Reason.com - Free Minds and Free Markets
Reason logo Reason logo
  • Latest
  • Magazine
    • Current Issue
    • Archives
    • Subscribe
    • Crossword
  • Video
  • Podcasts
    • All Shows
    • The Reason Roundtable
    • The Reason Interview With Nick Gillespie
    • The Soho Forum Debates
    • Just Asking Questions
    • The Best of Reason Magazine
    • Why We Can't Have Nice Things
  • Volokh
  • Newsletters
  • Donate
    • Donate Online
    • Donate Crypto
    • Ways To Give To Reason Foundation
    • Torchbearer Society
    • Planned Giving
  • Subscribe
    • Reason Plus Subscription
    • Print Subscription
    • Gift Subscriptions
    • Subscriber Support

Login Form

Create new account
Forgot password

Surveillance

Smartphone Experiment Shows How Your Metadata Tells Your Story

Scott Shackford | 9.15.2014 10:50 AM

Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests
Large image on homepages | Highways Agency / photo on flickr
(Highways Agency / photo on flickr)
Somebody tell Siri that snitches get stitches.
Credit: Highways Agency / photo on flickr

For one short week, a Dutch volunteer named Ton Siedsma with the digital rights group Bits of Freedom agreed to allow researchers to have full access to all his smartphone metadata. This is the information the National Security Agency (NSA) and other governments have been collecting from its own citizens while insisting the information did not violate our privacy.

Few actually believe the government's arguments, but how much can somebody figure out just from smartphone data? Thus, the experiment with Siedsma. It turns out, as has been growing increasingly clear, you can figure out a lot. According to an article subsequently published in Dutch media, researchers (from a university and a separate security firm) gathered 15,000 records in a week, complete with timestamps. Each time he did pretty much anything on the cell phone they were able to determine physically where he was. And they were able to figure out a lot about both his personal and professional life:

This is what we were able to find out from just one week of metadata from Ton Siedsma's life. Ton is a recent graduate in his early twenties. He receives e-mails about student housing and part-time jobs, which can be concluded from the subject lines and the senders. He works long hours, in part because of his lengthy train commute. He often doesn't get home until eight o'clock in the evening. Once home, he continues to work until late.

His girlfriend's name is Merel. It cannot be said for sure whether the two live together. They send each other an average of a hundred WhatsApp messages a day, mostly when Ton is away from home. Before he gets on the train at Amsterdam Central Station, Merel gives him a call. Ton has a sister named Annemieke. She is still a student: one of her e-mails is about her thesis, judging by the subject line.

They were able to determine what kind of silly viral videos Siedsma had been watching and what sort of companies were sending him email newsletters offering deals (apparently some folks don't automatically opt out of those). From the data they were able to determine that Siedsma worked as a lawyer for Bits of Freedom. They were able to make a fairly good estimate of what sort of issues he handles for the organization and what he does for the Bits of Freedom website.

In response to the "So what?" crowd there's more to be concerned about. Because Bits of Freedom is a politically involved organization, access to Siedsma's metadata provides a window into what Siedsma and his co-workers are doing that would be of interest to those in government who may see the group as adversaries. Researchers discovered an active e-mail thread with the subject title "Van Delden must go," referring to the head of the chairman of a Dutch intelligence supervisory body. They can see which members of parliament the Siedsma has contacted to discuss issues related to international trade agreements. They can see that he is likely a supporter of the Dutch "green left" party on the basis of him receiving e-mails from them at a private address, not as part of his political work. They could see which journalists he has been corresponding with via e-mail. All of this information has all sorts of potential to be abused politically.

And, they figured out how to hack his other accounts to get even more information about him:

The analysts from the Belgian iMinds compared Ton's data with a file containing leaked passwords. In early November, Adobe (the company behind the Acrobat PDF reader, Photoshop and Flash Player) announced that a file containing 150 million user names and passwords had been hacked. While the passwords were encrypted, the password hints were not. The analysts could see that some users had the same password as Ton, and their password hints were known to be 'punk metal', 'astrolux' and 'another day in paradise'. 'This quickly led us to Ton Siedsma's favourite band, Strung Out, and the password "strungout",' the analysts write.

With this password, they were able to access Ton's Twitter, Google and Amazon accounts. The analysts provided a screenshot of the direct messages on Twitter which are normally protected, meaning that they could see with whom Ton communicated in confidence. They also showed a few settings of his Google account. And they could order items using Ton's Amazon account – something which they didn't actually do. The analysts simply wanted to show how easy it is to access highly sensitive data with just a little information.

Read the Dutch report here.

(Hat tip to TechDirt)

Start your day with Reason. Get a daily brief of the most important stories and trends every weekday morning when you subscribe to Reason Roundup.

This field is for validation purposes and should be left unchanged.

NEXT: For $129, You Too Can Look Like a Victim of State Violence

Scott Shackford is a policy research editor at Reason Foundation.

SurveillanceCellphonesPrivacyCybersecurityInternetNSA
Share on FacebookShare on XShare on RedditShare by emailPrint friendly versionCopy page URL
Media Contact & Reprint Requests

Hide Comments (45)

Editor's Note: As of February 29, 2024, commenting privileges on reason.com posts are limited to Reason Plus subscribers. Past commenters are grandfathered in for a temporary period. Subscribe here to preserve your ability to comment. Your Reason Plus subscription also gives you an ad-free version of reason.com, along with full access to the digital edition and archives of Reason magazine. We request that comments be civil and on-topic. We do not moderate or assume any responsibility for comments, which are owned by the readers who post them. Comments do not represent the views of reason.com or Reason Foundation. We reserve the right to delete any comment and ban commenters for any reason at any time. Comments may only be edited within 5 minutes of posting. Report abuses.

  1. Mongo   11 years ago

    I hope you get ass cancer of the mouth, Shackford.

    1. Poppa Kilo   11 years ago

      You mad, bro?

    2. Francisco d'Anconia   11 years ago

      What's that all about?

      1. Mongo   11 years ago

        It's those streaming ads that are starting to show up regularly on this site.

        No volume control (they simply blast away at FULL volume). I know I can use my computer's volume control but vicious ad homs are quicker.

        No way to stop the video.

        Those streaming ads somehow fuck up the keyboard -- missing chunks of letters (see my previous comments in another post).
        They're worse than those awful Rotten Toenail ads from awhile back.

        Shackford gets paid by Reason. Reason gets paid by ads. My fury extended to the next article posted by Reason.

        1. Mongo   11 years ago

          P.S. I use my work computer so I don't have any ad-block capabilities.

          1. Mongo   11 years ago

            There I fuckng goes again!

            1. Scott S.   11 years ago

              Once I get out of ass-cancer-of-the-mouth chemotherapy, I'll alert the web team about the autoplay ads. I'm not seeing any myself.

              1. Mongo   11 years ago

                Thanks, SS -- nothing personal.

                1. Pl?ya Manhattan.   11 years ago

                  Oh Mongo, you're such a gentleman.

                  1. Francisco d'Anconia   11 years ago

                    Mongo only pawn...

        2. tarran   11 years ago

          Install ad block.

        3. Francisco d'Anconia   11 years ago

          AdBlock

          1. Francisco d'Anconia   11 years ago

            Oops, I didn't read down.

            1. Mongo   11 years ago

              Those steanming ads are starting to keep me awayfrom this site, Reason.

              Do ou see how those asfck up m keyboar aabilities?

              1. Francisco d'Anconia   11 years ago

                Did you email to complain?

                1. Mongo   11 years ago

                  Does anyone else experience this problem? Why would streaming ads mess with the keyboard??

                  1. Kaptious Kristen   11 years ago

                    I don't see any ads, period. Ad Block.

                  2. Francisco d'Anconia   11 years ago

                    Fist (I think) was bitching about Ads the other night.

                  3. DesigNate   11 years ago

                    I was getting the fucking verizon one ALL THE TIME.

                    It got so bad I just went ahead and put adblock for firefox on my computer.

      2. Las Vegas Window Wash   11 years ago

        Thats pretty intense.

  2. antisocial-ist   11 years ago

    So the NSA really really needs all of this data on its own citizens, but can't prevent the Boston bombings, and I heard this morning that they're basically clueless about ISIS. Why are they keeping up this charade?

    1. Francisco d'Anconia   11 years ago

      They gotta protect their phony baloney jobs?

      Oh, and expand their power.

      1. Florida Man   11 years ago

        Hurumph! Hurumph!

    2. thom   11 years ago

      Maybe because, as with every state security apparatus ever created, they understand their mission not as protecting people from outside harm, but as protecting the state from any threats, most of which are going to come from the millions of people who care considered under the control of the state.

    3. Las Vegas Accident Lawyer   11 years ago

      Yeah this is insane

  3. Kaptious Kristen   11 years ago

    A hundred texts a day?!?!?!?

    1. MegaloMonocle   11 years ago

      I tapped the brakes on that 100 texts a day thing, too.

      Assuming a 16 hour day, that's more than one every ten minutes on average.

      Get a fucking grip, already.

      [shakes cane, wanders off]

  4. The Sego Sago Kid   11 years ago

    'strungout' is an incredibly shitty password. If you have a password like that, you deserve what's coming to you.

    1. MegaloMonocle   11 years ago

      My rule of thumb is "no English" for passwords.

      I'm partial to Japanese and early Babylonian (Anglicized spelling, natch).

      1. Francisco d'Anconia   11 years ago

        Makes note.

        /NSA

      2. Invisible Finger   11 years ago

        I'd figure you for Latin.

      3. Invisible Finger   11 years ago

        His rule was probably "no Dutch".

        1. Curtisls87   11 years ago

          There are two things I can't stand, intolerance of other people, and the Dutch!

  5. xplorethings   11 years ago

    good article

    maha navratri 2014
    durga puja time table

  6. FreeMarketsWork   11 years ago

    Clearly, the only conversations that one can expect to be private anymore are whispered face-to-face chats in areas with a lot of background noise to obscure the words and physical obstructions to prevent surveillance camera operators from lip-reading.
    Welcome to the New World Order, Comrade, in the Land of the Manipulated and the Home of the Spied Upon.

  7. dainemark00   7 years ago

    If you are trying to catch your cheating spouse in the act, I strongly recommend you contact this awesome hacker that helped me monitor my husband's phone. I got virtually every information my hubby has been hiding over the months easily right in my own phone, the spy app diverted all his text messages, Whatsapp, multimedia sent through the phone, social networks on his phone, phone calls and deleted messages. He could not believe his eyes when he saw the evidence because he had no idea he was hacked.. Visit Dylan Cyber Company on his website w w w . procyberhelp . com , very affordable and reliable, thank me later
    Contact : P R O C Y B E R H E L P @ G M A I L . C O M or Whatsapp, +1 620 203 5003.

  8. dainemark00   7 years ago

    If you are trying to catch your cheating spouse in the act, I strongly recommend you contact this awesome hacker that helped me monitor my husband's phone. I got virtually every information my hubby has been hiding over the months easily right in my own phone, the spy app diverted all his text messages, Whatsapp, multimedia sent through the phone, social networks on his phone, phone calls and deleted messages. He could not believe his eyes when he saw the evidence because he had no idea he was hacked.. Visit Dylan Cyber Company on his website w w w . procyberhelp . com , very affordable and reliable, thank me later
    Contact : P R O C Y B E R H E L P @ G M A I L . C O M or Whatsapp, +1 620 203 5003.

  9. Florida Man   11 years ago

    Home by 8, I hardly call that working late.

  10. Florida Man   11 years ago

    You win this round Mr. "Reads the whole article" but I'll be back.
    /runs off cackling

  11. Francisco d'Anconia   11 years ago

    +1 Red Ryder

  12. Longtorso, Johnny   11 years ago

    +1 Winona Ryder

  13. gaoxiaen   11 years ago

    -one eyeball

  14. Florida Man   11 years ago

    I find Winona strangely attractive. My wife says I like damaged chicks at which point I stare blankly at here waiting for the irony to sink in.

  15. Florida Man   11 years ago

    Her not here

  16. Francisco d'Anconia   11 years ago

    Me 2.

Please log in to post comments

Mute this user?

  • Mute User
  • Cancel

Ban this user?

  • Ban User
  • Cancel

Un-ban this user?

  • Un-ban User
  • Cancel

Nuke this user?

  • Nuke User
  • Cancel

Un-nuke this user?

  • Un-nuke User
  • Cancel

Flag this comment?

  • Flag Comment
  • Cancel

Un-flag this comment?

  • Un-flag Comment
  • Cancel

Latest

How Palantir Is Expanding the Surveillance State

Elizabeth Nolan Brown | 6.2.2025 12:00 PM

The Gutting of the National Park Service

Liz Wolfe | 6.2.2025 9:30 AM

In Dangerous Times, Train for Self-Defense

J.D. Tuccille | 6.2.2025 7:00 AM

Welcoming Anti-Trump Liberals to the Free Trade Club

Katherine Mangu-Ward | From the July 2025 issue

Brickbat: Armed, Elderly, and Dangerous

Charles Oliver | 6.2.2025 4:00 AM

Recommended

  • About
  • Browse Topics
  • Events
  • Staff
  • Jobs
  • Donate
  • Advertise
  • Subscribe
  • Contact
  • Media
  • Shop
  • Amazon
Reason Facebook@reason on XReason InstagramReason TikTokReason YoutubeApple PodcastsReason on FlipboardReason RSS

© 2024 Reason Foundation | Accessibility | Privacy Policy | Terms Of Use

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

r

Do you care about free minds and free markets? Sign up to get the biggest stories from Reason in your inbox every afternoon.

This field is for validation purposes and should be left unchanged.

This modal will close in 10

Reason Plus

Special Offer!

  • Full digital edition access
  • No ads
  • Commenting privileges

Just $25 per year

Join Today!