Court papers indicate text messages from HMRC's 60886 number could snoop on Brit taxpayers' locations
- Reference: 1643284768
- News link: https://www.theregister.co.uk/2022/01/27/hmrc_ss7_hlr_lookups/
- Source link:
Her Majesty's Revenue and Customs had the potential to use SS7 to silently request that tax debtors' mobile phones give up location data over the past six years, according to papers filed in an obscure court case about a contract dispute.
SMS provider MMGRP Ltd, operators of HMRC's former 60886 text messaging service, filed a suit against the tax agency after losing the contract to send text messages on its behalf. Court documents obtained by The Register show that the secret surveillance capability was baked into otherwise mundane bulk SMS sending carried out by MMGRP Ltd.
[1]
The tax collection agency, which has the power to [2]retrospectively change laws , had been using SMS reminder messages as an enforcement tool.
[3]
[4]
We asked HMRC for comment, posing a series of questions including how long had it used HLR look-up techniques against taxpayers; did HMRC obtain necessary warrants to carry out HLR lookups and, if so, under what legislation and from which courts; how many times it had used this technique; under what circumstances it was deployed; and is the capability present in a contract with its new supplier.
In response, the Brit tax collection agency admitted to using home location register (HLR) checks, although it maintained: "HLR checks were used solely to check if a customer's phone number was still active before sending a SMS message."
What the papers say
The since-settled lawsuit over an alleged breach of public procurement laws was filed by the company which operated HMRC's former 60886 SMS sender number and brought the HMRC surveillance powers to light.
MMGRP sued the HMRC last summer alleging breach of [5]public contract regulations after the tax authority awarded a multi-million pound deal to one of MMGRP's rivals in March.
[6]
Particulars of claim filed in the High Court in July last year by the SMS provider said:
As part of the Existing Services, the Claimant also provides home location register ("HLR") services (the "HLR Services"). These allow for the screening of bad or dead numbers (i.e. ones which are incorrect or no longer used) and thus their exclusion from any transmissions.
The document also said the agency had asked for the capability of doing more than merely verifying that tax demands sent by text had been delivered, quoting the contract between the pair as requiring, under "Existing Services":
Location and service provider information associated with the recipient. This could be as little as the network provider of recipient (which would save us a stage in our investigative processes thanks to numbers being ported between networks). It could go as far as the location details of the recipient handset when the SMS delivery route is queried via the C7 or SS7 signalling protocol. The provision of SMS services will not be over the PSN.
In its defence document filed a month later, on 19 August last year, HMRC's legal team admitted that part of MMGRP's case, meaning they did not contest its truth.
The Reg wonders why HMRC did not dispute this in the legal papers, and why the capability was baked into the contract if the tax collector was not going to use it.
Describing the contract outlined in the lawsuit as "slightly odd", Professor Alan Woodward, the University of Surrey-based compsci expert, told The Register : "I can see how this might be required if HMRC must later prove that a letter was received and read in a specific jurisdiction. Someone they are taking to court might claim they never received it or that it had no effect where they were when they were served with some form of formal notice."
He added: "As with other powers, provided there is suitable legislation, oversight and transparency then it may have a place in chasing some of the tax evaders."
[7]
GSM [8]security expert Tobias Engel told The Register this location-finding service looked like a natural bolt-on to the SMS systems MMGRP was providing to HMRC, characterising it as a fairly routine service feature.
[9]You might want to consider the cost of not upgrading legacy tech, UK's Department for Work and Pensions told
[10]HMRC tool for measuring IR35 status is so great, employers are ditching it in their droves
[11]UK taxman breathes life into old relationship as Capgemini handed £51m deal extension
[12]Hauliers report problems with post-Brexit customs system but HMRC insists it is 'online and working as planned'
"A few years back this was still very easy," said Engel, "since getting SMS routing information (the infamous so-called 'HLR lookup') already revealed a coarse location of the phone, and that same routing information could then be used to query the network for a more precise location."
How does it work?
Signalling System Number 7 (SS7) is the signalling protocol used by mobile phone networks to route Short Messaging Service (SMS) messages.
Using SS7 to detect where messages were received is relatively simple. In essence SS7 tells mobile networks where to send messages based on which mast a particular phone number was last connected to. A register of those connections is kept and can be queried.
Thus the technique is called Home Location Register (HLR) lookup. Commands exist for querying a network's HLR for a particular Mobile Station Integrated Services Digital Network number (MSISDN, or "phone number" to you and I). If you know the location of a mast where that MSISDN was last connected, you've got a radius of where the phone could be located. Cross-referencing that radius with multiple masts helps triangulate a specific phone, and thus its user.
This is the data used by police forces and others to locate criminals by tracking their mobile phones.
Bitter contract dispute
MMGRP's lawsuit came about after HMRC had repeatedly extended the contract following its original expiry date of July 2020.
HMRC leaned heavily on the SMS provider for those short-duration extensions, raising the spectre of "reputational damage to HMRC, to outer [sic] Government Departments who utilise the service and ultimately to [MMG] as a provider" if the company didn't agree.
For its part, MMGRP admitted that director Daniel Layton, "in the heat of the moment" threatened to shut off HMRC's SMS services altogether when the tax authority told him it was awarding the contract to another company instead of renewing at the end of its existing term in early 2021.
"Mr Layton rapidly withdrew that threat," the company's particulars of claim added.
Ultimately the service was awarded to rival business IMImobile after lots of short-term extensions with MMGRP.
MMRGP owns the old HMRC 60886 SMS shortcode, which is why taxpayers are no longer advised to look out for messages from that number.
The court case has since been settled. HMRC does not say on its website that it makes use of HLR technology to identify taxpayers' locations - but does list [13]a range of ways in which it might try to contact them. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YfLPu5w@DRgK1kqjndhM@AAAAMQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.pinsentmasons.com/out-law/analysis/hmrcs-retrospective-change-vat-contract-terminations-practical-options-businesses
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfLPu5w@DRgK1kqjndhM@AAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YfLPu5w@DRgK1kqjndhM@AAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.gov.uk/guidance/public-sector-procurement-policy#public-contracts-regulations-2015
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YfLPu5w@DRgK1kqjndhM@AAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YfLPu5w@DRgK1kqjndhM@AAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2014/12/26/ss7_attacks/
[9] https://www.theregister.com/2022/01/21/dwp_1bn_pension_shortfall/
[10] https://www.theregister.com/2022/01/13/cest_tool_popularity/
[11] https://www.theregister.com/2022/01/11/hmrc_capgemini/
[12] https://www.theregister.com/2022/01/05/hauliers_gvms_problems/
[13] https://www.gov.uk/guidance/check-if-a-text-message-youve-received-from-hmrc-is-genuine
[14] https://whitepapers.theregister.com/
[1]Makes me think of this .
[1] https://www.youtube.com/watch?v=4GFwH8GXNTU
The inevitables: death and taxes. Death does not provide adequate cover for taxes. And now we know you are kept on a short leash for the taxes too.
Makes me wonder,... when will it become illegal not to own or carry a mobile phone?
That's actually a good question.
Especially since one can argue that a desktop PC, laptop or tablet can have much the same functionality, but without the convenience of being frisked in the street.
Oh man am I gonna be a pain in the Surveillance State' ass when I'm retired.
Oh man am I gonna be a pain in the Surveillance State' ass when I'm retired.
You're gonna go all Brill (Edward Lyle)? :-)
Most government departments, banks and insurance companies already assume that everyone is connected so a legal requirement may not be that far off.
Less contentious than chipping the population although suspect there may be some who have considered it.
I believe you are behind the times as most people have happily accepted the Covid vaccine which contains a chip readable by satellites and aliens. I know this is true because Margret, expert in global pandemics and Hair and Beauty Therapist on Facebook, said so.
I thought they were chips to enable 5G! Have I been lied to?
You'll need to get your booster dose for the antennas to grow to full lenght, otherwise you'll only get signal in urban areas.
my company set up 2FA for all our logins that used your mobile number. I have a friend who has no mobile phone, it was an interesting conundrum they hadn't thought of
I expect that there was a hidden option to select a landline, and get a VM instead of a text
My dad had to fill out a passenger form recently, to fly back from Norway.
Being my dad, he didn't bother reading the instructions, so when it asked him for a contact number, he put in his home landline number, which of course meant he couldn't receive the confirmation SMS.
This got worse, because there was no way to change the phone number, and he couldn't create a new registration using the same email address.
I got him to use my email address and forwarded it to my mum so they could get it done, but maybe I should have just have left him stuck in Norway ;)
(Mind you, perhaps the page should have checked that the phone number started 07, and rejected or queried the number otherwise)
Why would they make it illegal for citizens _not_ to do something like carry a tracking device or an ID card, when they can instead force regulated entities to make your life difficult if you don't do it?
That way 'all this new-fangled tech' gets the blame, instead of explicit state regulations which people might hold the state accountable for.
For example, PSD5 will make it impossible to use a card online without having your tracking device with you (and of course if you make a card payment in person, then they know your location because you're y'know - in person).
Any anonymising forwarder services out there?
What happens if the end user is connected via WiFi calling? - Three / O2 etc offer SMS and calls in and out bound over WiFi ......
Is anyone virtualising mobiles into a voip / wifi concentrator that receives SMS/calls and routes them down tunnels to the remote handsets?
Would all the crims be visible because their SS7 locations were a mast outside an industrial unit and a terraced house in Moss Side?
Asking for a friend .....
WTAF
The operation of the service as described seems like a breach of GDPR to me.
At no time has my network provider sought my consent to provide my location to various unsavoury third parties. (The rozzers/emergency services are fine imo)
Telco Commentards - just how widely accessible/queryable is the SS7 protocol?
Feels like a class action is in the offing.
Re: WTAF
Do you remember all those things you clicked OK on when you got your shiny new phone? It was probably in there.
Re: WTAF
Telco Commentards - just how widely accessible/queryable is the SS7 protocol?
Kinda depends. The non-associated (not in voice-band) signaling used for SMS and HLR for example does require access to a Telco network. GIven fair few, some high profile, SS7 hacks in in last 10 years or so things have improved somewhat and its not quite as bad as it used to be. Still, all it takes is one telco to have a weak point.
Re: WTAF
You can report that and let us know how that goes.
hint (likely answer from regulator): if you are not happy, you can change your network provider
Re: WTAF
Law enforcement is an exemption from the GDPR though.
Re: WTAF
I'm not sure why you got those downvotes, you're entirely correct. [1]From the ICO :
The UK GDPR does not prevent you sharing personal data with law enforcement authorities (known under data protection law as “competent authorities”) who are discharging their statutory law enforcement functions. The UK GDPR and the DPA 2018 allow for this type of data sharing where it is necessary and proportionate.
Of course, we might think that HMRC having the ability to get location data from people's phones is not necessary or proportionate, but as the law stands, they are on the [2]list of "Competent authorities" [sic] (see line 21).
[1] https://ico.org.uk/for-organisations/data-sharing-information-hub/sharing-personal-data-with-law-enforcement-authorities/
[2] https://www.legislation.gov.uk/ukpga/2018/12/schedule/7
Funny...
...how most seem to think that people should be made to pay their taxes..... until HMRC actually does something about collecting them from those actively trying to avoid paying.
Re: Funny...
Yes, the delight of knowing which extradition treaty to bang the villain to rights had me agreeing.
Till I thought about other government departments using the same idea to locate folks who have very good reason to not want to be located whilst they exercise the civil rights (or what's left of them). Like No.10 checking up some of Boris's own MPs who might be a little too near Melton Mowbray at this time.
Re: Funny...
Not me. All taxation is theft!
Re: Funny...
Presumably you've never (for example) used the NHS, and have paid them back any costs you incurred when you were born?
Or are you just fine in reaping the benefits of taxation whilst not wanting to contribute?
Alternate headline
Cattle offended by farmers use of electronic tracking devices.
Bonus:
Want to see who's tracking device was at the scene of a crime in the last 6 years, no problem.
"mobile phones give up location data over the past six years,"
"The Reg wonders why HMRC did not dispute this in the legal papers"
Do you... do you really...
Low hanging fruit
It's always about chasing a commoner hiding a few grand (in the tax man eyes) from the greedy tax man paws.
They can't afford legal defense, so often they just pay up, cry and forget.
Meanwhile when real tax evaders come in, they get red carpet treatment.
Re: Low hanging fruit
Bet they didn't ring the CFO of Amazon UK's mobile phone and request location data ... :-)
The Real Issue
It's one thing if the police can locate people through data that is used internally by the telephone system.
It's quite another thing, though if anyone - not just HM Revenue, but any private business - that uses a service, instead of a cell phone, to send text messages to people can request that their locations be given to it. The telephone service providers may have that information internally, as a result of how cellular phone calls are routed, but they should not be releasing it to anyone except the police.
Actually, location info should, of course, be provided in one other case in addition to use in assisting police investigations. It should be provided when emergency calls are made for police, fire, or ambulance services, such as when calling 911 in North America, or, I believe, 999 in the UK.
Be careful firing someone who knows where the bodies are buried. (Also explains why Cummings didn't get fired when his Barnard Castle excursion came to light.)