary question, am I locatable or not, with a useful one: by whom, with what accuracy, at what cost to them, and does it matter to me. The answer differs for a journalist protecting a source, an executive travelling in a sensitive jurisdiction, a lawyer whose appointments reveal a strategy, or a private individual annoyed that an advertiser knows their habits.&lt;/p&gt;
&lt;p&gt;What deserves attention, in fact, is not the performance of each of these mechanisms taken in isolation, but the fact that they overlap. A position accurate to fifty metres is not very interesting. A position accurate to fifty metres, every fifteen minutes, for two years, draws a home, a workplace, a religion, a health condition, an affair, a source. Location data is the metadata that makes all the others legible, and that is why it is worth so much.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Erik Rye, Dave Levin, &lt;a href=&#34;https://www.cs.umd.edu/~dml/papers/wifi-surveillance-sp24.pdf&#34;&gt;Surveilling the Masses with Wi-Fi-Based Positioning Systems&lt;/a&gt;, IEEE Symposium on Security and Privacy, 2024&lt;/li&gt;
&lt;li&gt;Alexander Heinrich et al., &lt;a href=&#34;https://petsymposium.org/popets/2021/popets-2021-0045.php&#34;&gt;Who Can Find My Devices? Security and Privacy of Apple&amp;rsquo;s Crowd-Sourced Bluetooth Location Tracking System&lt;/a&gt;, PoPETs, 2021&lt;/li&gt;
&lt;li&gt;Arsalan Mosenia et al., &lt;a href=&#34;https://arxiv.org/pdf/1802.01468&#34;&gt;PinMe: Tracking a Smartphone User around the World&lt;/a&gt;, IEEE Transactions on Multi-Scale Computing Systems&lt;/li&gt;
&lt;li&gt;Mathy Vanhoef et al., &lt;a href=&#34;https://papers.mathyvanhoef.com/asiaccs2016.pdf&#34;&gt;Why MAC Address Randomization is not Enough: An Analysis of Wi-Fi Network Discovery Mechanisms&lt;/a&gt;, AsiaCCS, 2016&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://arxiv.org/pdf/2401.17594&#34;&gt;5G NR Positioning Enhancements in 3GPP Release-18&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/deeplinks/2022/08/inside-fog-data-science-secretive-company-selling-mass-surveillance-local-police&#34;&gt;Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police&lt;/a&gt;, 2022&lt;/li&gt;
&lt;li&gt;Krebs on Security, &lt;a href=&#34;https://krebsonsecurity.com/2024/10/the-global-surveillance-free-for-all-in-mobile-ad-data/&#34;&gt;The Global Surveillance Free-for-All in Mobile Ad Data&lt;/a&gt;, 2024&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://ssd.eff.org/module/mobile-phones-location-tracking&#34;&gt;Mobile Phones: Location Tracking&lt;/a&gt;, Surveillance Self-Defense&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
  </channel>
</rss>